New Continual Federated Learning System for Intrusion Detection in SDN-Based Edge Computing

被引:0
|
作者
Chetouane, Ameni [1 ]
Karoui, Kamel [2 ]
机构
[1] Univ Manouba, Natl Sch Comp Sci, Manouba, Tunisia
[2] Univ Carthage, Natl Inst Appl Sci & Technol, Tunis, Tunisia
来源
关键词
continual learning; federated learning; intrusion detection; network security; security threats; software defined networking;
D O I
10.1002/cpe.8332
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software Defined Networking (SDN) is an open network approach that has been proposed to address some of the main problems with traditional networks. However, SDN faces cybersecurity issues. To provide a network defense against attacks, an Intrusion Detection System (IDS) needs to be updated and included into the SDN architecture on a regular basis. Machine learning methods have proved effective in detecting intrusions in SDN. Moreover, these techniques pose the problem of significant computational overload and the absence of regular updates when new cyber-attacks appear. To address these issues, we propose a new SDN-based cloud intrusion detection system called Continual Federated Learning (CFL). In CFL, we modify the classical federated learning process by granting a more important and dynamic role to each participating client. On the one hand, it can trigger this process whenever a new type of intrusion is detected. On the other hand, once the new model has been identified, the customer can decide whether or not to deploy it in his network. In addition, to verify the accuracy of the CFL system, we have formally specified it by a communication protocol. This specification organizes the exchanges between the different communicating entities involved in the CFL. To verify the accuracy of this specification, we described it using the PROMELA language and checked with the associated SPIN tool. On the experimental side, we deployed this specification of the CFL system in an SDN computing environment. We defined different scenarios, and we proposed that each client decides locally to deploy or not the newly obtained intrusion detection model. The decision is based on a modified metric where we integrate the severity of the intrusions. Experimental results using private local datasets show that the proposed CFL system can efficiently and accurately detect new types of intrusions while preserving client confidentiality. Thus, it can be considered a promising system for SDN-based edge computing.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Federated Learning Inspired Low-Complexity Intrusion Detection and Classification Technique for SDN-Based Industrial CPS
    Zainudin, Ahmad
    Akter, Rubina
    Kim, Dong-Seong
    Lee, Jae-Min
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (03): : 2442 - 2459
  • [2] Grid False Data Intrusion Detection Method Based on Edge Computing and Federated Learning
    Zhang, Yiying
    Liu, Yiyang
    Zhang, Nan
    Wang, Delong
    Zhang, Suxiang
    Wu, Yannian
    3D IMAGING-MULTIDIMENSIONAL SIGNAL PROCESSING AND DEEP LEARNING, VOL 1, 2022, 297 : 179 - 188
  • [3] Survey On SDN-based Intrusion Detection Systems
    Mostafa, Naneese
    Metwally, Khaled
    Badran, Khaled
    2024 14TH INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING, ICEENG 2024, 2024, : 317 - 322
  • [4] Blockchain and Federated Learning for Collaborative Intrusion Detection in Vehicular Edge Computing
    Liu, Hong
    Zhang, Shuaipeng
    Zhang, Pengfei
    Zhou, Xinqiang
    Shao, Xuebin
    Pu, Geguang
    Zhang, Yan
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2021, 70 (06) : 6073 - 6084
  • [5] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    INFORMATION, 2019, 10 (03)
  • [6] Deep Learning Feature Fusion Approach for an Intrusion Detection System in SDN-Based IoT Networks
    Ravi V.
    Chaganti R.
    Alazab M.
    IEEE Internet of Things Magazine, 2022, 5 (02): : 24 - 29
  • [7] Intelligent Resource Management at the Edge for Ubiquitous IoT: An SDN-Based Federated Learning Approach
    Balasubramanian, Venkatraman
    Alogaily, Moayad
    Reisslein, Martin
    Scaglione, Anna
    IEEE NETWORK, 2021, 35 (05): : 114 - 121
  • [8] Poster: A SDN-based Network Layer for Edge Computing
    Wang, An
    Zha, Zili
    Guo, Yang
    Chen, Songqing
    SEC'19: PROCEEDINGS OF THE 4TH ACM/IEEE SYMPOSIUM ON EDGE COMPUTING, 2019, : 334 - 336
  • [9] Federated Transfer Learning With Client Selection for Intrusion Detection in Mobile Edge Computing
    Cheng, Yanyu
    Lu, Jianyuan
    Niyato, Dusit
    Lyu, Biao
    Kang, Jiawen
    Zhu, Shunmin
    IEEE COMMUNICATIONS LETTERS, 2022, 26 (03) : 552 - 556
  • [10] SDN-Based Kernel Modular Countermeasure for Intrusion Detection
    Chin, Tommy
    Xiong, Kaiqi
    Rahouti, Mohamed
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 270 - 290