Conceptual Model for Network Traffic Anomaly Detection in Computer Systems
Abstract
We propose a graph neural network approach to network traffic anomaly detection that focuses on four adversarial technique classes from the MITRE ATT&CK framework: command and control (T1071), data exfiltration (T1041/T1048), reconnaissance (T1046/T1018), and lateral movement (T1021). We propose representing network traffic a sa d ynamic heterogeneous graph with three node types-hosts, services, and users-and four edge types. The architecture integrates Graph Attention Networks with Gated Recurrent Units, enabling modeling of both spatial dependencies and temporal attack evolution. The model adopts a multi-task learning paradigm with techniquespecific detection modules. Our experimental design encompasses validation across four datasets (LANL, CICIDS2017, CERT, CTU-13) and benchmarking using six comparative methods. Literature analysis indicates that graph-based techniques achieve 85% true positive rate at 0.9% false positive rate for lateral movement, versus 72% and 4.4% for traditional methods. The proposed approach ensures direct correspondence to MITRE ATT&CK technique categories, converting anomaly signals into structured threat intelligence.