JSAI2024

Presentation information

Poster Session

Poster session » Poster session

[4Xin2] Poster session 2

Fri. May 31, 2024 12:00 PM - 1:40 PM Room X (Event hall 1)

[4Xin2-40] GNN-based Anomaly Traffic Detection using Continuous Graph Considering Functional Transitions of Flow Data

〇Yusuke Akimoto1, Norihiro Okui2, Ayumu Kubota2, Takuya Yoshida3 (1.ARISE analytics Inc., 2.KDDI Research Inc., 3.Toyota Motor Corporation)

Keywords:Anomaly Detection, Cyber Security, IoT, Graph Neural Network

As more and more IoT devices are connected to the network, countermeasures against cyber-attacks against IoT devices have become an important issue. Recently, Graph Neural Network (GNN)-based methods have been proposed to detect malware-infected IoT devices. Compared to conventional methods that use only statistical information, GNN-based methods can take into account various communication relationships, such as communication paths, communication order, and functional coherence. On the other hand, most of the previous studies are based on static graphs over a specific period of time and fail to take into account changes in communication over time. In reality, most communication data changes with time, and a method that can handle dynamically changing communication is required. We propose a new anomaly detection method for dynamic graphs that represent the order and functional coherence of communications. By using a dynamic graph called Continuous Graph, we can handle a large amount of communication data with a low computational cost. Experiments were conducted on public datasets to evaluate the accuracy of the proposed method, and its effectiveness was confirmed.

Authentication for paper PDF access

A password is required to view paper PDFs. If you are a registered participant, please log on the site from Participant Log In.
You could view the PDF with entering the PDF viewing password bellow.

Password