Cerberus: Exploring Federated Prediction of Security Events

09/07/2022
by   Mohammad Naseri, et al.
0

Modern defenses against cyberattacks increasingly rely on proactive approaches, e.g., to predict the adversary's next actions based on past events. Building accurate prediction models requires knowledge from many organizations; alas, this entails disclosing sensitive information, such as network structures, security postures, and policies, which might often be undesirable or outright impossible. In this paper, we explore the feasibility of using Federated Learning (FL) to predict future security events. To this end, we introduce Cerberus, a system enabling collaborative training of Recurrent Neural Network (RNN) models for participating organizations. The intuition is that FL could potentially offer a middle-ground between the non-private approach where the training data is pooled at a central server and the low-utility alternative of only training local models. We instantiate Cerberus on a dataset obtained from a major security company's intrusion prevention product and evaluate it vis-a-vis utility, robustness, and privacy, as well as how participants contribute to and benefit from the system. Overall, our work sheds light on both the positive aspects and the challenges of using FL for this task and paves the way for deploying federated approaches to predictive security.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/12/2020

Salvaging Federated Learning by Local Adaptation

Federated learning (FL) is a heavily promoted approach for training ML m...
research
08/10/2023

FLShield: A Validation Based Federated Learning Framework to Defend Against Poisoning Attacks

Federated learning (FL) is revolutionizing how we learn from data. With ...
research
12/12/2021

Improving Performance of Federated Learning based Medical Image Analysis in Non-IID Settings using Image Augmentation

Federated Learning (FL) is a suitable solution for making use of sensiti...
research
07/02/2021

Segmented Federated Learning for Adaptive Intrusion Detection System

Cyberattacks are a major issues and it causes organizations great financ...
research
08/23/2023

Unsupervised anomalies detection in IIoT edge devices networks using federated learning

In a connection of many IoT devices that each collect data, normally tra...
research
07/21/2023

Project Florida: Federated Learning Made Easy

We present Project Florida, a system architecture and software developme...
research
03/05/2022

Accelerated carrier invoice factoring using predictive freight transport events

Invoice factoring is an invoice financing process where business organiz...

Please sign up or login with your details

Forgot password? Click here to reset