A Federated Learning-Based Approach for Predicting Cross-Domain Network Attack Behavior
摘要
The edge side of the new power system is fully extended and faces a dramatic increase in the risk of unknown attacks. Among the many forms of network attacks, Advanced Persistent Threat (APT) is a cross-domain network attack means with high targeting, persistence, concealment and phase characteristics. There are huge challenges for traditional network defense systems to detect and counteract APT attacks. To compensate for the limitations of traditional network defense systems in APT attack detection, this paper proposes a SIMRANK-based alert data division method to realize the correlation analysis of APT attack alerts and logs. Meanwhile, an APT behavior profiling model is constructed and an APT attack prediction algorithm based on convolutional neural network (CNN) and LSTM is designed to predict the phase shift of APT attacks. This paper adopts a federation learning framework to solve the cross-domain privacy security problem and uses alerts and logs from different network domains as simulation experiments. The simulation results show that the proposed APT profiling model and prediction algorithm can accurately characterize the APT behavior in different network domains at different stages, and the CNN-LSTM-based APT attack stage prediction model can accurately predict the transfer probability of APT attacks at different stages.