Proceedings of the Fuzzy System Symposium
22nd Fuzzy System Symposium
Session ID : 6F3-4
Conference information

Extraction of Anomaly Detection Rules without supervised information from Various Log Files Using Automatically Defined Groups - Knowledge Acquisition from Computer Log Files (1) -
*Yoshiaki KUROSAWAAkira HARATakumi ICHIMURAYuji KAWANO
Author information
CONFERENCE PROCEEDINGS FREE ACCESS

Details
Abstract

Our main purpose is to extract useful rules from log files on computers, to detect various levels of errors, and to automatically inform these errors or configuration mistakes to system administrators in order to easily manage them without knowledge. For this purpose, we performed an extraction experiment using Automatically Defined Groups (ADG), which is based on Genetic Programming. Moreover, we focused on "System State Pattern" related to the difference between normal daily state and abnormal state that some errors occur in the system. In this experiment, then, we tried to extract rules without any manually managed and supervised information, by using simple translation technique: regular expressions. As a result, 50 agents in the best individual were divided into 16 groups from 322 log files. This means that 16 rules were acquired. We confirmed these rules could detect some errors such as DNS configuration error. We could also find the importance of the rules because each rule with more agents tended to have a higher adopted frequency by evolutionary computation. Therefore, we consider that our method using ADG is useful for the diagnosis of computer systems, and helps administrators manage their systems without expert knowledge.

Content from these authors
© 2006 Japan Society for Fuzzy Theory and Intelligent Informatics
Previous article Next article
feedback
Top