PPT-GNN: A Practical Pre-Trained Spatio-Temporal Graph Neural Network for Network Security

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Van Langendonck, Louis, Castell-Uroz, Ismael, Barlet-Ros, Pere
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909227841224704
author Van Langendonck, Louis
Castell-Uroz, Ismael
Barlet-Ros, Pere
author_facet Van Langendonck, Louis
Castell-Uroz, Ismael
Barlet-Ros, Pere
contents Recent works have demonstrated the potential of Graph Neural Networks (GNN) for network intrusion detection. Despite their advantages, a significant gap persists between real-world scenarios, where detection speed is critical, and existing proposals, which operate on large graphs representing several hours of traffic. This gap results in unrealistic operational conditions and impractical detection delays. Moreover, existing models do not generalize well across different networks, hampering their deployment in production environments. To address these issues, we introduce PPTGNN, a practical spatio-temporal GNN for intrusion detection. PPTGNN enables near real-time predictions, while better capturing the spatio-temporal dynamics of network attacks. PPTGNN employs self-supervised pre-training for improved performance and reduced dependency on labeled data. We evaluate PPTGNN on three public datasets and show that it significantly outperforms state-of-the-art models, such as E-ResGAT and E-GraphSAGE, with an average accuracy improvement of 10.38%. Finally, we show that a pre-trained PPTGNN can easily be fine-tuned to unseen networks with minimal labeled examples. This highlights the potential of PPTGNN as a general, large-scale pre-trained model that can effectively operate in diverse network environments.
format Preprint
id arxiv_https___arxiv_org_abs_2406_13365
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle PPT-GNN: A Practical Pre-Trained Spatio-Temporal Graph Neural Network for Network Security
Van Langendonck, Louis
Castell-Uroz, Ismael
Barlet-Ros, Pere
Machine Learning
Artificial Intelligence
Cryptography and Security
Recent works have demonstrated the potential of Graph Neural Networks (GNN) for network intrusion detection. Despite their advantages, a significant gap persists between real-world scenarios, where detection speed is critical, and existing proposals, which operate on large graphs representing several hours of traffic. This gap results in unrealistic operational conditions and impractical detection delays. Moreover, existing models do not generalize well across different networks, hampering their deployment in production environments. To address these issues, we introduce PPTGNN, a practical spatio-temporal GNN for intrusion detection. PPTGNN enables near real-time predictions, while better capturing the spatio-temporal dynamics of network attacks. PPTGNN employs self-supervised pre-training for improved performance and reduced dependency on labeled data. We evaluate PPTGNN on three public datasets and show that it significantly outperforms state-of-the-art models, such as E-ResGAT and E-GraphSAGE, with an average accuracy improvement of 10.38%. Finally, we show that a pre-trained PPTGNN can easily be fine-tuned to unseen networks with minimal labeled examples. This highlights the potential of PPTGNN as a general, large-scale pre-trained model that can effectively operate in diverse network environments.
title PPT-GNN: A Practical Pre-Trained Spatio-Temporal Graph Neural Network for Network Security
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2406.13365