ETGuard: Malicious Encrypted Traffic Detection in Blockchain-based Power Grid Systems

Peng Zhou,Yongdong Liu,Lixun Ma,Weiye Zhang,Haohan Tan,Zhenguang Liu,Butian Huang
2024-08-20
Abstract:The escalating prevalence of encryption protocols has led to a concomitant surge in the number of malicious attacks that hide in encrypted traffic. Power grid systems, as fundamental infrastructure, are becoming prime targets for such attacks. Conventional methods for detecting malicious encrypted packets typically use a static pre-trained model. We observe that these methods are not well-suited for blockchain-based power grid systems. More critically, they fall short in dynamic environments where new types of encrypted attacks continuously emerge. Motivated by this, in this paper we try to tackle these challenges from two aspects: (1) We present a novel framework that is able to automatically detect malicious encrypted traffic in blockchain-based power grid systems and incrementally learn from new malicious traffic. (2) We mathematically derive incremental learning losses to resist the forgetting of old attack patterns while ensuring the model is capable of handling new encrypted attack patterns. Empirically, our method achieves state-of-the-art performance on three different benchmark datasets. We also constructed the first malicious encrypted traffic dataset for blockchain-based power grid scenario. Our code and dataset are available at <a class="link-external link-https" href="https://github.com/PPPmzt/ETGuard" rel="external noopener nofollow">this https URL</a>, hoping to inspire future research.
Cryptography and Security,Artificial Intelligence
What problem does this paper attempt to address?
The paper aims to address the issue of encrypted malicious traffic detection in blockchain power systems. Specifically, the authors propose a new framework called ETGuard for automatically detecting encrypted malicious traffic in blockchain power systems and gradually adapting to new attack patterns through incremental learning. Traditional methods perform poorly in blockchain power systems, especially when facing new types of encrypted attacks. Methods that rely on static pre-trained models struggle to cope with new threats in dynamic environments. To solve these problems, ETGuard adopts the following two innovations: 1. **Automatic Detection and Incremental Learning**: A framework is proposed that can automatically detect encrypted malicious traffic in blockchain power systems and continuously learn from new malicious traffic through an incremental learning mechanism to adapt to emerging attack types. 2. **Mathematical Derivation and Loss Function Design**: To effectively perform incremental learning, the paper derives an incremental learning loss function to ensure that the model does not forget old attack patterns while learning new ones. Additionally, a sample buffer is introduced to store representative traffic samples for subsequent incremental model updates. Experimental results show that ETGuard achieves state-of-the-art performance on three different benchmark datasets and performs excellently in real-world scenarios of blockchain power systems. Furthermore, the researchers have constructed the first malicious encrypted traffic dataset for blockchain power systems, GridET-2024, to support future research work.