Show simple item record

dc.contributor.authorAstekin, M.
dc.contributor.authorÖzcan, S.
dc.contributor.authorSözer, Hasan
dc.date.accessioned2020-09-09T10:05:32Z
dc.date.available2020-09-09T10:05:32Z
dc.date.issued2019
dc.identifier.isbn978-1-7281-0857-5
dc.identifier.urihttp://hdl.handle.net/10679/6930
dc.identifier.urihttps://ieeexplore.ieee.org/document/9006593
dc.description.abstractAnomalies during system execution can be detected by automated analysis of logs generated by the system. However, large scale systems can generate tens of millions of lines of logs within days. Centralized implementations of traditional machine learning algorithms are not scalable for such data. Therefore, we recently introduced a distributed log analysis framework for anomaly detection. In this paper, we introduce an extension of this framework, which can detect anomalies earlier via incremental analysis instead of the existing offline analysis approach. In the extended version, we periodically process the log data that is accumulated so far. We conducted controlled experiments based on a benchmark dataset to evaluate the effectiveness of this approach. We repeated our experiments with various periods that determine the frequency of analysis as well as the size of the data processed each time. Results showed that our online analysis can improve anomaly detection time significantly while keeping the accuracy level same as that is obtained with the offline approach. The only exceptional case, where the accuracy is compromised, rarely occurs when the analysis is triggered before all the log data associated with a particular session of events are collected.en_US
dc.language.isoengen_US
dc.publisherIEEEen_US
dc.relation.ispartof2019 IEEE International Conference on Big Data (Big Data)
dc.rightsrestrictedAccess
dc.titleIncremental analysis of large-scale system logs for anomaly detectionen_US
dc.typeConference paperen_US
dc.publicationstatusPublisheden_US
dc.contributor.departmentÖzyeğin University
dc.contributor.authorID(ORCID 0000-0002-2968-4763 & YÖK ID 23178) Sözer, Hasan
dc.contributor.ozuauthorSözer, Hasan
dc.identifier.startpage2119en_US
dc.identifier.endpage2127en_US
dc.identifier.wosWOS:000554828702028
dc.identifier.doihttps://doi.org/10.1109/BigData47090.2019.9006593en_US
dc.subject.keywordsLog analysisen_US
dc.subject.keywordsDistributed systemsen_US
dc.subject.keywordsParallel processingen_US
dc.subject.keywordsAnomaly detectionen_US
dc.subject.keywordsBig dataen_US
dc.subject.keywordsMachine learningen_US
dc.identifier.scopusSCOPUS:2-s2.0-85081345108
dc.relation.publicationcategoryConference Paper - International - Institutional Academic Staff


Files in this item

FilesSizeFormatView

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record


Share this page