JOURNAL ARTICLE

Federated Learning-Based Cyber Threat Hunting for APT Attack Detection in SDN-Enabled Networks

Abstract

Threat hunting is the action of seeking harmful actors lurking in the network or the system in the early stage with the assumption of attackers already broke the cy-ber defense solution. This defense solution requires collecting more knowledge inside and outside to search potential threats in each organization. To leverage the knowledge of multiple organizations and experts for cyber threat detection, there is a need for the collaboration without breaking data among data owners across the cybersecurity community. Meanwhile, Software Defined Networking (SDN) is the flexible and programmable network architecture, which enables network administrator to proactively enforce the security policy in the large-scale network. Obviously, it can help organizations to enforce dynamically threat hunting services. Thus, this work introduces a federated learning (FL) approach for cyber threat hunting in SDN-enabled networks to deploy a proactive APT attack detection and response by leveraging threat intelligence from collaborative parties. Our approach can enrich the outcome of machine learning (ML)-based or deep learning (DL)-based threat detectors in recognizing malicious indicators. The experimental results on NF-UQ-NIDS dataset and FedPlus model aggregation algorithm demonstrate the feasibility of FL-based cyber threat hunting with privacy preservation among data holders in SDN context.

Keywords:
Computer security Computer science Leverage (statistics) Context (archaeology) Cyber-attack Cyber threats Artificial intelligence

Metrics

13
Cited By
2.79
FWCI (Field Weighted Citation Impact)
29
Refs
0.86
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Software-Defined Networks and 5G
Physical Sciences →  Computer Science →  Computer Networks and Communications
Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Internet Traffic Analysis and Secure E-voting
Physical Sciences →  Computer Science →  Artificial Intelligence

Related Documents

JOURNAL ARTICLE

CYBER THREAT HUNTING IN BLOCKCHAIN-ENABLED IIOT NETWORKS USING BLOCKHUNTER AND FEDERATED LEARNING

VARUN MARAMRAJ,MADDI APARNA

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2024
JOURNAL ARTICLE

CYBER THREAT HUNTING IN BLOCKCHAIN-ENABLED IIOT NETWORKS USING BLOCKHUNTER AND FEDERATED LEARNING

VARUN MARAMRAJ,MADDI APARNA

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2024
JOURNAL ARTICLE

Federated learning-based intrusion detection in SDN-enabled IIoT networks

Phan The DuyTran Van HungNguyen Hong HaHien Do HoangVan-Hau Pham

Journal:   2021 8th NAFOSTED Conference on Information and Computer Science (NICS) Year: 2021
JOURNAL ARTICLE

A federated threat hunting system with big data analysis for SDN-enabled networks

Nghia To TrongHien Do HoangDoan Minh TrungPhan The DuyVan-Hau Pham

Journal:   2022 RIVF International Conference on Computing and Communication Technologies (RIVF) Year: 2022 Pages: 35-40
© 2026 ScienceGate Book Chapters — All rights reserved.