GAT-AD: Graph Attention Networks for contextual anomaly detection in network monitoring

IF 6.7 1区 工程技术 Q1 COMPUTER SCIENCE, INTERDISCIPLINARY APPLICATIONS
Hamid Latif-Martínez , José Suárez-Varela , Albert Cabellos-Aparicio , Pere Barlet-Ros
{"title":"GAT-AD: Graph Attention Networks for contextual anomaly detection in network monitoring","authors":"Hamid Latif-Martínez ,&nbsp;José Suárez-Varela ,&nbsp;Albert Cabellos-Aparicio ,&nbsp;Pere Barlet-Ros","doi":"10.1016/j.cie.2024.110830","DOIUrl":null,"url":null,"abstract":"<div><div>Network anomaly detection is essential to promptly detect and fix issues in the network. Particularly, detecting traffic anomalies enables the early detection of configuration errors, malicious activities, or equipment malfunctions that could lead to severe impact on the network. In this paper, we present <em>GAT-AD</em>, a Deep Learning-based anomaly detection solution for network monitoring systems, which integrates a custom neural network model based on Graph Attention Networks (GAT). Our solution monitors aggregated traffic on origin–destination flows and automatically defines contexts that group flows with similar past activity. The neural network model within <em>GAT-AD</em> can be efficiently trained in a self-supervised manner. We evaluate our solution against two state-of-the-art anomaly detection baselines also based on graph representations and Deep Learning, in two different datasets: <span><math><mrow><mo>(</mo><mi>i</mi><mo>)</mo></mrow></math></span> <em>WaDi</em>, which is a well-known dataset for anomaly detection in a distributed sensor network, and <span><math><mrow><mo>(</mo><mi>i</mi><mi>i</mi><mo>)</mo></mrow></math></span> <em>Abilene</em>, where we inject synthetically-generated anomalies into a dataset with real-world traffic from a large-scale backbone network. The results show that <em>GAT-AD</em> outperforms the two anomaly detection baselines: in <em>WaDi</em> by 14.1% in recall and 10.07% in F1-score, and in the <em>Abilene</em> dataset by <span><math><mo>≈</mo></math></span>17.5% recall with respect to the best baseline.</div></div>","PeriodicalId":55220,"journal":{"name":"Computers & Industrial Engineering","volume":"200 ","pages":"Article 110830"},"PeriodicalIF":6.7000,"publicationDate":"2025-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers & Industrial Engineering","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0360835224009525","RegionNum":1,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INTERDISCIPLINARY APPLICATIONS","Score":null,"Total":0}
引用次数: 0

Abstract

Network anomaly detection is essential to promptly detect and fix issues in the network. Particularly, detecting traffic anomalies enables the early detection of configuration errors, malicious activities, or equipment malfunctions that could lead to severe impact on the network. In this paper, we present GAT-AD, a Deep Learning-based anomaly detection solution for network monitoring systems, which integrates a custom neural network model based on Graph Attention Networks (GAT). Our solution monitors aggregated traffic on origin–destination flows and automatically defines contexts that group flows with similar past activity. The neural network model within GAT-AD can be efficiently trained in a self-supervised manner. We evaluate our solution against two state-of-the-art anomaly detection baselines also based on graph representations and Deep Learning, in two different datasets: (i) WaDi, which is a well-known dataset for anomaly detection in a distributed sensor network, and (ii) Abilene, where we inject synthetically-generated anomalies into a dataset with real-world traffic from a large-scale backbone network. The results show that GAT-AD outperforms the two anomaly detection baselines: in WaDi by 14.1% in recall and 10.07% in F1-score, and in the Abilene dataset by 17.5% recall with respect to the best baseline.
求助全文
约1分钟内获得全文 求助全文
来源期刊
Computers & Industrial Engineering
Computers & Industrial Engineering 工程技术-工程:工业
CiteScore
12.70
自引率
12.70%
发文量
794
审稿时长
10.6 months
期刊介绍: Computers & Industrial Engineering (CAIE) is dedicated to researchers, educators, and practitioners in industrial engineering and related fields. Pioneering the integration of computers in research, education, and practice, industrial engineering has evolved to make computers and electronic communication integral to its domain. CAIE publishes original contributions focusing on the development of novel computerized methodologies to address industrial engineering problems. It also highlights the applications of these methodologies to issues within the broader industrial engineering and associated communities. The journal actively encourages submissions that push the boundaries of fundamental theories and concepts in industrial engineering techniques.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信