用图神经网络提升智能家电的异常流量检测能力
GNN-enhanced Traffic Anomaly Detection for Next-Generation SDN-Enabled Consumer Electronics

- 融合攻击图与动态流量特征,构建安全感知的图神经网络模型
- 在小样本下仍达高准确率,各项指标优于现有方法
- 适合研究物联网安全或SDN架构的开发者参考
连接物联网的消费电子设备易受DDoS和Web类攻击,导致功能失效并被远程劫持,进而传播恶意代码。现有深度学习检测系统虽精度高,但依赖静态配置,难于维护。本文提出结合软件定义网络(SDN)与计算优先网络(CFN)的新型网络架构,并设计基于图神经网络的异常检测框架GNN-NAD。该框架将静态漏洞攻击图与动态流量特征融合,采用GSAGE图神经网络进行表征学习,再通过随机森林(RF)分类器实现检测。实验表明,在消费电子环境中,该方法即使在小样本下也显著优于现有技术,准确率、召回率、精确率和F1值全面领先。
原文摘要 · Abstract (English)
Consumer electronics (CE) connected to the Internet of Things are susceptible to various attacks, including DDoS and web-based threats, which can compromise their functionality and facilitate remote hijacking. These vulnerabilities allow attackers to exploit CE for broader system attacks while enabling the propagation of malicious code across the CE network, resulting in device failures. Existing deep learning-based traffic anomaly detection systems exhibit high accuracy in traditional network environments but are often overly complex and reliant on static infrastructure, necessitating manual configuration and management. To address these limitations, we propose a scalable network model that integrates Software-defined Networking (SDN) and Compute First Networking (CFN) for next-generation CE networks. In this network model, we propose a Graph Neural Networks-based Network Anomaly Detection framework (GNN-NAD) that integrates SDN-based CE networks and enables the CFN architecture. GNN-NAD uniquely fuses a static, vulnerability-aware attack graph with dynamic traffic features, providing a holistic view of network security. The core of the framework is a GNN model (GSAGE) for graph representation learning, followed by a Random Forest (RF) classifier. This design (GSAGE+RF) demonstrates superior performance compared to existing feature selection methods. Experimental evaluations on CE environment reveal that GNN-NAD achieves superior metrics in accuracy, recall, precision, and F1 score, even with small sample sizes, exceeding the performance of current network anomaly detection methods. This work advances the security and efficiency of next-generation intelligent CE networks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。