Knowledge graph visualization and anomaly detection from cyber threat intelligence dataset using graph neural networks based methods
COMPUTER NETWORKS, cilt.288, ss.112632, 2026 (SCI-Expanded, Scopus)
- Yayın Türü: Makale / Tam Makale
- Cilt numarası: 288
- Basım Tarihi: 2026
- Doi Numarası: 10.1016/j.comnet.2026.112632
- Dergi Adı: COMPUTER NETWORKS
- Derginin Tarandığı İndeksler: Applied Science & Technology Source, Information Science & Technology Abstracts (LISTA), EBSCO Communication Source, Business Source Ultimate (EBSCO), Communication Source (EBSCO), Engineering Source (EBSCO), Scopus, Technology Collection (ProQuest), Aerospace Database, Science Citation Index Expanded (SCI-EXPANDED), ABI/INFORM, Compendex, INSPEC, Library, Information Science & Technology Abstracts (LISTA), zbMATH
- Sayfa Sayıları: ss.112632
- Van Yüzüncü Yıl Üniversitesi Adresli: Evet
Özet
The growing scale and sophistication of modern cyberattacks demand anomaly detection models capable of capturing non-Euclidean and highly relational patterns embedded within network traffic. This study introduces a unified and interpretable graph-based framework for network anomaly detection that systematically evaluates four representative graph neural network (GNN) architectures—GCN, GAT, GIN, and GraphSAGE—under identical experimental settings. Using the UNSW-NB15 benchmark dataset, IP addresses are modeled as graph nodes and communication flows are modeled as directed edges with flow-level attributes, enabling the extraction of structural attack behaviors. To provide complementary external robustness evidence, the framework is additionally evaluated on CIC-DDoS2019 under a DDoS-focused scenario and on a CSE-CIC-IDS2018-based diverse intrusion dataset under a broader multi-attack benchmark setting. A consistent preprocessing pipeline, standardized model configuration, 5-fold stratified cross-validation, statistical validation, and sensitivity analysis are employed to evaluate robustness and stability. Experimental results show that GIN and GraphSAGE achieve the strongest performance, with F1-scores of 0.9693 0.0007 and 0.9721 0.0006, respectively, and ROC-AUC values above 0.99 across folds. In addition, computational profiling is conducted to analyze inference latency, throughput, the number of trainable parameters, and GPU memory usage, highlighting the scalability advantages of aggregation-based models. Beyond quantitative evaluation, a dynamic D3.js-based attack topology visualization is presented to reveal attacker–target interactions, dominant attack categories, and high-frequency communication paths. Overall, this study provides a reproducible benchmarking and visualization framework for interpretable and structurally aware graph-based cybersecurity analytics.