New Continual Federated Learning System for Intrusion Detection in SDN-Based Edge Computing

被引:0
|
作者
Chetouane, Ameni [1 ]
Karoui, Kamel [2 ]
机构
[1] Univ Manouba, Natl Sch Comp Sci, Manouba, Tunisia
[2] Univ Carthage, Natl Inst Appl Sci & Technol, Tunis, Tunisia
来源
关键词
continual learning; federated learning; intrusion detection; network security; security threats; software defined networking;
D O I
10.1002/cpe.8332
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software Defined Networking (SDN) is an open network approach that has been proposed to address some of the main problems with traditional networks. However, SDN faces cybersecurity issues. To provide a network defense against attacks, an Intrusion Detection System (IDS) needs to be updated and included into the SDN architecture on a regular basis. Machine learning methods have proved effective in detecting intrusions in SDN. Moreover, these techniques pose the problem of significant computational overload and the absence of regular updates when new cyber-attacks appear. To address these issues, we propose a new SDN-based cloud intrusion detection system called Continual Federated Learning (CFL). In CFL, we modify the classical federated learning process by granting a more important and dynamic role to each participating client. On the one hand, it can trigger this process whenever a new type of intrusion is detected. On the other hand, once the new model has been identified, the customer can decide whether or not to deploy it in his network. In addition, to verify the accuracy of the CFL system, we have formally specified it by a communication protocol. This specification organizes the exchanges between the different communicating entities involved in the CFL. To verify the accuracy of this specification, we described it using the PROMELA language and checked with the associated SPIN tool. On the experimental side, we deployed this specification of the CFL system in an SDN computing environment. We defined different scenarios, and we proposed that each client decides locally to deploy or not the newly obtained intrusion detection model. The decision is based on a modified metric where we integrate the severity of the intrusions. Experimental results using private local datasets show that the proposed CFL system can efficiently and accurately detect new types of intrusions while preserving client confidentiality. Thus, it can be considered a promising system for SDN-based edge computing.
引用
收藏
页数:18
相关论文
共 50 条
  • [11] SDN-based intrusion detection system for IoT using deep learning classifier (IDSIoT-SDL)
    Wani, Azka
    Revathi, S.
    Khaliq, Rubeena
    CAAI TRANSACTIONS ON INTELLIGENCE TECHNOLOGY, 2021, 6 (03) : 281 - 290
  • [12] Intrusion Detection for Wireless Edge Networks Based on Federated Learning
    Chen, Zhuo
    Lv, Na
    Liu, Pengfei
    Fang, Yu
    Chen, Kun
    Pan, Wu
    IEEE ACCESS, 2020, 8 (08): : 217463 - 217472
  • [13] Resource optimization in edge and SDN-based edge computing: a comprehensive study
    Nain, Ajay
    Sheikh, Sophiya
    Shahid, Mohammad
    Malik, Rohit
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (05): : 5517 - 5545
  • [14] A distributed SDN-based intrusion detection system for IoT using optimized forests
    Luo, Ke
    PLOS ONE, 2023, 18 (08):
  • [15] SDN-Based Network Intrusion Detection as DDoS defense system for Virtualization Environment
    Usman, Saifudin
    Winarno, Idris
    Sudarsono, Amang
    EMITTER-INTERNATIONAL JOURNAL OF ENGINEERING TECHNOLOGY, 2021, 9 (02) : 252 - 267
  • [16] Intrusion Detection Using Federated Learning for Computing
    Aashmi R.S.
    Jaya T.
    Computer Systems Science and Engineering, 2023, 45 (02): : 1295 - 1308
  • [17] Ensemble Learning for Intrusion Detection in SDN-Based Zero Touch Smart Grid Systems
    El Houda, Zakaria Abou
    Brik, Bouziane
    Khoukhi, Lyes
    PROCEEDINGS OF THE 2022 47TH IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2022), 2022, : 149 - 156
  • [18] FBA-SDN: A Federated Byzantine Approach for Blockchain-based Collaborative Intrusion Detection in Edge SDN
    Hayes, John
    Aneiba, Adel
    Gaber, Mohamed
    Islam, Md Shantanu
    Abozariba, Raouf
    2023 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS, 2023, : 427 - 433
  • [19] A Secured Framework for SDN-Based Edge Computing in IoT-Enabled Healthcare System
    Li, Junxia
    Cai, Jinjin
    Khan, Fazlullah
    Rehman, Ateeq Ur
    Balasubramaniam, Venki
    Sun, Jiangfeng
    Venu, P.
    IEEE ACCESS, 2020, 8 : 135479 - 135490
  • [20] An SDN-based Intrusion Detection System using SVM with Selective Logging for IP Traceback
    Hadem, Pynbianglut
    Saikia, Dilip Kumar
    Moulik, Soumen
    COMPUTER NETWORKS, 2021, 191