We present a novel approach in network security using unsupervised online machine learning method at the edge, through graph learning. The proposed system takes advantage of an online learning paradigm, by collecting real network data to build a ground truth of a network's topology, using shallow graph neural networks (GNNs). Our proposed solution includes an edge-based infrastructure, through K3s and Kafka, which could then scale to match the needs of larger networks. We then perform simple cyber-attacks and show how visual analysis can identify malicious behaviors, without any prior labeled data. Our results against simple attacks show promise that improved graph analytics should capture even more complex attack vectors. We then conclude with some suggestions for improved edge deployment, against larger and more complex networks.
Virgil O. Barnard is a senior machine learning scientist in the Artificial Intelligence and Machine Learning group at Riverside Research. He received his bachelor’s in mathematics from University of Kentucky in 2012. He received his Ph.D. (ABD) in computer science from University of Kentucky in 2019. He has performed as a technical AI lead on many contracts for customers in the DoD & IC while at Riverside Research since 2019 spanning image, electro-optic, signals, and radar-based modalities. He is currently researching agent-based reasoning over knowledge graphs.
LinkedINThe above listed authors are current or former employees of Riverside Research. Authors affiliated with other institutions are listed on the full paper. It is the responsibility of the author to list material disclosures in each paper, where applicable – they are not listed here. This academic papers directory is published in accordance with federal guidance to make public and available academic research funded by the federal government.