A Systematic Review of Graph‐Based Representation Techniques for Cyber‐Attack Detection Across Application Domains

Ali Melih Kanca, İlker Türker · Concurrency and Computation Practice and Experience · 2025

ABSTRACT Cyber‐attack detection faces increasing challenges due to more advanced threats beyond traditional signature‐based methods. Machine learning and deep learning have become essential in enhancing network security. Graph representation techniques capture structural and relational patterns across various data sources such as network traffic, system logs, and malware behaviors. Graph‐based metrics and algorithms enable deeper analysis and more accurate classification of malicious activities. This study offers a systematic review of research articles published between 2019 and 2024 on graph‐based representation methods for detecting cyber‐attacks. Unlike previous reviews that classify studies by algorithm type or detection approach, this work groups them into four application domains: (i) general IDS/NIDS systems, (ii) botnet and DDoS detection, (iii) IoT‐related threats, and (iv) advanced threats including Android malware, APTs, and encrypted traffic. Each domain is analyzed using graph modeling techniques, feature extraction methods (manual vs. automated), learning algorithms, and detection effectiveness. The review also introduces a five‐stage framework outlining how graph‐based methods can be integrated into cyber‐attack detection: data acquisition, graph construction, feature extraction, detection/classification, and threat identification. This framework offers a structured view of methodological variety across different application areas. Results indicate that graph‐based approaches provide a powerful alternative to traditional techniques, enabling richer structural modeling in cybersecurity. Finally, the study presents a future research roadmap advocating for interpretable, graph‐driven solutions tailored to the evolving landscape of cyber threats.

Read the paper · More papers on PaperTik