Find in Library
Search millions of books, articles, and more
Indexed Open Access Databases
nLSALog: An Anomaly Detection Framework for Log Sequence in Security Management
oleh: Ruipeng Yang, Dan Qu, Ying Gao, Yekui Qian, Yongwang Tang
Format: | Article |
---|---|
Diterbitkan: | IEEE 2019-01-01 |
Deskripsi
For the security defense in the current Intelligent Transportation System (ITS), malware is often used as the security analysis data source, but only the known attack type can be detected. A general anomaly detection framework is proposed, using log data as the analysis data source. By modeling the log template sequence as a natural language sequence and using the stacked Long Short-Term Memory (LSTM) with self-attention mechanism, the framework can effectively extract the hidden pattern of the log template sequence, and well express the dependencies inside the log template sequence. The experimental results show that the overall accuracy of log sequence anomaly detection of the detection framework is better than that of existing methods and the time cost is lower.