Cyber threat hunting using unsupervised federated learning and adversary emulation

被引:0
|
作者
Sheikhi, Saeid [1 ]
Kostakos, Panos [1 ]
机构
[1] Univ Oulu, Fac Informat Technol & Elect Engn, Ctr Ubiquitous Comp, Oulu, Finland
来源
2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR | 2023年
基金
芬兰科学院;
关键词
Threat hunting; Cyber threats; Threat actors; Federated learning; adversary emulation;
D O I
10.1109/CSR57506.2023.10224990
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rapid growth of communication networks, coupled with the increasing complexity of cyber threats, necessitates the implementation of proactive measures to protect networks and systems. In this study, we introduce a federated learning-based approach for cyber threat hunting at the endpoint level. The proposed method utilizes the collective intelligence of multiple devices to effectively and confidentially detect attacks on individual machines. A security assessment tool is also developed to emulate the behavior of adversary groups and Advanced Persistent Threat (APT) actors in the network. This tool provides network security experts with the ability to assess their network environment's resilience and aids in generating authentic data derived from diverse threats for use in subsequent stages of the federated learning (FL) model. The results of the experiments demonstrate that the proposed model effectively detects cyber threats on the devices while safeguarding privacy.
引用
收藏
页码:315 / 320
页数:6
相关论文
共 50 条
  • [1] Offensive Security: Towards Proactive Threat Hunting via Adversary Emulation
    Ajmal, Abdul Basit
    Shah, Munam Ali
    Maple, Carsten
    Asghar, Muhammad Nabeel
    Ul Islam, Saif
    IEEE ACCESS, 2021, 9 : 126023 - 126033
  • [2] Toward Effective Evaluation of Cyber Defense: Threat Based Adversary Emulation Approach
    Ajmal, Abdul Basit
    Khan, Shawal
    Alam, Masoom
    Mehbodniya, Abolfazl
    Webber, Julian
    Waheed, Abdul
    IEEE ACCESS, 2023, 11 : 70443 - 70458
  • [3] Cyber threat detection: Unsupervised hunting of anomalous commands (UHAC)
    Kayhan, Varol O.
    Agrawal, Manish
    Shivendu, Shivendu
    DECISION SUPPORT SYSTEMS, 2023, 168
  • [4] Block Hunter: Federated Learning for Cyber Threat Hunting in Blockchain-Based IIoT Networks
    Yazdinejad, Abbas
    Dehghantanha, Ali
    Parizi, Reza M.
    Hammoudeh, Mohammad
    Karimipour, Hadis
    Srivastava, Gautam
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (11) : 8356 - 8366
  • [5] An ensemble deep federated learning cyber-threat hunting model for Industrial Internet of Things
    Jahromi, Amir Namavar
    Karimipour, Hadis
    Dehghantanha, Ali
    COMPUTER COMMUNICATIONS, 2023, 198 : 108 - 116
  • [6] Automated Adversary Emulation for Cyber-Physical Systems via Reinforcement Learning
    Bhattacharya, Arnab
    Ramachandran, Thiagarajan
    Banik, Sandeep
    Dowling, Chase P.
    Bopardikar, Shaunak D.
    2020 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2020, : 1 - 6
  • [7] Robust Cyber Threat Intelligence Sharing Using Federated Learning for Smart Grids
    Rahman, Saifur
    Pal, Shantanu
    Jadidi, Zahra
    Karmakar, Chandan
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2024,
  • [8] Lurking in the shadows: Unsupervised decoding of beaconing communication for enhanced cyber threat hunting
    Mahboubi, Arash
    Luong, Khanh
    Jarrad, Geoff
    Camtepe, Seyit
    Bewong, Michael
    Bahutair, Mohammed
    Pogrebna, Ganna
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2025, 236
  • [9] Enabling Efficient Cyber Threat Hunting With Cyber Threat Intelligence
    Gao, Peng
    Shao, Fei
    Liu, Xiaoyuan
    Xiao, Xusheng
    Qin, Zheng
    Xu, Fengyuan
    Mittal, Prateek
    Kulkarni, Sanjeev R.
    Song, Dawn
    2021 IEEE 37TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2021), 2021, : 193 - 204
  • [10] Cyber Threat Hunting Using Large Language Models
    Tanksale, Vinayak
    PROCEEDINGS OF NINTH INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, VOL 5, ICICT 2024, 2024, 1000 : 629 - 641