{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T15:11:38Z","timestamp":1778166698225,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":25,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819709441","type":"print"},{"value":"9789819709458","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-981-97-0945-8_3","type":"book-chapter","created":{"date-parts":[[2024,2,24]],"date-time":"2024-02-24T20:02:14Z","timestamp":1708804934000},"page":"37-52","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["TAElog: A Novel Transformer AutoEncoder-Based Log Anomaly Detection Method"],"prefix":"10.1007","author":[{"given":"Changzhi","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kezhen","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Di","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xueying","family":"Han","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Du","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yutian","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhigang","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuling","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,2,25]]},"reference":[{"key":"3_CR1","doi-asserted-by":"publisher","unstructured":"Astekin, M., \u00d6zcan, S., S\u00f6zer, H.: Incremental analysis of large-scale system logs for anomaly detection. In: 2019 IEEE International Conference on Big Data (Big Data), pp. 2119\u20132127 (2019). https:\/\/doi.org\/10.1109\/BigData47090.2019.9006593","DOI":"10.1109\/BigData47090.2019.9006593"},{"key":"3_CR2","doi-asserted-by":"publisher","unstructured":"Berlin, K., Slater, D., Saxe, J.: Malicious behavior detection using windows audit logs. In: Proceedings of the 8th ACM Workshop on Artificial Intelligence and Security, pp. 35\u201344. Association for Computing Machinery (2015). https:\/\/doi.org\/10.1145\/2808769.2808773","DOI":"10.1145\/2808769.2808773"},{"issue":"1","key":"3_CR3","doi-asserted-by":"publisher","first-page":"1049","DOI":"10.1109\/TNSM.2021.3054356","volume":"18","author":"H Bian","year":"2021","unstructured":"Bian, H., Bai, T., Salahuddin, M.A., Limam, N., Daya, A.A., Boutaba, R.: Uncovering lateral movement using authentication logs. IEEE Trans. Netw. Serv. Manage. 18(1), 1049\u20131063 (2021). https:\/\/doi.org\/10.1109\/TNSM.2021.3054356","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"3_CR4","doi-asserted-by":"publisher","unstructured":"Borghesi, A., Bartolini, A., Lombardi, M., Milano, M., Benini, L.: Anomaly detection using autoencoders in high performance computing systems. In: Proceedings of the AAAI Conference on artificial intelligence, vol. 33, pp. 9428\u20139433 (2019). https:\/\/doi.org\/10.1609\/aaai.v33i01.33019428","DOI":"10.1609\/aaai.v33i01.33019428"},{"key":"3_CR5","doi-asserted-by":"publisher","first-page":"116263","DOI":"10.1016\/j.eswa.2021.116263","volume":"191","author":"M Catillo","year":"2022","unstructured":"Catillo, M., Pecchia, A., Villano, U.: AutoLog: anomaly detection by deep autoencoding of system logs. Expert Syst. Appl. 191, 116263 (2022). https:\/\/doi.org\/10.1016\/j.eswa.2021.116263","journal-title":"Expert Syst. Appl."},{"key":"3_CR6","doi-asserted-by":"publisher","unstructured":"Dongre, P.B., Malik, L.G.: A review on real time data stream classification and adapting to various concept drift scenarios. In: 2014 IEEE International Advance Computing Conference (IACC), pp. 533\u2013537 (2014). https:\/\/doi.org\/10.1109\/IAdCC.2014.6779381","DOI":"10.1109\/IAdCC.2014.6779381"},{"key":"3_CR7","doi-asserted-by":"publisher","unstructured":"Du, M., Li, F., Zheng, G., Srikumar, V.: DeepLog: anomaly detection and diagnosis from system logs through deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, pp. 1285\u20131298. Association for Computing Machinery (2017). https:\/\/doi.org\/10.1145\/3133956.3134015","DOI":"10.1145\/3133956.3134015"},{"key":"3_CR8","unstructured":"Dunia, R., Qin, S.J.: Multi-dimensional fault diagnosis using a subspace approach. In: American Control Conference, vol. 5. Citeseer (1997)"},{"issue":"5814","key":"3_CR9","doi-asserted-by":"publisher","first-page":"972","DOI":"10.1126\/science.1136800","volume":"315","author":"BJ Frey","year":"2007","unstructured":"Frey, B.J., Dueck, D.: Clustering by passing messages between data points. Science 315(5814), 972\u2013976 (2007)","journal-title":"Science"},{"key":"3_CR10","doi-asserted-by":"publisher","unstructured":"Gao, Y., Ma, Y., Li, D.: Anomaly detection of malicious users\u2019 behaviors for web applications based on web logs. In: 2017 IEEE 17th International Conference on Communication Technology (ICCT), pp. 1352\u20131355 (2017). https:\/\/doi.org\/10.1109\/ICCT.2017.8359854","DOI":"10.1109\/ICCT.2017.8359854"},{"key":"3_CR11","unstructured":"Ho, G., et al.: Hopper: modeling and detecting lateral movement. In: USENIX Security Symposium, pp. 3093\u20133110 (2021)"},{"issue":"1","key":"3_CR12","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1214\/aoms\/1177729694","volume":"22","author":"S Kullback","year":"1951","unstructured":"Kullback, S., Leibler, R.A.: On information and sufficiency. Ann. Math. Stat. 22(1), 79\u201386 (1951)","journal-title":"Ann. Math. Stat."},{"key":"3_CR13","doi-asserted-by":"publisher","unstructured":"Kwon, D., Natarajan, K., Suh, S.C., Kim, H., Kim, J.: An empirical study on network anomaly detection using convolutional neural networks. In: 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), pp. 1595\u20131598 (2018). https:\/\/doi.org\/10.1109\/ICDCS.2018.00178","DOI":"10.1109\/ICDCS.2018.00178"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Li, T., Ma, J., Pei, Q., Shen, Y., Lin, C., Ma, S., Obaidat, M.S.: AClog: attack chain construction based on log correlation. In: 2019 IEEE Global Communications Conference (GLOBECOM), pp. 1\u20136 (2019)","DOI":"10.1109\/GLOBECOM38437.2019.9013518"},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Lu, S., Wei, X., Li, Y., Wang, L.: Detecting anomaly in big data system logs using convolutional neural network. In: 2018 IEEE 16th International Conference on Dependable, Autonomic and Secure Computing, 16th International Conference on Pervasive Intelligence and Computing, 4th International Conference on Big Data Intelligence and Computing and Cyber Science and Technology Congress (DASC\/PiCom\/DataCom\/CyberSciTech), pp. 151\u2013158 (2018)","DOI":"10.1109\/DASC\/PiCom\/DataCom\/CyberSciTec.2018.00037"},{"key":"3_CR16","doi-asserted-by":"publisher","unstructured":"Meng, W., et al.: Device-agnostic log anomaly classification with partial labels. In: 2018 IEEE\/ACM 26th International Symposium on Quality of Service (IWQoS), pp. 1\u20136 (2018). https:\/\/doi.org\/10.1109\/IWQoS.2018.8624141","DOI":"10.1109\/IWQoS.2018.8624141"},{"key":"3_CR17","doi-asserted-by":"publisher","unstructured":"Moustafa, N., Slay, J.: UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), pp. 1\u20136 (2015). https:\/\/doi.org\/10.1109\/MilCIS.2015.7348942","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"3_CR18","doi-asserted-by":"publisher","first-page":"108616","DOI":"10.1016\/j.comnet.2021.108616","volume":"203","author":"Z Wang","year":"2022","unstructured":"Wang, Z., Tian, J., Fang, H., Chen, L., Qin, J.: LightLog: a lightweight temporal convolutional network for log anomaly detection on the edge. Comput. Netw. 203, 108616 (2022)","journal-title":"Comput. Netw."},{"key":"3_CR19","unstructured":"wuyifan18: Deeplog (2019). https:\/\/github.com\/wuyifan18\/DeepLog"},{"key":"3_CR20","doi-asserted-by":"publisher","unstructured":"Xu, W., Huang, L., Fox, A., Patterson, D., Jordan, M.: Online system problem detection by mining patterns of console logs. In: 2009 Ninth IEEE International Conference on Data Mining, pp. 588\u2013597 (2009). https:\/\/doi.org\/10.1109\/ICDM.2009.19","DOI":"10.1109\/ICDM.2009.19"},{"key":"3_CR21","doi-asserted-by":"publisher","unstructured":"Xu, W., Huang, L., Fox, A., Patterson, D., Jordan, M.I.: Detecting large-scale system problems by mining console logs. In: Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles, SOSP 2009, pp. 117\u2013132. Association for Computing Machinery, New York (2009). https:\/\/doi.org\/10.1145\/1629575.1629587","DOI":"10.1145\/1629575.1629587"},{"key":"3_CR22","doi-asserted-by":"publisher","unstructured":"Yen, S., Moh, M., Moh, T.S.: CausalConvLSTM: semi-supervised log anomaly detection through sequence modeling. In: 2019 18th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 1334\u20131341 (2019). https:\/\/doi.org\/10.1109\/ICMLA.2019.00217","DOI":"10.1109\/ICMLA.2019.00217"},{"issue":"3","key":"3_CR23","doi-asserted-by":"publisher","first-page":"1704","DOI":"10.1109\/TCYB.2019.2933548","volume":"51","author":"YH Yoo","year":"2021","unstructured":"Yoo, Y.H., Kim, U.H., Kim, J.H.: Recurrent reconstructive network for sequential anomaly detection. IEEE Trans. Cybern. 51(3), 1704\u20131715 (2021). https:\/\/doi.org\/10.1109\/TCYB.2019.2933548","journal-title":"IEEE Trans. Cybern."},{"key":"3_CR24","doi-asserted-by":"publisher","unstructured":"Yuan, L.P., Liu, P., Zhu, S.: Recompose event sequences vs. predict next events: a novel anomaly detection approach for discrete event logs. In: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, pp. 336\u2013348. Association for Computing Machinery (2021). https:\/\/doi.org\/10.1145\/3433210.3453098","DOI":"10.1145\/3433210.3453098"},{"key":"3_CR25","doi-asserted-by":"publisher","unstructured":"Zhang, X., et al.: Robust log-based anomaly detection on unstable log data. In: Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 807\u2013817. Association for Computing Machinery (2019). https:\/\/doi.org\/10.1145\/3338906.3338931","DOI":"10.1145\/3338906.3338931"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-97-0945-8_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,7]],"date-time":"2025-03-07T17:29:42Z","timestamp":1741368582000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-97-0945-8_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9789819709441","9789819709458"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-981-97-0945-8_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"25 February 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Inscrypt","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security and Cryptology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hangzhou","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 December 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 December 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cisc2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/inscrypt2023.github.io\/#","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"152","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"25% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}