Design of an Iterative Method for Zero-Day Attack Detection Using Adversarial Graph Temporal Convolutional Networks and Federated Learning
摘要
Recent years have witnessed the highly important issue of cybersecurity against zero-day attacks due to their powerful nature and tendency to cause much damage. Most traditional security measures fail to provide timely detection of these threats because, by definition, they lack the capability to adapt to new and emerging attack vectors & sets. In the article, we propose two novel architectures, AG-TCN and EFIL, that make the adaptability and accuracy of the zero-day threat detection significantly better in a cloud-native environment. The availability of most cybersecurity solutions in the market often experiences major challenges: very high false positive rates, and static nature of the models is modeled based on predefined threat signatures, which fail to detect new and unseen attack patterns. In addition, data processing models that operate conventionally are not immune to privacy issues and, more importantly, scalability issues in a distributed network. In the AG-TCN, we will propose an enhanced model for the integration of adversarial training, graph neural networks, and temporal convolutional networks to execute the spatial and temporal analyses of network traffic data samples. These patterns are precisely captured through unique integration that allows dynamic learning of node representations and temporal behaviors. The model approach can thus generalize more and identify anomalies signaling a zero-day attack. Adversarial training further extends this capacity to prepare the model to withstand adversarial attacks through improved resilience to them. The EFIL model uses the power of ensemble learning, federated learning, and incremental learning. In doing so, it improves privacy risks by enabling decentralized data processing and further enhancing collaborative learning between different organizations without the need to share sensitive information sets. Through the aggregation of models and incremental update of local models, EFIL effectively adapts to new and emerging threats and hence warrants high detection accuracy and robustness over temporal instance sets. The preliminary results from the trials of deploying AG-TCN and EFIL in the simulated environment look very promising. The AG-TCN showed an average detection accuracy of 95% and a false positive rate of 2%, whereas EFIL has shown outstanding performance, boasting an average F1 score of 0.92 across federated nodes. The implication of these results and the rise of cloud-native security with a scalable, adaptive, and privacy-preserving framework on zero-day threat detection is quite remarkable. These architectures not only set a new standard for the detection of zero-day attacks but also provide a solid blueprint for further developments in AI/ML-enabled cybersecurity solutions.