Netinfo Security ›› 2020, Vol. 20 ›› Issue (9): 1-5.doi: 10.3969/j.issn.1671-1122.2020.09.001

Previous Articles     Next Articles

Log Anomaly Detection Method Based on Improved Time Series Model

LU Jiali()   

  1. Beijing Topsec Science & Technology Inc., Beijing 100085, China
  • Received:2020-07-16 Online:2020-09-10 Published:2020-10-15
  • Contact: Jiali LU E-mail:lu_jiali@topsec.com.cn

Abstract:

Security log analysis plays an irreplaceable role in the field of network security. Aiming at the characteristics of security log, this paper proposes a multi-model combination time series anomaly detection algorithm. It combines the characteristics of time series, uses Fourier series to remove complex seasonal components, uses trend extrapolation to remove trend components, and then uses ESD testing to perform anomaly detection on random residual components. The experimental results show that the time series anomaly detection algorithm proposed in this paper has good detection accuracy.

Key words: security log, time series, anomaly detection

CLC Number: