Cyber Threat Intelligence Sharing Scheme Based on Federated Learning for Network Intrusion Detection

Author:

Sarhan Mohanad,Layeghy Siamak,Moustafa Nour,Portmann Marius

Abstract

AbstractThe uses of machine learning (ML) technologies in the detection of network attacks have been proven to be effective when designed and evaluated using data samples originating from the same organisational network. However, it has been very challenging to design an ML-based detection system using heterogeneous network data samples originating from different sources and organisations. This is mainly due to privacy concerns and the lack of a universal format of datasets. In this paper, we propose a collaborative cyber threat intelligence sharing scheme to allow multiple organisations to join forces in the design, training, and evaluation of a robust ML-based network intrusion detection system. The threat intelligence sharing scheme utilises two critical aspects for its application; the availability of network data traffic in a common format to allow for the extraction of meaningful patterns across data sources and the adoption of a federated learning mechanism to avoid the necessity of sharing sensitive users’ information between organisations. As a result, each organisation benefits from the intelligence of other organisations while maintaining the privacy of its data internally. In this paper, the framework has been designed and evaluated using two key datasets in a NetFlow format known as NF-UNSW-NB15-v2 and NF-BoT-IoT-v2. In addition, two other common scenarios are considered in the evaluation process; a centralised training method where local data samples are directly shared with other organisations and a localised training method where no threat intelligence is shared. The results demonstrate the efficiency and effectiveness of the proposed framework by designing a universal ML model effectively classifying various benign and intrusive traffic types originating from multiple organisations without the need for inter-organisational data exchange.

Funder

The University of Queensland

Publisher

Springer Science and Business Media LLC

Subject

Strategy and Management,Computer Networks and Communications,Hardware and Architecture,Information Systems

Reference50 articles.

1. Javaid, A., Niyaz, Q., Sun, W., Alam, M.: A deep learning approach for network intrusion detection system. EAI Endorsed Trans. Secur. Saf. 3(9), e2 (2016)

2. Whitman, M.E., Mattord, H.J.: Principles of Information Security. Cengage Learning, Boston (2011)

3. Ashoor, A.S., Gore, S.: Importance of intrusion detection system (ids). Int. J. Sci. Eng. Res. 2(1), 1–4 (2011)

4. Garcia-Teodoro, P., Diaz-Verdejo, J., Maciá-Fernández, G., Vázquez, E.: Anomaly-based network intrusion detection: techniques, systems and challenges. Comput. Secur. 28(1–2), 18–28 (2009)

5. van der Eijk, V., Schuijt, C.: Detecting cobalt strike beacons in netflow data

Cited by 38 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. XAITrafficIntell: Interpretable Cyber Threat Intelligence for Darknet Traffic Analysis;Journal of Network and Systems Management;2024-09-05

2. A federated learning-based zero trust intrusion detection system for Internet of Things;Ad Hoc Networks;2024-09

3. Against network attacks in renewable power plants: Malicious behavior defense for federated learning;Computer Networks;2024-08

4. Study on Empowering Cyber Security by Using Adaptive Machine Learning Methods;2024 Systems and Information Engineering Design Symposium (SIEDS);2024-05-03

5. Risk Prediction and Management for Effective Cyber Security Using Weighted Fuzzy C Means Clustering;2024 Third International Conference on Distributed Computing and Electrical Circuits and Electronics (ICDCECE);2024-04-26

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3