SaTC: CORE: Medium: Large-Scale Data Driven Anomaly Detection and Diagnosis from System Logs
SaTC: CORE: Medium: Large-Scale Data Driven Anomaly Detection and Diagnosis from System Logs
批准号:
1801446
负责人:
Robert Ricci
金额:
$110.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-01 至 2023-07-31
中文摘要
检测计算机系统中的异常和异常行为是确保计算机系统安全可靠的关键部分。记录程序所采取的操作的系统日志是异常检测的一个很有前途的数据来源。然而,进行日志分析的现有实践和工具需要深厚的专业知识,并且在定义和解释可能的异常时需要大量的人力参与,这限制了它们的可扩展性和有效性。该项目的目标是通过开发一个名为DeepLog的框架,通过(a)推进自然语言处理技术,从各种日志文件中提取结构化信息,以支持跨不同数据源和时间的分析,从而提高基于日志的异常检测的技术水平;(b)开发新方法,对合法工作流程进行建模,并随时间记录事件序列。(c)采用机器学习方法来识别代表潜在异常的工作流程的偏差,以及(d)为系统管理员创建工具,帮助他们更有效地诊断可能的安全问题。这项工作将被整合到一个免费提供的软件包中,以使其他研究人员和实践系统管理员受益,并用于支持研究机构的课堂和基于研究的教育活动。对于日志解析,团队将采用命名实体识别方法来解析非结构化日志和结构化日志,其中结构不是由正则表达式预先定义的,例如,将其解析为日志事件类型和参数的结构化键值对。这些数据可以看作是一个多维特征空间,其内容受到底层程序执行的约束,因此反映了一个隐藏的结构,该结构定义了一组有效的、非异常的执行序列。为了帮助阐明这种隐藏的结构,该团队将开发基于长短期记忆(LSTM)的神经网络模型,该模型使用键和值元素从从已知正常系统运行中提取的数据中提取程序行为的语义有意义的子序列。一旦使用已知的训练数据开发了这些模型,它们就可以通过标记考虑系统、日志和模型当前状态下意外的新日志条目来应用于异常检测;它们还可以用来推断前面描述的底层工作流和隐藏结构。这些模型将通过在线学习方法、管理员对报告异常严重性的反馈以及生成对抗训练模型得到改进。生成对抗训练模型创建执行序列,尽管异常,但与嵌入在日志和基于lstm的模型中的隐藏结构密切相关。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Detecting unusual and anomalous behavior in computer systems is a critical part of ensuring they are secure and trustworthy. System logs, which record actions taken by programs, are a promising source of data for such anomaly detection. However, existing practices and tools for doing log analysis require deep expertise, as well as heavy human involvement in both defining and interpreting possible anomalies, which limits their scalability and effectiveness. This project's goal is to improve the state of the art around log-based anomaly detection by developing a framework called DeepLog through (a) advancing natural language processing techniques to extract structured information from a wide variety of log files to support analysis across different data sources and across time, (b) developing new methods to model legitimate workflows and log event sequences over time, (c) adapting machine learning methods to identify deviations from those workflows that represent potential anomalies, and (d) creating tools for system administrators to help them diagnose possible security issues more effectively and efficiently. The work will be integrated into a freely available software package to benefit both other researchers and practicing system administrators and used to support both classroom and research-based educational activities at the investigators' institutions.Toward log parsing, the team will adapt named entity recognition methods to parse unstructured logs as well as structured logs where the structure is not pre-defined by, e.g., regular expressions, into structured key-value pairs of log event types and parameters. This data can be seen as a multi-dimensional feature space whose contents are constrained by the execution of the underlying programs and thus reflects a hidden structure that defines the set of valid, non-anomalous execution sequences. To help articulate this hidden structure, the team will develop long-short-term-memory (LSTM)-based neural network models that use both the key and value elements to extract semantically meaningful subsequences of program behavior from data extracted from system runs known to be normal. Once these models are developed using known-good training data, they can be applied to anomaly detection by flagging for consideration new log entries that are unexpected given the current state of the system, logs, and model; they can also be used to infer the underlying workflows and hidden structures described earlier. These models will be improved through that online learning methods, administrators' feedback about the seriousness of reported anomalies, and generative adversarial training models which create execution sequences that, though anomalous, hew closely to the hidden structures embedded in the logs and the LSTM-based models.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Rufaida Ahmed;J. Porter;Abubaker Abdelmutalab;R. Ricci]
通讯作者:
Rufaida Ahmed;J. Porter;Abubaker Abdelmutalab;R. Ricci
Right for the Right Reason: Evidence Extraction for Trustworthy Tabular Reasoning
正确的理由:为可信的表格推理提取证据
DOI:
10.18653/v1/2022.acl-long.231
发表时间:
2022
期刊:
Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics
影响因子:
--
作者:
[Gupta, Vivek, Zhang, Shuo, Vempala, Alakananda, He, Yujie, Choji, Temma, Srikumar, Vivek]
通讯作者:
Srikumar, Vivek
DOI:
10.18653/v1/2020.acl-main.438
发表时间:
2020-05
期刊:
ArXiv
影响因子:
--
作者:
[Xingyuan Pan;Maitrey Mehta;Vivek Srikumar]
通讯作者:
Xingyuan Pan;Maitrey Mehta;Vivek Srikumar
DOI:
10.18653/v1/2020.acl-main.744
发表时间:
2020-05
期刊:
ArXiv
影响因子:
--
作者:
[Tao Li;Parth Anand Jawale;M. Palmer;Vivek Srikumar]
通讯作者:
Tao Li;Parth Anand Jawale;M. Palmer;Vivek Srikumar
DOI:
10.18653/v1/p19-1028
发表时间:
2019-06
期刊:
ArXiv
影响因子:
--
作者:
[Tao Li;Vivek Srikumar]
通讯作者:
Tao Li;Vivek Srikumar
共 8 条
Collaborative Research: SII-NRDZ: ASPIRE: Advanced SPectrum Initiative for Research and Experimentation
-
批准号:2232474
-
项目类别:Cooperative Agreement
-
资助金额:$10.0万
-
财政年份:2022
-
负责人:Robert Ricci
-
依托单位:
CCRI: Planning-C: TopoCloud: A New Community Testbed With Unique Network Topology Flexibility
-
批准号:2213823
-
项目类别:Standard Grant
-
资助金额:$9.88万
-
财政年份:2022
-
负责人:Robert Ricci
-
依托单位:
CloudLab Phase III: Expanding the Frontiers of Cloud Computing Through World-Class Community Infrastructure
-
批准号:2027208
-
项目类别:Cooperative Agreement
-
资助金额:$1000.0万
-
财政年份:2020
-
负责人:Robert Ricci
-
依托单位:
CloudLab Phase II: Community Infrastructure To Expand the Frontiers of Cloud Computing Research
-
批准号:1743363
-
项目类别:Cooperative Agreement
-
资助金额:$968.83万
-
财政年份:2017
-
负责人:Robert Ricci
-
依托单位:
CloudLab: Flexible Scientific Infrastructure to Support Fundamental Advances in Cloud Architectures and Applications
-
批准号:1419199
-
项目类别:Cooperative Agreement
-
资助金额:$1000.0万
-
财政年份:2014
-
负责人:Robert Ricci
-
依托单位:
The Sixteenth GENI Engineering Conference
-
批准号:1304751
-
项目类别:Standard Grant
-
资助金额:$4.99万
-
财政年份:2013
-
负责人:Robert Ricci
-
依托单位:
MRI: Development of Apt, A Testbed Instrument with Adaptable Profiles for Network and Computational Science
-
批准号:1338155
-
项目类别:Standard Grant
-
资助金额:$240.0万
-
财政年份:2013
-
负责人:Robert Ricci
-
依托单位:
CI-ADDO-EN: Enhancing Emulab for Virtualization and Clouds
-
批准号:1059440
-
项目类别:Standard Grant
-
资助金额:$100.0万
-
财政年份:2011
-
负责人:Robert Ricci
-
依托单位:
Instructor's Reference Manual for Discovery Chemistry
-
批准号:9254016
-
项目类别:Standard Grant
-
资助金额:$14.3万
-
财政年份:1993
-
负责人:Robert Ricci
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: