4.7 Article

DeepSyslog: Deep Anomaly Detection on Syslog Using Sentence Embedding and Metadata

期刊

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/TIFS.2022.3201379

关键词

Metadata; Anomaly detection; Feature extraction; Semantics; Indexes; History; Event detection; Anomaly detection; sentence embedding; event metadata

资金

  1. NSF [CNS2019340]
  2. Key Research and Development Program of Hainan Province [ZDYF2021GXJS014]
  3. Key Research and Development Program of Hubei Province [2020AAA001]
  4. Key-Area Research and Development Programs of Guangdong Province [2020B0101650001]

向作者/读者索取更多资源

This paper proposes a DeepSyslog method that represents Syslog with the context of log events and event metadata. It uses unsupervised sentence embedding to extract the semantic and context information hidden in the log stream, and combines it with event metadata to achieve high performance.
Anomaly events indicating the unhealthy status of the computer system are recorded in the system log (Syslog). Therefore, Syslog-based anomaly event detection is crucial for diagnosing system issues and problems. However, existing log-based anomaly detection approaches use raw and unstructured log entries independently and incompletely, i.e., without considering the context of each event and event metadata in the logs. They employ incomplete representation of unstructured log data, limiting the deep learning model's capacity in the early stage, which tends to omit anomaly events and cause false alarms. In this work, we propose DeepSyslog, which represents Syslog with the context of log events and event metadata in the logs. Inspired by the sequence nature of the log stream, we employ unsupervised sentence embedding to extract the semantic and context information hidden in the log stream, rather than word embedding or one-hot embedding, which only capture the similarities between log words. The sentence embedding is further integrated with event metadata to form complete representations of Syslog, which can distinguish the anomaly caused by the correlated log entries and exceptional event metadata in the log. The simulation results on widely used log datasets show that DeepSyslog achieves high performance compared with the existing log-based anomaly event detection approaches.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据