This application discloses a multi-source fusion log
compression method and apparatus for
anomaly detection, belonging to the field of
anomaly detection technology. The multi-source fusion log
compression method for
anomaly detection includes: generating an audit
origination graph corresponding to the
system audit log, an application
origination graph corresponding to the application log, and
a domain name
origination graph corresponding to the
domain name system log based on the
system audit log corresponding to the electronic device, the application log corresponding to the target application in the electronic device, and the
domain name system log corresponding to the electronic device; fusing the
domain name origination graph into the application origination
graph based on the domain name nodes in the application origination graph to obtain a sub-fused origination graph; fusing the audit origination graph into the sub-fused origination
graph based on the event nodes in the audit origination graph to obtain a fused origination graph; and performing anomaly detection based on the fused origination graph. The multi-source fusion log
compression method for anomaly detection in this application can alleviate the problems of
semantic gap and dependency explosion.