syslrn: Learning What to Monitor for Efficient Anomaly Detection

03/29/2022
by   Davide Sanvito, et al.
0

While monitoring system behavior to detect anomalies and failures is important, existing methods based on log-analysis can only be as good as the information contained in the logs, and other approaches that look at the OS-level software state introduce high overheads. We tackle the problem with syslrn, a system that first builds an understanding of a target system offline, and then tailors the online monitoring instrumentation based on the learned identifiers of normal behavior. While our syslrn prototype is still preliminary and lacks many features, we show in a case study for the monitoring of OpenStack failures that it can outperform state-of-the-art log-analysis systems with little overhead.

READ FULL TEXT
research
09/16/2022

LogGD:Detecting Anomalies from System Logs by Graph Neural Networks

Log analysis is one of the main techniques engineers use to troubleshoot...
research
04/24/2023

MoniLog: An Automated Log-Based Anomaly Detection System for Cloud Computing Infrastructures

Within today's large-scale systems, one anomaly can impact millions of u...
research
05/18/2023

Semantic Anomaly Detection with Large Language Models

As robots acquire increasingly sophisticated skills and see increasingly...
research
09/14/2020

Advanced Virus Monitoring and Analysis System

This research proposed an architecture and a system which able to monito...
research
07/13/2023

Retroactive Parametrized Monitoring

In online monitoring, we first synthesize a monitor from a formal specif...
research
07/08/2022

Encoding NetFlows for State-Machine Learning

NetFlow data is a well-known network log format used by many network ana...
research
06/06/2021

Multilayer Representation and Multiscale Analysis on Data Networks

The constant increase in the complexity of data networks motivates the s...

Please sign up or login with your details

Forgot password? Click here to reset