University of Tennessee at Chattanooga
Log file anomaly detection using knowledge graphs and graph neural networks
Abstract
dc:description.abstractLog files contain valuable information for detecting abnormal behavior. To detect anomalies, researchers have proposed representing log files as knowledge graphs (KGs) and using KG completion (KGC) techniques to predict new facts. However, current research in this area is limited, and there is no end-to-end system that includes both KG generation and KGC for log-based anomaly detection. In this study, we present an end-to-end system that utilizes graph neural networks (GNNs) and KGC to detect anomalies in log files. The proposed system has two main components. The first component employs templates to generate a KG from logs that capture normal behavior. The second component applies KG embedding models enhanced with GNN layers to the generated KG and employs KGC to determine suspiciousness of new information through binary classification. We evaluated the proposed method using two public datasets with standard KGC metrics. The experimental results demonstrate its promising potential.
Degree
thesis:*- Grantor dc:publisher
- University of Tennessee at Chattanooga
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Payne, Lucas
- Contributors dc:contributor
-
- Xie, Mengjun
- Qin, Hong; Yang, Li
- College of Engineering and Computer Science
Subjects
dc:subject × 3Rights
dc:rights- Language dc:language
- English, eng
Identifiers
dc:identifier.*- Repository record dc:identifier
- https://scholar.utc.edu/theses/829
- OAI identifier oai:identifier
- oai:scholar.utc.edu:theses-2010