LogNADS: Network anomaly detection scheme based on log semantics representation

被引:14
|
作者
Liu, Xu [1 ,2 ]
Liu, Weiyou [1 ]
Di, Xiaoqiang [1 ,2 ,3 ]
Li, Jinqing [1 ,2 ]
Cai, Binbin [3 ]
Ren, Weiwu [1 ]
Yang, Huamin [1 ,2 ]
机构
[1] Changchun Univ Sci & Technol, Sch Comp Sci & Technol, Changchun, Peoples R China
[2] Jilin Prov Key Lab Network & Informat Secur, Changchun, Peoples R China
[3] Changchun Univ Sci & Technol, Informat Ctr, Changchun 130022, Peoples R China
关键词
Anomaly detection; Log; Semantics representation; LSTM;
D O I
10.1016/j.future.2021.05.024
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Semantics-aware anomaly detection based on log has attracted much attention. However, the existing methods based on the weighted aggregation of all word vectors might lose the semantic relationship of word order and cannot maintain the unique representation, and the methods based on word order-preserving by concatenating all word vectors might lead to a high computation time cost. To solve these issues and further improve the sequential anomaly detection, this paper proposes a network anomaly detection scheme LogNADS by designing a novel log semantics representation method and an adaptive sequence data construction method. It first discards the useless words and then selects theme words to hold the log abstraction and maintain a low time cost as well. Subsequently, it concatenates theme words' vectors based on the original word order to maintain the unique representation and avoid the word order loss. Furthermore, to better detect the sequential anomalies, we utilize the sliding window scheme and design a method to compute the optimal window size for constructing the log sequence self-adaptively, and then LSTM is built to extract timing characteristics of the log sequences. Experimental results conducted on the public benchmark HDFS dataset and BGL dataset demonstrate the effectiveness of LogNADS through comparing with other state-of-the-art methods in the detection accuracy and time cost. Moreover, the statistical significance tests prove the superior performance. (C) 2021 Elsevier B.V. All rights reserved.
引用
收藏
页码:390 / 405
页数:16
相关论文
共 50 条
  • [1] NADSR: A Network Anomaly Detection Scheme Based on Representation
    Liu, Xu
    Di, Xiaoqiang
    Liu, Weiyou
    Zhang, Xingxu
    Qi, Hui
    Li, Jinqing
    Zhao, Jianping
    Yang, Huamin
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT (KSEM 2020), PT I, 2020, 12274 : 380 - 387
  • [2] On the effectiveness of log representation for log-based anomaly detection
    Wu, Xingfang
    Li, Heng
    Khomh, Foutse
    [J]. EMPIRICAL SOFTWARE ENGINEERING, 2023, 28 (06)
  • [3] On the effectiveness of log representation for log-based anomaly detection
    Xingfang Wu
    Heng Li
    Foutse Khomh
    [J]. Empirical Software Engineering, 2023, 28
  • [4] LayerLog: Log sequence anomaly detection based on hierarchical semantics
    Zhang, Chunkai
    Wang, Xinyu
    Zhang, Hongye
    Zhang, Jiahua
    Zhang, Hanyu
    Liu, Chuanyi
    Han, Peiyi
    [J]. APPLIED SOFT COMPUTING, 2023, 132
  • [5] Network Log Anomaly Detection Based on GRU and SVDD
    Liu, Shirong
    Chen, Xiong
    Peng, Xingxiong
    Xiao, Ruliang
    [J]. 2019 IEEE INTL CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, BIG DATA & CLOUD COMPUTING, SUSTAINABLE COMPUTING & COMMUNICATIONS, SOCIAL COMPUTING & NETWORKING (ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM 2019), 2019, : 1244 - 1249
  • [6] LogEncoder: Log-Based Contrastive Representation Learning for Anomaly Detection
    Qi, Jiaxing
    Luan, Zhongzhi
    Huang, Shaohan
    Fung, Carol
    Yang, Hailong
    Li, Hanlu
    Zhu, Danfeng
    Qian, Depei
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (02): : 1378 - 1391
  • [7] Communication Network Anomaly Detection Based on Log File Analysis
    Cheng, Xin
    Wang, Ruizhi
    [J]. ROUGH SETS AND KNOWLEDGE TECHNOLOGY, RSKT 2014, 2014, 8818 : 240 - 248
  • [8] NADS-RA: Network Anomaly Detection Scheme Based on Feature Representation and Data Augmentation
    Liu, Xu
    Di, Xiaoqiang
    Ding, Qiang
    Liu, Weiyou
    Qi, Hui
    Li, Jinqing
    Yang, Huamin
    [J]. IEEE ACCESS, 2020, 8 : 214781 - 214800
  • [9] Log anomaly detection based on BERT
    Tang, Pan
    Guan, Yepeng
    [J]. SIGNAL IMAGE AND VIDEO PROCESSING, 2024, 18 (8-9) : 6431 - 6441
  • [10] DNS-based network anomaly detection and eradicating scheme
    Chen, Chang-Shang
    Wang, Shang-Rung
    Liu, Ta-Chung
    [J]. Journal of Internet Technology, 2007, 8 (03): : 329 - 335