基于演化决策的分布式日志驱动异常检测系统
密码学与安全
2025-04-04 v1 分布式、并行与集群计算
摘要
有效地从日志中检测异常对于增强网络安全防御、启用威胁的早期识别至关重要。尽管已取得的进展使异常检测系统在诸多方面(如后检测验证、可扩展性和有效维护)方面仍有不足。这些限制不仅阻碍了对新威胁的检测,也会损害整个系统的性能。为了应对这些挑战,我们提出了 CEDLog,一种新型实用框架,将 Elastic Weight Consolidation (EWC) 用于持续学习,并通过集成 Apache Airflow 和 Dask 实现可扩展的分布式计算。在 CEDLog 中,通过 MLP 和图卷积网络 (GCN) 的综合,利用事件日志中关键特征来检测异常。通过在大规模数据集上的比较,我们展示了 CEDLog 的优势,突出了高效更新和低误报率。
引用
@article{arxiv.2504.02322,
title = {Distributed Log-driven Anomaly Detection System based on Evolving Decision Making},
author = {Zhuoran Tan and Qiyuan Wang and Christos Anagnostopoulos and Shameem P. Parambath and Jeremy Singer and Sam Temple},
journal= {arXiv preprint arXiv:2504.02322},
year = {2025}
}
备注
This paper has been accepted at 45th IEEE International Conference on Distributed Computing Systems