An Anomaly Detection Technique for Business Processes based on Extended Dynamic Bayesian Networks

被引:17
作者
Pauwels, Stephen [1 ]
Calders, Toon [1 ]
机构
[1] Univ Antwerp, Antwerp, Belgium
来源
SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING | 2019年
关键词
Anomaly Detection; Probabilistic models; Event log and Workflow data; OUTLIER DETECTION;
D O I
10.1145/3297280.3297326
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Checking and analyzing various executions of different Business Processes can be a tedious task as the logs from these executions may contain lots of events, each with a (possibly large) number of attributes. We developed a way to automatically model the behavior captured in log files with dozens of attributes. The advantage of our method is that we do not need any prior knowledge about the data and the attributes. The learned model can then be used to detect anomalous executions in the data. To achieve this we extend the existing Dynamic Bayesian Networks with other (existing) techniques to better model the normal behavior found in log files. We introduce a new algorithm that is able to learn a model of a log file starting from the data itself. The model is capable of scoring events and cases, even when new values or new combinations of values appear in the log file, and has the ability to give a decomposition of the given score, indicating the root cause for the anomalies. Furthermore we show that our model can be used in a more general way for detecting Concept Drift.
引用
收藏
页码:494 / 501
页数:8
相关论文
共 37 条
  • [1] NEW LOOK AT STATISTICAL-MODEL IDENTIFICATION
    AKAIKE, H
    [J]. IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 1974, AC19 (06) : 716 - 723
  • [2] [Anonymous], MINING MULTIDIMENSIO
  • [3] [Anonymous], INSIGHT INFORM ABSTR
  • [4] [Anonymous], NOT BPMN VERS 2 0
  • [5] [Anonymous], 2004, P INT 2004
  • [6] [Anonymous], 1994, P WORKSH CONSTR LOG
  • [7] [Anonymous], DATASET
  • [8] [Anonymous], 2009, ACM SIGKDD Explorations Newsletter
  • [9] [Anonymous], 2012, ELEMENTS INFORM THEO
  • [10] [Anonymous], ARXIV180905650