Reducing Visibility-Graph Metrics for More Efficient Cyber-Attack Detection
Summary
This study examines whether cyber-attack classification based on Natural Visibility Graph (NVG) network-traffic descriptors can use fewer metrics without losing predictive capability. It evaluates 21 NVG-derived topological metrics and combines SHAP, grouped Permutation Importance, Boruta, and Recursive Feature Elimination into a Consensus Ranking. The ranked subsets, containing 15, 10, 7, 5, or 3 metrics, are tested against the full 21-metric configuration on the CICIDS2018 dataset with a CNN classifier and stratified five-fold cross-validation. The three highest-ranked metrics are the median, standard deviation, and mean of average clustering coefficient. In the reported evaluation, the Top3 configuration produced the highest observed mean accuracy, weighted F1 score, and Matthews correlation coefficient: 97.148%, 97.055%, and 0.9675, compared with 95.999%, 95.521%, and 0.9549 for Full21. Top3 also reduced total runtime from 14,961.39 seconds to 589.22 seconds, a 96.06% reduction. The results support importance-guided metric reduction as a compact NVG representation under this dataset, classifier, and validation setting.