Published April 19, 2023 | Version v1

Graph-Based Machine Learning Models For Network Attack Detection

Authors/Creators

Description

The increasing complexity and interconnectedness of modern digital infrastructures have rendered traditional, point-based network security measures largely ineffective. Conventional machine learning models often treat network traffic as independent, identically distributed (IID) data points, failing to capture the structural dependencies and relational context inherent in sophisticated cyber-attacks. This review explores the paradigm shift toward Graph-Based Machine Learning (GML) for network attack detection. By representing network entities—such as IP addresses, MAC addresses, and service ports—as nodes, and their interactions as edges, graph-based models can effectively map the \\\"topology of intent\\\" behind malicious activity. This article categorizes current GML methodologies, including Graph Convolutional Networks (GCNs), Graph Attention Networks (GATs), and Temporal Graphs, which account for the dynamic nature of traffic flows. We examine how these models excel at detecting \\\"lateral movement,\\\" \\\"botnet command-and-control,\\\" and \\\"distributed denial-of-service\\\" (DDoS) attacks by identifying anomalous structural patterns that are invisible to tabular analysis. Furthermore, the review addresses the challenges of scalability in massive-scale networks and the necessity for real-time graph processing. By synthesizing recent academic breakthroughs and industrial applications, this paper provides a strategic roadmap for deploying graph-based \\\"Relational Intelligence\\\" within Security Operations Centers. The findings suggest that GML significantly reduces false positives by providing contextual awareness, making it a cornerstone for the next generation of resilient, self-aware network defense systems.

Files

IJSRET_V9_issue2_227.pdf

Files (256.5 kB)

Name Size Download all
md5:2b4da935d9cc1de3c5008a37c1a77570
256.5 kB Preview Download

Additional details