arXiv:2602.07073cs.CRcs.AI2026-02

用图神经网络提前发现高危连接,防范未知漏洞攻击。

Pro-ZD: A Transferable Graph Neural Network Approach for Proactive Zero-Day Threats Mitigation

  • 构建加权最短路径模型识别风险连通路径
  • 在测试中对高危连接检测准确率超95%
  • 可自动优化防火墙规则,适合安全运维人员

当前企业网络中,边界与分布式防火墙规则共同控制访问。面对流量增加和网络架构多样化,组织依赖自动化工具生成规则与访问策略。然而,动态生成策略带来的风险,尤其是关键资产暴露问题,仍是重大挑战。这一挑战因远程办公、自带设备及云集成等趋势而加剧。本文提出Pro-ZD框架,采用图神经网络识别加权最短路径,用于发现网络配置错误及威胁关键资产的高风险连通路径,这些路径可能被零日攻击利用。该方法具有前瞻性,能自动微调防火墙规则与访问策略,以阻断高风险连接并防止未授权访问。实验表明,Pro-ZD在检测高风险连接方面具备强鲁棒性与跨环境迁移能力,平均准确率超过95%。

原文摘要 · Abstract (English)

In today's enterprise network landscape, the combination of perimeter and distributed firewall rules governs connectivity. To address challenges arising from increased traffic and diverse network architectures, organizations employ automated tools for firewall rule and access policy generation. Yet, effectively managing risks arising from dynamically generated policies, especially concerning critical asset exposure, remains a major challenge. This challenge is amplified by evolving network structures due to trends like remote users, bring-your-own devices, and cloud integration. This paper introduces a novel graph neural network model for identifying weighted shortest paths. The model aids in detecting network misconfigurations and high-risk connectivity paths that threaten critical assets, potentially exploited in zero-day attacks -- cyber-attacks exploiting undisclosed vulnerabilities. The proposed Pro-ZD framework adopts a proactive approach, automatically fine-tuning firewall rules and access policies to address high-risk connections and prevent unauthorized access. Experimental results highlight the robustness and transferability of Pro-ZD, achieving over 95% average accuracy in detecting high-risk connections. \

图神经网络网络安全零日攻击策略优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。