Unsupervised log message anomaly detection
dc.contributor.author | Farzad, Amir | |
dc.contributor.author | Gulliver, Thomas Aaron | |
dc.date.accessioned | 2020-08-22T00:20:38Z | |
dc.date.available | 2020-08-22T00:20:38Z | |
dc.date.copyright | 2020 | en_US |
dc.date.issued | 2020 | |
dc.description.abstract | Log messages are now broadly used in cloud and software systems. They are important for classification and anomaly detection as millions of logs are generated each day. In this paper, an unsupervised model for log message anomaly detection is proposed which employs Isolation Forest and two deep Autoencoder networks. The Autoencoder networks are used for training and feature extraction, and then for anomaly detection, while Isolation Forest is used for positive sample prediction. The proposed model is evaluated using the BGL, Openstack and Thunderbird log message data sets. The results obtained show that the number of negative samples predicted to be positive is low, especially with Isolation Forest and one Autoencoder. Further, the results are better than with other well-known models. | en_US |
dc.description.reviewstatus | Reviewed | en_US |
dc.description.scholarlevel | Faculty | en_US |
dc.identifier.citation | Farzad, A., & Gulliver, T. A. (2020). Unsupervised log message anomaly detection. ICT Express, 6(3), 229-237. https://doi.org/10.1016/j.icte.2020.06.003. | en_US |
dc.identifier.uri | https://doi.org/10.1016/j.icte.2020.06.003 | |
dc.identifier.uri | http://hdl.handle.net/1828/12020 | |
dc.language.iso | en | en_US |
dc.publisher | ICT Express | en_US |
dc.subject | Anomaly detection | en_US |
dc.subject | Classification | en_US |
dc.subject | Deep learning | en_US |
dc.subject | Log messages | en_US |
dc.subject | Unsupervised learning | en_US |
dc.title | Unsupervised log message anomaly detection | en_US |
dc.type | Article | en_US |