Graph-Based Approaches to Detect Network Anomalies and to Predict Attack Spread
S Rithuh Subhakkrith, Y. Jagadish Kumar, R. Harish, B Vishnu Dheeraj, S. Sesha Vidhya · 2024
Real world applications of data structures is enormous. Queues, stacks, trees, and graphs are commonly applied and implemented across various fields. To improve the efficiency of such implementations, optimisation through the underlying data structure can be considered. Computer networks inherently are based on graphs with communicating systems as nodes and communication channels as edges. Information flows between the communicating systems through the communication channel. To detect suspicious connections and information flow, an optimal graph structure is implemented by modelling the information flow as edges, and retaining the communicating systems as nodes. Graph analytics is performed to capture graphical relationships, and the final graph structure is formed with the features of the information flow split into node features and edge features. Then this graph structure is passed to Graph Neural Networks (GNN) that captures hidden relationships of the graph, and transforms these graph features in such a way that basic Machine Learning models like k-Nearest Neighbors (KNN), Support Vector Classifier (SVC), and Random Forest can train themselves and model into better anomalous connection classifiers. Eleven baseline models are trained using the traditional way, and using GNN transformed embeddings, and their performances are observed. Testing shows that all models show an improvement in the evaluatory scores. Finally, a logic is provided to build an attack sequence graph to track the route in which the attack spreads among infected systems.