arXiv:2505.08964cs.LGcs.AI2025-05被引 1

用图模型分析网络流量,实时发现异常行为和社区变化。

GPML: Graph Processing for Machine Learning

  • 将原始网络流量转为图结构,捕捉动态交互模式。
  • 支持社区与谱特征提取,提升实时检测与历史追溯能力。
  • 适合网络安全研究者与威胁检测系统开发者使用。

动态网络中复杂、多步且快速演化的攻击日益增多,亟需先进的网络威胁检测手段。GPML(Graph Processing for Machine Learning)库通过将原始网络流量日志转换为图表示,实现对网络行为的深入洞察。该库提供工具以检测交互异常及社区结构变化,支持社区与谱特征的提取,增强实时威胁检测与历史取证分析能力。GPML采用基于图的稳健方法,应对现代网络安全挑战。

原文摘要 · Abstract (English)

The dramatic increase of complex, multi-step, and rapidly evolving attacks in dynamic networks involves advanced cyber-threat detectors. The GPML (Graph Processing for Machine Learning) library addresses this need by transforming raw network traffic traces into graph representations, enabling advanced insights into network behaviors. The library provides tools to detect anomalies in interaction and community shifts in dynamic networks. GPML supports community and spectral metrics extraction, enhancing both real-time detection and historical forensics analysis. This library supports modern cybersecurity challenges with a robust, graph-based approach.

图神经网络网络安全异常检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。