Recurrent Neural Network Attention Mechanisms for Interpretable System Log Anomaly Detection

03/13/2018
by   Andy Brown, et al.
0

Deep learning has recently demonstrated state-of-the art performance on key tasks related to the maintenance of computer systems, such as intrusion detection, denial of service attack detection, hardware and software system failures, and malware detection. In these contexts, model interpretability is vital for administrator and analyst to trust and act on the automated analysis of machine learning models. Deep learning methods have been criticized as black box oracles which allow limited insight into decision factors. In this work we seek to "bridge the gap" between the impressive performance of deep learning models and the need for interpretable model introspection. To this end we present recurrent neural network (RNN) language models augmented with attention for anomaly detection in system logs. Our methods are generally applicable to any computer system and logging source. By incorporating attention variants into our RNN language models we create opportunities for model introspection and analysis without sacrificing state-of-the art performance. We demonstrate model performance and illustrate model interpretability on an intrusion detection task using the Los Alamos National Laboratory (LANL) cyber security dataset, reporting upward of 0.99 area under the receiver operator characteristic curve despite being trained only on a single day's worth of data.

READ FULL TEXT

page 6

page 7

research
12/02/2017

Recurrent Neural Network Language Models for Open Vocabulary Event-Level Cyber Anomaly Detection

Automated analysis methods are crucial aids for monitoring and defending...
research
12/02/2022

A Hybrid Deep Learning Anomaly Detection Framework for Intrusion Detection

Cyber intrusion attacks that compromise the users' critical and sensitiv...
research
03/12/2021

Explaining Network Intrusion Detection System Using Explainable AI Framework

Cybersecurity is a domain where the data distribution is constantly chan...
research
12/13/2020

Application of deep learning to enhance the accuracy of intrusion detection in modern computer networks

Application of deep learning to enhance the accuracy of intrusion detect...
research
07/19/2019

New Era of Deeplearning-Based Malware Intrusion Detection: The Malware Detection and Prediction Based On Deep Learning

With the development of artificial intelligence algorithms like deep lea...
research
06/21/2022

Can process mining help in anomaly-based intrusion detection?

In this paper, we consider the naive applications of process mining in n...
research
08/15/2023

LogPrompt: Prompt Engineering Towards Zero-Shot and Interpretable Log Analysis

Automated log analysis is crucial in modern software-intensive systems f...

Please sign up or login with your details

Forgot password? Click here to reset