Knowledge graph visualization and anomaly detection from cyber threat intelligence dataset using graph neural networks based methods

dc.contributor.authorYilmaz, Ali
dc.contributor.authorDas, Resul
dc.contributor.authorOzdem, Mehmet
dc.contributor.authorCanberk, Berk
dc.date.accessioned2026-09-08T07:13:37Z
dc.date.issued2026
dc.departmentFırat Üniveristesi
dc.description.abstractThe growing scale and sophistication of modern cyberattacks demand anomaly detection models capable of capturing non-Euclidean and highly relational patterns embedded within network traffic. This study introduces a unified and interpretable graph-based framework for network anomaly detection that systematically evaluates four representative graph neural network (GNN) architectures - GCN, GAT, GIN, and GraphSAGE - under identical experimental settings. Using the UNSW-NB15 benchmark dataset, IP addresses are modeled as graph nodes and communication flows are modeled as directed edges with flow-level attributes, enabling the extraction of structural attack behaviors. To provide complementary external robustness evidence, the framework is additionally evaluated on CIC-DDoS2019 under a DDoS-focused scenario and on a CSE-CIC-IDS2018-based diverse intrusion dataset under a broader multi-attack benchmark setting. A consistent preprocessing pipeline, standardized model configuration, 5-fold stratified cross-validation, statistical validation, and sensitivity analysis are employed to evaluate robustness and stability. Experimental results show that GIN and GraphSAGE achieve the strongest performance, with F1-scores of 0.9693 +/- 0.0007 and 0.9721 +/- 0.0006, respectively, and ROC-AUC values above 0.99 across folds. In addition, computational profiling is conducted to analyze inference latency, throughput, the number of trainable parameters, and GPU memory usage, highlighting the scalability advantages of aggregation-based models. Beyond quantitative evaluation, a dynamic D3.js-based attack topology visualization is presented to reveal attacker-target interactions, dominant attack categories, and high-frequency communication paths. Overall, this study provides a reproducible benchmarking and visualization framework for interpretable and structurally aware graph-based cybersecurity analytics.
dc.description.sponsorshipFirat University [999962] -- Scientific and Technological Research Council of Turkiye (TUBIdot;TAK) under the BIdot;DEB 2219 Program [5249902] -- TUBIdot;TAK 1515 Frontier R&D Laboratories Support Program for the Tuerk Telekom 6G RD Lab [5249902] -- This study is derived from Ali Y & imath;lmaz's PhD dissertation, titled Graph Neural Networks Based Anomaly Detection from Log Records (Thesis No: 999962) at Firat University. The core framework of this thesis research was subsequently extended and internationalized during Prof. Dr. Resul Das's postdoctoral tenure at Edinburgh Napier University (Scotland, UK), which was funded by the Scientific and Technological Research Council of Turkiye (TUB & Idot;TAK) under the B & Idot;DEB 2219 Program. Finally, the practical application, optimization, and finalization of this integrated work were fully supported and realized under the TUB & Idot;TAK 1515 Frontier R&D Laboratories Support Program for the Tuerk Telekom 6G R&D Lab (Project No. : 5249902).
dc.identifier.doi10.1016/j.comnet.2026.112632
dc.identifier.issn1389-1286
dc.identifier.issn1872-7069
dc.identifier.scopus2-s2.0-105046894990
dc.identifier.scopusqualityQ1
dc.identifier.urihttps://doi.org/10.1016/j.comnet.2026.112632
dc.identifier.urihttps://hdl.handle.net/11508/65521
dc.identifier.volume288
dc.identifier.wosWOS:001848294000001
dc.identifier.wosqualityQ2
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherElsevier
dc.relation.ispartofComputer Networks
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_WOS_20250903
dc.subjectKnowledge Graph Visualization
dc.subjectGraph Neural Networks
dc.subjectAnomaly Detection
dc.subjectComparative Analysis
dc.subjectGraph Visualization
dc.subjectDdos Detection
dc.titleKnowledge graph visualization and anomaly detection from cyber threat intelligence dataset using graph neural networks based methods
dc.typeArticle

Dosyalar