错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SSA-GAT: Graph-Based Self-supervised Learning for Network Intrusion Detection

  • Qian Liu,
  • Hui Zhang,
  • Youpeng Zhang,
  • Lin Fan,
  • Xue Jin

摘要

The attacks that derived from the advances of the Internet technology, despite sophistication, remain significantly outnumbered by benign traffic within networks. To deal with imbalance, traditional machine learning (ML) models rely heavily on resampling for data preprocessing, which changes the original data distribution and leads to suboptimal performance. Moreover, these ML algorithms operate on tabulated flows and thus ignore the network topology that is important to identify certain attacks. This paper proposes SSA-GAT, a Graph Attention Network (GAT)-based Network Intrusion Detection System (NIDS), which leverages a graph-based contrastive self-supervised learning framework. We propose four specific augmentation methods and a novel attentive readout function to facilitate the training process, utilizing the joint objective combining supervised and self-supervised losses to improve the performance of minority attack identification. Extensive experiments on the highly imbalanced CIC-IDS2017 dataset demonstrate that the proposed model has excellent performance. For extremely minority attacks, SSA-GAT achieves 62.5% and 66.7% F1 scores on infiltration (occurs only 36 times) and HeartBleed (occurs only 11 times), respectively.