Cyberattacks are increasingly threatening networked systems, often with the emergence of new types of unknown (zero-day) attacks and the rise of vulnerable devices. Such attacks can also target multiple components of a Supply Chain, which can be protected via Machine Learning (ML)-based Intrusion Detection Systems (IDSs). However, the need to learn large amounts of labelled data often limits the applicability of ML-based IDSs to cybersystems that only have access to private local data, while distributed systems such as Supply Chains have multiple components, each of which must preserve its private data while being targeted by the same attack To address this issue, this paper proposes a novel Decentralized and Online Federated Learning Intrusion Detection (DOF-ID) architecture based on the G-Network model with collaborative learning, that allows each IDS used by a specific component to learn from the experience gained in other components, in addition to its own local data, without violating the data privacy of other components. The performance evaluation results using public Kitsune and Bot-IoT datasets show that DOF-ID significantly improves the intrusion detection performance in all of the collaborating components, with acceptable computation time for online learning.
翻译:网络攻击日益威胁着各类网络系统,伴随新型未知(零日)攻击的涌现和易受攻击设备的增多,此类攻击还可能针对供应链的多个组件。基于机器学习的入侵检测系统虽能提供防护,但其需学习大量标注数据的特性,往往限制了其在仅能访问私有本地数据的网络系统中的应用。而供应链等分布式系统包含多个组件,每个组件在遭受相同攻击时必须保护自身私有数据。为解决该问题,本文提出一种基于G网络模型与协作学习的去中心化在线联邦学习入侵检测架构——DOF-ID,使特定组件使用的每个入侵检测系统,在保护其他组件数据隐私的前提下,既能利用自身本地数据,又能从其他组件的经验中学习。基于公开Kitsune和Bot-IoT数据集的性能评估结果表明,DOF-ID显著提升了所有协作组件的入侵检测性能,且在线学习计算耗时在可接受范围内。