Outline

Ingegneria Sismica

Ingegneria Sismica

False Alarm Suppression for Temporal Graph Neural Networks in Computer Network Intrusion Detection

Author(s): Yafei Li1, Yan Liu1, Jinpeng Chen1, Lu Zhong
1Department of Information Engineering, School of Rail Transit, Southwest Jiaotong University Hope College, Chengdu 610400, Sichuan, China
Li, Yafei. et al “False Alarm Suppression for Temporal Graph Neural Networks in Computer Network Intrusion Detection.” Ingegneria Sismica Volume 43 Issue 2: 1-22, doi:10.65102/is2026550.

Abstract

With the expansion of network services and the continuous complexity of attack forms, intrusion detection systems face problems such as high false positive rate and difficult to distinguish boundary samples in high dynamic traffic scenarios. Focusing on the demand of false positive suppression in computer network intrusion detection, this paper proposes a temporal graph neural network model for complex traffic scenarios. The method establishes the network traffic temporal correlation graph by session reconstruction and time window division, and integrates topology dependence extraction, behavior evolution modeling, re-discrimination of easily confused samples and false alarm constrained loss optimization to enhance the ability to identify the difference between normal fluctuations and real attacks. The experimental results based on NSL-KDD, UNSW-NB15 and CIC-IDS2017 datasets show that the Accuracy of the model reaches 96.1%, the F1-score is 95.4%, the AUC is 0.986, the FAR is reduced to 3.2%, and the Specificity is improved to 96.6%. In the NSL-KDD fine-grained attack type analysis, it also maintains a good detection effect on R2L and U2R covert attacks. The research shows that this method can effectively compress the false positive propagation space while ensuring the detection accuracy, which provides a feasible path for intelligent intrusion detection in complex network environment.

Keywords
Network intrusion detection; Temporal graph neural network; False alarm suppression; Abnormal traffic analysis

Related Articles

Huiqiao Liu1
1Yinchuan University of Energy, Ningxia, 750000, China
Xin Zhao1, Yan Li1, Xiangyang Cao1, Qiushuang Li1, Jianing Zhang1
1State Grid Shandong Electric Power Company Economic and Technological Research Institute ShanDong JiNan 250001, China
Dan Yang1
1School of Marxism, Suzhou Polytechnic University, Suzhou, 215104, China
Liuhang Shen1, Xiangwen Sun1
1Ulster college at Shaanxi University of Science &Technology, Xi’an,710021, Shaanxi, China