Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 管理學院
  3. 資訊管理學系
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/88408
Title: 基於圖卷積網路及注意力機制進行系統日誌異常偵測
System log anomaly detection based on graph convolutional network and attention mechanism
Authors: 黃欣鈺
Hsin-Yu Huang
Advisor: 陳建錦
Chien-Chin Chen
Keyword: 異常檢測,日誌分析,日誌序列,圖卷積網絡,注意力機制,
Anomaly Detection,Log Analysis,Log sequence,Graph Convolutional Network,Attention mechanism,
Publication Year : 2023
Degree: 碩士
Abstract: 異常偵測是建立安全可靠系統的關鍵步驟之一。目前,許多應用與服務都依賴於電腦系統,一旦發生故障,將對使用者和企業造成重大影響。為了避免造成巨額損失,我們可以透過監控系統日誌來了解系統的狀態,並建立自動異常偵測系統,以即時識別和解決異常情況。然而,有效分析日誌資料面臨著一些挑戰。因為日誌通常非常龐大且複雜,因此需要適當的分析工具和技術進行資料清理和預處理,以提高日誌分析的準確性和效率。過去的研究通常僅依賴於分析局部日誌事件的順序和頻率,忽略了日誌事件之間的結構關係和遠程依賴性,這可能導致潛在的誤報和性能不穩定。為此,本研究提出了一種基於圖的日誌異常偵測方法,首先將日誌進行前處理並分組成日誌序列,之後將日誌序列表示為圖結構,考慮事件之間的轉換關係,並將相關資訊作為有向邊的權重,用來捕捉了事件的發生順序和相互關係,接著通過使用圖卷積神經網絡結合注意機制,考慮到多層圖結構資訊,捕捉可能指示異常的日誌特徵並執行圖級分類。在分散式系統與超級電腦的日誌資料實驗顯示,我們提出的方法性能優於其他現有的基於日誌的異常偵測方法。
Anomaly detection is crucial for a secure and reliable system. Currently, many services rely on computer systems, and any failure can have a significant impact on users and businesses. To avoid substantial losses caused by failures, we can monitor system logs to understand the system's status and build an automated anomaly detection system to identify and resolve abnormal situations in real-time. However, effective analysis of log data faces several challenges. Due to the typically large and complex nature of logs, proper analysis tools and techniques are needed for data cleaning and preprocessing to enhance the accuracy and efficiency of log analysis. Past research often relied solely on analyzing the order and frequency of local log events, overlooking the structural relationships and long-range dependencies between log events, which could lead to potential false positives and performance instability. To address these challenges, this study proposes a graph-based approach for log anomaly detection. Firstly, the logs are preprocessed and grouped into log sequences. Then, the log sequences are represented as a graph structure, considering the transition relationships between events and using the relevant information as weights on directed edges to capture the occurrence order and interrelationships between events. Subsequently, by utilizing graph convolutional neural networks combined with attention mechanisms, the method takes into account the multi-layered graph structure information to capture log features that may indicate anomalies and perform graph-level classification. Experiments on log data from distributed systems and supercomputers demonstrate that our proposed method outperforms other existing log-based anomaly detection methods in terms of performance.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/88408
DOI: 10.6342/NTU202301942
Fulltext Rights: 未授權
Appears in Collections:資訊管理學系

Files in This Item:
File SizeFormat 
ntu-111-2.pdf
  Restricted Access
1.94 MBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved