{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:23:55Z","timestamp":1785954235900,"version":"3.56.0"},"reference-count":50,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,10,7]],"date-time":"2022-10-07T00:00:00Z","timestamp":1665100800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,10,7]],"date-time":"2022-10-07T00:00:00Z","timestamp":1665100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001794","name":"The University of Queensland","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001794","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2023,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The uses of machine learning (ML) technologies in the detection of network attacks have been proven to be effective when designed and evaluated using data samples originating from the same organisational network. However, it has been very challenging to design an ML-based detection system using heterogeneous network data samples originating from different sources and organisations. This is mainly due to privacy concerns and the lack of a universal format of datasets. In this paper, we propose a collaborative cyber threat intelligence sharing scheme to allow multiple organisations to join forces in the design, training, and evaluation of a robust ML-based network intrusion detection system. The threat intelligence sharing scheme utilises two critical aspects for its application; the availability of network data traffic in a common format to allow for the extraction of meaningful patterns across data sources and the adoption of a federated learning mechanism to avoid the necessity of sharing sensitive users\u2019 information between organisations. As a result, each organisation benefits from the intelligence of other organisations while maintaining the privacy of its data internally. In this paper, the framework has been designed and evaluated using two key datasets in a NetFlow format known as NF-UNSW-NB15-v2 and NF-BoT-IoT-v2. In addition, two other common scenarios are considered in the evaluation process; a centralised training method where local data samples are directly shared with other organisations and a localised training method where no threat intelligence is shared. The results demonstrate the efficiency and effectiveness of the proposed framework by designing a universal ML model effectively classifying various benign and intrusive traffic types originating from multiple organisations without the need for inter-organisational data exchange.<\/jats:p>","DOI":"10.1007\/s10922-022-09691-3","type":"journal-article","created":{"date-parts":[[2022,10,7]],"date-time":"2022-10-07T04:03:47Z","timestamp":1665115427000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":151,"title":["Cyber Threat Intelligence Sharing Scheme Based on Federated Learning for Network Intrusion Detection"],"prefix":"10.1007","volume":"31","author":[{"given":"Mohanad","family":"Sarhan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siamak","family":"Layeghy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nour","family":"Moustafa","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marius","family":"Portmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,10,7]]},"reference":[{"issue":"9","key":"9691_CR1","volume":"3","author":"A Javaid","year":"2016","unstructured":"Javaid, A., Niyaz, Q., Sun, W., Alam, M.: A deep learning approach for network intrusion detection system. EAI Endorsed Trans. Secur. Saf. 3(9), e2 (2016)","journal-title":"EAI Endorsed Trans. Secur. Saf."},{"key":"9691_CR2","volume-title":"Principles of Information Security","author":"ME Whitman","year":"2011","unstructured":"Whitman, M.E., Mattord, H.J.: Principles of Information Security. Cengage Learning, Boston (2011)"},{"issue":"1","key":"9691_CR3","first-page":"1","volume":"2","author":"AS Ashoor","year":"2011","unstructured":"Ashoor, A.S., Gore, S.: Importance of intrusion detection system (ids). Int. J. Sci. Eng. Res. 2(1), 1\u20134 (2011)","journal-title":"Int. J. Sci. Eng. Res."},{"issue":"1\u20132","key":"9691_CR4","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2008.08.003","volume":"28","author":"P Garcia-Teodoro","year":"2009","unstructured":"Garcia-Teodoro, P., Diaz-Verdejo, J., Maci\u00e1-Fern\u00e1ndez, G., V\u00e1zquez, E.: Anomaly-based network intrusion detection: techniques, systems and challenges. Comput. Secur. 28(1\u20132), 18\u201328 (2009)","journal-title":"Comput. Secur."},{"key":"9691_CR5","unstructured":"van\u00a0der Eijk, V., Schuijt, C.: Detecting cobalt strike beacons in netflow data"},{"key":"9691_CR6","doi-asserted-by":"crossref","unstructured":"Bhatt, P., Yano, E.T., Gustavsson, P.: Towards a framework to detect multi-stage advanced persistent threats attacks. In: 2014 IEEE 8th International Symposium on Service Oriented System Engineering, pp. 390\u2013395, IEEE (2014)","DOI":"10.1109\/SOSE.2014.53"},{"key":"9691_CR7","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Portmann, M.: Feature analysis for ML-based IIoT intrusion detection. arXiv:2108.12732 (2021)","DOI":"10.21203\/rs.3.rs-2035633\/v1"},{"issue":"7","key":"9691_CR8","first-page":"98","volume":"1","author":"I Goodfellow","year":"2016","unstructured":"Goodfellow, I., Bengio, Y., Courville, A.: Machine learning basics. Deep Learn. 1(7), 98\u2013164 (2016)","journal-title":"Deep Learn."},{"issue":"6245","key":"9691_CR9","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1126\/science.aaa8415","volume":"349","author":"MI Jordan","year":"2015","unstructured":"Jordan, M.I., Mitchell, T.M.: Machine learning: trends, perspectives, and prospects. Science 349(6245), 255\u2013260 (2015)","journal-title":"Science"},{"key":"9691_CR10","doi-asserted-by":"crossref","first-page":"381","DOI":"10.21275\/ART20203995","volume":"9","author":"B Mahesh","year":"2020","unstructured":"Mahesh, B.: Machine learning algorithms-a review. IJSR 9, 381\u2013386 (2020)","journal-title":"IJSR"},{"issue":"10","key":"9691_CR11","doi-asserted-by":"publisher","first-page":"11994","DOI":"10.1016\/j.eswa.2009.05.029","volume":"36","author":"C-F Tsai","year":"2009","unstructured":"Tsai, C.-F., Hsu, Y.-F., Lin, C.-Y., Lin, W.-Y.: Intrusion detection by machine learning: a review. Expert Syst. Appl. 36(10), 11994\u201312000 (2009)","journal-title":"Expert Syst. Appl."},{"issue":"1","key":"9691_CR12","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1109\/SURV.2013.052213.00046","volume":"16","author":"MH Bhuyan","year":"2013","unstructured":"Bhuyan, M.H., Bhattacharyya, D.K., Kalita, J.K.: Network anomaly detection: methods, systems and tools. IEEE Commun. Surv. Tutor. 16(1), 303\u2013336 (2013)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"9691_CR13","unstructured":"Brown, R., Lee, R.M.: The evolution of cyber threat intelligence (CTI): 2019 sans CTI survey. SANS Institute. https:\/\/www.sans.org\/white-papers\/38790\/. Accessed 12 July 2021 (2019)"},{"key":"9691_CR14","unstructured":"Zhao, Y., Li, M., Lai, L., Suda, N., Civin, D., Chandra, V.: Federated learning with non-IID data. arXiv:1806.00582 (2018)"},{"key":"9691_CR15","unstructured":"Layeghy, S., Gallagher, M., Portmann, M.: Benchmarking the benchmark-analysis of synthetic NIDS datasets. arXiv:2104.09029 (2021)"},{"key":"9691_CR16","unstructured":"Clauset, A.: A brief primer on probability distributions. In: Santa Fe Institute (2011)"},{"key":"9691_CR17","unstructured":"Aupek, A. et\u00a0al.: Architectural design of enterprise wide standard operating environments (2006)"},{"key":"9691_CR18","unstructured":"Youssef, A., Aerts, J.-M., Vanrumste, B., Luca, S.: A localised learning approach applied to human activity recognition. IEEE Intell. Syst. (2020)"},{"issue":"3","key":"9691_CR19","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1109\/MWC.2016.1600317WC","volume":"24","author":"N Kato","year":"2016","unstructured":"Kato, N., Fadlullah, Z.M., Mao, B., Tang, F., Akashi, O., Inoue, T., Mizutani, K.: The deep learning vision for heterogeneous network traffic control: Proposal, challenges, and future perspective. IEEE Wirel. Commun. 24(3), 146\u2013153 (2016)","journal-title":"IEEE Wirel. Commun."},{"issue":"4","key":"9691_CR20","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1007\/s10922-005-9000-y","volume":"13","author":"Y Bhole","year":"2005","unstructured":"Bhole, Y., Popescu, A.: Measurement and analysis of http traffic. J. Netw. Syst. Manage. 13(4), 357\u2013371 (2005)","journal-title":"J. Netw. Syst. Manage."},{"key":"9691_CR21","unstructured":"Nardi, M., Valerio, L., Passarella, A.: Centralised vs decentralised anomaly detection: when local and imbalanced data are beneficial. In: Third International Workshop on Learning with Imbalanced Domains: Theory and Applications, pp.\u00a07\u201320, PMLR (2021)"},{"key":"9691_CR22","doi-asserted-by":"crossref","unstructured":"Abbasi, M., Shahraki, A., Taherkordi, A.: Deep learning for network traffic monitoring and analysis (NTMA): a survey. Comput. Commun. (2021)","DOI":"10.1016\/j.comcom.2021.01.021"},{"issue":"3","key":"9691_CR23","first-page":"1","volume":"13","author":"Q Yang","year":"2019","unstructured":"Yang, Q., Liu, Y., Cheng, Y., Kang, Y., Chen, T., Yu, H.: Federated learning. Synth. Lect. Artif. Intell. Mach. Learn. 13(3), 1\u2013207 (2019)","journal-title":"Synth. Lect. Artif. Intell. Mach. Learn."},{"key":"9691_CR24","doi-asserted-by":"crossref","unstructured":"Truex, S., Baracaldo, N., Anwar, A.\u00a0, Steinke, T., Ludwig, H., Zhang, R., Zhou, Y.: A hybrid approach to privacy-preserving federated learning. In: Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security, pp.\u00a01\u201311 (2019)","DOI":"10.1145\/3338501.3357370"},{"issue":"3","key":"9691_CR25","doi-asserted-by":"publisher","first-page":"2022","DOI":"10.1109\/TWC.2019.2961673","volume":"19","author":"K Yang","year":"2020","unstructured":"Yang, K., Jiang, T., Shi, Y., Ding, Z.: Federated learning via over-the-air computation. IEEE Trans. Wireless Commun. 19(3), 2022\u20132035 (2020)","journal-title":"IEEE Trans. Wireless Commun."},{"key":"9691_CR26","doi-asserted-by":"crossref","unstructured":"Imteaj, A., Thakker, U., Wang, S., Li, J., Amini, M.H.: A survey on federated learning for resource-constrained IoT devices. IEEE Internet Things J. (2021)","DOI":"10.1007\/978-3-031-11748-0_2"},{"issue":"12","key":"9691_CR27","doi-asserted-by":"publisher","first-page":"2663","DOI":"10.3390\/app8122663","volume":"8","author":"D Preuveneers","year":"2018","unstructured":"Preuveneers, D., Rimmer, V., Tsingenopoulos, I., Spooren, J., Joosen, W., Ilie-Zudor, E.: Chained anomaly detection models for federated learning: an intrusion detection case study. Appl. Sci. 8(12), 2663 (2018)","journal-title":"Appl. Sci."},{"issue":"6","key":"9691_CR28","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1109\/MNET.011.2000286","volume":"34","author":"SA Rahman","year":"2020","unstructured":"Rahman, S.A., Tout, H., Talhi, C., Mourad, A.: Internet of things intrusion detection: centralized, on-device, or federated learning? IEEE Netw. 34(6), 310\u2013317 (2020)","journal-title":"IEEE Netw."},{"issue":"2","key":"9691_CR29","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MC.2018.2888764","volume":"52","author":"K Siddique","year":"2019","unstructured":"Siddique, K., Akhtar, Z., Aslam Khan, F., Kim, Y.: Kdd cup 99 data sets: a perspective on the role of data sets in network intrusion detection research. Computer 52(2), 41\u201351 (2019)","journal-title":"Computer"},{"key":"9691_CR30","doi-asserted-by":"crossref","unstructured":"Mothukuri, V., Khare, P., Parizi, R.M., Pouriyeh, S., Dehghantanha, A., Srivastava, G.: Federated learning-based anomaly detection for IoT security attacks. IEEE Internet Things J. (2021)","DOI":"10.1109\/JIOT.2021.3077803"},{"key":"9691_CR31","doi-asserted-by":"crossref","unstructured":"Popoola, S.I., Ande, R., Adebisi, B., Gui, G., Hammoudeh, M., Jogunola, O.: Federated deep learning for zero-day botnet attack detection in IoT edge devices. IEEE Internet Things J. (2021)","DOI":"10.3390\/electronics10091104"},{"key":"9691_CR32","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., Arcas, B.A.: Communication-efficient learning of deep networks from decentralized data. In: Artificial Intelligence and Statistics, pp.\u00a01273\u20131282, PMLR (2017)"},{"key":"9691_CR33","doi-asserted-by":"publisher","DOI":"10.1016\/j.phycom.2020.101157","volume":"42","author":"R Zhao","year":"2020","unstructured":"Zhao, R., Yin, Y., Shi, Y., Xue, Z.: Intelligent intrusion detection based on federated learning aided long short-term memory. Phys. Commun. 42, 101157 (2020)","journal-title":"Phys. Commun."},{"key":"9691_CR34","doi-asserted-by":"crossref","unstructured":"Zhao, R., Wang, Y., Xue, Z., Ohtsuki, T., Adebisi, B., Gui, G.: Semi-supervised federated learning based intrusion detection method for internet of things. IEEE Internet Things J. (2022)","DOI":"10.1109\/JIOT.2022.3175918"},{"issue":"3","key":"9691_CR35","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1145\/212094.212114","volume":"27","author":"T Dietterich","year":"1995","unstructured":"Dietterich, T.: Overfitting and undercomputing in machine learning. ACM Comput. Surv. (CSUR) 27(3), 326\u2013327 (1995)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"9691_CR36","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102402","volume":"110","author":"N Truong","year":"2021","unstructured":"Truong, N., Sun, K., Wang, S., Guitton, F., Guo, Y.: Privacy preservation in federated learning: an insightful survey from the GDPR perspective. Comput. Secur. 110, 102402 (2021)","journal-title":"Comput. Secur."},{"key":"9691_CR37","doi-asserted-by":"publisher","DOI":"10.1201\/9780203507353","volume-title":"The Practical Guide to HIPAA Privacy and Security Compliance","author":"R Herold","year":"2003","unstructured":"Herold, R., Beaver, K.: The Practical Guide to HIPAA Privacy and Security Compliance. CRC Press, Boca Raton (2003)"},{"issue":"1","key":"9691_CR38","doi-asserted-by":"crossref","first-page":"13","DOI":"10.69554\/BKQK7610","volume":"10","author":"M Cortet","year":"2016","unstructured":"Cortet, M., Rijks, T., Nijland, S.: Psd2: the digital transformation accelerator for banks. J. Paym. Strateg. Syst. 10(1), 13\u201327 (2016)","journal-title":"J. Paym. Strateg. Syst."},{"key":"9691_CR39","doi-asserted-by":"crossref","unstructured":"Seo, J., Kim, K., Park, M., Park, M., Lee, K.: An analysis of economic impact on IoT under GDPR. In: 2017 International Conference on Information and Communication Technology Convergence (ICTC), pp.\u00a0879\u2013881 (2017)","DOI":"10.1109\/ICTC.2017.8190804"},{"key":"9691_CR40","doi-asserted-by":"crossref","unstructured":"Wagner, C., Dulaunoy, A., Wagener, G., Iklody, A.: Misp: the design and implementation of a collaborative threat intelligence sharing platform. In: Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security, pp.\u00a049\u201356 (2016)","DOI":"10.1145\/2994539.2994542"},{"key":"9691_CR41","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Portmann, M.: An explainable machine learning-based network intrusion detection system for enabling generalisability in securing IoT networks. arXiv:2104.07183 (2021)","DOI":"10.21203\/rs.3.rs-2035633\/v1"},{"key":"9691_CR42","doi-asserted-by":"crossref","unstructured":"Portmann, M.: Netflow datasets for machine learning-based network intrusion detection systems. In: Big Data Technologies and Applications: 10th EAI International Conference, BDTA 2020 and 13th EAI International Conference on Wireless Internet, WiCON 2020, Virtual Event, December 11, 2020: Proceedings, vol.\u00a0371, p.\u00a0117, Springer Nature (2021)","DOI":"10.1007\/978-3-030-72802-1_9"},{"key":"9691_CR43","doi-asserted-by":"crossref","unstructured":"Claise, B., Sadasivan, G., Valluri, V., Djernaes, M.: Cisco systems netflow services export version 9 (2004)","DOI":"10.17487\/rfc3954"},{"key":"9691_CR44","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., Portmann, M.: Towards a standard feature set of NIDS datasets. arXiv:2101.11315 (2021)"},{"key":"9691_CR45","doi-asserted-by":"crossref","unstructured":"Moustafa, N., Slay, J.: Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), pp\u00a01\u20136, IEEE (2015)","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"9691_CR46","unstructured":"Deri, L., SpA, N.: nprobe: an open source netflow probe for gigabit networks. In: TERENA Networking Conference, pp\u00a01\u20134 (2003)"},{"key":"9691_CR47","doi-asserted-by":"publisher","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","volume":"100","author":"N Koroniotis","year":"2019","unstructured":"Koroniotis, N., Moustafa, N., Sitnikova, E., Turnbull, B.: Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset. Futur. Gener. Comput. Syst. 100, 779\u2013796 (2019)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"9691_CR48","unstructured":"Google, \u201cTensorflow.\u201d https:\/\/www.tensorflow.org"},{"key":"9691_CR49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-28954-6","volume-title":"Explainable AI: Interpreting, Explaining and Visualizing Deep Learning","author":"W Samek","year":"2019","unstructured":"Samek, W., Montavon, G., Vedaldi, A., Hansen, L.K., M\u00fcller, K.-R.: Explainable AI: Interpreting, Explaining and Visualizing Deep Learning, vol. 11700. Springer, Berlin (2019)"},{"key":"9691_CR50","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102496","volume":"112","author":"R Coulter","year":"2022","unstructured":"Coulter, R., Zhang, J., Pan, L., Xiang, Y.: Domain adaptation for windows advanced persistent threat detection. Comput. Secur. 112, 102496 (2022)","journal-title":"Comput. Secur."}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-022-09691-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-022-09691-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-022-09691-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,5]],"date-time":"2024-10-05T09:06:37Z","timestamp":1728119197000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-022-09691-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,7]]},"references-count":50,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,1]]}},"alternative-id":["9691"],"URL":"https:\/\/doi.org\/10.1007\/s10922-022-09691-3","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10,7]]},"assertion":[{"value":"7 May 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 July 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 September 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 October 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}}],"article-number":"3"}}