The invention relates to the technical field of log detection, in particular to a real-time
anomaly detection and tracing method and
system for a
cloud storage log, and the method comprises the following steps: calculating an
authentication failure proportion based on a
user identifier and an
internet protocol address, constructing a proportion change sequence, comparing an abrupt change threshold, screening candidate sections, fitting a slope, and aggregating anomaly records; calculating a fluctuation difference sequence, extracting a causal fracture node, recombining a subsequence graph, extracting a cross-node
record and correcting a
timestamp, connecting a transmission
edge based on the
timestamp, and accounting time consumption to construct a
traceability path. According to the method, the serious defect that a fixed threshold value cannot sense
system load fluctuation is overcome by constructing a dynamic proportion change slope, a causal fracture node is established to drive log atlas recombination so as to break an information barrier of a cross-node distributed environment, and a median function is used for correcting time migration to eliminate disorder interference caused by
clock asynchronization; and the accurate risk tracing is realized by connecting the correction
timestamp with the access transmission edge.