Szczegóły publikacji
Opis bibliograficzny
Distributed continual intrusion detection: a collaborative replay framework / Kamil FABER, Bartłomiej ŚNIEŻYŃSKI, Roberto Corizzo // W: 2023 IEEE international conference on Big data [Dokument elektroniczny] : December 15–18, 2023, Sorrento, Italy : proceedings / ed. by Jingrui He, [et al.]. — Wersja do Windows. — Dane tekstowe. — [Piscataway] : IEEE, cop. 2023. — e-ISBN: 979-8-3503-2445-7. — S. 3255–3263. — Wymagania systemowe: Adobe Reader. — Bibliogr. s. 3263, Abstr. — Publikacja dostępna online od: 2024-01-22
Autorzy (3)
- AGHFaber Kamil
- AGHŚnieżyński Bartłomiej
- Corizzo Roberto
Słowa kluczowe
Dane bibliometryczne
| ID BaDAP | 152338 |
|---|---|
| Data dodania do BaDAP | 2024-04-16 |
| Tekst źródłowy | URL |
| DOI | 10.1109/BigData59044.2023.10386211 |
| Rok publikacji | 2023 |
| Typ publikacji | materiały konferencyjne (aut.) |
| Otwarty dostęp | |
| Wydawca | Institute of Electrical and Electronics Engineers (IEEE) |
| Konferencja | IEEE International Conference on Big Data 2023 |
Abstract
Intrusion Detection System is a strategic analytical tool for the security of organizations and institutions. Among existing approaches, distributed and collaborative intrusion detection approaches are particularly effective since they combine data analysis from multiple sources to provide increased model robustness. Although many state-of-the-art approaches have the ability to adapt to evolving environments and incoming data, they are subject to catastrophic forgetting of past knowledge. At the same time, recent works in lifelong continual anomaly detection showcase the merit of simultaneous adaptation and knowledge retention. However, lifelong methods are thus far limited to the analysis of a single data source and do not provide distributed and collaborative learning capabilities. In this paper, we fill this gap by proposing a novel distributed continual learning intrusion detection framework with collaborative experience replay. The system is built from independent Detection Nodes and a Continual Learning Center. While the nodes are in charge of data selection and intrusion detection, the Continual Learning Center implements a collaborative replay strategy, performs model updates, and broadcasts the most recent model to the nodes. The separation of responsibilities allows for the decomposition of the system into task-oriented services, leading to a modular, flexible, and scalable architecture. An extensive evaluation involving popular network intrusion detection datasets shows the potential of our framework and the improvement in detection performance that can be achieved with the collaborative replay strategy.