错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

System for Detecting Anomalies in Information Security Logs

  • Alexey M. Vulfin,
  • Pavel S. Lozhnikov,
  • Alexey E. Sulavko,
  • Elena A. Atarskaya,
  • Anastasiya D. Kirillova

摘要

The work proposes models and algorithms for detecting anomalies in the functioning of an information system based on the analysis of information security tools logs using neural network models. The purpose of the research is to improve models and algorithms for analyzing text logs to increase the efficiency of detecting abnormal states of the system. The novelty of the proposed preprocessing algorithm, analysis model and anomaly detection algorithm is based on the use of deep and machine learning methods and models. A distinctive feature is the combination of stages of the processing pipeline and feature extraction, as well as the use of a neural network model of an autoencoder with long short-term memory in combination with machine learning models for adaptive selection of anomalous chains of events. A distinctive feature is the combination of stages of the processing and feature extraction pipeline, as well as the use of a neural network model of an autoencoder with long short-term memory for adaptive selection of anomalous chains of events. This makes it possible to increase the efficiency of analyzing text logs of event registration in SIEM, and, consequently, to increase the efficiency of identifying anomalous states of information system components potentially related to the actions of an attacker.