Towards Detection of Zero-Day Botnet Attack in IoT Networks Using Federated Learning

Towards Detection of Zero-Day Botnet Attack in IoT Networks Using Federated Learning
复制标题

DOI:
10.1109/icc45041.2023.10279423
复制
发表时间:
2023-05
期刊:
ICC 2023 - IEEE International Conference on Communications
影响因子:
--
通讯作者:
Jielun Zhang;Shicong Liang;Feng Ye;R. Hu;Yi Qian
Jielun Zhang;Shicong Liang;Feng Ye;R. Hu;Yi Qian
中科院分区:
其他
文献类型:
--
作者:
Jielun Zhang;Shicong Liang;Feng Ye;R. Hu;Yi Qian

文献摘要

相似文献

自动化物联网(IoT)设备不断生成大量数据。然而,物联网网络可能容易受到僵尸网络攻击,其中一组物联网设备可能被恶意软件感染并形成僵尸网络。最近,人工智能(AI)算法已经被引入来检测和抵抗物联网网络中的此类僵尸网络攻击。然而,大多数现有的基于深度学习的算法都是以集中的方式设计和实现的。因此,这些方法在检测针对一组物联网设备的零日僵尸网络攻击时可能是次优的。此外,集中式人工智能方法需要共享来自物联网设备的数据跟踪以用于培训目的,这会危及用户隐私。为了解决本文中的这些问题,我们提出了一个基于联邦学习的零日僵尸网络攻击检测模型框架,其中开发了一种新的物联网设备聚合算法,以便在不影响用户隐私的情况下实现更好的模型聚合。评价是在开放数据集上进行的,即,N-BaIoT评估结果表明,所提出的学习框架与新的聚合算法优于现有的基线聚合算法在联邦学习零日僵尸网络攻击检测物联网网络。
Automated Internet of Things (IoT) devices generate a considerable amount of data continuously. However, an IoT network can be vulnerable to botnet attacks, where a group of IoT devices can be infected by malware and form a botnet. Recently, Artificial Intelligence (AI) algorithms have been introduced to detect and resist such botnet attacks in IoT networks. However, most of the existing Deep Learning-based algorithms are designed and implemented in a centralized manner. Therefore, these approaches can be sub-optimal in detecting zero-day botnet attacks against a group of IoT devices. Besides, a centralized AI approach requires sharing of data traces from the IoT devices for training purposes, which jeopardizes user privacy. To tackle these issues in this paper, we propose a federated learning based framework for a zero-day botnet attack detection model, where a new aggregation algorithm for the IoT devices is developed so that a better model aggregation can be achieved without compromising user privacy. Evaluations are conducted on an open dataset, i.e., the N-BaIoT. The evaluation results demonstrate that the proposed learning framework with the new aggregation algorithm outperforms the existing baseline aggregation algorithms in federated learning for zero-day botnet attack detection in IoT networks.