Intrusion Detection Systems (IDSs) are essential part of a security solution to monitor the network traffics and detect malicious attacks. In a collaborative IDS, multiple IDSs work together to effectively detect large scaled and across platforms or operating systems attacks. However, the participating nodes in a CIDS may hesitate to share their network traffic data due to privacy concerns. In this paper, we propose a federated learning enabled CIDS architecture leveraging its privacy-reserving feature. An unsupervised machine learning algorithm, Self-Organizing Maps (SOM), is adopted as the intrusion detection method. Based on our knowledge, this research is the first attempt incorporating SOM and federated learning into CIDS. We believe that the proposed framework can greatly improve both precision and recall of the intrusion detection. This paper is research in progress. We are in the process of developing a preliminary research prototype and designing experiments for validations.
Related links
Details
Title
An Architecture for Federated Learning Enabled Collaborative Intrusion Detection Systems
Publication Details
AMCIS 2021 Proceedings
Resource Type
Conference proceeding
Conference
Americas Conference on Information Systems (AMCIS), 27th (Montreal, Canada, 2021)
Publisher
Assoc Information Systems
Number of pages
5
Identifiers
WOS:000672599800027; 99381798340706600
Academic Unit
Center for Cybersecurity and AI; Hal Marcus College of Science and Engineering