arXiv論文メモ
新着一覧
cs.CR / cs.AI · 査読状況未確認

通信データのグラフ構造に現れる攻撃の特徴

Topological Signatures of Cyber-Attack Classes in Natural Visibility Graph Representations of Network Traffic

Ali Melih Kanca and Ilker Turker

この論文をやさしく読む

ひとことで言うと

ネットワーク通信の時系列をグラフに変え、攻撃の種類によって異なる構造的な特徴が現れるかを調べた。

何に役立つ?

侵入検知の特徴量や、攻撃ごとの通信パターンを分析する方法の検討に役立つ。実運用のネットワークで同じ性能を実証した結果ではない。

この研究の面白いところ

76特徴を10種類のグラフ指標に変換して760の記述量を作り、分類性能だけでなく攻撃と正常通信の統計的な差も検証した。

どこまで分かった?

評価はCSE-CIC-IDS2018データセットと層化5分割交差検証に基づく。別のネットワークや未知の攻撃への性能は要旨には示されていない。

v2のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

自然可視グラフ(NVG)に基づく表現は、時系列のネットワーク通信にある構造的なパターンを捉える有望な方法である。しかし、異なるサイバー攻撃の種類が、その表現でそれぞれ固有の位相的な特徴を示すかは十分に分かっていない。本研究はCSE-CIC-IDS2018データセットを使い、NVGによる通信データの表現が、攻撃の識別と構造の把握にどれだけ役立つかを調べる。76個の数値的な通信特徴を、40観測ずつの重なり合う区間内でそれぞれNVGに変換し、各グラフから10種類のグラフ理論的指標を抽出した。これにより、各区間につき760個の位相的な記述量を得た。 多分岐の畳み込みニューラルネットワークを用い、層化5分割交差検証で識別能力を評価した結果、平均正解率は96.20%、Matthews相関係数は0.9566だった。攻撃の種類ごとの位相的な違いを調べるため、Kruskal–Wallis検定とMann–WhitneyのU検定を、Benjamini–Hochberg法による偽発見率補正および効果量の指標と組み合わせた。攻撃対正常通信の比較10,640件のうち、7,777件(73.1%)は偽発見率補正後も統計的に有意で、そのうち4,844件はCliffのデルタで大きな効果を示した。全体として特に大きな差は、逆方向の通信やパケット長に関する特徴と、連結性、クラスタリング、中心性の指標との組み合わせに多く見られた。これらの結果は、NVG由来の表現が高い識別能力を持ち、攻撃の種類に応じた位相的パターンも明らかにできることを示す。

v2の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-22(UTC)
最新改訂
2026-09-24 · v2
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Natural Visibility Graph (NVG)-based representations provide a promising approach for capturing structural patterns in sequential network traffic. However, whether different cyber-attack classes exhibit distinctive topological signatures in such representations remains insufficiently understood. This study investigates the discriminative and structural characteristics of NVG-based network traffic representations using the CSE-CIC-IDS2018 dataset. Seventy-six numerical traffic features were independently transformed into NVGs within overlapping frames of 40 observations, and ten graph-theoretic metrics were extracted from each graph, resulting in 760 topological descriptors per frame. The discriminative capability of these representations was evaluated using a multi-branch convolutional neural network (CNN) with stratified five-fold cross-validation. The model achieved an average accuracy of 96.20% and a Matthews correlation coefficient (MCC) of 0.9566. To characterize class-specific topological differences, Kruskal-Wallis and Mann-Whitney U tests were combined with Benjamini-Hochberg false discovery rate correction and effect-size measures. Of the 10,640 attack-versus-benign comparisons, 7,777 (73.1%) remained statistically significant after FDR correction, with 4,844 exhibiting large Cliff's delta effects. The strongest global differences were predominantly associated with backward-traffic and packet-length-related features combined with connectivity, clustering, and centrality measures. These findings indicate that NVG-derived representations can provide strong discriminative capability while revealing class-dependent topological patterns associated with different cyber-attack classes.

arXiv ID: 2609.26990 / 要約の誤りについて