Digital Forensics based on Federated Learning in IoT Environment
Hania Mohamed, Nickolaos Koroniotis, Nour Moustafa · 2023
The prevalence of Internet of Things (IoT) devices and increasing cyber-attacks, especially Advanced Persistent Threats (APTs), require automating the forensics investigation process in the IoT networks. The effectiveness of existing digital forensic techniques and tools, when tasked with finding attack traces and their origins in IoT environments suffers due to the inherent volatility and heterogeneity of the IoT. To address these issues, we aim at developing a deep federated learning-based digital forensic method, which identifies cyber-attacks and examines their attributes in IoT networks. The proposed method is designed based on Federated Learning (FL) to preserve data privacy to learn multi-stage attack events and define their traces. Our method uses FL rounds to train a Convolutional Neural Network (CNN) model locally on IoT network data and share only the learned hyperparameters with the federated server instead of sharing the evidence data. The method is evaluated using the ToN-IoT dataset and compared with other two peer machine-learning models and a non-FL technique that uses the same Deep Learning (DL) model and settings. The results showed that the proposed method outperforms the other ones in discovering attacks by achieving 81.69% detection accuracy in less training time than the non-FL method when dropping the network flow identifiers features besides guaranteeing data privacy. The Proposed method would be deployed at the identification, examination and analysis phases of digital forensics to automate its process and offer forensically sound evidence that could be used in a court of law.