Threat Detection and Intelligence Sharing Using a Decentralized Federated Learning
Open AccessDownloadable Content
Network threat detection systems, with the ability to share threat intelligence between organizations, can enable organizations to plan, prevent, or handle cyberattacks. In practice, due to the sensitive nature of these data, sharing data across different organizations – faces legal and logistical obstacles. Sharing data can be challenging due to various factors, such as the lack of standardization, the risk of reputation damage from sharing data, the difficulty of establishing trust among participants, the risk of violating privacy or antitrust laws, government data over-classification, and varying legal frameworks across jurisdictions. These obstacles have prevented organizations from sharing data that would be useful for threat detection and intelligence sharing (Zibak & Simpson, 2019). To address these security and privacy concerns, Google introduced the concept of Federated Learning (FL) in 2016. In a Federated Learning system, to overcome data privacy and security challenges, participants only share learned model weights instead of raw data.This praxis implements HPE Swarm Learning, a blockchain-based decentralized Federated Learning system, to detect and share threat intelligence among participants. The implementation of Swarm Learning is evaluated against the centralized Federated Learning model on the same dataset. We further assess the Swarm Learning implementation by comparing the performance of two popular machine learning models – LSTM and 1D-CNN- commonly used for cyber threat detection.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.