• e - ISSN No : 2832-4277
IJRTTE Logo

INTERNATIONAL JOURNAL OF RECENT TRENDS IN TECHNOLOGY AND ENGINEERING (IJRTTE)

Autonomous Cyber-Risk Scoring Using Graph Neural Signature

P. K. Anjani
Professor, Department of Management Studies, Sona College of Technology, India.
Muthukumar K
Associate Professor, Department of Electrical and Electronics Engineering, Sri Krishna College of Engineering and Technology, Inia.
R Roseline
Assistant Professor, PG Department of Computer Applications, St. Joseph's College of Arts and Science (Autonomous), India.

Keywords: Autonomous Cyber-Risk Scoring; Graph Neural Signatures; Cybersecurity Knowledge Graph; Dynamic Attack Graph; Explainable GNN; Risk Propagation; Intrusion Detection; Threat Intelligence; AI-Driven Cyber Defense.

Abstract

Cyberattacks are now more dynamic, quick, and hard to track using conventional security measures. The current models of intrusion detection and risk scoring are mainly limited to detection of attacks, are based on static rules,or do not offer capabilities of interpretation and instant prioritization of risks. To solve these problems, this paper proposes an Autonomous Cyber-Risk Scoring System based on Graph Neural Signatures (ACRSGNS). The suggested framework integrates dynamic attack graphs, knowledge graphs of cybersecurity, and graph neural networks and learns structural and behavioral patterns of cyber threats automatically. Such patterns that are referred to as graph neural signatures help the system to compute correct and interpretable risk scores of network assets, users and connections. Multi-hop attack propagation is also modeled and the human understandable explanations are given to the risks decision. Experiments using real-world data indicate that ACS-GNS outperforms the currently existing models using GNNs as well as knowledgegraphs in terms of the quality of risk scoring, attack-path prediction, explain ability, and processing time. In general, this piece of work illustrates a coherent and clever methodology of real-time evaluation of cyber-risk, which can be adopted in the contemporary SOC setting.
Download Certificate
Details

References

  1. François, M., Ardila, P.-H., & Messaï, M. (2025). Physics-Informed Graph Neural Networks for Attack Path Prediction. Journal of Cybersecurity and Privacy, 5(2), 15. https://doi.org/10.3390/jcp5020015
  2. Ilot, T., Madhoun, N. E., Agha, K. A., & Zannou, A. (2023). Graph neural networks for intrusion detection: A survey. IEEE Access, 11, 49114–49139. https://doi.org/10.1109/ACCESS.2023.3273519
  3. Zhong, M., Lin, M., Zhang, C., & Xu, Z. (2024). A survey on graph neural networks for intrusion detection systems: Methods, trends and challenges. Computers & Security, 141, 103821. https://doi.org/10.1016/j.cose.2024.103821
  4. Altaf, T., Wang, X. M. W., Yu, G., Liu, R. P., & Braun, R. (2024). GNN-based network traffic analysis for the detection of sequential attacks in IoT. Electronics, 13(12), 2274. https://doi.org/10.3390/electronics13122274
  5. Le, H.-D., & Park, M. (2024). Enhancing multi-class attack detection in graph neural network through feature aware management. Electronics, 13(12), 2404. https://doi.org/10.3390/electronics13122404
  6. Wang, Y., Han, Z., Du, Y., & others. (2025). HS-GAT: A network intrusion detection system based on graph neural network for edge computing. Cybersecurity, 8, 27. https://doi.org/10.1186/s42400-025-00396-5
  7. Nguyen, T.-T., & Park, M. (2025). HL-GNN: A continual-learning-based graph neural network for multi-incremental intrusion detection systems. Electronics, 14(14), 2756. https://doi.org/10.3390/electronics14142756
  8. Shen, L. F. (2023). Cybersecurity knowledge graphs. Knowledge and Information Systems, 65, 3511–3551. https://doi.org/10.1007/s10115-023-01890-3
  9. Liu, K., Wang, F., Ding, Z., Liang, S., Yu, Z., & Zhou, Y. (2022). Recent progress of using knowledge graph for cybersecurity. Electronics, 11(15), 2257. https://doi.org/10.3390/electronics11152257
  10. Wang, P., Liu, J., Hao, D., & Zhou, S. (2022). A cybersecurity knowledge graph completion method based on ensemble learning and adversarial training. Applied Sciences, 12(24), 12947. https://doi.org/10.3390/app122412947
  11. Li, H., Yang, Q., Deng, C., & Pan, H. (2025). CyberKGC: Constructing a cybersecurity knowledge graph based on SecureBERT Plus for CTI reports. Informatics, 12(3), 100. https://doi.org/10.3390/informatics12030100
  12. Piplai, A., Mittal, S., Joshi, A., Finin, T., Holt, J., & Zak, R. (2020). Creating cybersecurity knowledge graphs from malware after action reports. IEEE Access, 8, 211691–211703. https://doi.org/10.1109/ACCESS.2020.3039234
  13. Zhao, X., Jiang, R., Han, Y., Li, A., & Peng, Z. (2024). A survey on cybersecurity knowledge graph construction. Computers & Security, 138, 103524. https://doi.org/10.1016/j.cose.2023.103524
  14. Alarifi, H., Hsie, A., Albalawi, H., & Ahmad, H. (2025). Enhancing cybersecurity through autonomous knowledge graph construction by integrating heterogeneous data sources. PeerJ Computer Science, 11, e2768. https://doi.org/10.7717/peerj-cs.2768
  15. Gillani, E., Liu, J., & Abubakar Aliyu, A. (2024). Knowledge graph reasoning for cyber attack detection. IET Communications, 18(2), e3–e? https://doi.org/10.1049/cmu2.12736
  16. Wang, P., Zhang, Y., Zhou, Z., & Wang, Y. (2025). SE-LKM: A semantic chunking and large language model-based cybersecurity knowledge graph construction method. Electronics, 14(14), 2578. https://doi.org/10.3390/electronics14142578
  17. Cremer, F., Sheehan, B., Fortmann, M., & others. (2022). Cyber risk and cybersecurity: A systematic review of data availability. The Geneva Papers on Risk and Insurance - Issues and Practice, 47, 698–736. https://doi.org/10.1057/s41288-022-00266-6
  18. Gandhi, P., & Raffinot, E. (2021). Explainable AI methods in cyber risk management. Quality and Reliability Engineering International, 37(6), 2515–2527. https://doi.org/10.1002/qre.2979
  19. Hariri, L., & Rahman, M. M. H. (2025). AI, machine learning and deep learning in cyber risk management. Discover Sustainability, 6, 359. https://doi.org/10.1007/s43621-025-01012-3
  20. Zadeh, A., Lavies, B., Zehburin, H., & Hopkin, D. (2023). A cybersecurity risk quantification and classification framework for informed risk mitigation decisions. Decision Analytics Journal, 9, 100328. https://doi.org/10.1016/j.dajour.2023.100328
  21. Yao, D., & Garcia de Soto, B. (2024). Cyber risk assessment framework for the construction industry using machine learning techniques. Buildings, 14(6), 1561. https://doi.org/10.3390/buildings14061561
  22. Adeboye, O. A., Akter, H. F., & Lalib, H. S. (2025). Quantifying the multidimensional impact of cyber attacks in digital financial services: A systematic literature review. Sensors, 25(14), 4345. https://doi.org/10.3390/s25144345
  23. Devilyal, S., Goyal, H. R., & Sharma, S. (2025). ICDRIFT: A dynamic cyber risk estimation technique for intelligent cyber-physical systems in PCS. The Open Bioinformatics Journal, 18. https://doi.org/10.2174/011187503062358002250600083754
  24. Celesar, R. M., Webber, T., Fontesana, L. H., & Marcos, C. (2025). Dynamic risk assessment approach for analyzing cyber security events in medical IoT networks. Internet of Things, 29, 101437. https://doi.org/10.1016/j.iot.2024.101437