Detecting Unknown Threat Based on Continuous-Time Dynamic Heterogeneous Graph Network

8Citations
Citations of this article
10Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Unknown threats have caused severe damage in critical infrastructures. To solve this issue, the graph-based methods have been proposed because of their ability for learning complex interaction patterns of network entities with discrete graph snapshots. However, such methods are challenged by the computer networking model characterized by the natural continuous-time dynamic heterogeneous graph (CDHG). In this paper, we propose a CDHG-based graph neural network model, namely, CDHGN, for unknown threat detection. It first constructs the CDHG using interaction relationships among network entities extracted from various log records. Then, it trains the detection model based on a heterogeneous attention network and performs streaming detection for live online network events. We implement a prototype and conduct extensive experiments on a comprehensive cybersecurity dataset with more than nine million records. Experimental result shows that the proposed method can achieve superior detection performance than the state-of-the-art methods.

Cite

CITATION STYLE

APA

Gao, P., Yang, W., Zhang, H., Wei, X., Huang, H., Luo, W., … Hao, Y. (2022). Detecting Unknown Threat Based on Continuous-Time Dynamic Heterogeneous Graph Network. Wireless Communications and Mobile Computing, 2022. https://doi.org/10.1155/2022/7502294

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free