Zur Hauptnavigation wechseln Zur Suche wechseln Zum Hauptinhalt wechseln

Collaborative Anomaly Detection in Log Data: Comparative Analysis and Evaluation Framework

  • André García Gómez
  • , Max Landauer
  • , Markus Wurzenberger
  • , Florian Skopik
  • , Edgar Weippl

Veröffentlichungen: Beitrag in FachzeitschriftArtikelPeer Reviewed

Abstract

Log Anomaly Collaborative Intrusion Detection Systems (CIDS) are designed to detect suspicious activities and security breaches by analyzing log files using anomaly detection techniques while leveraging collaboration between multiple entities (e.g., different systems, organizations, or network nodes). Unlike traditional Intrusion Detection Systems (IDS) that require centralized algorithm updates and data aggregation, CIDS enable decentralized updates without extensive data exchange, improving efficacy, scalability, and compliance with regulatory constraints. Additionally, inter-detector communication helps to reduce the number of false positives. These systems are particularly useful in distributed environments, where individual system have limited visibility into potential threats. This paper reviews the current landscape of Log Anomaly CIDS and introduces an open-source framework designed to create benchmark datasets for evaluating system performance. We categorize log anomaly detectors into three categories: Sequential-wise, Embedding-wise, and Graph-wise. Furthermore, our open framework facilitates rigorous evaluation against different challenges identifying weaknesses in existing methods like Deeplog and enhancing model robustness.
OriginalspracheEnglisch
Aufsatznummer108090
Seitenumfang1
FachzeitschriftFuture Generation Computer Systems
Jahrgang175
DOIs
PublikationsstatusVeröffentlicht - 17 Aug. 2025

Fördermittel

Funded by the European Union under the European Defence Fund (GA No. 101121403 - NEWSROOM and GA No. 101121414 - LATACC). Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Commission. Neither the European Union nor the granting authority can be held responsible for them. This work is co-funded by the Austrian FFG Kiras project ASOC (GA no. FO999905301).

ÖFOS 2012

  • 102016 IT-Sicherheit

Zitationsweisen