Cerberus: Exploring Federated Prediction of Security Events

Cerberus: Exploring Federated Prediction of Security Events
复制标题

DOI:
10.1145/3548606.3560580
复制
发表时间:
2022-09
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Mohammad Naseri;Yufei Han;Enrico Mariconti;Yun Shen;G. Stringhini;Emiliano De Cristofaro
Mohammad Naseri;Yufei Han;Enrico Mariconti;Yun Shen;G. Stringhini;Emiliano De Cristofaro
中科院分区:
其他
文献类型:
--
作者:
Mohammad Naseri;Yufei Han;Enrico Mariconti;Yun Shen;G. Stringhini;Emiliano De Cristofaro

文献摘要

相似文献

针对网络攻击的现代防御越来越依赖于主动方法,例如,根据过去的事件来预测对手的下一步行动构建准确的预测模型需要来自许多组织的知识;唉,这需要披露敏感信息,如网络结构,安全态势和策略,这通常是不可取的或完全不可能的。在本文中,我们探讨了使用联邦学习(FL)来预测未来的安全事件的可行性。为此,我们介绍了Cerberus,这是一个能够为参与组织协作训练循环神经网络(RNN)模型的系统。直觉是,FL可能会在非私有方法(其中训练数据在中央服务器上汇集)和仅训练本地模型的低效用替代方案之间提供中间地带。我们实例化Cerberus从一个主要的安全公司的入侵防御产品获得的数据集,并评估它相对维斯实用性,鲁棒性和隐私,以及参与者如何贡献和受益于系统。总的来说,我们的工作揭示了使用FL执行此任务的积极方面和挑战,并为部署联邦方法以实现预测性安全铺平了道路。
Modern defenses against cyberattacks increasingly rely on proactive approaches, e.g., to predict the adversary's next actions based on past events. Building accurate prediction models requires knowledge from many organizations; alas, this entails disclosing sensitive information, such as network structures, security postures, and policies, which might often be undesirable or outright impossible. In this paper, we explore the feasibility of using Federated Learning (FL) to predict future security events. To this end, we introduce Cerberus, a system enabling collaborative training of Recurrent Neural Network (RNN) models for participating organizations. The intuition is that FL could potentially offer a middle-ground between the non-private approach where the training data is pooled at a central server and the low-utility alternative of only training local models. We instantiate Cerberus on a dataset obtained from a major security company's intrusion prevention product and evaluate it vis-à-vis utility, robustness, and privacy, as well as how participants contribute to and benefit from the system. Overall, our work sheds light on both the positive aspects and the challenges of using FL for this task and paves the way for deploying federated approaches to predictive security.