首页|面向类重叠日志的一致性异常检测模型

面向类重叠日志的一致性异常检测模型

扫码查看
在系统日志异常检测中,决策边界出现的类重叠问题将导致传统分类器很难实现正确分类.为避免耗时的预处理技术或依赖特定算法,提出一致性异常检测模型.该模型计算样本与不同类别的隶属度,根据传统分类器的准确率差值选择最佳模糊度分离出类重叠日志;通过集成分类器的不一致性度量函数得到p值,根据预设置信度得到类重叠日志标签.实验结果表明,相比传统分类器,该模型的召回率和F值等平均提高10百分点左右,验证了该模型在处理类重叠问题的有效性.
CONFORMAL ANOMALY DETECTION MODEL FOR CLASS OVERLAP LOGS
In system log anomaly detection,the class overlap of decision boundaries makes it difficult for traditional classifiers to achieve correct classification.In order to avoid time-consuming preprocessing techniques or dependence on specific algorithms,a conformal anomaly detection model is proposed.The model calculated the membership degree of samples and different categories,and selected the best fuzzy degree to separate the class overlap logs according to the accuracy difference of the traditional classifier.The p value was obtained by integrating the non-conformal measure function of the ensemble learning classifier,and the class overlapping log labels were obtained according to the preset confidence.Experimental results show that compared with the traditional classifiers,the recall rate and F-measure of the proposed model are increased by about 10 percentage points on average,which verifies the effectiveness of the proposed model in dealing with class overlap.

Anomaly detectionClass overlapConformal detectionFuzzy degreeConfidence

吕宗平、梁孟孟、顾兆军、刘春波、王志

展开 >

中国民航大学信息安全测评中心 天津 300300

中国民航大学计算机科学与技术学院 天津 300300

南开大学网络空间安全学院 天津 300350

异常检测 类重叠 一致性检测 模糊度 置信度

国家自然科学基金项目国家自然科学基金项目民航安全能力建设项目民航安全能力建设项目中国科学院重点部署项目天津市自然科学基金项目

6187220261601467PESA2019073PESA2019074KFZD-SW-44019JCYBJC15500

2024

计算机应用与软件
上海市计算技术研究所 上海计算机软件技术开发中心

计算机应用与软件

CSTPCD北大核心
影响因子:0.615
ISSN:1000-386X
年,卷(期):2024.41(8)
  • 4