Incremental Analysis of Large-Scale System Logs for Anomaly Detection

被引:0
|
作者
Astekin, Merve [1 ]
Ozcan, Selim [1 ]
Sozer, Hasan [2 ]
机构
[1] TUBITAK BILGEM, Inst Informat Technol, Kocaeli, Turkey
[2] Ozyegin Univ, Dept Comp Sci, Istanbul, Turkey
关键词
log analysis; distributed systems; parallel processing; anomaly detection; big data; machine learning;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Anomalies during system execution can be detected by automated analysis of logs generated by the system. However, large scale systems can generate tens of millions of lines of logs within days. Centralized implementations of traditional machine learning algorithms are not scalable for such data. Therefore, we recently introduced a distributed log analysis framework for anomaly detection. In this paper, we introduce an extension of this framework, which can detect anomalies earlier via incremental analysis instead of the existing offline analysis approach. In the extended version, we periodically process the log data that is accumulated so far. We conducted controlled experiments based on a benchmark dataset to evaluate the effectiveness of this approach. We repeated our experiments with various periods that determine the frequency of analysis as well as the size of the data processed each time. Results showed that our online analysis can improve anomaly detection time significantly while keeping the accuracy level same as that is obtained with the offline approach. The only exceptional case, where the accuracy is compromised, rarely occurs when the analysis is triggered before all the log data associated with a particular session of events are collected.
引用
收藏
页码:2119 / 2127
页数:9
相关论文
共 50 条
  • [1] DILAF: A framework for distributed analysis of large-scale system logs for anomaly detection
    Astekin, Merve
    Zengin, Harun
    Sozer, Hasan
    [J]. SOFTWARE-PRACTICE & EXPERIENCE, 2019, 49 (02): : 153 - 170
  • [2] Anomaly States Monitoring of Large-Scale Systems with Intellectual Analysis of System Logs
    Sheluhin, Oleg
    Osin, Andrey
    [J]. PROCEEDINGS OF THE 24TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT), 2019, : 395 - 401
  • [3] Feedback-Aware Anomaly Detection Through Logs for Large-Scale Software Systems
    HAN Jing
    JIA Tong
    WU Yifan
    HOU Chuanjia
    LI Ying
    [J]. ZTE Communications, 2021, 19 (03) : 88 - 94
  • [4] Evaluation of Distributed Machine Learning Algorithms for Anomaly Detection from Large-Scale System Logs: A Case Study
    Astekin, Merve
    Zengin, Harun
    Sozer, Hasan
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 2071 - 2077
  • [5] LogFlash: Real-time Streaming Anomaly Detection and Diagnosis from System Logs for Large-scale Software Systems
    Jia, Tong
    Wu, Yifan
    Hou, Chuanjia
    Li, Ying
    [J]. 2021 IEEE 32ND INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE 2021), 2021, : 80 - 90
  • [6] Large Scale Anomaly Detection in Data Center Logs and Metrics
    Martinez-Alvarez, Rafael P.
    Giraldo-Rodriguez, Carlos
    Chaves-Dieguez, David
    [J]. ECSA 2018: PROCEEDINGS OF THE 12TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE: COMPANION PROCEEDINGS, 2018,
  • [7] Incremental Large-Scale Electrostatic Analysis
    Ye, Zuochang
    Zhu, Zhenhai
    Phillips, Joel R.
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2009, 28 (11) : 1641 - 1653
  • [8] Performance Anomaly and Change Point Detection For Large-Scale System Management
    Trubin, Igor
    [J]. ICPE'20: COMPANION OF THE ACM/SPEC INTERNATIONAL CONFERENCE ON PERFORMANCE ENGINEERING, 2020, : 7 - 7
  • [9] A novel multi-modal incremental tensor decomposition for anomaly detection in large-scale networks
    Fan, Rongqiao
    Fan, Qiyuan
    Li, Xue
    Wang, Puming
    Xu, Jing
    Jin, Xin
    Yao, Shaowen
    Liu, Peng
    [J]. INFORMATION SCIENCES, 2024, 681
  • [10] Frequency Domain Analysis of Large-Scale Proxy Logs for Botnet Traffic Detection
    Bottazzi, Giovanni
    Italiano, Giuseppe F.
    Rutigliano, Giuseppe G.
    [J]. SECURITY OF INFORMATION AND NETWORKS (SIN'16), 2016, : 76 - 80