Pith. sign in

REVIEW 2 cited by

Automating Botnet Detection with Graph Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2003.06344 v1 pith:S3IXMJ4J submitted 2020-03-13 cs.CR cs.LGstat.ML

classification cs.CRcs.LGstat.ML
keywords botnetdetectionbotnetsdatagraphlearningnetworknetworks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Botnets are now a major source for many network attacks, such as DDoS attacks and spam. However, most traditional detection methods heavily rely on heuristically designed multi-stage detection criteria. In this paper, we consider the neural network design challenges of using modern deep learning techniques to learn policies for botnet detection automatically. To generate training data, we synthesize botnet connections with different underlying communication patterns overlaid on large-scale real networks as datasets. To capture the important hierarchical structure of centralized botnets and the fast-mixing structure for decentralized botnets, we tailor graph neural networks (GNN) to detect the properties of these structures. Experimental results show that GNNs are better able to capture botnet structure than previous non-learning methods when trained with appropriate data, and that deeper GNNs are crucial for learning difficult botnet topologies. We believe our data and studies can be useful for both the network security and graph learning communities.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Enhanced Feature Extraction for IoT Network Intrusion Detection Using GNNs and KAN

    cs.CR 2026-07 conditional novelty 5.5 of 10

    SKGFusionKAN (GraphSAGE + multi-scale selective kernel attention + gated fusion + KAN) outperforms GAT, E-GraphSAGE, Anomal-E and SCENE on four IoT NIDS benchmarks.

  2. Graph Classification via Network Usable Information: From Representation Evaluation to Structure Selection

    cs.LG 2026-07 conditional novelty 4.0 of 10

    Classical degree centrality and a clustering-based NUI score often match or beat propagation embeddings for graph classification on IMDB-BINARY and IMDB-MULTI without end-to-end GNN training.

Pith tools