Продлённая аутентификация на основе анализа журналов пользователя в ОС

DOI: 10.21293/1818-0442-2025-28-4-39-49

Скачать текст статьи в формате PDF

Скачать JATS xml

Аннотация: Статья посвящена систематизации современных методов извлечения признаков и выявления аномалий на основе анализа журналов операционной системы для решения задачи продлённой аутентификации. Рассматриваются и классифицируются подходы к обработке и структурированию системных логов, включая извлечение количественных, индексных, семантических, временных, параметрических и графовых признаков. Проведен обзор открытых наборов данных для анализа логов и выполнен сравнительный анализ эффективности различных методов извлечения признаков и алгоритмов обнаружения аномалий, включая статистические методы, классическое машинное обучение, нейронные сети и гибридные модели. Эффективность оценивалась с точки зрения показателей качества работы классификаторов, решающих итоговую задачу. Определены наиболее перспективные направления для разработки систем продлённой аутентификации. Результаты исследования могут быть применены для повышения безопасности информационных систем за счёт разработки адаптивных механизмов аутентификации на основе мониторинга пользовательской активности.

Ключевые слова: продлённая аутентификация, машинное обучение, отбор признаков, информационная безопасность

Сведения о финансировании: Данная работа выполнялась в рамках Программы развития ТУСУРа на 2025–2036 годы, Программы стратегического академического лидерства «Приоритет 2030».

Библиография статьи:
Лошак И. С. Продлённая аутентификация на основе анализа журналов пользователя в ОС / И. С. Лошак, Е. Ю. Костюченко // Доклады Томского государственного университета систем управления и радиоэлектроники. – 2025. – Т. 28, № 4. – С. 39–49. DOI: 10.21293/1818-0442-2025-28-4-39-49

Авторы и правообладатели:

  • Лошак И. С. , Томский государственный университет систем управления и радиоэлектроники (Томск, Россия)
  • Костюченко Е. Ю. , Томский государственный университет систем управления и радиоэлектроники (Томск, Россия)

  • 1. ГОСТ Р 58833–2020. Национальный стандарт Российской Федерации. Защита информации. Идентификация и аутентификация. – М.: Стандартинформ, 2020. – 32 c.
  • 2. European Data Protection Supervisor. Biometric Continuous Authentication [Электронный ресурс]. – URL: https://www.edps.europa.eu/press-publications/publications/techsonar/biometric-continuous-authentication_en (дата обращения: 10.12.2024).
  • 3. ГОСТ Р ИСО/МЭК 15408-1–2012. Информационная технология. Методы и средства обеспечения безопасности. Критерии оценки безопасности информационных технологий. – М.: Стандартинформ, 2012. – 75 c.
  • 4. Романов А.С. Обобщенная методика идентификации автора неизвестного текста / А.С. Романов, А.А. Шелупанов, С.С. Бондарчук // Доклады ТУСУР. – 2010. – № 3-1 (21). – С. 108–112.
  • 5. Fedotova A. Authorship attribution of social media and literary Russian-language texts using machine learning methods and feature selection / A. Fedotova, A. Romanov, A. Kurtukova, A. Shelupanov // Future Internet. – 2021. – Vol. 14, No. 1. – P. 4. DOI: 10.3390/fi14010004.
  • 6. Дорошенко Т.Ю. Система аутентификации на основе динамики рукописной подписи / Т.Ю. Дорошенко, Е.Ю. Костюченко // Доклады ТУСУР. – 2014. – № 2 (32). – С. 219–223.
  • 7. Рахманенко И.А. Автоматическая верификация диктора по произвольной фразе с применением свёрточных глубоких сетей доверия / И.А. Рахманенко, А.А. Шелупанов, Е.Ю. Костюченко // Компьютерная оптика. – 2020. – Т. 44, № 4. – С. 596–605.
  • 8. Затеев С. В. Продленная аутентификация на основе анализа клавиатурного почерка // II Всерос. науч.-практ. конф. «Теория и практика обеспечения информационной безопасности». – М.: МТУСИ, 2023. – С. 116–124.
  • 9. Актуальные направления развития методов и средств защиты информации / А.А. Шелупанов, О.О. Евсютин, А.А. Конев, Е.Ю. Костюченко, Д.В. Кручинин, Д.С. Никифоров // Доклады ТУСУР. – 2017. – Т. 20, № 3. – С. 11–24.
  • 10. Ma J. Automatic parsing and utilization of system log features in log analysis: A survey / J. Ma, Y. Liu, H. Wan, G. Sun // Applied Sciences. – 2023. – Vol. 13, No. 8. – P. 4930.
  • 11. A survey on automated log analysis for reliability engineering / S. He, P. He, Zh. Chen, T. Yang, Yu. Su, M.R. Lyu // ACM computing surveys (CSUR). – 2021. – Vol. 54, No. 6. – P. 1–37.
  • 12. Detecting large-scale system problems by mining console logs / W. Xu, L. Huang, A. Fox, D. Patterson, M.I. Jordan // Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles. – Big Sky: Association for Computing Machinery, 2009. – P. 117–132.
  • 13. Oliner A. What supercomputers say: A study of five system logs / A. Oliner, J. Stearley // 37th Annual IEEE/IFIP international conference on dependable systems and networks (DSN'07). – Washington: IEEE, 2007. – P. 575–584.
  • 14. Du M. Deeplog: Anomaly detection and diagnosis from system logs through deep learning / M. Du, F. Li, G. Zheng, V. Srikumar // Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. – Dallas: Association for Computing Machinery, 2017. – P. 1285–1298.
  • 15. Loghub: A large collection of system log datasets for ai-driven log analytics / J. Zhu, Sh. He, P. He, J. Liu, M.R. Lyu // 2023 IEEE 34th International Symposium on Software Reliability Engineering (ISSRE). – Florence: IEEE, 2023. – P. 355–366.
  • 16. He Sh. Experience report: System log analysis for anomaly detection / Sh. He, J. Zhu, P. He, M.R. Lyu // 2016 IEEE 27th International Symposium on software reliability engineering (ISSRE). – Ottawa: IEEE, 2016. – P. 207–218.
  • 17. Abin A.A. Continuous user authentication using a combination of operation and application-related features / A.A. Abin, P. Hosseini, R.A. Torabian // Journal of Innovations in Computer Science and Engineering (JICSE). – 2023. – Vol. 1. – P. 11–22.
  • 18. Pokhrel R. Anomaly-based–intrusion detection system using user profile generated from system logs / R. Pokhrel, P. Pokharel, A.K. Timalsina // International Journal of Scientific and Research Publications (IJSRP). – 2019. – Vol. 9. – P. 8631.
  • 19. Zhao N. An empirical investigation of practical log anomaly detection for online service systems / N. Zhao, H. Wang, Z. Li, X. Peng // Proceedings of the 29th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering. – Athens: Association for Computing Machinery, 2021. – P. 1404–1415.
  • 20. Logdp: Combining dependency and proximity for log-based anomaly detection / Y. Xie, H. Zhang, B. Zhang, M.A. Babar, Sh. Lu // International Conference on Service-Oriented Computing. – Dubai: Cham: Springer International Publishing, 2021. – P. 708–716.
  • 21. Lu S. Detecting anomaly in big data system logs using convolutional neural network / S. Lu, X. Wei, Y. Li, L. Wang // 2018 IEEE 16th Intl Conf on Dependable, Autonomic and Secure Computing, 16th Intl Conf on Pervasive Intelligence and Computing, 4th Intl Conf on Big Data Intelligence and Computing and Cyber Science and Technology Congress (DASC/PiCom/DataCom/CyberSciTech). – Athens: IEEE, 2018. – P. 151–158.
  • 22. Yen S. Causalconvlstm: Semi-supervised log anomaly detection through sequence modeling / S. Yen, M. Moh, T.S. Moh // 2019 18th IEEE International Conference on Machine Learning and Applications (ICMLA). – Boca Raton: IEEE, 2019. – P. 1334–1341.
  • 23. Bertero C. Experience report: Log mining using natural language processing and application to anomaly detection / C. Bertero, M. Roy, C. Sauvanaud, G. Trédan // 2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE). – Toulouse: IEEE, 2017. – P. 351–360.
  • 24. Loganomaly: Unsupervised detection of sequential and quantitative anomalies in unstructured logs / W. Meng, Y. Liu, Y. Zhu, Sh. Zhang, D. Pei, Y. Liu, Y. Chen, R. Zhang, Sh. Tao, P. Sun, R. Zhou // IJCAI. – 2019. – Vol. 19, No. 7. – P. 4739–4745.
  • 25. Robust log-based anomaly detection on unstable log data / X. Zhang, Y. Xu, Q. Lin, B. Qiao, H. Zhang, Y. Dang et al. // Proceedings of the 2019 27th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering. – Tallinn: Association for Computing Machinery, 2019. – P. 807–817.
  • 26. LogEvent2vec: LogEvent-to-vector based anomaly detection for large-scale logs in internet of things / J. Wang, Y. Tang, Sh. He, Ch. Zhao, P.K. Sharma, O. Alfarraj, A. Tolba // Sensors. – 2020. – Vol. 20, No. 9. – P. 2451.
  • 27. Doc2vec-based insider threat detection through behaviour analysis of multi-source security logs / L. Liu, Ch. Chen, J. Zhang, O. De Vel, Y. Xiang // 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). – Guangzhou: IEEE, 2020. – P. 301–309.
  • 28. Hitanomaly: Hierarchical transformers for anomaly detection in system log / Sh. Huang, Y. Liu, C. Fung, R. He, Y. Zhao, H. Yang, Z. Luan // IEEE transactions on network and service management. – 2020. – Vol. 17, No. 4. – P. 2064–2076.
  • 29. Robust and transferable anomaly detection in log data using pre-trained language models / H. Ott, J. Bogatinovski, A. Acker, S. Nedelkoski, O. Kao // 2021 IEEE/ACM international workshop on cloud intelligence (CloudIntelligence). – Madrid: IEEE, 2021. – P. 19–24.
  • 30. Unsupervised Log Anomaly Detection Method Based on Multi-Feature / Sh. He, T. Deng, B. Chen, R.S. Sherratt, J. Wang // Computers, Materials & Continua. – 2023. – Vol. 76, No. 1. – P. 517–541.
  • 31. Lv D. ConAnomaly: Content-based anomaly detection for system logs / D. Lv, N. Luktarhan, Y. Chen // Sensors. – 2021. – Vol. 21, No. 18. – P. 6125.
  • 32. Ryciak P. Anomaly detection in log files using selected natural language processing methods / P. Ryciak, K. Wasielewska, A. Janicki // Applied Sciences. – 2022. – Vol. 12, No. 10. – P. 5089.
  • 33. Corney M. Detection of anomalies from user profiles generated from system logs / M. Corney, G. Mohay, A. Clark // Proceedings of the Ninth Australasian Information Security Conference. – Perth: Australian Computer Society, 2011. – P. 23–31.
  • 34. Li Y. Time-dependent representation for neural event sequence prediction / Y. Li, N. Du, S. Bengio // arXiv preprint arXiv:1708.00065. – 2017. – P. 1–11.
  • 35. Rak T. Using Data Mining techniques for detecting dependencies in the Outcoming Data of a web-based system / T. Rak, R. Żyła // Applied Sciences. – 2022. – Vol. 12, No. 12. – P. 6115.
  • 36. Swisslog: Robust and unified deep learning based log anomaly detection for diverse faults / X. Li, P. Chen, L. Jing, Z. He, G. Yu // 2020 IEEE 31st International Symposium on Software Reliability Engineering (ISSRE). – Coimbra: IEEE, 2020. – P. 92–103.
  • 37. AllInfoLog: Robust diverse anomalies detection based on all log features / R. Xiao, H. Chen, J. Lu, W. Li, Sh. Jin // IEEE Transactions on Network and Service Management. – 2022. – Vol. 20, No. 3. – P. 2529–2543.
  • 38. Backes M. Walk2friends: Inferring social links from mobility profiles / M. Backes, M. Humbert, J. Pang, Y. Zhang // Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. – Dallas: Association for Computing Machinery, 2017. – P. 1943–1957.
  • 39. Dai H. Discriminative embeddings of latent variable models for structured data / H. Dai, B. Dai, L. Song // International conference on machine learning. – New York: PMLR, 2016. – P. 2702–2711.
  • 40. Neural network-based graph embedding for cross-platform binary code similarity detection / X. Xu, Ch. Liu, Q. Feng, H. Yin, L. Song, D. Song // Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. – Dallas: Association for Computing Machinery, 2017. – P. 363–376.
  • 41. Non-Intrusive performance profiling for entire software stacks based on the flow reconstruction principle / X. Zhao, K. Rodrigues, Y. Luo, D. Yuan, M. Stumm // 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16). – Savannah: USENIX Association, 2016. – P. 603–618.
  • 42. Holmes: real-time apt detection through correlation of suspicious information flows / S.M. Milajerdi, R. Gjomemo, B. Eshete, R. Sekar, V.N. Venkatakrishnan // 2019 IEEE symposium on security and privacy (SP). – San Francisco: IEEE, 2019. – P. 1137–1152.
  • 43. RShield: A refined shield for complex multi-step attack detection based on temporal graph network / W. Yang, P. Gao, H. Huang, X. Wei, W. Liu, Sh. Zhu & W. Luo // International Conference on Database Systems for Advanced Applications. – Hyderabad: Cham: Springer International Publishing, 2022. – P. 468–480.
  • 44. Grover A. node2vec: Scalable feature learning for networks / A. Grover, J. Leskovec // Proceedings of the 22nd ACM SIGKDD international conference on Knowledge discovery and data mining. – San Francisco: Association for Computing Machinery, 2016. – P. 855–864.
  • 45. Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise / F. Liu, Y. Wen, D. Zhang, X. Jiang, X. Xing, D. Meng // Proceedings of the 2019 ACM SIGSAC conference on computer and communications security. – London: Association for Computing Machinery, 2019. – P. 1777–1794.
  • 46. A real-time anomaly detection method for industrial control systems based on long-short period deterministic finite automaton / X. Lin, Y. Yao, B. Hu, W. Yang, X. Zhou, G. Li, W. Zhang // IEEE Internet of Things Journal. – 2025. – Vol. 12, No. 10. – P. 14599–14621.
  • 47. LogLens: A real-time log analysis system / B. Debnath, M. Solaimani, M.A. Gulzar Gulzar, N. Arora et al. // 2018 IEEE 38th international conference on distributed computing systems (ICDCS). – Vienna: IEEE, 2018. – P. 1052–1062.
  • 48. Semi-supervised log-based anomaly detection via probabilistic label estimation / L. Yang, J. Chen, Z. Wang, W. Wang, J. Jiang, X. Dong, W. Zhang // 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE). – Madrid: IEEE, 2021. – P. 1448–1460.
  • 49. Deeptralog: Trace-log combined microservice anomaly detection through graph-based deep learning / Ch. Zhang, X. Peng, Ch. Sha, K. Zhang, Zh. Fu, X. Wu, Q. Lin, D. Zhang // Proceedings of the 44th international conference on software engineering. – Pittsburgh: Association for Computing Machinery, 2022. – P. 623–634.
  • 50. LightLog: A lightweight temporal convolutional network for log anomaly detection on the edge / Z. Wang, J. Tian, H. Fang, L. Chen, J. Qin // Computer Networks. – 2022. – Vol. 203. – P. 108616.
  • 51. Guo H. Logbert: Log anomaly detection via bert / H. Guo, S. Yuan, X. Wu // 2021 international joint conference on neural networks (IJCNN). – Shenzhen: IEEE, 2021. – P. 1–8.
  • 52. Almodovar C. LogFiT: Log anomaly detection using fine-tuned language models / C. Almodovar, F. Sabrina, S. Karimi, S. Azad // IEEE Transactions on Network and Service Management. – 2024. – Vol. 21, No. 2. – P. 1715–1723.
  • 53. Hadadi F. LLM meets ML: Data-efficient Anomaly Detection on Unseen Unstable Logs / F. Hadadi, Q. Xu, D. Bianculli, L. Briand // ACM Transactions on Software Engineering and Methodology. – 2025. DOI: 10.1145/3771283.
  • 54. Logformer: Cascaded Transformer for System Log Anomaly Detection / F. Hang, W. Guo, H. Chen, L. Xie, Ch. Zhou, Y. Liu // Computer Modeling in Engineering & Sciences (CMES). – 2023. – Vol. 136, No. 1. – P. 517–529.
  • 55. Translog: A unified transformer-based framework for log anomaly detection / H. Guo, X. Lin, J. Yang, Y. Zhuang, J. Bai, T. Zheng, B. Zhang, Z. Li // arXiv preprint arXiv:2201.00016. – 2022. – P. 1–7.
  • 56. Self-attentive classification-based anomaly detection in unstructured logs / S. Nedelkoski, J. Bogatinovski, A. Acker, J. Cardoso, O. Kao // 2020 IEEE International Conference on Data Mining (ICDM). – Sorrento: IEEE, 2020. – P. 1196–1201.
  • 57. TraLogAnomaly: A microservice system anomaly detection approach based on hybrid event sequences / X. Wei, Ch.-ai Sun, P. Yang, X.-Y. Zhang, D. Towey // Science of Computer Programming. – 2025. – Vol. 245. – P. 103303.
  • 58. Catillo M. AutoLog: Anomaly detection by deep autoencoding of system logs / M. Catillo, A. Pecchia, U. Villano // Expert Systems with Applications. – 2022. – Vol. 191. – P. 116263.
  • 59. SecEncoder: Logs are All You Need in Security / M.F. Bulut, Y. Liu, N. Ahmad, M. Turner, S.A. Ouahmane, C. Andrews, L. Greenwald // arXiv preprint arXiv:2411.07528. – 2024. DOI: 10.48550/arXiv.2411.07528.
  • 60. Bereketoglu A.B. Hybrid Meta-Learning Framework for Anomaly Forecasting in Nonlinear Dynamical Systems via Physics-Inspired Simulation and Deep Ensembles // arXiv preprint arXiv:2506.13828. – 2025. DOI: 10.48550/arXiv.2506.13828.
  • 61. Husselman L. Anomaly Detection with Windows Event Logs: A comparative study between traditional and ML based approaches: Master’s thesis. – University of Zurich, 2024. – 184 p.
  • 62. Кечеджиев А.С. Методика выявления аномалий в данных оценки кибератак с использованием Random Forest и градиентного бустинга в машинном обучении / А.С. Кечеджиев, О.Л. Цветкова, А.И. Дубровина // Вестник Дагестанского гос. техн. ун-та. Технические науки. – 2024. – Т. 51, № 3. – С. 72–85.
  • 63. Wu X. On the effectiveness of log representation for log-based anomaly detection / X. Wu, H. Li, F. Khomh // Empirical Software Engineering. – 2023. – Vol. 28, No. 6. – P. 137.
Адрес редакции

  634050, г. Томск, пр. Ленина, 40, МК, каб. 310/2

  (3822) 701-582, внутр.: 1456

  journal@tusur.ru