Skip to content
Conference

Conceptual Model for Network Traffic Anomaly Detection in Computer Systems

Sep 2026 · Automation, Control, and Information Technology · pp. 879-884 · 0 citations · 49 references

Abstract

We propose a graph neural network approach to network traffic anomaly detection that focuses on four adversarial technique classes from the MITRE ATT&CK framework: command and control (T1071), data exfiltration (T1041/T1048), reconnaissance (T1046/T1018), and lateral movement (T1021). We propose representing network traffic a sa d ynamic heterogeneous graph with three node types-hosts, services, and users-and four edge types. The architecture integrates Graph Attention Networks with Gated Recurrent Units, enabling modeling of both spatial dependencies and temporal attack evolution. The model adopts a multi-task learning paradigm with techniquespecific detection modules. Our experimental design encompasses validation across four datasets (LANL, CICIDS2017, CERT, CTU-13) and benchmarking using six comparative methods. Literature analysis indicates that graph-based techniques achieve 85% true positive rate at 0.9% false positive rate for lateral movement, versus 72% and 4.4% for traditional methods. The proposed approach ensures direct correspondence to MITRE ATT&CK technique categories, converting anomaly signals into structured threat intelligence.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.