{"id":"https://openalex.org/W2767094836","doi":"https://doi.org/10.1145/3133956.3134015","title":"DeepLog","display_name":"DeepLog","publication_year":2017,"publication_date":"2017-10-27","ids":{"openalex":"https://openalex.org/W2767094836","doi":"https://doi.org/10.1145/3133956.3134015","mag":"2767094836"},"language":"en","primary_location":{"id":"doi:10.1145/3133956.3134015","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3133956.3134015","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102737328","display_name":"Min Du","orcid":"https://orcid.org/0000-0002-8277-0206"},"institutions":[{"id":"https://openalex.org/I223532165","display_name":"University of Utah","ror":"https://ror.org/03r0ha626","country_code":"US","type":"education","lineage":["https://openalex.org/I223532165"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Min Du","raw_affiliation_strings":["University of Utah, Salt Lake City, UT, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Utah, Salt Lake City, UT, USA","institution_ids":["https://openalex.org/I223532165"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100450462","display_name":"Li Fei-Fei","orcid":"https://orcid.org/0000-0002-7481-0810"},"institutions":[{"id":"https://openalex.org/I223532165","display_name":"University of Utah","ror":"https://ror.org/03r0ha626","country_code":"US","type":"education","lineage":["https://openalex.org/I223532165"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Feifei Li","raw_affiliation_strings":["University of Utah, Salt Lake City, UT, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Utah, Salt Lake City, UT, USA","institution_ids":["https://openalex.org/I223532165"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038414975","display_name":"Guineng Zheng","orcid":"https://orcid.org/0000-0002-4356-5840"},"institutions":[{"id":"https://openalex.org/I223532165","display_name":"University of Utah","ror":"https://ror.org/03r0ha626","country_code":"US","type":"education","lineage":["https://openalex.org/I223532165"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guineng Zheng","raw_affiliation_strings":["University of Utah, Salt Lake City, UT, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Utah, Salt Lake City, UT, USA","institution_ids":["https://openalex.org/I223532165"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5013135203","display_name":"Vivek Srikumar","orcid":"https://orcid.org/0000-0003-0419-6568"},"institutions":[{"id":"https://openalex.org/I223532165","display_name":"University of Utah","ror":"https://ror.org/03r0ha626","country_code":"US","type":"education","lineage":["https://openalex.org/I223532165"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Vivek Srikumar","raw_affiliation_strings":["University of Utah, Salt Lake City, UT, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Utah, Salt Lake City, UT, USA","institution_ids":["https://openalex.org/I223532165"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":69.2045,"has_fulltext":false,"cited_by_count":1636,"citation_normalized_percentile":{"value":0.99950024,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1285","last_page":"1298"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9932000041007996,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9919000267982483,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7898114919662476},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.7766628265380859},{"id":"https://openalex.org/keywords/debugging","display_name":"Debugging","score":0.6692949533462524},{"id":"https://openalex.org/keywords/anomaly","display_name":"Anomaly (physics)","score":0.5798760652542114},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5307042002677917},{"id":"https://openalex.org/keywords/web-log-analysis-software","display_name":"Web log analysis software","score":0.5253854393959045},{"id":"https://openalex.org/keywords/trustworthiness","display_name":"Trustworthiness","score":0.5168931484222412},{"id":"https://openalex.org/keywords/root","display_name":"Root (linguistics)","score":0.43827423453330994},{"id":"https://openalex.org/keywords/workflow","display_name":"Workflow","score":0.4191342890262604},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.17351233959197998},{"id":"https://openalex.org/keywords/web-server","display_name":"Web server","score":0.13685342669487},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.11971932649612427},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.09119495749473572}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7898114919662476},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.7766628265380859},{"id":"https://openalex.org/C168065819","wikidata":"https://www.wikidata.org/wiki/Q845566","display_name":"Debugging","level":2,"score":0.6692949533462524},{"id":"https://openalex.org/C12997251","wikidata":"https://www.wikidata.org/wiki/Q567560","display_name":"Anomaly (physics)","level":2,"score":0.5798760652542114},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5307042002677917},{"id":"https://openalex.org/C104352257","wikidata":"https://www.wikidata.org/wiki/Q1238961","display_name":"Web log analysis software","level":5,"score":0.5253854393959045},{"id":"https://openalex.org/C153701036","wikidata":"https://www.wikidata.org/wiki/Q659974","display_name":"Trustworthiness","level":2,"score":0.5168931484222412},{"id":"https://openalex.org/C171078966","wikidata":"https://www.wikidata.org/wiki/Q111029","display_name":"Root (linguistics)","level":2,"score":0.43827423453330994},{"id":"https://openalex.org/C177212765","wikidata":"https://www.wikidata.org/wiki/Q627335","display_name":"Workflow","level":2,"score":0.4191342890262604},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.17351233959197998},{"id":"https://openalex.org/C11392498","wikidata":"https://www.wikidata.org/wiki/Q11288","display_name":"Web server","level":3,"score":0.13685342669487},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.11971932649612427},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.09119495749473572},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C26873012","wikidata":"https://www.wikidata.org/wiki/Q214781","display_name":"Condensed matter physics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C173576120","wikidata":"https://www.wikidata.org/wiki/Q2641220","display_name":"Static web page","level":4,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3133956.3134015","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3133956.3134015","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5682781618","display_name":null,"funder_award_id":"1314945, 1514520","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G814274616","display_name":null,"funder_award_id":"61729202","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W35047313","https://openalex.org/W179699880","https://openalex.org/W179875071","https://openalex.org/W208057840","https://openalex.org/W560655873","https://openalex.org/W1520857056","https://openalex.org/W1540258466","https://openalex.org/W1563576199","https://openalex.org/W1574901103","https://openalex.org/W1919179112","https://openalex.org/W1965626898","https://openalex.org/W1990089904","https://openalex.org/W2039157918","https://openalex.org/W2045812729","https://openalex.org/W2064675550","https://openalex.org/W2096017373","https://openalex.org/W2102632804","https://openalex.org/W2114554028","https://openalex.org/W2115056012","https://openalex.org/W2120416238","https://openalex.org/W2126529005","https://openalex.org/W2137723287","https://openalex.org/W2153470728","https://openalex.org/W2169953282","https://openalex.org/W2293825325","https://openalex.org/W2326344342","https://openalex.org/W2401686019","https://openalex.org/W2402268235","https://openalex.org/W2520381032","https://openalex.org/W2522585932","https://openalex.org/W2527994611","https://openalex.org/W2536393303","https://openalex.org/W2557283755","https://openalex.org/W2560021099","https://openalex.org/W2573182830","https://openalex.org/W2583874385","https://openalex.org/W2585367509","https://openalex.org/W2901999534","https://openalex.org/W2949888546","https://openalex.org/W2952729433","https://openalex.org/W2953384591","https://openalex.org/W2963042536","https://openalex.org/W2998704965","https://openalex.org/W3006210356","https://openalex.org/W4242838928","https://openalex.org/W4243157141","https://openalex.org/W4285719527","https://openalex.org/W4407831773"],"related_works":["https://openalex.org/W4321442002","https://openalex.org/W2015265939","https://openalex.org/W2284072287","https://openalex.org/W2611067230","https://openalex.org/W2480201319","https://openalex.org/W2387706296","https://openalex.org/W2155788121","https://openalex.org/W4235469518","https://openalex.org/W362492756","https://openalex.org/W2890345561"],"abstract_inverted_index":{"Anomaly":[0],"detection":[1,207],"is":[2,20,45,55,176],"a":[3,8,17,88,100,104],"critical":[4,30],"step":[5],"towards":[6],"building":[7],"secure":[9],"and":[10,25,37,58,65,82,119,184],"trustworthy":[11],"system.":[12],"The":[13],"primary":[14],"purpose":[15],"of":[16,77],"system":[18,23,35,63,71,101,169],"log":[19,43,102,114,123,131,158,170,195],"to":[21,32,98,111,141,156],"record":[22],"states":[24],"significant":[26],"events":[27],"at":[28],"various":[29,70],"points":[31],"help":[33],"debug":[34],"failures":[36],"perform":[38,185],"root":[39,186],"cause":[40,187],"analysis.":[41],"Such":[42],"data":[44,54,132,196,212],"universally":[46],"available":[47],"in":[48,147],"nearly":[49],"all":[50],"computer":[51],"systems.":[52],"Log":[53],"an":[56,148,174],"important":[57],"valuable":[59],"resource":[60],"for":[61,79],"understanding":[62],"status":[64],"performance":[66],"issues;":[67],"therefore,":[68],"the":[69,127,144,167,181],"logs":[72],"are":[73],"naturally":[74],"excellent":[75],"source":[76],"information":[78],"online":[80,149],"monitoring":[81],"anomaly":[83,175,183,206],"detection.":[84],"We":[85],"propose":[86],"DeepLog,":[87],"deep":[89],"neural":[90],"network":[91],"model":[92,99,128,146],"utilizing":[93],"Long":[94],"Short-Term":[95],"Memory":[96],"(LSTM),":[97],"as":[103],"natural":[105],"language":[106],"sequence.":[107],"This":[108],"allows":[109],"DeepLog":[110,145,163,200],"automatically":[112],"learn":[113],"patterns":[115,124,159],"from":[116,126,130,166],"normal":[117,134],"execution,":[118],"detect":[120],"anomalies":[121],"when":[122],"deviate":[125],"trained":[129],"under":[133],"execution.":[135],"In":[136],"addition,":[137],"we":[138],"demonstrate":[139],"how":[140],"incrementally":[142],"update":[143],"fashion":[150],"so":[151,171],"that":[152,172,199],"it":[153],"can":[154,179],"adapt":[155],"new":[157],"over":[160,193],"time.":[161],"Furthermore,":[162],"constructs":[164],"workflows":[165],"underlying":[168],"once":[173],"detected,":[177],"users":[178],"diagnose":[180],"detected":[182],"analysis":[188],"effectively.":[189],"Extensive":[190],"experimental":[191],"evaluations":[192],"large":[194],"have":[197],"shown":[198],"has":[201],"outperformed":[202],"other":[203],"existing":[204],"log-based":[205],"methods":[208],"based":[209],"on":[210],"traditional":[211],"mining":[213],"methodologies.":[214]},"counts_by_year":[{"year":2026,"cited_by_count":113},{"year":2025,"cited_by_count":315},{"year":2024,"cited_by_count":240},{"year":2023,"cited_by_count":252},{"year":2022,"cited_by_count":186},{"year":2021,"cited_by_count":214},{"year":2020,"cited_by_count":161},{"year":2019,"cited_by_count":112},{"year":2018,"cited_by_count":42},{"year":2016,"cited_by_count":1}],"updated_date":"2026-06-14T07:44:22.658603","created_date":"2017-11-10T00:00:00"}
