Claim Missing Document
Check
Articles

Found 2 Documents
Search

Log Anomaly Detection with Conformal Alert Control and Evidence-Grounded Incident Ticket Generation Qi Xin
Aviation Electronics, Information Technology, Telecommunications, Electricals, and Controls (AVITEC) Vol 8, No 2 (2026): August
Publisher : Institut Teknologi Dirgantara Adisutjipto

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.28989/avitec.v8i2.3974

Abstract

Operational logs are a primary source of evidence for reliability engineering, incident response, and security operations, but log anomaly detection is useful only when scores can be translated into controlled alerts and auditable incident evidence. This paper presents a reproducible end-to-end AIOps pipeline that normalizes raw logs into templates, aggregates them into sliding windows, scores anomalies with representative detectors, calibrates alerts with conformal prediction, and generates evidence-grounded incident tickets. The revised evaluation includes BGL_2k and two additional public sequence benchmarks, HDFS and OpenStack, and adds representative LogAnomaly-style and LogBERT-lite baselines to the original TF-IDF+LR, Isolation Forest, DeepLog-style LSTM, and Transformer comparisons. On BGL_2k, Isolation Forest provides the best ranking performance among the original four detectors (test PR-AUC = 0.750), while the additional HDFS experiment shows that the masked-context LogBERT-lite baseline obtains the strongest sequence-level result (PR-AUC = 0.947, F1 = 0.905). OpenStack remains difficult because the available normal training sample is very small, producing low F1 across all added baselines. We also report inference latency, throughput, memory footprint, conformal alpha sensitivity, window-size sensitivity, model-strategy ablations, and structured false-positive/false-negative patterns. The results should be interpreted as reproducible operational validation of the detection-calibration-ticket workflow rather than a claim of state-of-the-art detector accuracy. The pipeline demonstrates how calibrated scores and template-level evidence can support practical alert control and ITSM-ready ticket generation.
Host-Based Intrusion Detection with System Call Sequences: Window Localization and Forensic Narratives Qi Xin
Aviation Electronics, Information Technology, Telecommunications, Electricals, and Controls (AVITEC) Vol 8, No 2 (2026): August
Publisher : Institut Teknologi Dirgantara Adisutjipto

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.28989/avitec.v8i2.3973

Abstract

Host-based intrusion detection systems (HIDS) and endpoint detection and response platforms increasingly rely on high-volume host telemetry such as system-call and API-call sequences. Accurate trace classification is useful, but operational response also requires localization of the suspicious fragment and a readable evidence narrative. This paper presents an analyst-oriented HIDS workflow with three stages: window-based detection using 3-gram logistic regression, 1D CNN, BiLSTM with attention pooling, and Transformer encoder models; suspicious-window localization using maximum-probability window selection and attention attribution; and evidence-grounded forensic narrative generation from the same localized evidence. The main ADFA-LD evaluation uses 1,263 training traces and 316 test traces; the best detector, 3-gram logistic regression with W=100, achieves precision 0.958, recall 0.913, F1 0.935, and AUROC 0.980. To address dataset-size and cross-telemetry concerns, this study adds two bounded additional evaluations: an eight-family Windows API-call sequence experiment on Mal-API-2019 and a large NetFlow stress test on NF-ToN-IoT-v3 with 10,000, 20,000, 50,000, and 100,000 training records. The NetFlow experiment shows that deep models become more stable as data volume increases, but the linear baseline remains strongest at 100,000 records (F1=0.888), while the Transformer improves to F1=0.856. These results support a careful conclusion: larger datasets help deep models, but they do not automatically make a Transformer outperform a strong shallow baseline when the signal is dominated by compact local motifs or well-separated tabular flow features.