在使用联合学习方法的软件定义网络中,用于自主恶意软件检测和防御的可扩展架构
Ripal Ranpara1, Shobhit K Patel2, Om Prakash Kumar3
1Faculty of Computer Applications, Marwadi University, Rajkot, 360003, India.
Scientific reports
|August 18, 2025
概括
本研究介绍了一个联合学习 (FL) 架构,用于在软件定义网络 (SDN) 中进行可扩展,自主恶意软件检测. 虽然对已知的攻击有效,但性能因现实世界的数据复杂性而有所不同.
科学领域:
- 网络安全 网络安全
- 机器学习 机器学习
- 网络安全架构 网络安全架构
背景情况:
- 软件定义网络 (SDN) 提供集中控制,但需要强有力的安全措施.
- 传统的恶意软件检测与现代网络的规模和动态性质作斗争.
- 联合学习 (FL) 为分布式机器学习提供了一种保护隐私的方法.
研究的目的:
- 为使用联合学习 (FL) 的 SDN 提出可扩展和自主恶意软件检测和防御架构.
- 将SDN的数据处理与FL的分散学习相结合,以实现可适应的网络安全.
- 评估架构在不同数据条件下检测各种网络威胁的性能.
主要方法:
- 开发一种新的架构,将SDN功能与FL原则相结合.
- 实施分布式学习方法,只共享模型更新,保护数据隐私.
- 使用平衡和不平衡的现实世界数据集进行测试和性能分析 (例如,CICIDS 2017,UNSW-NB15).
主要成果:
- 通过平衡数据集,实现了对受控DDoS和尸网络攻击的高达96%的检测率.
- 在不平衡,多样化的数据集和复杂的场景 (如数据泄露) 的现实模拟中,整体准确性降至59.50%.
- 证明了低延迟 (<1s),显著的吞吐量恢复 (300-500 Mbps),并最大限度地减少了通信开销.
结论:
- 拟议的基于FL的SDN架构为恶意软件检测提供了一个可扩展的,保护隐私的框架.
- 对主要威胁的有效性很高,但需要进一步增强,以检测微妙的攻击.
- 未来的工作应该集中在丰富的数据集和改进的功能工程,以应对现实世界的部署挑战.
相关概念视频
Distributed Loads: Problem Solving
731
Beams are structural elements commonly employed in engineering applications requiring different load-carrying capacities. The first step in analyzing a beam under a distributed load is to simplify the problem by dividing the load into smaller regions, which allows one to consider each region separately and calculate the magnitude of the equivalent resultant load acting on each portion of the beam. The magnitude of the equivalent resultant load for each region can be determined by calculating...
731
Distribution Reliability and Automation
155
Distribution reliability in electrical power systems is critical for ensuring an uninterrupted power supply to consumers at minimal cost. According to IEEE Standard Terms, reliability is the probability that a device will function without failure over a specified time period or amount of usage. For electric power distribution, this translates to maintaining continuous power supply and addressing customer concerns over power outages. Several indices, as defined by IEEE Standard 1366-2012, are...
155

