Extended authentication based on user log analysis in the operating system

DOI: 10.21293/1818-0442-2025-28-4-39-49

Download article in PDF format

JATS xml

Abstract: The paper is devoted to the systematization of modern methods for feature extraction and anomaly detection based on the analysis of operating system logs to address the problem of extended authentication. Approaches to processing and structuring system logs are reviewed and classified, including the extraction of quantitative, index, semantic, temporal, parametric, and graph features. An overview of open datasets for log analysis is provided. The authors performed a comparative analysis of the effectiveness of various feature extraction methods and anomaly detection algorithms, encompassing statistical methods, classical machine learning, neural networks, and hybrid models. Effectiveness was evaluated in terms of the performance metrics of classifiers solving the final task. The most promising areas for developing extended authentication systems are identified. The research results can be applied to to enhance the security of information systems through the development of adaptive authentication mechanisms based on user activity monitoring.

Keywords: extended authentication, machine learning, feature extraction, information security

Funding: This work was carried out within the framework of the TUSUR Development Program for 2025–2036 and the Strategic Academic Leadership Program "Priority 2030."

For citation:
Loshak I. S., Kostyuchenko E. Yu. Extended authentication based on user log analysis in the operating system. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2025, vol. 28, no. 4, pp. 39–49. DOI: 10.21293/1818-0442-2025-28-4-39-49

Authors and copyright holders:

  • Loshak I. S. , Tomsk State University of Control Systems and Radioelectronics (Tomsk, Russia)
  • Kostyuchenko E. Yu. , Tomsk State University of Control Systems and Radioelectronics (Tomsk, Russia)

  • 1. GOST R 58833–2020. Natsional'nyj standart Rossijskoi Federatsii. Zashchita informatsii. Identifikatsiya i autentifikatsiya [National standard of the Russian Federation. Information protection. Identification and authentication]. Moscow, Standartinform, 2020, 32 p.
  • 2. European Data Protection Supervisor. Biometric Continuous Authentication. Available at: https://www.edps.europa.eu/press-publications/publications/techsonar/biometriccontinuous-authentication_en (Accessed: 10 December 2024).
  • 3. GOST R ISO/IEC 15408-1–2012. Informatsionnaya tekhnologiya. Metody i sredstva obespecheniya bezopasnosti. Kriterii otsenki bezopasnosti informatsionnyh tekhnologii [Information technology. Security techniques. Evaluation criteria for IT security]. Part 1: Introduction and general model. Moscow, Standartinform, 2012, 75 p.
  • 4. Romanov A.S., Shelupanov A.A., Bondarchuk S.S. [Generalized authorship identification technique]. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2010, No. 3-1 (21), pp. 108–112 (in Russ.)
  • 5. Fedotova A., Romanov A., Kurtukova A., Shelupanov A. Authorship attribution of social media and literary Russian-language texts using machine learning methods and feature selection. Future Internet, 2021, vol. 14, no. 1, pp. 4. DOI: 10.3390/fi14010004.
  • 6. Doroshenko T.Y., Kostyuchenko E.Yu. [The authentication system based on dynamic handwritten signature]. Doklady TUSUR, 2014, no. 2(32), pp. 219–223 (in Russ.)
  • 7. Rakhmanenko I.A., Shelupanov A.A., Kostyuchenko E.Yu. [Automatic text-independent speaker verification using convolutional deep belief network]. Computer Optics, 2020, vol. 44, no. 4, pp. 596–605 (in Russ.).
  • 8. Zateev S.V. Prodlenaya autentifikatciya na ocnove klaviaturnogo pocherka [Continuous authentication based on keystroke dynamics analysis]. II Vserossijskaya nauchno-prakticheskaya konferentsiya «Teoriya i praktika obespecheniya informatsionnoi bezopasnosti» [2nd All-Russian scientific and practical conference «Theory and practice of information security»], M.: MTUCI, 2023, pp. 116 (in Russ.)
  • 9. Shelupanov A.A., Evsyutin O.O., Konev A.A., Kostyuchenko E.Yu., Kruchinin D.V., Nikiforov D.S. [Modern trends in development of methods and means for information protection]. Doklady TUSUR, 2017, vol. 20, no. 3, pp. 11–24 (in Russ.).
  • 10. Ma J., Liu Y., Wan H., Sun G. Automatic parsing and utilization of system log features in log analysis: A survey. Applied Sciences, 2023, vol. 13, no. 8, pp. 4930.
  • 11. He S., He P., Chen Zh., Yang T., Su Yu., Lyu M.R. A survey on automated log analysis for reliability engineering. ACM computing surveys (CSUR), 2021, vol. 54, no. 6, pp. 1–37.
  • 12. Xu W., Huang L., Fox A., Patterson D., Jordan M.I. Detecting large-scale system problems by mining console logs. Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles, Big Sky, Association for Computing Machinery, 2009, pp. 117–132.
  • 13. Oliner A., Stearley J. What supercomputers say: A study of five system logs. 37th annual IEEE/IFIP international conference on dependable systems and networks (DSN'07), Washington, IEEE, 2007, pp. 575–584.
  • 14. Du M., Li F., Zheng G., Srikumar V. Deeplog: Anomaly detection and diagnosis from system logs through deep learning. Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, Dallas, Association for Computing Machinery, 2017, pp. 1285–1298.
  • 15. Zhu J., He Sh., He P., Liu J., Lyu M.R. Loghub: A large collection of system log datasets for ai-driven log analytics. 2023 IEEE 34th International Symposium on Software Reliability Engineering (ISSRE), Florence, IEEE, 2023, pp. 355–366.
  • 16. He Sh., Zhu J., He P., Lyu M.R. Experience report: System log analysis for anomaly detection. 2016 IEEE 27th international symposium on software reliability engineering (ISSRE), Ottawa, IEEE, 2016, pp. 207–218.
  • 17. Abin A.A., Hosseini P., Torabian R.A. Continuous user authentication using a combination of operation and application-related features. Journal of Innovations in Computer Science and Engineering (JICSE), 2023, vol. 1, pp. 11–22.
  • 18. Pokhrel R., Pokharel P., Timalsina A.K. Anomalybased–intrusion detection system using user profile generated from system logs. International Journal of Scientific and Research Publications (IJSRP), 2019, vol. 9, pp. 8631.
  • 19. Zhao N., Wang H., Li Z., Peng X. An empirical investigation of practical log anomaly detection for online service systems. Proceedings of the 29th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering, Athens, Association for Computing Machinery, 2021, pp. 1404–1415.
  • 20. Xie Y., Zhang H., Zhang B., Babar M.A., Lu Sh. Logdp: Combining dependency and proximity for log-based anomaly detection. International Conference on Service-Oriented Computing, Dubai, Cham: Springer International Publishing, 2021, pp. 708–716.
  • 21. Lu S., Wei X., Li Y., Wang L. Detecting anomaly in big data system logs using convolutional neural network. 2018 IEEE 16th Intl Conf on Dependable, Autonomic and Secure Computing, 16th Intl Conf on Pervasive Intelligence and Computing, 4th Intl Conf on Big Data Intelligence and Computing and Cyber Science and Technology Congress (DASC/PiCom/DataCom/CyberSciTech), Athens, IEEE, 2018, pp. 151–158.
  • 22. Yen S., Moh M., Moh T.S. Causalconvlstm: Semi-supervised log anomaly detection through sequence modeling. 2019 18th IEEE International Conference on Machine Learning and Applications (ICMLA), Boca Raton, IEEE, 2019, pp. 1334–1341.
  • 23. Bertero C., M. Roy, Sauvanaud C., Trédan G. Experience report: Log mining using natural language processing and application to anomaly detection. 2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), Toulouse, IEEE, 2017, pp. 351–360.
  • 24. Meng W., Liu Y., Zhu Y., Zhang Sh., Pei D., Liu Y., Chen Y., Zhang R., Tao Sh., Sun P., Zhou R. Loganomaly: Unsupervised detection of sequential and quantitative anomalies in unstructured logs. IJCAI, 2019, vol. 19, no. 7, pp. 4739–4745.
  • 25. Zhang X. Xu Y., Lin Q., Qiao B., Zhang H., Dang Y. et al. Robust log-based anomaly detection on unstable log data. Proceedings of the 2019 27th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering, Tallinn, Association for Computing Machinery, 2019, pp. 807–817.
  • 26. Wang J., Tang Y., He Sh., Zhao Ch., Sharma P.K., Alfarraj O., Tolba A. LogEvent2vec: LogEvent-to-vector based anomaly detection for large-scale logs in internet of things. Sensors, 2020, vol. 20, no. 9, pp. 2451.
  • 27. Liu L., Chen Ch., Zhang J., De Vel O., Xiang Y. Doc2vec-based insider threat detection through behaviour analysis of multi-source security logs. 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Guangzhou, IEEE, 2020, pp. 301–309.
  • 28. Huang Sh., Liu Y., Fung C., He R., Zhao Y., Yang H., Luan Z. Hitanomaly: Hierarchical transformers for anomaly detection in system log. IEEE Transactions on network and service management, 2020, vol. 17, no. 4, pp. 2064–2076.
  • 29. Ott H., Bogatinovski J., Acker A., Nedelkoski S., Kao O. Robust and transferable anomaly detection in log data using pre-trained language models. 2021 IEEE/ACM International workshop on cloud intelligence (CloudIntelligence), Madrid, IEEE, 2021, pp. 19–24.
  • 30. He Sh., Deng T., Chen B., Sherratt R.S., Wang J. Unsupervised Log Anomaly Detection Method Based on MultiFeature. Computers, Materials & Continua, 2023, vol. 76, no. 1, pp. 517–541.
  • 31. Lv D., Luktarhan N., Chen Y. ConAnomaly: Content-based anomaly detection for system logs. Sensors, 2021, vol. 21, no. 18, pp. 6125.
  • 32. Ryciak P., Wasielewska K., Janicki A. Anomaly detection in log files using selected natural language processing methods. Applied Sciences, 2022, vol. 12, no. 10, pp. 5089.
  • 33. Corney M., Mohay G., Clark A. Detection of anomalies from user profiles generated from system logs. Proceedings of the Ninth Australasian Information Security Conference, Perth, Australian Computer Society, 2011, pp. 23–31.
  • 34. Li Y., Du N., Bengio S. Time-dependent representation for neural event sequence prediction. arXiv preprint arXiv:1708.00065, 2017, pp. 1–11.
  • 35. Rak T., Żyła R. Using Data Mining techniques for detecting dependencies in the Outcoming Data of a web-based system. Applied Sciences, 2022, vol. 12, no. 12, pp. 6115.
  • 36. Li X., Chen P., Jing L., He Z., Yu G. Swisslog: Robust and unified deep learning based log anomaly detection for diverse faults. 2020 IEEE 31st International Symposium on Software Reliability Engineering (ISSRE), Coimbra, IEEE, 2020, pp. 92–103.
  • 37. Xiao R., Chen H., Lu J., Li W., Jin Sh. AllInfoLog: Robust diverse anomalies detection based on all log features. IEEE Transactions on Network and Service Management, 2022, vol. 20, no. 3, pp. 2529–2543.
  • 38. Backes M., Humbert M., Pang J., Zhang Y. Walk2friends: Inferring social links from mobility profiles. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, Association for Computing Machinery, 2017, pp. 1943–1957.
  • 39. Dai H., Dai B., Song L. Discriminative embeddings of latent variable models for structured data. International conference on machine learning, New York, PMLR, 2016, pp. 2702–2711.
  • 40. Xu X., Liu Ch., Feng Q., Yin H., Song L., Song D. Neural network-based graph embedding for cross-platform binary code similarity detection. Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, Dallas, Association for Computing Machinery, 2017, pp. 363–376.
  • 41. Zhao X., Rodrigues K., Luo Y., Yuan D., Stumm M. Non-Intrusive performance profiling for entire software stacks based on the flow reconstruction principle. 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16), Savannah, USENIX Association, 2016, pp. 603–618.
  • 42. Milajerdi S.M., Gjomemo R., Eshete B., Sekar R., Venkatakrishnan V.N. Holmes: real-time apt detection through correlation of suspicious information flows. 2019 IEEE symposium on security and privacy (SP), San Francisco, IEEE, 2019, pp. 1137–1152.
  • 43. Yang W., Gao P., Huang H., Wei X., Liu W., Zhu Sh. & Luo W. RShield: A refined shield for complex multi-step attack detection based on temporal graph network. International Conference on Database Systems for Advanced Applications, Hyderabad, Cham: Springer International Publishing, 2022, pp. 468–480.
  • 44. Grover A., Leskovec J. node2vec: Scalable feature learning for networks. Proceedings of the 22nd ACM SIGKDD international conference on Knowledge discovery and data mining, San Francisco: Association for Computing Machinery, 2016, pp. 855–864.
  • 45. Liu F., Wen Y., Zhang D., Jiang X., Xing X., Meng D. Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise. Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, London, Association for Computing Machinery, 2019, pp. 1777–1794.
  • 46. Lin X., Yao Y., Hu B., Yang W., Zhou X., Li G., Zhang W. A real-time anomaly detection method for industrial control systems based on long-short period deterministic finite automaton. IEEE Internet of Things Journal, 2025, vol. 12, no. 10, pp. 14599–14621.
  • 47. Debnath B., Solaimani M., Gulzar Gulzar M.A., Arora N. et al. LogLens: A real-time log analysis system .2018 IEEE 38th international conference on distributed computing systems (ICDCS), Vienna, IEEE, 2018, pp. 1052–1062.
  • 48. Yang L., Chen J., Wang Z., Wang W., Jiang J., Dong X., Zhang W. Semi-supervised log-based anomaly detection via probabilistic label estimation. 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE), Madrid, IEEE, 2021, pp. 1448–1460.
  • 49. Zhang C., Peng X., Sha Ch., Zhang K., Fu Zh., Wu X., Lin Q., Zhang D. Deeptralog: Trace-log combined microservice anomaly detection through graph-based deep learning. Proceedings of the 44th international conference on software engineering, Pittsburgh, Association for Computing Machinery, 2022, pp. 623–634.
  • 50. Wang Z., Tian J., Fang H., Chen L., Qin J. LightLog: A lightweight temporal convolutional network for log anomaly detection on the edge. Computer Networks, 2022, vol. 203, pp. 108616.
  • 51. Guo H., Yuan S., Wu X. Logbert: Log anomaly detection via bert. 2021 International Joint Conference on Neural Networks (IJCNN), Shenzhen, IEEE, 2021, pp. 1–8.
  • 52. Almodovar C., Sabrina F., Karimi S., Azad S. LogFiT: Log anomaly detection using fine-tuned language models. IEEE Transactions on Network and Service Management, 2024, vol. 21, no. 2, pp. 1715–1723.
  • 53. Hadadi F., Xu Q., Bianculli D., Briand L. LLM meets ML: Data-efficient Anomaly Detection on Unseen Unstable Logs. ACM Transactions on Software Engineering and Methodology, 2025. DOI: 10.1145/3771283.
  • 54. Hang F., Guo W., Chen H., Xie L., Zhou Ch., Liu Y. Logformer: Cascaded Transformer for System Log Anomaly Detection. Computer Modeling in Engineering & Sciences (CMES), 2023, vol. 136, no. 1, P. 517–529.
  • 55. Guo H., Lin X., Yang J., Zhuang Y., Bai J., Zheng T., Zhang B., Li Z. Translog: A unified transformer-based framework for log anomaly detection. arXiv preprint arXiv:2201.00016, 2022, pp. 1–7.
  • 56. Nedelkoski S., Bogatinovski J., Acker A., Cardoso J., Kao O. Self-attentive classification-based anomaly detection in unstructured logs. 2020 IEEE International Conference on Data Mining (ICDM), Sorrento, IEEE, 2020, pp. 1196–1201.
  • 57. Wei X. Sun Ch.-ai, Yang P., Zhang X.-Y., Towey D. TraLogAnomaly: A microservice system anomaly detection approach based on hybrid event sequences. Science of Computer Programming, 2025, vol. 245, pp. 103303.
  • 58. Catillo M., Pecchia A., Villano U. AutoLog: Anomaly detection by deep autoencoding of system logs. Expert Systems with Applications, 2022, vol. 191, pp. 116263.
  • 59. Bulut M.F., Liu Y., Ahmad N., Turner M., Ouahmane S.A., Andrews C., Greenwald L. SecEncoder: Logs are All You Need in Security. arXiv preprint arXiv:2411.07528, 2024. DOI: 10.48550/arXiv.2411.07528.
  • 60. Bereketoglu A.B. Hybrid Meta-Learning Framework for Anomaly Forecasting in Nonlinear Dynamical Systems via Physics-Inspired Simulation and Deep Ensembles. arXiv preprint arXiv:2506.13828, 2025. DOI: 10.48550/arXiv.2506.13828.
  • 61. Husselman L. Anomaly Detection with Windows Event Logs: A comparative study between traditional and ML based approaches. Master’s thesis, University of Zurich, 2024, 184 p.
  • 62. Kechedzhiev A.S., Tsvetkova O.L., Dubrovina A.I. Terskikh M., Tishina E. [Methodology for detecting anomalies in cyber attack assessment data using Random Forest and Gradient Boosting in machine learning]. Herald of Daghestan State Technical University. Technical Sciences, 2024, vol. 51, no. 3, pp. 72–85 (in Russ.)
  • 63. Wu X., Li H., Khomh F. On the effectiveness of log representation for log-based anomaly detection. Empirical Software Engineering, 2023, vol. 28, no. 6, pp. 137.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates