Cyber threat hunting using unsupervised federated learning and adversary emulation

被引:0
作者
Sheikhi, Saeid [1 ]
Kostakos, Panos [1 ]
机构
[1] Univ Oulu, Fac Informat Technol & Elect Engn, Ctr Ubiquitous Comp, Oulu, Finland
来源
2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR | 2023年
基金
芬兰科学院;
关键词
Threat hunting; Cyber threats; Threat actors; Federated learning; adversary emulation;
D O I
10.1109/CSR57506.2023.10224990
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rapid growth of communication networks, coupled with the increasing complexity of cyber threats, necessitates the implementation of proactive measures to protect networks and systems. In this study, we introduce a federated learning-based approach for cyber threat hunting at the endpoint level. The proposed method utilizes the collective intelligence of multiple devices to effectively and confidentially detect attacks on individual machines. A security assessment tool is also developed to emulate the behavior of adversary groups and Advanced Persistent Threat (APT) actors in the network. This tool provides network security experts with the ability to assess their network environment's resilience and aids in generating authentic data derived from diverse threats for use in subsequent stages of the federated learning (FL) model. The results of the experiments demonstrate that the proposed model effectively detects cyber threats on the devices while safeguarding privacy.
引用
收藏
页码:315 / 320
页数:6
相关论文
共 50 条
  • [31] FedX: Unsupervised Federated Learning with Cross Knowledge Distillation
    Han, Sungwon
    Park, Sungwon
    Wu, Fangzhao
    Kim, Sundong
    Wu, Chuhan
    Xie, Xing
    Cha, Meeyoung
    COMPUTER VISION - ECCV 2022, PT XXX, 2022, 13690 : 691 - 707
  • [32] Threat Hunting using GRR Rapid Response
    Rasheed, Hussein
    Hadi, Ali
    Khader, Mariam
    2017 INTERNATIONAL CONFERENCE ON NEW TRENDS IN COMPUTING SCIENCES (ICTCS), 2017, : 155 - 160
  • [33] Cyber Threat Hunting Through Automated Hypothesis and Multi-Criteria Decision Making
    Horta Neto, Antonio Jose
    Pereira dos Santos, Anderson Fernandes
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 1823 - 1830
  • [34] Privacy-preserving federated learning cyber-threat detection for intelligent transport systems with blockchain-based security
    Moulahi, Tarek
    Jabbar, Rateb
    Alabdulatif, Abdulatif
    Abbas, Sidra
    El Khediri, Salim
    Zidi, Salah
    Rizwan, Muhammad
    EXPERT SYSTEMS, 2023, 40 (05)
  • [35] A Machine Learning Approach to Threat Hunting in Malicious PDF Files
    Teymourlouei, Haydar
    Harris, Vareva E.
    2023 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE, CSCI 2023, 2023, : 782 - 787
  • [36] Enhancing the Aggregation of the Federated Learning for the Industrial Cyber Physical Systems
    Guendouzi, Souhila Badra
    Ouchani, Samir
    Malki, Mimoune
    2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 197 - 202
  • [37] FedCrack: Federated Transfer Learning With Unsupervised Representation for Crack Detection
    Jin, Xiating
    Bu, Jiajun
    Yu, Zhi
    Zhang, Hui
    Wang, Yaonan
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (10) : 11171 - 11184
  • [38] Hybrid quantum enhanced federated learning for cyber attack detection
    Subramanian, G.
    Chinnadurai, M.
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [39] Personalized federated unsupervised learning for nozzle condition monitoring using vibration sensors in additive manufacturing
    Makanda, Inno Lorren Desir
    Jiang, Pingyu
    Yang, Maolin
    ROBOTICS AND COMPUTER-INTEGRATED MANUFACTURING, 2025, 93
  • [40] Federated Learning in Healthcare with Unsupervised and Semi-Supervised Methods
    Panos-Basterra, Juan
    Dolores Ruiz, M.
    Martin-Bautista, Maria J.
    FLEXIBLE QUERY ANSWERING SYSTEMS, FQAS 2023, 2023, 14113 : 182 - 193