IP Library › Granted Patent US 12,609,871
Granted Patent B2
US 12,609,871 · App. 18/367,775 · Granted Apr 21, 2026

Detecting network anomalies using network flow data

Inventors: Tsuwang Hsieh (Sammamish, WA); Santiago Martin Segarra (Houston, TX); Sathiya Kumaran Mani (Kirkland, WA); Srikanth Kandula (Redmond, WA); Michael Dean Wong (Princeton, NJ)
Assignee: Microsoft Technology Licensing, LLC
H04L41/16H04L41/145H04L41/147H04L43/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,871
App. No.
18/367,775
Granted
Apr 21, 2026
Kind
B2
Abstract

This document relates to automating detecting anomalies in network behavior of an application Generally, the disclosed techniques can obtain network flow data for an application. A machine learning model can be used to process the network flow data to detect anomalies. The machine learning model can be retrained over time to adapt to changing network behavior of the application. In some cases, a graph neural network is employed to detect the anomalies.

Claims (55)

1 . A method comprising:

identifying a subset of cloud resources within a data center that execute application instances associated with a particular application;

determining respective network addresses of the application instances;

based at least on respective network addresses of the application instances, obtaining network flow data reflecting aggregate statistics for network communications among the application instances;

generating graphs based at least on the network flow data, the graphs having nodes representing the application instances and edges representing respective network flow data for pairs of nodes connected by the edges;

based at least on the graphs, training a machine learning model to represent individual edges of each graph as corresponding embeddings; and

outputting the trained machine learning model.

2 . The method of claim 1 , wherein the outputting comprises:

outputting the trained machine learning model over a network, to shared memory, or to storage,

wherein the outputting renders the trained machine learning model available for subsequent inference processing and anomaly detection.

3 . The method of claim 2 , the network communications comprising internal communications by the application within the data center.

4 . The method of claim 1 , the machine learning model comprising a graph neural network.

5 . The method of claim 4 , wherein each application instance corresponds to a different Internet Protocol address or a different virtual machine.

6 . The method of claim 4 , wherein the training comprises determining weights of the graph neural network based at least on the graphs.

7 . The method of claim 6 , wherein the training comprises determining the weights of the graph neural network based at least on a reconstruction loss reflecting a difference between actual network flow data for a particular edge and reconstructed network flow data derived from a particular embedding for the particular edge.

8 . The method of claim 7 , wherein the training comprises determining the weights of the graph neural network based at least on a temporal loss that encourages similarity of embeddings between temporally-adjacent graphs.

9 . The method of claim 8 , wherein the training comprises determining the weights of the graph neural network based at least on a contrastive loss determined using an augmentation strategy.

10 . The method of claim 9 , the augmentation strategy comprising random edge and node removal.

11 . The method of claim 9 , the augmentation strategy comprising adding noise to edge features.

12 . The method of claim 9 , the augmentation strategy comprising removing non-application edges from one or more of the graphs.

13 . A system comprising:

a hardware processing unit; and

a storage resource storing computer-readable instructions which, when executed by the hardware processing unit, cause the hardware processing unit to:

identify a subset of cloud resources within a data center that execute application instances associated with a particular application;

determine respective network addresses of the application instances;

based at least on respective network addresses of the application instances, obtain network flow data reflecting aggregate statistics for network communications among the application instances;

generate graphs based at least on the network flow data, the graphs having nodes representing the application instances and edges representing respective network flow data for pairs of nodes connected by the edges;

based at least on the graphs, train a machine learning model to represent individual edges of each graph as corresponding embeddings; and

output the trained machine learning model.

14 . The system of claim 13 , wherein the aggregate statistics employed to train the machine learning model include at least one of:

for each pair of application instances that communicate with one another:

a number of packets transmitted or received over a period of time,

a number of bytes transmitted or received over the period of time,

a number of ports used over the period of time,

a number of transmission control protocol flows used over the period of time, or

a number of user datagram protocol flows used over the period of time.

15 . The system of claim 13 , wherein the machine learning model is a graph neural network, and the aggregate statistics employed to train the graph neural network include:

for each pair of application instances that communicate with one another:

a number of packets transmitted or received over a period of time,

a number of bytes transmitted or received over the period of time,

a number of ports used over the period of time,

a number of transmission control protocol flows used over the period of time, and

a number of user datagram protocol flows used over the period of time.

16 . The system of claim 13 , wherein the embeddings, when decoded, characterize the network flow data along the edges of the graphs.

17 . The system of claim 16 , wherein the computer-readable instructions, when executed by the hardware processing unit, cause the hardware processing unit to:

during training, learn weights that are applied to the network flow data to determine the embeddings.

18 . The system of claim 17 , wherein the computer-readable instructions, when executed by the hardware processing unit, cause the hardware processing unit to:

learn the weights based at least on reconstruction loss calculated using the embeddings.

19 . A computer-readable storage medium storing instructions which, when executed by a processing device, cause the processing device to perform acts comprising:

identifying a subset of cloud resources within a data center that execute application instances associated with a particular application;

determining respective network addresses of the application instances;

based at least on respective network addresses of the application instances, obtaining network flow data reflecting aggregate statistics for network communications among the application instances;

generating graphs based at least on the network flow data, the graphs having nodes representing the application instances and edges representing respective network flow data for pairs of nodes connected by the edges;

based at least on the graphs, training a machine learning model to represent individual edges of each graph as corresponding embeddings; and

outputting the trained machine learning model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2023
From: HSIEH, TSUWANG; SEGARRA, SANTIAGO MARTIN; MANI, SATHIYA KUMARAN; KANDULA, SRIKANTH; WONG, MICHAEL DEAN
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065575/0933 →
Continuity (1)
Related Publication 20250088428A1 · Mar 13, 2025
References Cited (113)
US 7843843B1 · Papp, III · 2010 [cited by examiner]
US 11316746B1 · Bitterfeld · 2022 [cited by examiner]
US 11620128B1 · Chawda · 2023 [cited by examiner]
US 20210334194A1 · Xiao · 2021 [cited by examiner]
US 20220188850A1 · Costabello · 2022 [cited by examiner]
US 20220343329A1 · Wang · 2022 [cited by examiner]
US 20230118864A1 · Zhang · 2023 [cited by examiner]
US 20240250886A1 · Eng · 2024 [cited by examiner]
WO WO2022167840A1 · 2022 [cited by examiner]
“Aviatrix Cloud Firewall™”, Aviatrix, Retrieved from URL: https://aviatrix.com/distributed-cloud-firewall/, Retrieved on Jul. 16, 2025, 11 pages. [cited by applicant]
Burns, et al., “Borg, Omega, and Kubernetes” Communications of the ACM, vol. 59, No. 5, May 2016, pp. 50-57. [cited by applicant]
Campbell, et al., “Intrusion detection at 100G”, State of the Practice Reports, Article No. 14, Nov. 12, 2011, pp. 1-9. [cited by applicant]
Campbell, et al., “Prototyping a 100G monitoring system”, 20th Euromicro International Conference on Parallel, Distributed and Network-based Processing, Feb. 12, 2012, 5 pages. [cited by applicant]
“Configure flow logs”, Tigera, Retrieved from URL: https://docs.tigera.io/calico-cloud/visibility/elastic/flow/, Retrieved on Jul. 16, 2025, 2 pages. [cited by applicant]
“Discover the innovative world of Napatech Software, SmartNICs and IPUs used in cloud, enterprise and telecom datacenter networks”, Napa:tech, Retrieved from URL: https://www.napatech.com/products/, Retrieved on Jul. 28… [cited by applicant]
“Endace DAG Data Capture Cards”, Retrieved from URL: http://www.emulex.com/products/network—visibility—products—and—services/endacedag-data—capture-cards/features/, Retrieved on Feb. 23, 2015, 2 pages. [cited by applicant]
Hossain, Munawar, “Trends in Data Center Security: Part 1—Traffic Trends”, Cisco, Retrieved from URL: https://blogs.cisco.com/security/trends-in-data-center-security-part-1-traffic-trends, May 21, 2014, 8 pages. [cited by applicant]
Hsieh, et al., “NetVigil: Robust and Low-Cost Anomaly Detection for East-West Data Center Security”, Proceedings of the 21st USENIX Symposium on Networked Systems Design and Implementation, Apr. 16-18, 2024, pp. 1771-17… [cited by applicant]
“Introduction to Cilium & Hubble”, Cilium, Retrieved from URL: https://docs.cilium.io/en/stable/overview/intro/, Retrieved on Jul. 16, 2025, 6 pages. [cited by applicant]
Leland, et al., “On the Self—Similar Nature of Ethernet Traffic”, Conference proceedings on Communications architectures, protocols and applications, Oct. 1, 1993, pp. 183-193. [cited by applicant]
Mchenry, Chris, “A Deeper Look at the Distributed Cloud Firewall: A Firewall for the Cloud Era”, Retrieved from URL: https://aviatrix.com/blog/a-deeper-look-at-the-distributed-cloud-firewall-a-firewall-for-the-cloud-era… [cited by applicant]
“Myricom Sniffer 10G: Sniffer10G Documentation and FAQ”, Retrieved from URL: https://www.myricom.com/software/sniffer10g.html□, Retrieved on Dec. 8, 2015, 3 pages. [cited by applicant]
“Observe. Protect. Adapt.”, Suricata, Retrieved from URL: https://suricata.io/, Retrieved on Jul. 16, 2025, 6 pages. [cited by applicant]
Paxson, Vern, “Bro: a system for detecting network intruders in real-time”, Computer networks, vol. 31, Issue 23-24, Dec. 14, 1999, pp. 2435-2463. [cited by applicant]
“PF_RING™—Open Source packet capture framework”, NTOP, Retrieved from URL: https://www.ntop.org/products/packet-capture/pf_ring/, Retrieved on Jul. 28, 2025, 6 pages. [cited by applicant]
Roesch, Martin, “Short—lightweight intrusion detection for networks”, In Proceedings of Lisa, vol. 99, No. 1, Nov. 7-12, 1999, pp. 229-238. [cited by applicant]
Roy, et al., “Inside the social network's (datacenter) network”, Proceedings of the ACM Conference on Special Interest Group on Data Communication, Aug. 17, 2015, pp. 123-137. [cited by applicant]
“Scaling Suricata Performance to 100 Gbps With Napatech SmartNICs”, Napa: Tech, Retrieved from URL: https://www.napatech.com/support/resources/solution-descriptions/scaling-suricata-performance-to-100-gbps-with-napatech… [cited by applicant]
Schneider, et al., “Packet Capture in 10-Gigabit Ethernet Environments Using Contemporary Commodity Hardware”, International Conference on Passive and Active Network Measurement, 2007, pp. 207-217. [cited by applicant]
“Specs Needed for 10GBps”, Zeek, Retrieved from URL: http://mailman.icsi.berkeley.edu/pipermail/zeek/2019-September/014574.html, Sep. 18, 2019, 1 page. [cited by applicant]
Stoffer, et al., “100G Intrusion Detection”, Berkeley Lab, Aug. 2015, 32 pages. [cited by applicant]
Vallentin, et al., “The NIDS Cluster: Scalable, Stateful Network Intrusion Detection on Commodity Hardware”, International Workshop on Recent Advances in Intrusion Detection, 2007, pp. 107-126. [cited by applicant]
“VMware NSX”, VirtualizationWorks, Retrieved from URL: https://www.virtualizationworks.com/NSX.asp, Retrieved on Jul. 16, 2025, 2 pages. [cited by applicant]
“VMware NSX”, VMware by Broadcom, Retrieved from URL: https://www.vmware.com/products/cloud-infrastructure/nsx.html, Retrieved on Jul. 16, 2025, 8 pages. [cited by applicant]
Weaver, et al., “The Shunt: An FPGA-Based Accelerator for Network Intrusion Prevention”, Proceedings of the ACM/SIGDA 15th international symposium on Field programmable gate arrays, Feb. 18, 2007, pp. 109-206. [cited by applicant]
“2017 Equifax data breach”, Retrieved from: https://en.wikipedia.org/wiki/2017_Equifax_data_breach, Jul. 28, 2023, 10 Pages. [cited by applicant]
“2020 United States federal government data breach”, Retrieved from: https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach, May 17, 2023, 42 Pages. [cited by applicant]
“Cloud Network Security”, Retrieved from: https://www.paloaltonetworks.com/prisma/cloud/cloud-network-security, Retrieved Date: May 6, 2023, 17 Pages. [cited by applicant]
“Data protection”, Retrieved from: https://commission.europa.eu/law/law-topic/data-protection_en, Retrieved Date: May 6, 2023, 3 Pages. [cited by applicant]
“Deep Graph Library”, Retrieved from: https://www.dgl.ai/, Retrieved Date: May 6, 2023, 4 Pages. [cited by applicant]
“Logging IP traffic using VPC Flow Logs”, Retrieved from: https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html, Retrieved Date: May 6, 2023, 14 Pages. [cited by applicant]
“Microsoft Digital Defense Report”, Retrieved from: https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2022, Retrieved Date: May 6, 2023, 4 Pages. [cited by applicant]
“NetworkX”, Retrieved from:https://networkx.org/, Apr. 2023, 1 Page. [cited by applicant]
“Pandas”, Retrieved from: https://pandas.pydata.org/, Retrieved Date: May 6, 2023, 4 Pages. [cited by applicant]
“PyTorch”, Retrieved from: https://pytorch.org/, Retrieved Date: May 6, 2023, 4 Pages. [cited by applicant]
“Simulate, Validate, and Mitigate with the Infection Monkey”, Retrieved from: https://www.akamai.com/infectionmonkey, Retrieved Date: May 6, 2023, 12 Pages. [cited by applicant]
“Zero Trust: the security paradigm for the modern organization”, Retrieved from: https://www.illumio.com/solutions/zero-trust, Retrieved Date: May 6, 2023, 7 Pages. [cited by applicant]
Akoglu, et al., “Graph based Anomaly Detection and Description: A Survey”, In Journal of Data Mining and Knowledge Discovery, vol. 29, Issue 3, May 2015, pp. 626-688. [cited by applicant]
Akoglu, et al., “Oddball: Spotting Anomalies in Weighted Graphs”, In Proceedings of 14th Pacific-Asia Conference in Advances in Knowledge Discovery and Data Mining, Jun. 21, 2010, 12 Pages. [cited by applicant]
Arzani, et al., “PrivateEye: Scalable and Privacy-Preserving Compromise Detection in the Cloud”, In Proceedings of the 17th USENIX Symposium on Networked Systems Design and Implementation, Feb. 25, 2020, pp. 797-815. [cited by applicant]
Bilge, et al., “Before we knew it: An Empirical Study of Zero-day Attacks in the Real World”, In Proceedings of ACM Conference on Computer and Communications Security, Oct. 16, 2012, pp. 833-844. [cited by applicant]
Chakrabarti, Deepayan, “AutoPart: Parameter-Free Graph Partitioning and Outlier Detection”, In Proceedings of 8th European Conference on Principles and Practice of Knowledge Discovery in Databases, Sep. 20, 2004, 12 Pag… [cited by applicant]
Chandola, et al., “Anomaly Detection: A Survey”, In Journal ACM Computing Surveys, vol. 41, Issue 3, Jul. 1, 2009, 58 Pages. [cited by applicant]
Chau, et al., “Detecting Fraudulent Personalities in Networks of Online Auctioneers”, In Proceedings of 10th European Conference on Principles and Practice of Knowledge Discovery in Databases, Sep. 18, 2006, pp. 103-114. [cited by applicant]
Chowdhury, et al., “Unfolding WMMSE using graph neural networks for efficient power allocation”, In Journal of IEEE Transactions on Wireless Communications, vol. 20, Issue 9, Sep. 2021, pp. 6004-6017. [cited by applicant]
Cortes, et al., “Communities of Interest”, In Proceedings of the 4th International Conference in Advances in Intelligent Data Analysis, Sep. 13, 2001, 10 Pages. [cited by applicant]
Dai, et al., “Detecting Anomalies in Bipartite Graphs with Mutual Dependency Principles”, In Proceedings of IEEE 12th International Conference on Data Mining, Dec. 10, 2012, pp. 171-180. [cited by applicant]
Fedus, et al., “Deep Graph Infomax”, In Proceedings of the International Conference on Learning Representations, May 6, 2019, 12 Pages. [cited by applicant]
Fu, et al., “Realtime Robust Malicious Traffic Detection via Frequency Domain Analysis”, In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Nov. 15, 2021, pp. 3431-3446. [cited by applicant]
Noble, et al., “Graph-Based Anomaly Detection”, In Proceedings of Ninth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Aug. 24, 2003, pp. 631-636. [cited by applicant]
Gao, et al., “On Community Outliers and their Efficient Detection in Information Networks”, In Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Jul. 25, 2010, 10 Pages. [cited by applicant]
Hamilton, et al., “Inductive Representation Learning on Large Graphs”, In Proceeding of 31st Conference on Neural Information Processing Systems, Dec. 4, 2017, 11 Pages. [cited by applicant]
Hassani, et al., “Contrastive Multi-View Representation Learning on Graphs”, In International Conference on Machine Learning, Nov. 21, 2020, 11 Pages. [cited by applicant]
He, et al., “An Overview on the Application of Graph Neural Networks in Wireless Networks”, In Journal of IEEE Open Journal of the Communications Society, vol. 2, Nov. 17, 2021, pp. 2547-2565. [cited by applicant]
Hu, et al., “An embedding approach to anomaly detection”, In Proceedings of IEEE 32nd International Conference on Data Engineering, May 16, 2016, pp. 385-396. [cited by applicant]
Hu, et al., “Strategies for Pre-Training Graph Neural Networks”, In Proceedings of 8th International Conference on Learning Representations, Apr. 26, 2020, 22 Pages. [cited by applicant]
Ide, et al., “Eigenspace-Based Anomaly Detection in Computer Systems”, In Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Aug. 22, 2004, pp. 440-449. [cited by applicant]
Modi, et al., “A Survey of Intrusion Detection Techniques in Cloud”, In Journal of Network and Computer Applications, vol. 36, Issue 1, Jan. 2013, 14 Pages. [cited by applicant]
Jiao, et al., “Sub-graph Contrast for Scalable Self-supervised Graph Representation Learning”, In Proceedings of IEEE International Conference on Data Mining, Nov. 17, 2020, pp. 222-231. [cited by applicant]
Kazwini, et al., “Flow Logging for Network Security Groups”, Retrieved from: https://learn.microsoft.com/en-us/azure/network-watcher/network-watcher-nsg-flow-logging-overview, May 24, 2023, 20 Pages. [cited by applicant]
Khraisat, et al., “Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges”, In Journal of Cybersecurity, vol. 2, Jul. 17, 2019, 22 Pages. [cited by applicant]
Kindervag, John, “Build Security into Your Network's DNA: The Zero Trust Network Architecture”, In Forrester Research Inc, vol. 27, Nov. 5, 2010, 27 Pages. [cited by applicant]
Kipf, et al., “Semi-Supervised Classification with Graph Convolutional Networks”, In Proceedings of 5th International Conference on Learning Representations, Apr. 24, 2017, 14 Pages. [cited by applicant]
Kumar, et al., “Signature Based Intrusion Detection System using SNORT”, In International Journal of Computer Applications & Information Technology, vol. 1, Issue III, Nov. 2012, pp. 35-41. [cited by applicant]
Mirsky, et al., “Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection”, In Proceedings of 25th Annual Network and Distributed System Security Symposium, Feb. 18, 2018, 15 Pages. [cited by applicant]
Liao, et al., “Intrusion Detection System: A Comprehensive Review”, In Journal of Network and Computer Applications, vol. 36, Jan. 1, 2013, pp. 16-24. [cited by applicant]
Liu, et al., “Accelerated Local Anomaly Detection via Resolving Attributed Networks”, In Proceedings of Proceedings of the Twenty-Sixth International Joint Conference on Artificial Intelligence, Aug. 29, 2017, pp. 2337-… [cited by applicant]
Liu, et al., “Graph Self-supervised Learning: A Survey”, In Journal of IEEE Transactions on Knowledge and Data Engineering, vol. 35, Issue 6, Jun. 1, 2023, pp. 5879-5900. [cited by applicant]
Lo, et al., “E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IOT”, In Proceedings of IEEE/IFIP Network Operations and Management Symposium, Apr. 25, 2022, 9 Pages. [cited by applicant]
Ma, et al., “A Comprehensive Survey on Graph Anomaly Detection with Deep Learning”, In Journal of IEEE Transactions on Knowledge and Data Engineering, Jan. 8, 2021, 32 Pages. [cited by applicant]
Marcus, Willett, “Lessons of the SolarWinds Hack”, In Journal of Survival vol. 63, Issue 2, Mar. 30, 2021, pp. 7-26. [cited by applicant]
Zhang, et al., “Deep Learning on Graphs: A Survey”, In Journal of IEEE Transactions on Knowledge and Data Engineering, vol. 34, Issue 1, Jan. 1, 2022, pp. 249-270. [cited by applicant]
Zhao, et al., “Achieving 100Gbps Intrusion Prevention on a Single Server”, In 14th USENIX Symposium on Operating Systems Design and Implementation, Nov. 4, 2020, pp. 1083-1100. [cited by applicant]
Zheng, et al., “AddGraph: Anomaly Detection in Dynamic Graph Using Attention-based Temporal GCN”, In Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, vol. 3, Aug. 10, 2019, pp.… [cited by applicant]
Zheng, et al., “One-Class Adversarial Nets for Fraud Detection”, In Proceedings of the Thirty-Third AAAI Conference on Artificial Intelligence, vol. 33, Issue 1, Jul. 17, 2019, pp. 1286-1293. [cited by applicant]
Zhu, et al., “Packet-Level Telemetry in Large Datacenter Networks”, In Proceedings of the ACM Conference on Special Interest Group on Data Communication, Aug. 17, 2015, pp. 479-491. [cited by applicant]
Pang, et al., “Deep Learning for Anomaly Detection: A Review”, In Journal of ACM Computing Surveys, vol. 54, Issue 2, Jan. 2020, 36 Pages. [cited by applicant]
Peng, et al., “Graph Representation Learning via Graphical Mutual Information Maximization”, In Proceedings of the Web Conference, Apr. 20, 2020, 11 Pages. [cited by applicant]
Qiu, et al., “GCC: Graph Contrastive Coding for Graph Neural Network Pre-Training”, In Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, Aug. 2020, 11 Pages. [cited by applicant]
Rahman, et al., “Efficient and Scalable Socware Detection in Online Social Networks”, In Proceedings of the 21st USENIX Conference on Security Symposium, Jun. 2012, 16 Pages. [cited by applicant]
Renovate, et al., “GoogleCloudPlatform / microservices-demo”, Retrieved from: https://github.com/GoogleCloudPlatform/microservices-demo, Jun. 16, 2023, 7 Pages. [cited by applicant]
Rose, et al., “Zero Trust Architecture”, In Publication of NIST Special Publication, Report No. 800-207 Journal, Aug. 10, 2020, 59 Pages. [cited by applicant]
Schneide, Fredb., “Least Privilege and More Computer Security”, In Journal of IEEE Security & Privacy, vol. 1, Issue 5, Oct. 14, 2003, pp. 55-59. [cited by applicant]
Sharma, et al., “Different Firewall techniques: A Survey”, In Proceedings of fifth International Conference on Computing, Communications and Networking Technologies, Jul. 11, 2014, 6 Pages. [cited by applicant]
Sikarwar, et al., “Micro Segmentation: Today's Success Formulae”, In International Journal of Operations Management and Services, vol. 2, Issue 1, Nov. 2012, 6 Pages. [cited by applicant]
Sun, et al., “InfoGraph: Unsupervised and Semi-supervised Graph-level Representation Learning via Mutual Information Maximization”, In International Conference on Learning Representations, Apr. 26, 2020, 16 Pages. [cited by applicant]
Suresh, et al., “Adversarial Graph Augmentation to Improve Graph Contrastive Learning”, In Journal of Advances in Neural Information Processing Systems, Dec. 6, 2021, 14 Pages. [cited by applicant]
Zhu, et al., “Graph Contrastive Learning with Adaptive Augmentation”, In Proceedings of the Web Conference, Apr. 2021, 12 Pages. [cited by applicant]
Teng, et al., “Anomaly Detection in Dynamic Networks using Multi-view Time-series Hypersphere Learning”, In Proceedings of the ACM on Conference on Information and Knowledge Management, Nov. 6, 2017, pp. 827-836. [cited by applicant]
Tian, et al., “Real-time Lateral Movement Detection based on Evidence Reasoning Network for Edge Computing Environment”, In Journal of IEEE Transactions on Industrial Informatics, vol. 15, Issue 7, Jul. 2019, pp. 4285-4… [cited by applicant]
Vanickis, et al., “Access Control Policy Enforcement for Zero-trust-Networking”, In Proceedings of 29th Irish Signals and Systems Conference, Jun. 21, 2018, 6 Pages. [cited by applicant]
Velickovic, et al., “Graph Attention Networks”, In Proceedings of 6th International Conference on Learning Representations, Apr. 30, 2018, 12 Pages. [cited by applicant]
Wang, et al., “Decoupling Representation Learning and Classification for GNN-based Anomaly Detection”, In Proceedings of the 44th International ACM SIGIR Conference on Research and Development in Information Retrieval, … [cited by applicant]
Wang, et al., “Dynamic Graph CNN for Learning on Point Clouds”, In Journal of CM Transactions on Graphics, vol. 38, Issue 5, Oct. 2019, 12 Pages. [cited by applicant]
Wu, et al., “A Comprehensive Survey on Graph Neural Networks”, In Journal of IEEE Transactions on Neural Networks and Learning Systems, vol. 32, Issue 1, Jan. 2021, pp. 4-24. [cited by applicant]
You, et al., “Graph Contrastive Learning Automated”, In Proceedings of the 38th International Conference on Machine Learning, Jul. 1, 2021, 12 Pages. [cited by applicant]
You, et al., “Graph Contrastive Learning with Augmentations”, In Proceedings of 34th Conference on Neural Information Processing Systems, Dec. 6, 2020, 12 Pages. [cited by applicant]
Zhou, et al., “Graph Neural Networks: A Review of Methods and Applications”, In Journal of AI open, vol. 1, Jan. 1, 2020, pp. 57-81. [cited by applicant]
Gamage, et al., “Deep Learning Methods in Network Intrusion Detection: A Survey and an Objective Comparison”, In Journal of Network and Computer Applications, vol. 169, Nov. 1, 2020. [cited by applicant]
Jiang, Weiwei, “Graph-based Deep Learning for Communication Networks: A Survey”, In Journal of Computer Communications, vol. 185, Mar. 1, 2022. [cited by applicant]
Kwon, et al., “A Survey of Deep Learning-based Network Anomaly Detection”, In Journal of Cluster Computing, vol. 22, Jan. 2019. [cited by applicant]
Masdari, et al., “A Survey and Taxonomy of the Fuzzy Signature-based Intrusion Detection Systems”, In Journal of Applied Soft Computing, vol. 92, Jul. 2020. [cited by applicant]
Tankard, Colin, “Advanced Persistent Threats and How to Monitor and Deter Them”, In Journal of Network Security, vol. 2011, Issue 8, Aug. 2011, pp. 16-19. [cited by applicant]