Cyber threat hunting using unsupervised federated learning and adversary emulation

被引:0
作者
Sheikhi, Saeid [1 ]
Kostakos, Panos [1 ]
机构
[1] Univ Oulu, Fac Informat Technol & Elect Engn, Ctr Ubiquitous Comp, Oulu, Finland
来源
2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR | 2023年
基金
芬兰科学院;
关键词
Threat hunting; Cyber threats; Threat actors; Federated learning; adversary emulation;
D O I
10.1109/CSR57506.2023.10224990
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rapid growth of communication networks, coupled with the increasing complexity of cyber threats, necessitates the implementation of proactive measures to protect networks and systems. In this study, we introduce a federated learning-based approach for cyber threat hunting at the endpoint level. The proposed method utilizes the collective intelligence of multiple devices to effectively and confidentially detect attacks on individual machines. A security assessment tool is also developed to emulate the behavior of adversary groups and Advanced Persistent Threat (APT) actors in the network. This tool provides network security experts with the ability to assess their network environment's resilience and aids in generating authentic data derived from diverse threats for use in subsequent stages of the federated learning (FL) model. The results of the experiments demonstrate that the proposed model effectively detects cyber threats on the devices while safeguarding privacy.
引用
收藏
页码:315 / 320
页数:6
相关论文
共 50 条
  • [41] FedChain-Hunter: A reliable and privacy-preserving aggregation for federated threat hunting framework in SDN-based IIoT
    Duy, Phan The
    Quyen, Nguyen Huu
    Khoa, Nghi Hoang
    Tran, Tuan-Dung
    Pham, Van-Hau
    INTERNET OF THINGS, 2023, 24
  • [42] FedCL: An Efficient Federated Unsupervised Learning for Model Sharing in IoT
    Zhao, Chen
    Gao, Zhipeng
    Wang, Qian
    Mo, Zijia
    Yu, Xinlei
    COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT I, 2022, 460 : 115 - 134
  • [43] Timely Anomalous Behavior Detection in Fog-IoT Systems using Unsupervised Federated Learning
    Ribeiro Junior, Franklin Magalhaes
    Kamienski, Carlos Alberto
    2022 IEEE 8TH WORLD FORUM ON INTERNET OF THINGS, WF-IOT, 2022,
  • [44] Last Line of Defense: Reliability Through Inducing Cyber Threat Hunting With Deception in SCADA Networks
    Ajmal, Abdul Basit
    Alam, Masoom
    Khaliq, Awais Abdul
    Khan, Shawal
    Qadir, Zakria
    Mahmud, M. A. Parvez
    IEEE ACCESS, 2021, 9 : 126789 - 126800
  • [45] Data-Driven Threat Hunting Using Sysmon
    Mavroeidis, Vasileios
    Josang, Audun
    ICCSP 2018: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, 2018, : 82 - 88
  • [46] Federated LSTM Model for Enhanced Anomaly Detection in Cyber Security: A Novel Approach for Distributed Threat
    Sahu, Aradhana
    El-Ebiary, Yousef A. Baker
    Saravanan, K. Aanandha
    Thilagam, K.
    Devi, Gunnam Rama
    Gopi, Adapa
    Taloba, Ahmed I.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (06) : 1237 - 1249
  • [47] Deep learning for cyber threat detection in IoT networks: A review
    Aldhaheri A.
    Alwahedi F.
    Ferrag M.A.
    Battah A.
    Internet of Things and Cyber-Physical Systems, 2024, 4 : 110 - 128
  • [48] Robust Federated Learning Based on Metrics Learning and Unsupervised Clustering for Malicious Data Detection
    Li, Jiaming
    Zhang, Xinyue
    Zhao, Liang
    ACMSE 2022: PROCEEDINGS OF THE 2022 ACM SOUTHEAST CONFERENCE, 2022, : 238 - 242
  • [49] How to cope with malicious federated learning clients: An unsupervised learning-based approach
    Onsu, Murat Arda
    Kantarci, Burak
    Boukerche, Azzedine
    COMPUTER NETWORKS, 2023, 234
  • [50] Federated Learning For Cyber Security: SOC Collaboration For Malicious URL Detection
    Khramtsova, Ekaterina
    Hammerschmidt, Christian
    Lagraa, Sofian
    State, Radu
    2020 IEEE 40TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2020, : 1316 - 1321