Generalizing Flow Classification for Distributed Denial-of-Service over Different Networks

Leonardo Henrique de Melo, Gustavo de Carvalho Bertoli, Lourenço Alves Pereira, Osamu Saotome, Marcelo F. Domingues, Aldri Luiz dos Santos · GLOBECOM 2022 - 2022 IEEE Global Communications Conference · 2022

With the growth in connected devices and network traffic, these systems require automated and fast approaches to achieve secure operations. Hence, machine learning-based network intrusion detection has become the state-of-the-art approach to tackle uncertainties and new attacks. However, the generalization of the models when exposed to different domains and workloads remains an open issue. In this paper, we propose using federated learning (FL) with sampling methods and feature selection to improve the generalization of the trained global model when evaluated in different network contexts. We evaluate this approach to classify network flows representing benign traffic and distributed denial-of-service attacks. Our proposed approach results in an 85% improvement compared with the naive evaluation of training in one context and evaluating others. Moreover, it presented a similar performance to a statistical algorithm with the reported generalization capability on flow-based network traffic classification. Additionally, this FL-based approach brings data privacy and distributed learning capability to the table.

Read the paper · More papers on PaperTik