System for Detecting Anomalies in Information Security Logs
摘要
The work proposes models and algorithms for detecting anomalies in the functioning of an information system based on the analysis of information security tools logs using neural network models. The purpose of the research is to improve models and algorithms for analyzing text logs to increase the efficiency of detecting abnormal states of the system. The novelty of the proposed preprocessing algorithm, analysis model and anomaly detection algorithm is based on the use of deep and machine learning methods and models. A distinctive feature is the combination of stages of the processing pipeline and feature extraction, as well as the use of a neural network model of an autoencoder with long short-term memory in combination with machine learning models for adaptive selection of anomalous chains of events. A distinctive feature is the combination of stages of the processing and feature extraction pipeline, as well as the use of a neural network model of an autoencoder with long short-term memory for adaptive selection of anomalous chains of events. This makes it possible to increase the efficiency of analyzing text logs of event registration in SIEM, and, consequently, to increase the efficiency of identifying anomalous states of information system components potentially related to the actions of an attacker.