DILAF: A framework for distributed analysis of large‐scale system logs for anomaly detection. (20th November 2018)
- Record Type:
- Journal Article
- Title:
- DILAF: A framework for distributed analysis of large‐scale system logs for anomaly detection. (20th November 2018)
- Main Title:
- DILAF: A framework for distributed analysis of large‐scale system logs for anomaly detection
- Authors:
- Astekin, Merve
Zengin, Harun
Sözer, Hasan - Other Names:
- Bosch Jan guestEditor.
Cooper Kendra M. L. guestEditor.
Paulisch Frances guestEditor. - Abstract:
- Summary: System logs constitute a rich source of information for detection and prediction of anomalies. However, they can include a huge volume of data, which is usually unstructured or semistructured. We introduce DILAF, a framework for distributed analysis of large‐scale system logs for anomaly detection. DILAF is comprised of several processes to facilitate log parsing, feature extraction, and machine learning activities. It has two distinguishing features with respect to the existing tools. First, it does not require the availability of source code of the analyzed system. Second, it is designed to perform all the processes in a distributed manner to support scalable analysis in the context of large‐scale distributed systems. We discuss the software architecture of DILAF and we introduce an implementation of it. We conducted controlled experiments based on two datasets to evaluate the effectiveness of the framework. In particular, we evaluated the performance and scalability attributes under various degrees of parallelism. Results showed that DILAF can maintain the same accuracy levels while achieving more than 30% performance improvement on average as the system scales, compared to baseline approaches that do not employ fully distributed processing.
- Is Part Of:
- Software, practice & experience. Volume 49:Number 2(2019)
- Journal:
- Software, practice & experience
- Issue:
- Volume 49:Number 2(2019)
- Issue Display:
- Volume 49, Issue 2 (2019)
- Year:
- 2019
- Volume:
- 49
- Issue:
- 2
- Issue Sort Value:
- 2019-0049-0002-0000
- Page Start:
- 153
- Page End:
- 170
- Publication Date:
- 2018-11-20
- Subjects:
- anomaly detection -- big data -- distributed systems -- log analysis -- machine learning -- parallel processing -- software architecture
Computer software -- Periodicals
Computer programming -- Periodicals
Computer programs -- Periodicals
005.3 - Journal URLs:
- http://onlinelibrary.wiley.com/ ↗
- DOI:
- 10.1002/spe.2653 ↗
- Languages:
- English
- ISSNs:
- 0038-0644
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 8321.453000
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 11398.xml