EG-ConMix: An Intrusion Detection Method Based on Graph Contrastive Learning
摘要
With the rise in the number of IoT devices, security issues become increasingly prominent. The impact of threats can be minimized by deploying Network Intrusion Detection System (NIDS) by monitoring network traffic, detecting and discovering intrusions, and issuing security alerts promptly. Most intrusion detection research in recent years has been directed towards the pair of traffic itself without considering the interrelationships among them, thus limiting the monitoring of complex IoT network attack events. Besides, anomalous traffic in real networks accounts for only a small fraction, which leads to a severe imbalance problem in the dataset that makes algorithmic learning and prediction extremely difficult. This paper presents an EG-ConMix approach, which is founded on E-GraphSAGE and integrates a data augmentation component to tackle the challenge of data imbalance. In addition, we incorporate contrastive learning to discern the difference between normal and malicious traffic samples, facilitating the extraction of key features. Thorough experiments conducted on two publicly accessible datasets reveal that EG-ConMix surpasses current state-of-the-art methods in intrusion detection. Remarkably, it demonstrates significant advantages in both the velocity of learning and precision when applied to large-scale network structures.