FedChain-Hunter: A reliable and privacy-preserving aggregation for federated threat hunting framework in SDN-based IIoT

被引:7
作者
Duy, Phan The
Quyen, Nguyen Huu
Khoa, Nghi Hoang
Tran, Tuan-Dung
Pham, Van-Hau [1 ]
机构
[1] Univ Informat Technol, Informat Secur Lab, Ho Chi Minh City, Vietnam
关键词
Software defined networking; SDN; Federated learning; Blockchain; Data privacy; Secure aggregation; Threat hunting; Industrial internet of things; BLOCKCHAIN;
D O I
10.1016/j.iot.2023.100966
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the development of the Industrial Internet of Things (IIoT), cyber threats and attacks have become major issues and concerns in Industry 4.0 due to the negative impacts on the infrastructures and services across organizations. Nevertheless, due to the issues in preserving privacy and transparency, there is a lack of threat intelligence sharing among parties, leading to the low performance in uncovering malicious actors. In fact, the method of gathering and exploiting such data has been getting more crucial in a trend of machine learning (ML) adoption in cybersecurity. In this scenario, Federated Learning (FL) can assume a significant role in constructing an ML-based threat hunting solution for IIoT networks. This can be achieved by harnessing data resources from diverse parties, utilizing a local training strategy that eliminates the need for centralized data collection. Hence, this paper proposes FedChain-Hunter, a blockchain and FL-based threat-hunting framework to mutually seek cyber threats while ensuring data privacy and the transparency in the contribution of data owners. Specifically, Software Defined Networking (SDN) with programmable and flexible security orchestration is used to easily monitor and gather appropriate security events in the IIoT network. In addition, the Fully Homomorphic Encryption (HE) and Differential Privacy (DP) are integrated into the FL scheme to provide strong security and privacy-preserving aggregation for each ML model update. Also, the blockchain adoption offers the transparency, auditability for collaboration and contribution management through a decentralized platform. The experimental results on 5 datasets indicate that FedChain-Hunter can achieve high performance for cyber threat detection with security, reliability, and privacy guarantee.
引用
收藏
页数:23
相关论文
共 86 条
[1]   Federated Intrusion Detection in Blockchain-Based Smart Transportation Systems [J].
Abdel-Basset, Mohamed ;
Moustafa, Nour ;
Hawash, Hossam ;
Razzak, Imran ;
Sallam, Karam M. ;
Elkomy, Osama M. .
IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (03) :2523-2537
[2]   Federated Threat-Hunting Approach for Microservice-Based Industrial Cyber-Physical System [J].
Abdel-Basset, Mohamed ;
Hawash, Hossam ;
Sallam, Karam .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (03) :1905-1917
[3]   A Survey on Federated Learning: The Journey From Centralized to Distributed On-Site Learning and Beyond [J].
AbdulRahman, Sawsan ;
Tout, Hanine ;
Ould-Slimane, Hakima ;
Mourad, Azzam ;
Talhi, Chamseddine ;
Guizani, Mohsen .
IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (07) :5476-5497
[4]   A Survey on Homomorphic Encryption Schemes: Theory and Implementation [J].
Acar, Abbas ;
Aksu, Hidayet ;
Uluagac, A. Selcuk ;
Conti, Mauro .
ACM COMPUTING SURVEYS, 2018, 51 (04)
[5]   A Cyber Kill Chain Approach for Detecting Advanced Persistent Threats [J].
Ahmed, Yussuf ;
Asyhari, A. Taufiq ;
Rahman, Md Arafatur .
CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 67 (02) :2497-2513
[6]   Last Line of Defense: Reliability Through Inducing Cyber Threat Hunting With Deception in SCADA Networks [J].
Ajmal, Abdul Basit ;
Alam, Masoom ;
Khaliq, Awais Abdul ;
Khan, Shawal ;
Qadir, Zakria ;
Mahmud, M. A. Parvez .
IEEE ACCESS, 2021, 9 :126789-126800
[7]   A Survey of Machine and Deep Learning Methods for Internet of Things (IoT) Security [J].
Al-Garadi, Mohammed Ali ;
Mohamed, Amr ;
Al-Ali, Abdulla Khalid ;
Du, Xiaojiang ;
Ali, Ihsan ;
Guizani, Mohsen .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2020, 22 (03) :1646-1685
[8]  
Alazab M., 2021, IEEE Trans. Ind. Inform.
[9]   Integration of blockchain and federated learning for Internet of Things: Recent advances and future challenges [J].
Ali, Mansoor ;
Karimipour, Hadis ;
Tariq, Muhammad .
COMPUTERS & SECURITY, 2021, 108
[10]   A Survey on Security and Privacy Issues in Edge-Computing-Assisted Internet of Things [J].
Alwarafy, Abdulmalik ;
Al-Thelaya, Khaled A. ;
Abdallah, Mohamed ;
Schneider, Jens ;
Hamdi, Mounir .
IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (06) :4004-4022