TPE-NIDS: uses graph neural networks to detect malicious traffic
Yawen Zhang, Yuchen Zhang, Yue Wu, Cheng Li · 2022
At present, with the development of information technology, the means of attack are developing from a single attack to a multi-means combined attack, in which harm is much greater than a single attack, and it is more difficult to detect and control. Intrusion detection is the most common network security defense measure. Network intrusion detection system monitors network traffic in real time, provides dynamic protection, and greatly improves network security. We proposed an effective intrusion detection method based on a graph neural network. Specifically, a new edge embedding generation algorithm TPE-GraphSAGE is proposed to achieve feature aggregation and transformation on the original features to generate high-quality new features. Then the transformed data is used to train the graph edge classifier to establish the intrusion detection model TPE-NIDS. Finally, a comparative experiment is carried out on the UNSW-NB15 dataset to assess the performance of the model in binary classification and multi-classification respectively. The F1 score of our method is 96.82% for binary classification and 96.45% for multi-classification, which has great advantages in accuracy and detection efficiency.