A Robust Distributed Intrusion Detection System for Collusive Attacks on Edge of Things

Wassila Lalouani, Mohamed Younis · 2022 IEEE Wireless Communications and Networking Conference (WCNC) · 2022

The popular means for safeguarding against cyberattacks is to employ an intrusion detection system (IDS). Contemporary IDS designs apply machine learning (ML)-based approaches to recognize attack signatures. Yet, the dynamic nature of an Edge-of-Things (EoT) requires continual IDS adaptation by incorporating new intelligence and gained knowledge from security logs in order to detect unknown malicious behaviors. The scale of the system makes the collection of voluminous logs to be impractical. Moreover, sharing security logs by the involved devices would raise privacy concerns. This paper overcomes these challenges by proposing a novel IDS for EoT. The proposed IDS employs federated learning to enable edge nodes to share a model rather than raw data and aggregate the provided models in a hierarchical manner. In addition, our approach recognizes the presence of any individual or colluding attempts to degrade the IDS by providing erroneous (poisonous) data. We apply an iterative voting algorithm to associate trust to participating devices and a Louvain method for uncovering collusive communities. The validation results using a public dataset confirm the effectiveness of our approach.

Read the paper · More papers on PaperTik