科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ Journal of Cloud Computing Advances Systems and Applications2025-10-28· Computer science

Advanced system log analyzer for anomaly detection and cyber forensic investigations using LSTM and transformer networks

Leeladhar Chourasiya, Sushma Khatri, Umesh Kumar Lilhore, Sarita Simaiya, Roobaea Alroobaea, Abdullah M. Baqasah, Majed Alsafyani, Monish Khan

原始摘要(英文原文)· Original abstract
This framework presents an innovative methodology that combines LSTM, Transformer, and GNN models to effectively capture both temporal and spatial patterns within log data, thus improving cybersecurity anomaly detection and forensic analysis. By utilizing LSTM networks, the system is able to model sequential log patterns over time, which aids in identifying hidden attack behaviors. Transformer architectures are employed to examine contextual relationships within logs, allowing for accurate, context-sensitive classification. Moreover, Graph Neural Networks (GNNs) depict logs as interconnected graphs, which facilitates the identification of coordinated multi-stage attacks from various sources. The integration of these models enables a thorough analysis of log data, simultaneously capturing dynamic temporal sequences and intricate relationships. The system autonomously correlates logs from system, network, and application sources to reconstruct attack timelines and identify emerging threats in real time. Empirical assessments on datasets such as HDFS, CICIDS, and UNSW-NB15 indicate that this integrated approach outperforms traditional methods, achieving detection accuracies of up to 98.2%, minimizing false positives, and expediting forensic investigations—thereby significantly enhancing the capabilities of automated cybersecurity monitoring and response.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Advanced system log analyzer for anomaly detection and cyber forensic investigations using LSTM and transformer networks — 科研速览 Science Skim