Feature-enhanced cloud container abnormal log classification method based on graph convolutional neural network

By adopting the feature enhancement method based on graph convolutional neural network in the exception log classification task of cloud container applications, the problem of low efficiency and accuracy in the existing technology is solved, and efficient feature extraction and precise classification of exception logs of cloud container applications is realized.

CN115934666BActive Publication Date: 2025-05-16CENT SOUTH UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211500810.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-05-16
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

The prior art has low efficiency and accuracy in the exception log classification task of cloud container applications, and it is impossible to effectively handle the disordered, irregular and complex graph structure of exception logs in cloud container applications.

Method used

A feature enhancement method based on graph convolution neural network is adopted. By dividing the exception log into stack trace data frames and constructing a graph structure, point features and edge relationships are input into graph convolution neural network for feature enhancement, and finally similarity measurement and classification are performed through the full connection layer and activation function.

Benefits of technology

It improves the feature extraction effect and classification accuracy of exception logs for cloud container applications, and can more effectively handle the complex structure of exception logs in cloud container applications, and achieve efficient exception log classification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115934666B_ABST
    Figure CN115934666B_ABST
Patent Text Reader

Abstract

In an embodiment of the present disclosure, a method for classifying abnormal logs of feature-enhanced cloud containers based on a graph convolutional neural network is provided, belonging to the technical field of data processing, specifically including: reading abnormal logs from an abnormal log dataset; dividing the abnormal logs into stack trace data frames; marking and cropping the stack trace data frames; constructing the stack trace data frames into input feature vectors F of a Bert model in ; inputting the input feature vector F in into an encoder, and outputting a feature vector F out and splitting it into [F CLS , F log ; constructing a graph, taking the vector F log as the point feature and the cosine similarity result of the vector F CLS as the edge relationship, and inputting the graph into a graph convolutional neural network; mapping the abnormal log feature vector enhanced by the graph convolutional neural network through a fully connected layer and an activation function into a one-dimensional feature vector, then performing similarity measurement on the one-dimensional vector, and classifying the abnormal logs accordingly. Through the solution of the present disclosure, the efficiency and accuracy of abnormal log classification are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The disclosed embodiments relate to the field of data processing technology, and in particular to a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network. Background Art

[0002] At present, exception log classification refers to the process in which programmers analyze exception log categories, locate program vulnerabilities, and assign them to corresponding repair programs to patch vulnerabilities and solve potential security issues. The key fields in the exception log can assist programmers in completing the exception log classification work and then repair application software vulnerabilities. Therefore, exception logs are a key information resource for repairing application software vulnerabilities.

[0003] The introduction of the automatic crash reporting system has greatly improved the speed of exception log generation and increased the workload of programmers in the exception log classification task. At present, compared with the traditional machine learning method, the exception log classification method based on deep learning avoids the artificial setting of the exception log feature extraction process and is more superior in handling the exception log classification task. Among them, the stack trace-based similarity measurement method is a method based on deep learning to measure the similarity of exception log reports, which is mainly used for exception log classification tasks. The core idea is to divide the exception log report into several stack trace data frames and input them into the neural network for iterative training to obtain the feature vector representation of the stack trace data frame. Then, the exception log classification task is completed through the fully connected layer. The stack trace-based similarity measurement method uses a deep learning model to extract the exception log vector representation, which has a good application in the exception log classification task of user-level applications.

[0004] The feature vector representation of stack data frames is the key process of the abnormal log classification task. At present, the long short-term memory network (LSTM) is generally used to process the abnormal log stack trace data frames generated in time series. Specifically, two LSTMs are used, one of which receives the stack trace data frames sequentially and the other receives the stack trace data frames in reverse order. The output results of the two networks are connected to form a bidirectional long short-term memory network (BiLSTM) to complete the feature vector representation of the stack data frame. The stack trace similarity measurement method based on BiLSTM has achieved good results in the abnormal log classification task of user-level applications, but the abnormal log stack data content of cloud container applications is disordered, unfixed and contains complex graph structures. Therefore, the method is not effective in extracting the feature vector of cloud container abnormal logs, and cannot accurately complete the abnormal log classification task of cloud container applications.

[0005] It can be seen that there is an urgent need for a feature-enhanced cloud container abnormal log classification method based on graph convolutional neural network with high efficiency and accuracy in abnormal log classification for cloud container applications. Summary of the invention

[0006] In view of this, an embodiment of the present disclosure provides a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network, which at least partially solves the problem of poor efficiency and accuracy in abnormal log classification for cloud container applications in the prior art.

[0007] The present disclosure provides a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network, including:

[0008] Step 1, read the exception log from the exception log data set;

[0009] Step 2, dividing the exception log into stack trace data frames;

[0010] Step 3, marking and trimming the stack trace data frame;

[0011] Step 4: Construct the stack trace data frame as the input feature vector F of the Bert model in ;

[0012] Step 5: Input feature vector F in Input encoder, output feature vector F out and split into [F CLS ,F log ];

[0013] Step 6: Build a graph and transform the vector F log As a point feature, the vector F CLS The cosine similarity result of is taken as the edge relationship, and the graph is input into the graph convolutional neural network for correlation optimization and feature enhancement.

[0014] In step 7, the abnormal log feature vector after graph convolutional neural network feature enhancement is mapped into a one-dimensional feature vector through a fully connected layer and an activation function, and then the one-dimensional vector is measured for similarity, and the abnormal log is classified accordingly.

[0015] According to a specific implementation of the embodiment of the present disclosure, step 2 specifically includes:

[0016] The information in the exception log is divided into a number of data frames and stored in the stack in a first-in-last-out manner to form the stack trace data frame, wherein the format of each stack trace data frame is (frame name, offset).

[0017] According to a specific implementation of the embodiment of the present disclosure, step 4 specifically includes:

[0018] Step 4.1: construct a cloud container exception log stack trace data frame T = {t1, t2, ..., t L}, where L is the number of stack trace data frames, first add the word unit CLS to the head of each group of stack trace data frames, and add the word unit SEP to the tail of each stack trace data frame;

[0019] Step 4.2, using the sentence conversion network, convert the stack trace data frame T into an embedding vector V = {v i |v i ∈R (S +L+1)×K ,i=1,2,…,S+L+1}, where S represents the number of words in the abnormal log and K represents the dimension of the embedding vector;

[0020] Step 4.3, use the linear projection functions sin(·) and cos(·) to encode the position information and obtain the encoding vector P that embeds the position information;

[0021] Step 4.4, merge vectors V, P, S to get the input feature vector F in ={f i |f i ∈R (S+L+1)×D ,i=1,2,...,S+L+1}, where D is the dimension of the input vector and f1 is the embedding vector corresponding to the word CLS.

[0022] According to a specific implementation method of the embodiment of the present disclosure, the expression of the encoding vector P is:

[0023]

[0024] Among them, pos represents the sequential position index of the encoding vector, and i represents the dimension index of the encoding vector.

[0025] According to a specific implementation of an embodiment of the present disclosure, the encoder has a residually connected multi-head self-attention mechanism sublayer and a residually connected multi-layer perceptron sublayer.

[0026] According to a specific implementation of the embodiment of the present disclosure, step 5 specifically includes:

[0027] Step 5.1, transform the vector F in Input encoder, after encoding, get output vector with consistent dimension in is the output vector corresponding to the word unit CLS;

[0028] Step 5.2, for the output vector F out Make the following split:

[0029]

[0030] Get [F CLS ,F log].

[0031] According to a specific implementation of the embodiment of the present disclosure, step 6 specifically includes:

[0032] Step 6.1, transform the vector F CLS The cosine similarity result of is regarded as the edge relationship. By calculating the cosine similarity, the similarity relationship matrix V can be obtained;

[0033] Step 6.2, construct a graph and transform the vector F log As point features, the matrix V is input into the graph convolutional neural network as an edge relationship for correlation optimization and feature enhancement.

[0034] According to a specific implementation method of the embodiment of the present disclosure, the calculation formula of each element in the similarity relationship matrix V is:

[0035] According to a specific implementation of the embodiment of the present disclosure, the graph convolutional neural network propagation rule is:

[0036]

[0037] in, It refers to the adjacency matrix of the undirected graph composed of abnormal logs, I n refers to the unit matrix, indicating that each point is adjacent to itself. yes The degree matrix of σ(·) represents the activation function, H (l+1) and H (l) are the input and output feature matrices of the lth layer, representing the features learned in the current layer, W (l) is the weight value of the lth layer.

[0038] The feature-enhanced cloud container abnormal log classification scheme based on graph convolutional neural network in the embodiment of the present disclosure includes: step 1, reading abnormal logs from abnormal log data set; step 2, dividing abnormal logs into stack trace data frames; step 3, marking and clipping the stack trace data frames; step 4, constructing the stack trace data frames as the input feature vector F of the Bert model in ; Step 5, input feature vector F in Input encoder, output feature vector F out and split into [F CLS ,F log ]; Step 6, construct a graph and transform the vector F log As a point feature, the vector F CLSThe cosine similarity result is taken as the edge relationship, and the graph is input into the graph convolutional neural network for correlation optimization and feature enhancement. In step 7, the feature vector of the abnormal log after the feature enhancement of the graph convolutional neural network is mapped into a one-dimensional feature vector through a fully connected layer and an activation function, and then the one-dimensional vector is measured for similarity, and the abnormal logs are classified accordingly.

[0039] The beneficial effects of the embodiments of the present disclosure are as follows: through the scheme of the present disclosure, the characteristics of the cloud container application exception log are described by adding the word CLS, the similarities between different exception logs are indirectly reflected through feature comparison, the feature vector is reconstructed by using the position information encoding, so that the feature vector carries the position information of the stack trace data frame, and the global feature vector extraction process is optimized through the encoder's multiple attention mechanism and multi-layer perceptron module, which solves the problem of poor feature extraction of the cloud container application's exception log, and uses the graph convolutional neural network to fuse the graph structure information of the cloud container application's exception log to further achieve feature enhancement, and accurately complete the cloud container application's exception log classification task. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0041] Figure 1 A flowchart of a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network provided in an embodiment of the present disclosure;

[0042] Figure 2 A schematic diagram of an implementation framework of a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0043] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0044] The following describes the embodiments of the present disclosure through specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present disclosure.

[0045] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.

[0046] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The drawings only show components related to the present disclosure rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0047] Additionally, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, it will be understood by those skilled in the art that the aspects described may be practiced without these specific details.

[0048] The disclosed embodiment provides a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network. The method can be applied to the abnormal log classification process of cloud container applications in Internet scenarios.

[0049] See also Figure 1 , is a flow chart of a feature-enhanced cloud container abnormal log classification method based on a graph convolutional neural network provided by an embodiment of the present disclosure. Figure 1 and Figure 2 As shown, the method mainly comprises the following steps:

[0050] Step 1, read the exception log from the exception log data set;

[0051] In specific implementation, when an abnormal situation occurs in a cloud container application, the system automatically records the errors that occur during the software operation into a log file, which describes in detail the various key fields of the software abnormality, such as: abnormality name, abnormality occurrence time, etc., to form an abnormal log and store it in the abnormal log data set. Exception log classification is the process of analyzing the abnormal log category, locating program vulnerabilities and assigning them to corresponding repair programs for vulnerability patching and solving potential security issues. When the abnormal log needs to be classified, the abnormal log can be read from the abnormal log data set for subsequent processing.

[0052] Step 2, dividing the exception log into stack trace data frames;

[0053] Furthermore, the step 2 specifically includes:

[0054] The information in the exception log is divided into a number of data frames and stored in the stack in a first-in-last-out manner to form the stack trace data frame, wherein the format of each stack trace data frame is (frame name, offset).

[0055] In specific implementation, the information in the exception log can be divided into several data frames and stored in the stack in a first-in-last-out manner to form the stack trace data frame for subsequent analysis and processing, wherein the format of each stack trace data frame is (frame name, offset).

[0056] Step 3, marking and trimming the stack trace data frame;

[0057] In specific implementation, the stack trace data frame can be marked and trimmed according to prior knowledge, so as to facilitate the subsequent extraction of better feature vectors.

[0058] Step 4: Construct the stack trace data frame as the input feature vector F of the Bert model in ;

[0059] Based on the above embodiment, step 4 specifically includes:

[0060] Step 4.1: construct a cloud container exception log stack trace data frame T = {t1, t2, ..., t L}, where L is the number of stack trace data frames, first add the word unit CLS to the head of each group of stack trace data frames, and add the word unit SEP to the tail of each stack trace data frame;

[0061] Step 4.2, using the sentence conversion network, convert the stack trace data frame T into an embedding vector V = {v i|v i ∈R (S +L+1)×K ,i=1,2,…,S+L+1}, where S represents the number of words in the abnormal log and K represents the dimension of the embedding vector;

[0062] Step 4.3, use the linear projection functions sin(·) and cos(·) to encode the position information and obtain the encoding vector P that embeds the position information;

[0063] Step 4.4, merge vectors V, P, S to get the input feature vector F in ={f i |f i ∈R (S+L+1)×D ,i=1,2,...,S+L+1}, where D is the dimension of the input vector and f1 is the embedding vector corresponding to the word CLS.

[0064] Furthermore, the expression of the encoding vector P is:

[0065]

[0066] Among them, pos represents the sequential position index of the encoding vector, and i represents the dimension index of the encoding vector.

[0067] In specific implementation, the Bert model is a model that introduces a multi-layer perceptual attention mechanism, which optimizes the extraction process of the global feature vector of the abnormal log stack data tracking frame. Step 4 specifically includes:

[0068] Step A1: construct a cloud container exception log stack trace data frame T = {t1, t2, ..., t L}, where L is the number of stack trace data frames. First, add the word CLS to the head of each stack trace data frame, and add the word SEP to the tail of each stack trace data frame. The word is a special marker that is added to a fixed position of the exception log stack trace data frame to distinguish different exception logs and different stack trace data frames of the same exception log.

[0069] Step A2, using the sentence conversion network, convert the stack trace data frame T into an embedding vector V = {v i |v i ∈R (S +L+1)×K ,i=1,2,…,S+L+1}, where S represents the number of words in the exception log and K represents the dimension of the embedding vector.

[0070] Step A3, use the linear projection functions sin(·) and cos(·) to encode the position information and obtain the encoding vector P embedded with the position information, which is expressed as:

[0071]

[0072] Where pos represents the sequential position index of the encoded vector, and i represents the dimension index of the encoded vector.

[0073] Step A4: merge vectors V, P, S to obtain input feature vector F in ={f i |f i ∈R (S+L+1)×D ,i=1,2,…,S+L+1}, where D is the dimension of the input vector and f1 is the embedding vector corresponding to the word CLS.

[0074] Step 5: Input feature vector F in Input encoder, output feature vector F out and split into [F CLS ,F log ];

[0075] Optionally, the encoder has a residually connected multi-head self-attention mechanism sublayer and a residually connected multi-layer perceptron sublayer.

[0076] Furthermore, the step 5 specifically includes:

[0077] Step 5.1, transform the vector F in Input encoder, after encoding, get output vector with consistent dimension in is the output vector corresponding to the word unit CLS;

[0078] Step 5.2, for the output vector F out Make the following split:

[0079]

[0080] Get [F CLS ,F log ].

[0081] In specific implementation, step 5 may specifically include:

[0082] In step B1, the encoder consists of a multi-head self-attention mechanism sub-layer with residual connections and a multi-layer perceptron sub-layer with residual connections. The residual connection makes the input vector and output vector of the encoder consistent in size.

[0083] Step B2: vector F in Input encoder, after encoding, get output vector with consistent dimension in is the output vector corresponding to the word unit CLS, which records the relevant information of the log category.

[0084] Step B3: output vector F out Make the following split:

[0085]

[0086] It can be expressed as [F CLS ,F log ].

[0087] Step 6: Build a graph and transform the vector F log As a point feature, the vector F CLS The cosine similarity result of is taken as the edge relationship, and the graph is input into the graph convolutional neural network for correlation optimization and feature enhancement.

[0088] Based on the above embodiment, step 6 specifically includes:

[0089] Step 6.1, transform the vector F CLS The cosine similarity result of is regarded as the edge relationship. By calculating the cosine similarity, the similarity relationship matrix V can be obtained;

[0090] Step 6.2, construct a graph and transform the vector F log As point features, the matrix V is input into the graph convolutional neural network as an edge relationship for correlation optimization and feature enhancement.

[0091] Furthermore, the calculation formula for each element in the similarity matrix V is:

[0092] Furthermore, the graph convolutional neural network propagation rule is:

[0093]

[0094] in, It refers to the adjacency matrix of the undirected graph composed of abnormal logs, I n refers to the unit matrix, indicating that each point is adjacent to itself. yes The degree matrix of σ(·) represents the activation function, H (l+1) and H (l) are the input and output feature matrices of the lth layer, representing the features learned in the current layer, W (l) is the weight value of the lth layer.

[0095] In specific implementation, step 6 may specifically include:

[0096] Step C1, transform the vector F CLS The cosine similarity result of is regarded as the edge relationship. By calculating the cosine similarity, we can get the similarity relationship matrix V, whose elements Vij The calculation process is as follows:

[0097]

[0098] Step C2, construct a graph and transform the vector F log As point features, the matrix V is input into the graph convolutional neural network as an edge relationship for correlation optimization to achieve feature enhancement. The propagation rule of the multi-layer graph convolutional neural network is in the following form:

[0099]

[0100] in, It refers to the adjacency matrix of the undirected graph composed of abnormal logs, I n It refers to the unit matrix, which means that each point is adjacent to itself; yes The degree matrix of σ(·) represents the activation function, such as Rel u; H (l+1) and H (l) are the input and output feature matrices of the lth layer, representing the features learned by the current layer; W (l) is the weight value of the lth layer.

[0101] In step 7, the abnormal log feature vector after graph convolutional neural network feature enhancement is mapped into a one-dimensional feature vector through a fully connected layer and an activation function, and then the one-dimensional vector is measured for similarity, and the abnormal log is classified accordingly.

[0102] In specific implementation, after the abnormal log feature vector corresponding to the graph constructed in step 6 is enhanced through the graph convolutional neural network, the abnormal log feature vector can be mapped into a one-dimensional feature vector through a fully connected layer and an activation function such as a Rel u function, and then the one-dimensional vector is measured for similarity, and the abnormal log is classified based on this, and the classification result is output.

[0103] The feature-enhanced cloud container abnormal log classification method based on graph convolutional neural network provided in this embodiment describes the characteristics of the cloud container application abnormal log by adding the word unit CLS, indirectly reflects the similarity between different abnormal logs by feature comparison, reconstructs the feature vector by encoding the position information, so that the feature vector carries the position information of the stack trace data frame, and optimizes the global feature vector extraction process by the multiple attention mechanism and multi-layer perceptron module of the encoder; optimizes the feature correlation by using the graph convolutional network, and utilizes the characteristic that the graph convolutional network can update the features of similar nodes according to the adjacency matrix of the nodes in the graph, that is, it uses the relationship between the edges to iterate the information of the points, maintains the similar information between the data, learns the similarity between the data points by the graph convolutional network, integrates the similar information in the output matrix, and further enhances the feature vector of the cloud container abnormal log.

[0104] The units involved in the embodiments described in the present disclosure may be implemented by software or by hardware.

[0105] It should be understood that various parts of the present disclosure may be implemented in hardware, software, firmware, or a combination thereof.

[0106] The above is only a specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed in the present disclosure should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.

Claims

1. A feature-enhanced cloud container abnormal log classification method based on graph convolutional neural network, characterized in that: include: Step 1, read the exception log from the exception log data set; Step 2, dividing the exception log into stack trace data frames; Step 3, marking and trimming the stack trace data frame; Step 4: Construct the stack trace data frame as the input feature vector F of the Bert model in ; The step 4 specifically includes: Step 4.1: construct a cloud container exception log stack trace data frame T = {t1, t2, ..., t L }, where L is the number of stack trace data frames, first add the word unit CLS to the head of each group of stack trace data frames, and add the word unit SEP to the tail of each stack trace data frame; Step 4.2, using the sentence conversion network, convert the stack trace data frame T into an embedding vector V = {v i |v i ∈R (S +L+1)×K ,i=1,2,…,S+L+1}, where S represents the number of words in the abnormal log and K represents the dimension of the embedding vector; Step 4.3, use the linear projection functions sin(·) and cos(·) to encode the position information and obtain the encoding vector P that embeds the position information; Step 4.4, merge vectors V, P, S to get the input feature vector F in ={f i |f i ∈R (S+L+1)×D ,i=1,2,...,S+L+1}, where D is the dimension of the input vector and f1 is the embedding vector corresponding to the word CLS; Step 5: Input feature vector F in Input encoder, output feature vector F out and split into [F CLS ,F log ]; Step 6: Build a graph and transform the vector F log As a point feature, the vector F CLS The cosine similarity result of is taken as the edge relationship, and the graph is input into the graph convolutional neural network for correlation optimization and feature enhancement. In step 7, the abnormal log feature vector after graph convolutional neural network feature enhancement is mapped into a one-dimensional feature vector through a fully connected layer and an activation function, and then the one-dimensional vector is measured for similarity, and the abnormal log is classified accordingly.

2. The method according to claim 1, characterized in that , the step 2 specifically includes: The information in the exception log is divided into a number of data frames and stored in the stack in a first-in-last-out manner to form the stack trace data frame, wherein the format of each stack trace data frame is (frame name, offset).

3. The method according to claim 2, characterized in that , the expression of the encoding vector P is Among them, pos represents the sequential position index of the encoding vector, and i represents the dimension index of the encoding vector.

4. The method according to claim 3, characterized in that , the encoder has a residually connected multi-head self-attention mechanism sub-layer and a residually connected multi-layer perceptron sub-layer.

5. The method according to claim 4, characterized in that , the step 5 specifically includes: Step 5.1, transform the vector F in Input encoder, after encoding, get output vector with consistent dimension in is the output vector corresponding to the word unit CLS; Step 5.2, for the output vector F out Make the following split: Get [F CLS ,F log ].

6. The method according to claim 5, characterized in that , the step 6 specifically includes: Step 6.1, transform the vector F CLS The cosine similarity result of is regarded as the edge relationship. By calculating the cosine similarity, the similarity relationship matrix V can be obtained; Step 6.2, construct a graph and transform the vector F log As point features, the matrix V is input into the graph convolutional neural network as an edge relationship for correlation optimization and feature enhancement.

7. The method according to claim 6, characterized in that , the calculation formula of each element in the similarity matrix V is 8. The method according to claim 7, characterized in that ,The graph convolutional neural network propagation rule is: in, It refers to the adjacency matrix of the undirected graph composed of abnormal logs, I n refers to the unit matrix, indicating that each point is adjacent to itself. yes The degree matrix of σ(·) represents the activation function, H (l+1) and H (l) are the input and output feature matrices of the lth layer, representing the features learned in the current layer, W (l) is the weight value of the lth layer.

Citation Information

Patent Citations

  • Network security anomaly detection algorithm and detection system based on clustering graph neural network

    CN112165496A

  • Big data platform log anomaly detection method based on attention mechanism layer

    CN114661544A