ERFS: Efficient Feature Graph Representation for Intrusion Detection Based on Flow Semantic Association
Yiqing Luo, Mingshu He, Xiaojuan Wang · IEEE Transactions on Cognitive Communications and Networking · 2025
The detection of network threats remains a fundamental task in cyberspace defense. Graphs are capable of capturing rich structural information and retaining content information. They are widely applicable in the field of threat detection. However, existing graph-based threat detection methods are computationally complex and challenging to apply in real-world network scenarios, where topologies may be incomplete or invisible. To address this, we propose ERFS, an efficient feature graph representation method for intrusion detection based on flow semantic correlation. This method aims to enhance the feature representation of network behavior. The proposed method first constructs a semantic correlation graph to depict the inherent semantic relationships within and between network flows. This is followed by the use of a messaging network to update and learn the information of graph nodes. The updated nodes are then aggregated into flow-level semantic feature representations for node classification, thereby achieving threat detection. The key innovation of this approach lies in graph construction and learning. The semantic correlation graph is constructed based on contextual correlation features and does not rely on topological information. It addresses the existing dependency issue of traditional graph construction methods on network topology. On the other hand, it introduces a small-window learning mechanism and a global sharing mechanism for edge weights. These mechanisms enable graph learning within a small-window range while globally sharing representations of identical nodes and edge weight values. It also addresses challenges in current graph construction methods, such as high computational complexity and low efficiency. Furthermore, the evaluation results indicate that this method achieved classification accuracies of 99.99%, 98.81%, 100%, 97.87%, and 99.64% on five public datasets (CIC IDS2017, CIC DOS2017, CIC DDoS2019, USTC-TFC2016, and ISCX VPN-nonVPN), respectively. These results surpass those of existing advanced models. The code is available on:https://github.com/sixteen23333/ERFS.