A Self-forming Community Approach for Intrusion Detection in Heterogeneous Networks
摘要
Detecting intrusions in modern network infrastructures is challenging because of the growing size and, along with it, the increasing complexity of structure. While several approaches try to cope with those challenges, few address problems arising from heterogeneity and changes within those infrastructures. We present a self-forming community approach that integrates federated learning (FL) with distributed intrusion detection systems based on anomaly detection. It autonomously separates the anomaly detection models into communities at runtime with the goal of mutual information exchange using FL techniques to improve detection accuracy. Community formation is realized via the introduction of a similarity score between each pair of models, indicating which models would profit from aggregation. Through a re-evaluation of the similarity score during runtime, changes in the deployed infrastructure can be considered, and the communities adapted. Our experiments show our approach reported no false alarms when evaluated with a real-world dataset and an intrusion detection rate of up to 97%.