{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T10:16:40Z","timestamp":1781518600831,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,10,30]],"date-time":"2017-10-30T00:00:00Z","timestamp":1509321600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61729202"],"award-info":[{"award-number":["61729202"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1314945, 1514520"],"award-info":[{"award-number":["1314945, 1514520"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,10,30]]},"DOI":"10.1145\/3133956.3134015","type":"proceedings-article","created":{"date-parts":[[2017,10,27]],"date-time":"2017-10-27T12:48:18Z","timestamp":1509108498000},"page":"1285-1298","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1513,"title":["DeepLog"],"prefix":"10.1145","author":[{"given":"Min","family":"Du","sequence":"first","affiliation":[{"name":"University of Utah, Salt Lake City, UT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Feifei","family":"Li","sequence":"additional","affiliation":[{"name":"University of Utah, Salt Lake City, UT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guineng","family":"Zheng","sequence":"additional","affiliation":[{"name":"University of Utah, Salt Lake City, UT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vivek","family":"Srikumar","sequence":"additional","affiliation":[{"name":"University of Utah, Salt Lake City, UT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2017,10,30]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"VAST Challenge 2011. 2011. MC2 - Computer Networking Operations. (2011). http:\/\/hcil2.cs.umd.edu\/newvarepository\/VAST%20Challenge%202011\/challenges\/MC2%20-%20Computer%20Networking%20Operations\/ [Online; accessed 08-May-2017]."},{"key":"e_1_3_2_2_2_1","volume-title":"USENIX Symposium on Operating Systems Design and Implementation (OSDI). 264--285","author":"Abadi Mart\u00edn","year":"2016","unstructured":"Mart\u00edn Abadi, Paul Barham, Jianmin Chen, Zhifeng Chen, Andy Davis, Jeffrey Dean, Matthieu Devin, Sanjay Ghemawat, Geoffrey Irving, Michael Isard, et almbox. 2016 TensorFlow: A system for large-scale machine learning Proc. USENIX Symposium on Operating Systems Design and Implementation (OSDI). 264--285."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/944919.944966"},{"key":"e_1_3_2_2_4_1","volume-title":"International Conference on Software Engineering (ICSE ). 468--479","author":"Beschastnikh Ivan","year":"2014","unstructured":"Ivan Beschastnikh, Yuriy Brun, Michael D Ernst, and Arvind Krishnamurthy 2014. Inferring models of concurrent systems from logs of their behavior with CSight Proc. International Conference on Software Engineering (ICSE ). 468--479."},{"key":"e_1_3_2_2_5_1","volume-title":"2014 IEEE Symposium on. IEEE, 227--242","author":"Bittau Andrea","year":"2014","unstructured":"Andrea Bittau, Adam Belay, Ali Mashtizadeh, David Mazi\u00e8res, and Dan Boneh. 2014. Hacking blind Security and Privacy (SP), 2014 IEEE Symposium on. IEEE, 227--242."},{"key":"e_1_3_2_2_6_1","volume-title":"keras. https:\/\/github.com\/fchollet\/keras. (2015). [Online","author":"Chollet Fran\u00e7ois","year":"2017","unstructured":"Fran\u00e7ois Chollet. 2015. keras. https:\/\/github.com\/fchollet\/keras. (2015). [Online; accessed 08-May-2017]."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2012.67"},{"key":"e_1_3_2_2_8_1","volume-title":"Proc. Neural Information Processing Systems Conference (NIPS). 3079--3087","author":"Dai Andrew M","year":"2015","unstructured":"Andrew M Dai and Quoc V Le 2015. Semi-supervised sequence learning. In Proc. Neural Information Processing Systems Conference (NIPS). 3079--3087."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2016.0103"},{"key":"e_1_3_2_2_10_1","volume-title":"ATOM: Efficient Tracking, Monitoring, and Orchestration of Cloud Resources","author":"Du Min","year":"2017","unstructured":"Min Du and Feifei Li. 2017. ATOM: Efficient Tracking, Monitoring, and Orchestration of Cloud Resources. IEEE Transactions on Parallel and Distributed Systems (2017)."},{"key":"e_1_3_2_2_11_1","volume-title":"IEEE International Conference on Data Mining (ICDM). 149--158","author":"Fu Qiang","year":"2009","unstructured":"Qiang Fu, Jian-Guang Lou, Yi Wang, and Jiang Li. 2009. Execution anomaly detection in distributed systems through unstructured log analysis Proc. IEEE International Conference on Data Mining (ICDM). 149--158."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/3176748.3176757"},{"key":"e_1_3_2_2_13_1","volume-title":"Deep Learning","author":"Goodfellow Ian","unstructured":"Ian Goodfellow, Yoshua Bengio, and Aaron Courville. 2016. Deep Learning. MIT Press. http:\/\/www.deeplearningbook.org."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2983323.2983358"},{"key":"e_1_3_2_2_15_1","volume-title":"Proc. Large Installation System Administration Conference (LISA). 145--152","author":"Hansen Stephen E","year":"1993","unstructured":"Stephen E Hansen and E Todd Atkins 1993. Automated System Monitoring and Notification with Swatch. Proc. Large Installation System Administration Conference (LISA). 145--152."},{"key":"e_1_3_2_2_16_1","volume-title":"International Conference on Dependable Systems and Networks (DSN). 654--661","author":"He Pinjia","year":"2016","unstructured":"Pinjia He, Jieming Zhu, Shilin He, Jian Li, and Michael R Lyu 2016. An evaluation study on log parsing and its use in log mining Proc. International Conference on Dependable Systems and Networks (DSN). 654--661."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2016.21"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_2_19_1","volume-title":"International Conference on Software Engineering (ICSE ). 102--111","author":"Lin Qingwei","year":"2016","unstructured":"Qingwei Lin, Hongyu Zhang, Jian-Guang Lou, Yu Zhang, and Xuewei Chen 2016. Log clustering based problem identification for online service systems Proc. International Conference on Software Engineering (ICSE ). 102--111."},{"key":"e_1_3_2_2_20_1","volume-title":"IEEE International Conference on Data Mining (ICDM). 251--260","author":"Liu Chaochun","year":"2016","unstructured":"Chaochun Liu, Huan Sun, Nan Du, Shulong Tan, Hongliang Fei, Wei Fan, Tao Yang, Hao Wu, Yaliang Li, and Chenwei Zhang. 2016. Augmented LS\u2122 Framework to Construct Medical Self-diagnosis Android Proc. IEEE International Conference on Data Mining (ICDM). 251--260."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835883"},{"key":"e_1_3_2_2_22_1","volume-title":"Proc. USENIX Annual Technical Conference (ATC). 231--244","author":"Lou Jian-Guang","year":"2010","unstructured":"Jian-Guang Lou, Qiang Fu, Shengqi Yang, Ye Xu, and Jiang Li 2010. Mining Invariants from Console Logs for System Problem Detection. Proc. USENIX Annual Technical Conference (ATC). 231--244."},{"key":"e_1_3_2_2_23_1","volume-title":"ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (SIGKDD). 1255--1264","author":"Makanju Adetokunbo AO","year":"2009","unstructured":"Adetokunbo AO Makanju, A Nur Zincir-Heywood, and Evangelos E Milios 2009. Clustering event logs using iterative partitioning Proc. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (SIGKDD). 1255--1264."},{"key":"e_1_3_2_2_24_1","volume-title":"Foundations of statistical natural language processing","author":"Manning Christopher D","unstructured":"Christopher D Manning and Hinrich Sch\u00fctze 1999. Foundations of statistical natural language processing. MIT Press."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2010-343"},{"key":"e_1_3_2_2_26_1","volume-title":"USENIX Symposium on Networked Systems Design and Implementation (NSDI). 26--26","author":"Nagaraj Karthik","year":"2012","unstructured":"Karthik Nagaraj, Charles Killian, and Jennifer Neville. 2012. Structured comparative analysis of systems logs to diagnose performance problems Proc. USENIX Symposium on Networked Systems Design and Implementation (NSDI). 26--26."},{"key":"e_1_3_2_2_27_1","unstructured":"Christopher Olah. 2015. Understanding LS\u2122 Networks. (2015). http:\/\/colah.github.io\/posts\/2015-08-Understanding-LSTMsshownote[Online; accessed 16-May-2017]."},{"key":"e_1_3_2_2_28_1","volume-title":"International Conference on Dependable Systems and Networks (DSN). 45--56","author":"Oprea Alina","year":"2015","unstructured":"Alina Oprea, Zhou Li, Ting-Fang Yen, Sang H Chin, and Sumayah Alrwais 2015. Detection of early-stage enterprise infection by mining large-scale log data Proc. International Conference on Dependable Systems and Networks (DSN). 45--56."},{"key":"e_1_3_2_2_29_1","volume-title":"Proc. Annual Conference on Linux Clusters.","author":"Prewett James E","year":"2003","unstructured":"James E Prewett. 2003. Analyzing cluster log files using Logsurfer. In Proc. Annual Conference on Linux Clusters."},{"key":"e_1_3_2_2_30_1","volume-title":"Introducing CloudLab: Scientific Infrastructure for Advancing Cloud Architectures and Applications. USENIX ;login","author":"Ricci Robert","year":"2014","unstructured":"Robert Ricci, Eric Eide, and The CloudLab Team. 2014. Introducing CloudLab: Scientific Infrastructure for Advancing Cloud Architectures and Applications. USENIX ;login:, Vol. 39, 6 (Dec. 2014). https:\/\/www.usenix.org\/publications\/login\/dec14\/ricci"},{"key":"e_1_3_2_2_31_1","volume-title":"Proc. Large Installation System Administration Conference (LISA). 133--150","author":"Rouillard John P","year":"2004","unstructured":"John P Rouillard. 2004. Real-time Log File Analysis Using the Simple Event Correlator (SEC). Proc. Large Installation System Administration Conference (LISA). 133--150."},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2015.7113365"},{"key":"e_1_3_2_2_33_1","volume-title":"The Open Source Elastic Stack. (2017). https:\/\/www.elastic.co\/products[Online","author":"Stack Elastic","year":"2017","unstructured":"Elastic Stack. 2017. The Open Source Elastic Stack. (2017). https:\/\/www.elastic.co\/products[Online; accessed 16-May-2017]."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"crossref","unstructured":"Martin Sundermeyer Ralf Schl\u00fcter and Hermann Ney. 2012. LSTM Neural Networks for Language Modeling.. In Interspeech. 194--197.","DOI":"10.21437\/Interspeech.2012-65"},{"key":"e_1_3_2_2_35_1","volume-title":"Neural Information Processing Systems Conference (NIPS). 3104--3112","author":"Sutskever Ilya","year":"2014","unstructured":"Ilya Sutskever, Oriol Vinyals, and Quoc V Le. 2014. Sequence to sequence learning with neural networks Proc. Neural Information Processing Systems Conference (NIPS). 3104--3112."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2010.76"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2063576.2063690"},{"key":"e_1_3_2_2_38_1","volume-title":"IEEE International Conference on Data Mining (ICDM). 588--597","author":"Xu Wei","year":"2009","unstructured":"Wei Xu, Ling Huang, Armando Fox, David Patterson, and Michael Jordan 2009. Online system problem detection by mining patterns of console logs Proc. IEEE International Conference on Data Mining (ICDM). 588--597."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629587"},{"key":"e_1_3_2_2_40_1","volume-title":"ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (SIGKDD). 499--508","author":"Yamanishi Kenji","year":"2015","unstructured":"Kenji Yamanishi and Yuko Maruyama 2015. Dynamic syslog mining for network failure monitoring Proc. ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (SIGKDD). 499--508."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523670"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2872362.2872407"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","unstructured":"Ding Yuan Haohui Mai Weiwei Xiong Lin Tan Yuanyuan Zhou and Shankar Pasupathy. 2010. SherLog: error diagnosis by connecting clues from run-time logs ACM SIGARCH computer architecture news. ACM 143--154. 10.1145\/1736020.1736038","DOI":"10.1145\/1736020.1736038"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2016.7840733"},{"key":"e_1_3_2_2_45_1","volume-title":"Proc. USENIX Symposium on Operating Systems Design and Implementation (OSDI). 603--618","author":"Zhao Xu","year":"2016","unstructured":"Xu Zhao, Kirk Rodrigues, Yu Luo, Ding Yuan, and Michael Stumm 2016. Non-intrusive performance profiling for entire software stacks based on the flow reconstruction principle. In Proc. USENIX Symposium on Operating Systems Design and Implementation (OSDI). 603--618."}],"event":{"name":"CCS '17: 2017 ACM SIGSAC Conference on Computer and Communications Security","location":"Dallas Texas USA","acronym":"CCS '17","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3133956.3134015","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3133956.3134015","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3133956.3134015","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:13:26Z","timestamp":1750212806000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3133956.3134015"}},"subtitle":["Anomaly Detection and Diagnosis from System Logs through Deep Learning"],"short-title":[],"issued":{"date-parts":[[2017,10,30]]},"references-count":45,"alternative-id":["10.1145\/3133956.3134015","10.1145\/3133956"],"URL":"https:\/\/doi.org\/10.1145\/3133956.3134015","relation":{},"subject":[],"published":{"date-parts":[[2017,10,30]]},"assertion":[{"value":"2017-10-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}