Off-line analysis and on-line large language model combined anomaly detection method and system
By combining offline analysis and online large language model, the problem of existing anomaly detection technology lacks interpretability in complex system log processing and encrypted malicious traffic analysis is solved, and a highly interpretable anomaly detection report generation is achieved, which improves the practicality and reliability of detection.
Patent Information
- Application Number
- CN202510263321.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-27
AI Technical Summary
Existing anomaly detection technologies lack accuracy and interpretability when dealing with complex system logs or facing encrypted malicious traffic, especially when it is necessary to quickly locate and analyze the causes of abnormalities.
Combining offline analysis and online large language model, an abnormality analysis report with high interpretability is generated by combining offline detection based on the Transformer model with online anomaly analysis of the large language model.
Improve the practicality and reliability of abnormal detection. The generated report contains detailed log-level, Token-level outliers and natural language explanations of the causes of abnormalities to help users quickly understand abnormalities.
Smart Images

Figure CN120217038A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer science, and specifically, to an anomaly detection method and system combining offline analysis and online large language models. Background Art
[0002] Existing anomaly detection technologies mainly rely on machine learning models or rule-based detection methods. However, these methods often lack accuracy and interpretability when dealing with complex system logs or encrypted malicious traffic, especially when it is necessary to quickly locate and analyze the causes of anomalies. In recent years, deep learning models based on Transformer encoders have shown high detection accuracy in anomaly detection, but their interpretability remains a challenge.
[0003] To solve the above problems, the present invention proposes an interpretable anomaly detection method combining offline analysis and online large language models. By combining offline detection based on the Transformer model with online anomaly analysis of large language models, an anomaly analysis report with high interpretability is generated, thereby improving the practicality and reliability of anomaly detection.
[0004] Chinese Invention Application No. 202210950614.0 discloses "A Log Anomaly Detection Method, Device, Equipment and Storage Medium", and the method includes the steps: S1, obtaining the first timestamp and the first log content of the log message to be detected; S2, preprocessing the first timestamp and the first log content to obtain a second timestamp and a second log content; S3, performing feature extraction processing on the second timestamp and the second log content to obtain a log vector sequence; S4, inputting the log vector sequence into a trained TRANSFORMER model to obtain a log sequence vector; S5, inputting the log sequence vector into a trained hypersphere model to obtain an anomaly detection result. Summary of the Invention
[0005] To solve the technical problem of the lack of interpretability in existing log anomaly detection, the present invention provides an anomaly detection method and system combining offline analysis and online large language models. The technical solution adopted by the present invention is:
[0006] The first aspect of the present invention provides an anomaly detection method combining offline analysis and online large language models, and the method includes:
[0007] Obtain a log sequence;
[0008] Input the log sequence into a pre-trained anomaly log detection model to obtain anomaly logs;
[0009] Perform offline anomaly analysis on the anomaly logs to obtain an offline anomaly analysis result;
[0010] Perform online anomaly analysis on the abnormal log to obtain the online anomaly analysis result;
[0011] Combine the offline anomaly analysis result and the online anomaly analysis result to generate an interpretable anomaly detection report.
[0012] As a preferred solution, the method for obtaining the log sequence includes:
[0013] Group the preset original logs according to time order or event relevance to generate a log sequence.
[0014] As a preferred solution, the pre-trained abnormal log detection model includes Transformer encoder Encoder1 and Transformer encoder Encoder2.
[0015] As a preferred solution, the method for performing offline anomaly analysis on the abnormal log to obtain the offline anomaly analysis result includes:
[0016] Calculate the anomaly value of each abnormal log to obtain the log-level anomaly analysis result;
[0017] Calculate the anomaly value of each Token in the abnormal log to obtain the Token-level anomaly analysis result.
[0018] As a preferred solution, the method for calculating the anomaly value of each abnormal log to obtain the log-level anomaly analysis result includes:
[0019] Load the weights of the abnormal log detection model;
[0020] Initialize the cumulative anomaly value V of all logs in the abnormal log I to 0;
[0021] Extract the attention weight W1 of encoder Encoder1;
[0022] For each pair of attention weights (I1, I2) ∈ W1:
[0023] the attention weight of;
[0024] the attention weight of;
[0025] Return V I as the anomaly value S of the log L ;
[0026] The method for calculating the anomaly value of each Token in the abnormal log to obtain the Token-level anomaly analysis result includes:
[0027] Load the weights of the exception log detection model;
[0028] Initialize the cumulative exception value V of the Token to 0;
[0029] Extract the attention weight W2 of the encoder Encoder2;
[0030] For each pair of attention weights (T1, T2) ∈ W2:
[0031] The attention weight;
[0032] The attention weight;
[0033] Return V T As the outlier S of the log T .
[0034] As a preferred solution, the method for online anomaly analysis of the exception log to obtain an online anomaly analysis result includes:
[0035] Send the exception log to a preset online large language model to generate an online anomaly analysis result through prompt words, where the prompt words include:
[0036] Context information describing the log content;
[0037] Request the online large language model to analyze the cause of the exception log.
[0038] The second aspect of the present invention provides an anomaly detection system combining offline analysis and an online large language model. The system includes a log sequence acquisition module, an anomaly detection module, an offline anomaly analysis module, an online anomaly analysis module, and an anomaly detection report generation module;
[0039] The log sequence acquisition module is used to acquire a log sequence;
[0040] The anomaly detection module is used to input the log sequence into a pre-trained exception log detection model to obtain an exception log;
[0041] The offline anomaly analysis module is used to perform offline anomaly analysis on the exception log to obtain an offline anomaly analysis result;
[0042] The online anomaly analysis module is used to perform online anomaly analysis on the exception log to obtain an online anomaly analysis result;
[0043] The anomaly detection report generation module is used to combine the offline anomaly analysis result and the online anomaly analysis result to generate an interpretable anomaly detection report.
[0044] As a preferred solution, the anomaly detection module includes a Transformer encoder Encoder1 and a Transformer encoder Encoder2;
[0045] The Transformer encoder Encoder1 is used to calculate the anomaly value of each log;
[0046] The Transformer encoder Encoder2 is used to calculate the anomaly value of each Token in the anomaly log.
[0047] The third aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the foregoing anomaly detection method combining offline analysis and online large language model are implemented.
[0048] The fourth aspect of the present invention provides a computer device, including a storage medium, a processor, and a computer program stored in the storage medium and executable by the processor. When the computer program is executed by the processor, the steps of the foregoing anomaly detection method combining offline analysis and online large language model are implemented.
[0049] Compared with the prior art, the beneficial effects of the present invention are:
[0050] By combining local anomaly analysis and online large language model analysis, the anomaly detection report generated by the present invention includes detailed log-level and Token-level anomaly values and natural language explanations of the anomaly causes, helping users quickly understand the anomalies. The present invention combines the efficient detection ability of the offline model and the context understanding ability of the online large language model, providing more comprehensive anomaly detection and analysis results. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a flowchart of the anomaly detection method combining offline analysis and online large language model provided in this embodiment. DETAILED DESCRIPTION
[0052] The drawings are only for illustrative purposes and cannot be construed as a limitation of the present invention;
[0053] It should be clear that the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the embodiments of the present application.
[0054] The terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the embodiments of the present application. The singular forms "a", "the", and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0055] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims. In the description of the present application, it should be understood that the terms "first", "second", "third", etc. are only used to distinguish similar objects and do not have to be used to describe a specific order or sequence, nor can they be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.
[0056] In addition, in the description of the present application, unless otherwise specified, "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after. The following further elaborates on the present invention in conjunction with the accompanying drawings and embodiments.
[0057] The following further elaborates on the present invention in conjunction with the accompanying drawings and embodiments.
[0058] Embodiment 1
[0059] Please refer to Figure 1 , this embodiment provides an anomaly detection method combining offline analysis and an online large language model, and the method includes:
[0060] S1: Obtain a log sequence;
[0061] In a specific embodiment, the method for obtaining a log sequence includes:
[0062] Group the preset original logs according to time order or event relevance to generate a log sequence.
[0063] S2: Input the log sequence into a pre-trained anomaly log detection model to obtain anomaly logs;
[0064] In a specific embodiment, the pre-trained anomaly log detection model includes a Transformer encoder Encoder1 and a Transformer encoder Encoder2.
[0065] S3: Perform offline anomaly analysis on the anomaly log to obtain an offline anomaly analysis result;
[0066] In a specific embodiment, the method for performing offline anomaly analysis on the anomaly log to obtain an offline anomaly analysis result includes:
[0067] Calculate the anomaly value of each anomaly log to obtain a log-level anomaly analysis result;
[0068] Calculate the anomaly value of each Token in the anomaly log to obtain a Token-level anomaly analysis result.
[0069] In a specific embodiment, the method for calculating the anomaly value of each anomaly log to obtain a log-level anomaly analysis result includes:
[0070] Load the weights of the anomaly log detection model;
[0071] Initialize the cumulative anomaly value V of all logs in the anomaly log i to 0;
[0072] Extract the attention weight W1 of the encoder Encoder1;
[0073] For each attention weight pair (I1, I2) ∈ W1:
[0074] of the attention weight;
[0075] of the attention weight;
[0076] Return V I as the anomaly value S of the log L ;
[0077] The method for calculating the anomaly value of each Token in the anomaly log to obtain a Token-level anomaly analysis result includes:
[0078] Load the weights of the anomaly log detection model;
[0079] Initialize the cumulative anomaly value V of the Token to 0;
[0080] Extract the attention weight W2 of the encoder Encoder2;
[0081] For each attention weight pair (T1, T2) ∈ W2:
[0082] The attention weight of
[0083] The attention weight of
[0084] Return V T The outlier S as a log T .
[0085] S4: Perform online anomaly analysis on the abnormal log to obtain an online anomaly analysis result;
[0086] In a specific embodiment, the method for performing online anomaly analysis on the abnormal log to obtain an online anomaly analysis result includes:
[0087] Send the abnormal log to a preset online large language model, and generate an online anomaly analysis result through prompt words, where the prompt words include:
[0088] Context information describing the log content;
[0089] Request the online large language model to analyze the cause of the abnormal log.
[0090] S5: Combine the offline anomaly analysis result and the online anomaly analysis result to generate an interpretable anomaly detection report.
[0091] Embodiment 2
[0092] This embodiment provides an anomaly detection system that combines offline analysis and an online large language model. The system includes a log sequence acquisition module, an anomaly detection module, an offline anomaly analysis module, an online anomaly analysis module, and an anomaly detection report generation module;
[0093] The log sequence acquisition module is used to acquire a log sequence;
[0094] The anomaly detection module is used to input the log sequence into a pre-trained abnormal log detection model to obtain an abnormal log;
[0095] The offline anomaly analysis module is used to perform offline anomaly analysis on the abnormal log to obtain an offline anomaly analysis result;
[0096] The online anomaly analysis module is used to perform online anomaly analysis on the abnormal log to obtain an online anomaly analysis result;
[0097] The anomaly detection report generation module is used to combine the offline anomaly analysis result and the online anomaly analysis result to generate an interpretable anomaly detection report.
[0098] In a specific embodiment, the anomaly detection module includes a Transformer encoder Encoder1 and a Transformer encoder Encoder2;
[0099] The Transformer encoder Encoder1 is used to calculate the anomaly value of each log;
[0100] The Transformer encoder Encoder2 is used to calculate the anomaly value of each Token in the anomaly log.
[0101] Embodiment 3
[0102] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the anomaly detection method combining offline analysis and an online large language model described in Embodiment 1 are implemented.
[0103] Embodiment 4
[0104] A computer device includes a storage medium, a processor, and a computer program stored in the storage medium and executable by the processor. When the computer program is executed by the processor, the steps of the anomaly detection method combining offline analysis and an online large language model described in Embodiment 1 are implemented.
[0105] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, rather than limiting the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or variations can be made based on the above description. It is not necessary and impossible to enumerate all implementation manners here. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the claims of the present invention.
Claims
1. Anomaly detection method combining offline analysis with online large language model, characterized in that: The method comprises: Get the log sequence; Inputting the log sequence into a pre-trained abnormal log detection model to obtain abnormal logs; Performing offline exception analysis on the exception log to obtain offline exception analysis results; Performing online abnormality analysis on the abnormality log to obtain an online abnormality analysis result; The offline anomaly analysis result and the online anomaly analysis result are combined to generate an explainable anomaly detection report.
2. The anomaly detection method combining offline analysis with online large language model according to claim 1, characterized in that: Methods for obtaining log sequences include: The preset original logs are grouped according to time sequence or event correlation to generate log sequences.
3. The anomaly detection method combining offline analysis with online large language model according to claim 1, characterized in that: The pre-trained abnormal log detection model includes Transformer encoder Encoder1 and Transformer encoder Encoder2.
4. The anomaly detection method combining offline analysis with online large language model according to claim 3 is characterized in that: The method of performing offline abnormality analysis on the abnormality log to obtain the offline abnormality analysis result includes: Calculate the abnormal value of each abnormal log and obtain the log-level abnormal analysis result; Calculate the abnormal value of each Token in the abnormal log and obtain the Token-level abnormality analysis results.
5. The anomaly detection method combining offline analysis with online large language model according to claim 4 is characterized in that: Methods for calculating the abnormal value of each abnormal log and obtaining log-level abnormality analysis results include: Loading the weights of the abnormal log detection model; Initialize the accumulated abnormal value V of all logs in the abnormal log I is 0; Extract the attention weight W1 of encoder Encoder1; For each attention weight pair (I1,I2)∈W1: The attention weight of The attention weight of Return V I The outlier value S as a log L ; The method of calculating the abnormal value of each token in the abnormal log and obtaining the token-level abnormal analysis result includes: Loading the weights of the abnormal log detection model; Initialize the accumulated abnormal value V of the Token to 0; Extract the attention weight W2 of encoder Encoder2; For each attention weight pair (T1,T2)∈W2: The attention weight of The attention weight of Return V T Outliers as logs T .
6. The anomaly detection method combining offline analysis with online large language model according to claim 1, characterized in that: The method of performing online abnormality analysis on the abnormality log to obtain the online abnormality analysis result includes: The abnormal log is sent to a preset online large language model, and an online abnormal analysis result is generated through prompt words, wherein the prompt words include: Contextual information describing the log content; The online large language model is requested to analyze the cause of the abnormal log.
7. An anomaly detection system combining offline analysis with an online large language model, characterized in that: The system includes a log sequence acquisition module, an anomaly detection module, an offline anomaly analysis module, an online anomaly analysis module, and an anomaly detection report generation module; The log sequence acquisition module is used to acquire the log sequence; The anomaly detection module is used to input the log sequence into a pre-trained anomaly log detection model to obtain an anomaly log; The offline exception analysis module is used to perform offline exception analysis on the exception log to obtain an offline exception analysis result; The online exception analysis module is used to perform online exception analysis on the exception log to obtain an online exception analysis result; The anomaly detection report generation module is used to combine the offline anomaly analysis result and the online anomaly analysis result to generate an anomaly detection report with interpretability.
8. The anomaly detection system combining offline analysis with online large language model according to claim 7, characterized in that: The anomaly detection module includes Transformer encoder Encoder1 and Transformer encoder Encoder2; The Transformer encoder Encoder1 is used to calculate the outlier value of each log; The Transformer encoder Encoder2 is used to calculate the abnormal value of each Token in the abnormal log.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the anomaly detection method combining offline analysis with an online large language model are implemented as described in any one of claims 1 to 6.
10. A computer device, characterized in that: The invention comprises a storage medium, a processor, and a computer program stored in the storage medium and executable by the processor, wherein when the computer program is executed by the processor, the steps of the anomaly detection method combining offline analysis with an online large language model as described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Log anomaly detection method and device, equipment and storage medium
CN115454788A