Cyber Threat Intelligence Sharing Scheme Based on Federated Learning for Network Intrusion Detection

被引:0
|
作者
Mohanad Sarhan
Siamak Layeghy
Nour Moustafa
Marius Portmann
机构
[1] University of Queensland,
[2] University of New South Wales,undefined
关键词
Cyber threat intelligence; Federated learning; Machine learning; NetFlow; Network intrusion detection;
D O I
暂无
中图分类号
学科分类号
摘要
The uses of machine learning (ML) technologies in the detection of network attacks have been proven to be effective when designed and evaluated using data samples originating from the same organisational network. However, it has been very challenging to design an ML-based detection system using heterogeneous network data samples originating from different sources and organisations. This is mainly due to privacy concerns and the lack of a universal format of datasets. In this paper, we propose a collaborative cyber threat intelligence sharing scheme to allow multiple organisations to join forces in the design, training, and evaluation of a robust ML-based network intrusion detection system. The threat intelligence sharing scheme utilises two critical aspects for its application; the availability of network data traffic in a common format to allow for the extraction of meaningful patterns across data sources and the adoption of a federated learning mechanism to avoid the necessity of sharing sensitive users’ information between organisations. As a result, each organisation benefits from the intelligence of other organisations while maintaining the privacy of its data internally. In this paper, the framework has been designed and evaluated using two key datasets in a NetFlow format known as NF-UNSW-NB15-v2 and NF-BoT-IoT-v2. In addition, two other common scenarios are considered in the evaluation process; a centralised training method where local data samples are directly shared with other organisations and a localised training method where no threat intelligence is shared. The results demonstrate the efficiency and effectiveness of the proposed framework by designing a universal ML model effectively classifying various benign and intrusive traffic types originating from multiple organisations without the need for inter-organisational data exchange.
引用
收藏
相关论文
共 50 条
  • [1] Cyber Threat Intelligence Sharing Scheme Based on Federated Learning for Network Intrusion Detection
    Sarhan, Mohanad
    Layeghy, Siamak
    Moustafa, Nour
    Portmann, Marius
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (01)
  • [2] BFLS: Blockchain and Federated Learning for sharing threat detection models as Cyber Threat Intelligence
    Jiang, Tongtong
    Shen, Guowei
    Guo, Chun
    Cui, Yunhe
    Xie, Bo
    [J]. COMPUTER NETWORKS, 2023, 224
  • [3] Campus Network Intrusion Detection based on Federated Learning
    Chen, Junjun
    Guo, Qiang
    Fu, Zhongnan
    Shang, Qun
    Ma, Hao
    Wu, Di
    [J]. 2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [4] LUUNU - BLOCKCHAIN, MISP, MODEL CARDS AND FEDERATED LEARNING ENABLED CYBER THREAT INTELLIGENCE SHARING PLATFORM
    Bandara, Eranga
    Shetty, Sachin
    Mukkamala, Ravi
    Rahaman, Abdul
    Liang, Xueping
    [J]. PROCEEDINGS OF THE 2022 ANNUAL MODELING AND SIMULATION CONFERENCE (ANNSIM'22), 2022, : 235 - 245
  • [5] A survey on cyber threat intelligence sharing based on Blockchain
    Ahmed El-Kosairy
    Nashwa Abdelbaki
    Heba Aslan
    [J]. Advances in Computational Intelligence, 2023, 3 (3):
  • [6] A federated learning method for network intrusion detection
    Tang, Zhongyun
    Hu, Haiyang
    Xu, Chonghuan
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2022, 34 (10):
  • [7] Boosting Cyber-Threat Intelligence via Collaborative Intrusion Detection
    Guarascio, Massimo
    Cassavia, Nunziato
    Pisani, Francesco Sergio
    Manco, Giuseppe
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 135 : 30 - 43
  • [8] Boosting Cyber-Threat Intelligence via Collaborative Intrusion Detection
    Guarascio, Massimo
    Cassavia, Nunziato
    Pisani, Francesco Sergio
    Manco, Giuseppe
    [J]. Future Generation Computer Systems, 2022, 135 : 30 - 43
  • [9] Artificial Intelligence-Based Anomalies Detection Scheme for Identifying Cyber Threat on IoT-Based Transport Network
    Gupta, Huma
    Sharma, Sanjeev
    Agrawal, Sanjay
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 1716 - 1724
  • [10] Cyber Security Threat Intelligence Sharing Model Based on Blockchain
    Huang K.
    Lian Y.
    Feng D.
    Zhang H.
    Liu Y.
    Ma X.
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2020, 57 (04): : 836 - 846