Robust Federated Learning for Mitigating Advanced Persistent Threats in Cyber-Physical Systems

被引:0
|
作者
Hallaji, Ehsan [1 ]
Razavi-Far, Roozbeh [1 ,2 ]
Saif, Mehrdad [1 ]
机构
[1] Univ Windsor, Dept Elect & Comp Engn, Windsor, ON N9B 3P4, Canada
[2] Univ New Brunswick, Fac Comp Sci, Fredericton, NB E3B 5A3, Canada
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 19期
基金
加拿大自然科学与工程研究理事会;
关键词
federated learning; advanced persistent threats; robust aggregation; cyber security; malware triage; INTRUSION DETECTION; CHALLENGES; SECURITY;
D O I
10.3390/app14198840
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Malware triage is essential for the security of cyber-physical systems, particularly against Advanced Persistent Threats (APTs). Proper data for this task, however, are hard to come by, as organizations are often reluctant to share their network data due to security concerns. To tackle this issue, this paper presents a secure and distributed framework for the collaborative training of a global model for APT triage without compromising privacy. Using this framework, organizations can share knowledge of APTs without disclosing private data. Moreover, the proposed design employs robust aggregation protocols to safeguard the global model against potential adversaries. The proposed framework is evaluated using real-world data with 15 different APT mechanisms. To make the simulations more challenging, we assume that edge nodes have partial knowledge of APTs. The obtained results demonstrate that participants in the proposed framework can privately share their knowledge, resulting in a robust global model that accurately detects APTs with significant improvement across different model architectures. Under optimal conditions, the designed framework detects almost all APT scenarios with an accuracy of over 90 percent.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Improving Security and Privacy in Advanced Federated Learning Environments for Cyber-Physical Systems
    Gaba, Shivani
    Budhiraja, Ishan
    Kumar, Vimal
    2024 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS 2024, 2024, : 1822 - 1827
  • [2] Analysis and Computation of Adaptive Defense Strategies Against Advanced Persistent Threats for Cyber-Physical Systems
    Huang, Linan
    Zhu, Quanyan
    DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2018, 2018, 11199 : 205 - 226
  • [3] Flip the Cloud: Cyber-Physical Signaling Games in the Presence of Advanced Persistent Threats
    Pawlick, Jeffrey
    Farhang, Sadegh
    Zhu, Quanyan
    DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2015, 2015, 9406 : 289 - 308
  • [4] A dynamic games approach to proactive defense strategies against Advanced Persistent Threats in cyber-physical systems
    Huang, Linan
    Zhu, Quanyan
    COMPUTERS & SECURITY, 2020, 89
  • [5] Learning Games for Defending Advanced Persistent Threats in Cyber Systems
    Zhu, Tianqing
    Ye, Dayong
    Cheng, Zishuo
    Zhou, Wanlei
    Yu, Philip S.
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2023, 53 (04): : 2410 - 2422
  • [6] Federated Learning for Data Privacy Preservation in Vehicular Cyber-Physical Systems
    Lu, Yunlong
    Huang, Xiaohong
    Dai, Yueyue
    Maharjan, Sabita
    Zhang, Yan
    IEEE NETWORK, 2020, 34 (03): : 50 - 56
  • [7] A Federated Learning Approach to Frequent Itemset Mining in Cyber-Physical Systems
    Ahmed, Usman
    Srivastava, Gautam
    Lin, Jerry Chun-Wei
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2021, 29 (04)
  • [8] Cyber-Physical Systems: Security Threats and Countermeasures
    Hammoudeh, Mohammad
    Epiphaniou, Gregory
    Pinto, Pedro
    JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2023, 12 (01)
  • [9] A Federated Learning Approach to Frequent Itemset Mining in Cyber-Physical Systems
    Usman Ahmed
    Gautam Srivastava
    Jerry Chun-Wei Lin
    Journal of Network and Systems Management, 2021, 29
  • [10] REVIEW ON THE USE OF FEDERATED LEARNING MODELS FOR THE SECURITY OF CYBER-PHYSICAL SYSTEMS
    War, Muhammed rafeeq
    Singh, Yashwant
    Sheikh, Zakir ahmad
    Singh, Pradeep kumar
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2025, 26 (01): : 16 - 33