In recent years, machine learning (ML) techniques have been increasingly applied to the domain of computer security, specifically for the classification of malicious network traffic, leveraging patterns and anomalies within vast datasets to identify potential threats. This paper delves into the specific role of Graph Neural Networks (GNNs) within this context, assessing their potential advantages and limitations in comparison to traditional ML techniques for the task of malicious traffic classification. GNNs, which require graph data structures as input, offer a novel approach by exploiting the relational information inherent in network traffic, potentially providing a more nuanced understanding of complex interactions that define malicious activities. Through a comprehensive analysis, this study aims to illuminate the conditions under which GNNs represent a superior or inferior choice for the detection of network-based threats, contributing to a more informed integration of ML techniques in enhancing cyber defense mechanisms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detecting Malware Traffic with Graph Neural Networks

  • Matthew Straughn,
  • Armon Barton,
  • Bruce Allen

摘要

In recent years, machine learning (ML) techniques have been increasingly applied to the domain of computer security, specifically for the classification of malicious network traffic, leveraging patterns and anomalies within vast datasets to identify potential threats. This paper delves into the specific role of Graph Neural Networks (GNNs) within this context, assessing their potential advantages and limitations in comparison to traditional ML techniques for the task of malicious traffic classification. GNNs, which require graph data structures as input, offer a novel approach by exploiting the relational information inherent in network traffic, potentially providing a more nuanced understanding of complex interactions that define malicious activities. Through a comprehensive analysis, this study aims to illuminate the conditions under which GNNs represent a superior or inferior choice for the detection of network-based threats, contributing to a more informed integration of ML techniques in enhancing cyber defense mechanisms.