Algorithms for anomaly detection of traces in logs of process aware information systems

被引:74
作者
Bezerra, Fabio [1 ]
Wainer, Jacques [2 ]
机构
[1] Univ Fed Rural Amazonia, Cyberspace Inst, Belem, Para, Brazil
[2] Univ Estadual Campinas, Inst Comp, Campinas, SP, Brazil
关键词
Anomaly detection; Process mining; Process-aware systems; PROCESS MODELS; WORKFLOW MODELS; EXECUTIONS; FRAMEWORK; CHECKING; ISSUES; FRAUD;
D O I
10.1016/j.is.2012.04.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper discusses four algorithms for detecting anomalies in logs of process aware systems. One of the algorithms only marks as potential anomalies traces that are infrequent in the log. The other three algorithms: threshold, iterative and sampling are based on mining a process model from the log, or a subset of it. The algorithms were evaluated on a set of 1500 artificial logs, with different profiles on the number of anomalous traces and the number of times each anomalous traces was present in the log. The sampling algorithm proved to be the most effective solution. We also applied the algorithm to a real log, and compared the resulting detected anomalous traces with the ones detected by a different procedure that relies on manual choices. (c) 2012 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 44
页数:12
相关论文
共 49 条
[1]  
Accorsi R., 2011, Proceedings of the 2011 6th International Conference on IT Security Incident Management and IT Forensics (IMF 2011), P3, DOI 10.1109/IMF.2011.13
[2]  
Accorsi R, 2010, LECT NOTES BUS INF P, V47, P207
[3]  
Agrawal R, 1998, LECT NOTES COMPUT SC, V1377, P469
[4]  
[Anonymous], 2006, THESIS TU EINDHOVEN
[5]  
Bezerra Fabio, 2011, International Journal of Business Process Integration and Management, V5, P121, DOI 10.1504/IJBPIM.2011.040204
[6]  
BEZERRA F, 2008, 10 INT C ENT INF SYS, P11
[7]  
Bezerra F., 2008, P KDD 2008 WORKSH DA, P1
[8]  
Bezerra F, 2009, LECT NOTES BUS INF P, V29, P149
[9]  
Bezerra F, 2008, APPLIED COMPUTING 2008, VOLS 1-3, P951
[10]   Process diagnostics using trace alignment: Opportunities, issues, and challenges [J].
Bose, R. P. Jagadeesh Chandra ;
van der Aalst, Wil M. P. .
INFORMATION SYSTEMS, 2012, 37 (02) :117-141