DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep Learning
Explore this paper's citation graph
Summary
DeepLog, a deep neural network model utilizing Long Short-Term Memory (LSTM), is proposed, to model a system log as a natural language sequence, which allows DeepLog to automatically learn log patterns from normal execution, and detect anomalies when log patterns deviate from the model trained from log data under normal execution.
- Type
- article
- Published
- 2017-10-30
- Cited by
- 2,019
- References
- 46
- OpenAlex
- https://openalex.org/W2767094836
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:4232579
Keywords
Computer science, Anomaly detection, Debugging, Anomaly (physics), Data mining
References
- Analyzing cluster log files using Logsurfer
- Automated System Monitoring and Notification with Swatch
- Recurrent neural network based language model
- Real-time Log File Analysis Using the Simple Event Correlator (SEC)
- Foundations of Statistical Natural Language Processing
- PerfAugur: Robust diagnostics for performance anomalies in cloud services
- Mining Invariants from Console Logs for System Problem Detection
- Structured Comparative Analysis of Systems Logs to Diagnose Performance Problems
- A Primer on Neural Network Models for Natural Language Processing
- Detection of Early-Stage Enterprise Infection by Mining Large-Scale Log Data
- Dynamic syslog mining for network failure monitoring
- Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks
- Detecting large-scale system problems by mining console logs
- Long Short-Term Memory
- Event Logs for the Analysis of Software Failures: A Rule-Based Approach
- Execution Anomaly Detection in Distributed Systems through Unstructured Log Analysis
- Online System Problem Detection by Mining Patterns of Console Logs
- Clustering event logs using iterative partitioning
- Mining program workflow from interleaved traces
- Inferring models of concurrent systems from logs of their behavior with CSight
Cited by
- Recurrent Neural Network Attention Mechanisms for Interpretable System Log Anomaly Detection
- Adaptive Performance Anomaly Detection in Distributed Systems Using Online SVMs
- Detecting monitor compromise using evidential reasoning: poster
- DIoT: A Self-learning System for Detecting Compromised IoT Devices
- Execution anomaly detection in large-scale systems through console log analysis
- Towards Autonomic Science Infrastructure: Architecture, Limitations, and Open Issues
- LogLens: A Real-Time Log Analysis System
- Desh: deep learning for system health prediction of lead times to failure in HPC
- An unsupervised framework for detecting anomalous messages from syslog log files
- ROPNN: Detection of ROP Payloads Using Deep Neural Networks
- Monitoring Release Logs at Adyen: Feature Extraction and Anomaly Detection
- Attention-Based Bi-LSTM Model for Anomalous HTTP Traffic Detection
- Threat Intelligence Computing
- Next Stop "NoOps": Enabling Cross-System Diagnostics Through Graph-Based Composition of Logs and Metrics
- Deep Learning in Information Security
- Tiresias: Predicting Security Events Through Deep Learning
- Large scale anomaly detection in data center logs and metrics
- Spell: Online Streaming Parsing of Large Unstructured System Logs
- Pipeline for Real-time Anomaly Detection in Log Data Streams using Apache Kafka and Apache Spark
- IoT-KEEPER: Securing IoT Communications in Edge Networks
Related papers
- Using submission log data to investigate novice programmers’ employment of debugging strategies
- Studying the advancement in debugging practice of professional software developers
- Analysis and Comparison of the Debugging Method of the Embedded System
- Debugging: from novice to expert
- Towards an Understanding of the Causes of Difficulties in Debugging