A Convolutional Auto-Encoder Method for Anomaly Detection on System Logs

Yu Cui, Yiping Sun, Jinglu Hu, Gehao Sheng

研究成果: Conference contribution

13 被引用数 (Scopus)

抄録

Anomaly detection on system logs is to report system failures with utilization of console logs collected from devices, which ensures the reliability of systems. Most previous researches split logs into sequential time windows and regarded each window as an independent instance for classification using popular machine learning methods like support vector machine(SVM), however, neglected the time patterns under logs. Those approaches also suffer from information loss due to the vector representation, and high dimensionality if there is a large number of log events. To make up these deficiencies, unlike most traditional methods that used a vector to represent a period behavior at the macro level, we construct a 2D matrix to reveal more detailed system behaviors in the time period by dividing each window into sequential subwindows. To provide a more efficient representation, we further use the ant colony optimization algorithm to find a highly-coupled event template as the horizontal index of the 2D window matrix to replace the disordered one. To capture time dependencies, a multi-module convolutional auto-encoder is configured as that different paralleled modules scan among different time intervals to extract information respectively. These features are then concatenated in latent space as the final input, which contains diversified time information, for classification by SVM. The experiments on Blue Gene/L log dataset showed that our proposed method outperforms the state-of-art SVM method.

本文言語English
ホスト出版物のタイトルProceedings - 2018 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2018
出版社Institute of Electrical and Electronics Engineers Inc.
ページ3057-3062
ページ数6
ISBN(電子版)9781538666500
DOI
出版ステータスPublished - 2019 1月 16
イベント2018 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2018 - Miyazaki, Japan
継続期間: 2018 10月 72018 10月 10

出版物シリーズ

名前Proceedings - 2018 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2018

Conference

Conference2018 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2018
国/地域Japan
CityMiyazaki
Period18/10/718/10/10

ASJC Scopus subject areas

  • 情報システム
  • 情報システムおよび情報管理
  • 健康情報学
  • 人工知能
  • コンピュータ ネットワークおよび通信
  • 人間とコンピュータの相互作用

フィンガープリント

「A Convolutional Auto-Encoder Method for Anomaly Detection on System Logs」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル