Knowledge graph visualization and anomaly detection from cyber threat intelligence dataset using graph neural networks based methods
| dc.contributor.author | Yilmaz, Ali | |
| dc.contributor.author | Das, Resul | |
| dc.contributor.author | Ozdem, Mehmet | |
| dc.contributor.author | Canberk, Berk | |
| dc.date.accessioned | 2026-09-08T07:13:37Z | |
| dc.date.issued | 2026 | |
| dc.department | Fırat Üniveristesi | |
| dc.description.abstract | The growing scale and sophistication of modern cyberattacks demand anomaly detection models capable of capturing non-Euclidean and highly relational patterns embedded within network traffic. This study introduces a unified and interpretable graph-based framework for network anomaly detection that systematically evaluates four representative graph neural network (GNN) architectures - GCN, GAT, GIN, and GraphSAGE - under identical experimental settings. Using the UNSW-NB15 benchmark dataset, IP addresses are modeled as graph nodes and communication flows are modeled as directed edges with flow-level attributes, enabling the extraction of structural attack behaviors. To provide complementary external robustness evidence, the framework is additionally evaluated on CIC-DDoS2019 under a DDoS-focused scenario and on a CSE-CIC-IDS2018-based diverse intrusion dataset under a broader multi-attack benchmark setting. A consistent preprocessing pipeline, standardized model configuration, 5-fold stratified cross-validation, statistical validation, and sensitivity analysis are employed to evaluate robustness and stability. Experimental results show that GIN and GraphSAGE achieve the strongest performance, with F1-scores of 0.9693 +/- 0.0007 and 0.9721 +/- 0.0006, respectively, and ROC-AUC values above 0.99 across folds. In addition, computational profiling is conducted to analyze inference latency, throughput, the number of trainable parameters, and GPU memory usage, highlighting the scalability advantages of aggregation-based models. Beyond quantitative evaluation, a dynamic D3.js-based attack topology visualization is presented to reveal attacker-target interactions, dominant attack categories, and high-frequency communication paths. Overall, this study provides a reproducible benchmarking and visualization framework for interpretable and structurally aware graph-based cybersecurity analytics. | |
| dc.description.sponsorship | Firat University [999962] -- Scientific and Technological Research Council of Turkiye (TUBIdot;TAK) under the BIdot;DEB 2219 Program [5249902] -- TUBIdot;TAK 1515 Frontier R&D Laboratories Support Program for the Tuerk Telekom 6G RD Lab [5249902] -- This study is derived from Ali Y & imath;lmaz's PhD dissertation, titled Graph Neural Networks Based Anomaly Detection from Log Records (Thesis No: 999962) at Firat University. The core framework of this thesis research was subsequently extended and internationalized during Prof. Dr. Resul Das's postdoctoral tenure at Edinburgh Napier University (Scotland, UK), which was funded by the Scientific and Technological Research Council of Turkiye (TUB & Idot;TAK) under the B & Idot;DEB 2219 Program. Finally, the practical application, optimization, and finalization of this integrated work were fully supported and realized under the TUB & Idot;TAK 1515 Frontier R&D Laboratories Support Program for the Tuerk Telekom 6G R&D Lab (Project No. : 5249902). | |
| dc.identifier.doi | 10.1016/j.comnet.2026.112632 | |
| dc.identifier.issn | 1389-1286 | |
| dc.identifier.issn | 1872-7069 | |
| dc.identifier.scopus | 2-s2.0-105046894990 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.uri | https://doi.org/10.1016/j.comnet.2026.112632 | |
| dc.identifier.uri | https://hdl.handle.net/11508/65521 | |
| dc.identifier.volume | 288 | |
| dc.identifier.wos | WOS:001848294000001 | |
| dc.identifier.wosquality | Q2 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Elsevier | |
| dc.relation.ispartof | Computer Networks | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_WOS_20250903 | |
| dc.subject | Knowledge Graph Visualization | |
| dc.subject | Graph Neural Networks | |
| dc.subject | Anomaly Detection | |
| dc.subject | Comparative Analysis | |
| dc.subject | Graph Visualization | |
| dc.subject | Ddos Detection | |
| dc.title | Knowledge graph visualization and anomaly detection from cyber threat intelligence dataset using graph neural networks based methods | |
| dc.type | Article |







