Conceptual Model for Network Traffic Anomaly Detection in Computer Systems
We propose a graph neural network approach to network traffic anomaly detection that focuses on four adversarial technique classes from the MITRE ATT&CK framework: command and control (T1071), data exfiltration (T1041/T1048), reconnaissance (T1046/T1018), and lateral movement (T1021). We propose representing network tr...