Related Experiment Video
Updated: Aug 28, 2025

11:18
Closed-loop Neuro-robotic Experiments to Test Computational Properties of Neuronal Networks
Published on: March 2, 2015
10.4K
Graph neural networks and cross-protocol analysis for detecting malicious IP addresses
Yonghong Huang1, Joanna Negrete2, John Wagener3
1Hillsboro, OR 97229 USA.
Summary
This study introduces a novel method using cross-protocol analysis and graph neural networks (GNNs) for faster, scalable internet protocol (IP) reputation assessment. The approach effectively identifies malicious IP addresses with high accuracy, even with limited labeled data, enhancing online security.
Area of Science:
- Cybersecurity
- Machine Learning
- Network Security
Background:
- Internet Protocol (IP) addresses are fundamental to global connectivity, but assessing their security risk is complex due to heterogeneous services.
- Adversaries exploit the ambiguity of IP reputation, while traditional methods like dirty-listing lack speed and scalability for emerging threats.
- The dynamic nature of cyber threats requires advanced techniques to accurately assess IP reputation in real-time.
Purpose of the Study:
- To develop a more efficient and scalable method for assessing internet protocol (IP) address reputation.
- To address the limitations of traditional IP reputation assessment techniques in speed and scalability.
- To leverage cross-protocol analysis and graph neural networks (GNNs) for improved detection of malicious IP addresses.
Main Methods:
- Implemented a cross-protocol supervised approach, combining features from web, email, and Domain Name System (DNS) protocols.
- Utilized graph neural networks (GNNs) with discriminant features incorporated as node features for semi-supervised learning.
- Trained the algorithm on a sparse, real-world dataset with a small percentage of labeled IP addresses.
Main Results:
- Achieved high accuracy in detecting malicious IP addresses at scale.
- Demonstrated the effectiveness of the GNN-based approach with a limited amount of labeled data ().
- The system successfully identified suspicious IPs by leveraging relational graph structures and neighbor influence.
Conclusions:
- Cross-protocol analysis combined with GNNs offers a powerful solution for scalable and rapid IP reputation assessment.
- Semi-supervised learning with GNNs significantly reduces the need for extensive labeled data in cybersecurity applications.
- This approach enhances the ability to detect and mitigate emerging cyber threats, improving overall internet security posture.

