跳到主要內容

簡易檢索 / 詳目顯示

研究生: 黃子峻
Huang, Tzu-Chun
論文名稱: FedSOC:多客戶端環境下的聯邦式日誌異常偵測系統
FedSOC: A Federated Log Anomaly Detection System for Multi-Client Environments
指導教授: 孫士勝
Sun, Shi-Sheng
口試委員: 左瑞麟
Tso, Ray-lin
蔡孟勳
Tsai, Meng-Hsun
高大宇
Kao, Da-Yu
學位類別: 碩士
Master
系所名稱: 資訊學院 - 資訊安全碩士學位學程
Master Program in Information Security
論文出版年: 2026
畢業學年度: 114
語文別: 中文
論文頁數: 86
中文關鍵詞: FedSOC日誌隱私資料去中心化異常偵測
外文關鍵詞: FedSOC, Log Privacy, Data Decentralization, Anomaly Detection
相關次數: 點閱:15下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 近年資安異常事件日益增加,主管機關明文要求相關單位須透過安全維運中心(SOC)集中監控系統日誌以偵測異常事件;然而自建 SOC 成本高昂,多數企業與政府單位因而選擇將 SOC 業務委外。由於系統日誌普遍含有主機名稱、IP 位址、使用者名稱等高度敏感之識別資訊,當原始日誌跨越組織邊界傳送至委外 SOC 時,便衍生潛在的資料外洩風險,也暴露出傳統集中式 SOC 在日誌隱私保護上的限制。
    為解決上述隱私衝突,本研究提出聯邦式日誌異常偵測架構「FedSOC」。透過聯邦式學習將原始日誌資料去中心化,原始日誌得以嚴格保留於各客戶端本地之分析主機,客戶端僅需將運算後之模型梯度與分析結果上傳至 FedSOC 伺服端,即可在不外洩原始日誌的前提下,讓 SOC 持續進行整體異常事件分析與模型最佳化。於 Thunderbird、BGL、Spirit 三個公開大型日誌資料集上之實驗顯示,FedSOC 之 F1-Score 均達 0.95 以上(最高 0.998),效能與集中式架構相當,且在 Non-IID 資料分佈情境下仍能維持穩定效能。本研究為委外資安監控提供一套兼顧偵測效能與日誌隱私保護之可行方案。


    As cybersecurity threats have grown in recent years, regulatory authorities now explicitly require organizations to monitor system logs through a centralized Security Operations Center (SOC) to detect threats. Building an in-house SOC, however, is costly, so most enterprises and government agencies choose to outsource their SOC operations. System logs typically contain highly sensitive identifiers such as hostnames, IP addresses, and usernames. When raw logs are transmitted across organizational boundaries to an outsourced SOC, this creates a potential risk of data leakage and exposes the limitations of the traditional centralized SOC in protecting log privacy.
    To resolve this privacy conflict, this study proposes a federated log anomaly detection framework called FedSOC. By using federated learning to decentralize the raw log data, the original logs remain strictly on each client's local analysis host. Each client uploads only its computed model gradients and analysis results to the FedSOC server, allowing the SOC to perform overall threat analysis and model optimization without ever exposing the raw logs. Experiments on three large public log datasets (Thunderbird, BGL, and Spirit) show that FedSOC achieves an F1-Score above 0.95 (up to 0.998), matching the performance of a centralized architecture while remaining stable under Non-IID data distributions. This work offers a practical solution for outsourced security monitoring that balances detection performance with log privacy protection.

    致謝 I
    摘要 II
    Abstract III
    圖目錄 VII
    表目錄 VIII
    第一章 緒論 1
    1.1 研究背景 1
    1.1.1 安全維運中心於多客戶端環境中的監控需求 1
    1.1.2 集中式日誌採集面臨的隱私挑戰 2
    1.1.3 聯邦式學習作為兼顧偵測與隱私之可能方向 3
    1.2 研究動機 3
    1.3 研究目的 5
    1.4 研究貢獻 6
    1.5 論文架構 8
    第二章 文獻探討 9
    2.1 日誌解析 10
    2.2 日誌異常偵測 12
    2.2.1 資料處理 12
    2.2.2 機器學習模型 14
    2.3 聯邦式學習 15
    2.3.1 聚合策略 18
    2.4 日誌隱私風險 19
    第三章 系統架構 20
    3.1 傳統SOC架構分析 20
    3.2 FedSOC整體架構 23
    3.3 資料流動邊界與交換範圍界定 24
    3.4 PEAS任務環境描述 25
    3.5 系統運作流程 27
    3.5.1 系統整體架構概觀 27
    3.5.2 客戶端偵測流程 29
    第四章 研究方法 30
    4.1 日誌解析 30
    4.2 日誌嵌入表示與滑動視窗建構 31
    4.2.1 語意嵌入表示(Semantic Embedding)31
    4.2.2 滑動視窗建構(Sliding Window Construction) 31
    4.3 Transformer Autoencoder 模型 32
    4.3.1 Encoder 架構 32
    4.3.2 Decoder 架構 32
    4.3.3 損失函數設計 33
    4.3.4 異常判定機制 34
    4.4 聯邦式學習訓練流程 35
    4.4.1 FedAvg聚合策略 36
    4.4.2 FedProx 聚合策略 38
    4.4.3 SecAgg+ 安全聚合協定 39
    第五章 實驗設計與結果分析 44
    5.1 實驗設計 44
    5.1.1 實驗環境設定 44
    5.1.2 資料集描述 46
    5.1.3 評估指標 51
    5.2 偵測效能驗證 52
    5.2.1 IID 實驗結果 53
    5.2.2 Non-IID 實驗結果 60
    5.2.3 IID與Non-IID比較 65
    5.3 隱私與韌性驗證 66
    5.3.1 聚合策略韌性比較:FedAvg與FedProx(客戶端斷線模擬) 67
    5.4 效率驗證與討論 71
    5.4.1 與集中式模型之比較 71
    5.4.2 通訊成本分析 73
    5.4.3 實驗結果分析與討論 76
    第六章 結論與未來展望 80
    6.1 研究總結 80
    6.2 未來研究方向 81
    6.2.1 系統規模化擴展與實務維運效能評估 82
    6.2.2 聯邦式學習對抗式防禦機制之強化 82
    參考文獻 83

    [1] B. Raghu and L. Sami, Microsoft Unified XDR and SIEM Solution Handbook: Modernize and build a unified SOC platform for future-proof security. UK: Packt Publishing, 2024.
    [2] H. Liu et al., “UAC-AD: Unsupervised Adversarial Contrastive Learning for Anomaly Detection on Multi-Modal Data in Microservice Systems,” IEEE Transactions on Services Computing, vol. 17, no. 6, pp. 3887–3900, Jan. 2024, doi: 10.1109/TSC.2024.3411481.
    [3] M. Du, F. Li, G. Zheng, and V. Srikumar, “DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep Learning,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, in CCS ’17. New York, NY, USA: Association for Computing Machinery, Oct. 2017, pp. 1285–1298. doi: 10.1145/3133956.3134015.
    [4] B. Li, S. Ma, R. Deng, K.-K. R. Choo, and J. Yang, “Federated Anomaly Detection on System Logs for the Internet of Things: A Customizable and Communication-Efficient Approach,” IEEE Transactions on Network and Service Management, vol. 19, no. 2, pp. 1705–1716, Jun. 2022, doi: 10.1109/TNSM.2022.3152620.
    [5] J. Zhou et al., “LogDLR: Unsupervised Cross-System Log Anomaly Detection Through Domain-Invariant Latent Representation,” IEEE Transactions on Dependable and Secure Computing, vol. 22, no. 4, pp. 4456–4471, Jul. 2025, doi: 10.1109/TDSC.2025.3548050.
    [6] K. Bonawitz et al., “Practical Secure Aggregation for Federated Learning on User-Held Data,” presented at the NIPS 2016 workshop on Private Multi-Party Machine Learning, Dec. 2016. [Online]. Available: https://pmpml.github.io/PMPML16/papers/PMPML16_paper_8.pdf
    [7] Scott Lupton, Hironori Washizaki, N. Yoshioka, and Y. Fukazawa, “Landscape and Taxonomy of Online Parser-Supported Log Anomaly Detection Methods,” IEEE Access, vol. 12, pp. 78193–78218, 2024, doi: 10.1109/ACCESS.2024.3387287.
    [8] “LogPAI.” Accessed: Aug. 09, 2025. [Online]. Available: http://www.logpai.com
    [9] LOGPAI, “LOGPAI.” [Online]. Available: https://github.com/logpai
    [10] P. He, J. Zhu, Z. Zheng, and M. R. Lyu, “Drain: An Online Log Parsing Approach with Fixed Depth Tree,” in 2017 IEEE International Conference on Web Services (ICWS), Jun. 2017, pp. 33–40. doi: 10.1109/ICWS.2017.13.
    [11] M. Du and F. Li, “Spell: Online Streaming Parsing of Large Unstructured System Logs,” IEEE Transactions on Knowledge and Data Engineering, vol. 31, no. 11, pp. 2213–2227, Jan. 2019, doi: 10.1109/TKDE.2018.2875442.
    [12] S. Yu, P. He, N. Chen, and Y. Wu, “Brain: Log Parsing With Bidirectional Parallel Tree,” IEEE Transactions on Services Computing, vol. 16, no. 5, pp. 3224–3237, Sep. 2023, doi: 10.1109/TSC.2023.3270566.
    [13] J. Xu, R. Yang, Y. Huo, C. Zhang, and P. He, “DivLog: Log Parsing with Prompt Enhanced In-Context Learning,” in 2024 IEEE/ACM 46th International Conference on Software Engineering (ICSE), Apr. 2024, pp. 2457–2468. Accessed: Aug. 09, 2025. [Online]. Available: https://ieeexplore.ieee.org/document/10548166
    [14] I. Sedki, A. Hamou-Lhadj, O. Ait-Mohamed, and M. A. Shehab, “An Effective Approach for Parsing Large Log Files,” in 2022 IEEE International Conference on Software Maintenance and Evolution (ICSME), Oct. 2022, pp. 1–12. doi: 10.1109/ICSME55016.2022.00009.
    [15] M. Raeiszadeh, F. Estrada-Solano, R. H. Glitho, J. Eker, and R. A. F. Mini, “ALogSCAN: A Self-Supervised Dual Network for Adaptive and Timely Log Anomaly Detection in Clouds,” IEEE Transactions on Machine Learning in Communications and Networking, vol. 3, pp. 864–882, 2025, doi: 10.1109/TMLCN.2025.3594653.
    [16] C. Almodovar, F. Sabrina, S. Karimi, and S. Azad, “LogFiT: Log Anomaly Detection Using Fine-Tuned Language Models,” IEEE Transactions on Network and Service Management, vol. 21, no. 2, pp. 1715–1723, Apr. 2024, doi: 10.1109/TNSM.2024.3358730.
    [17] J. Qi et al., “LogEncoder: Log-Based Contrastive Representation Learning for Anomaly Detection,” IEEE Transactions on Network and Service Management, vol. 20, no. 2, pp. 1378–1391, Jun. 2023, doi: 10.1109/TNSM.2023.3239522.
    [18] W. Yuan, H. Sun, M. Pang, H. Wang, G. Wu, and Y. Zhang, “LogContrast: Log-based Anomaly Detection Using BERT and Contrastive Learning,” in 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Feb. 2024, pp. 2510–2516. doi: 10.1109/TrustCom63139.2024.00349.
    [19] J. Tian, M. Li, L. Chen, Z. Wang, X. Nie, and J. Qin, “SSDALog: Semi-Supervised Domain Adaptation for Incremental Log-Based Anomaly Detection,” IEEE Transactions on Information Forensics and Security, vol. 20, pp. 6607–6619, 2025, doi: 10.1109/TIFS.2025.3583483.
    [20] J. Tian, M. Li, Z. Wang, L. Chen, J. Qin, and R. Zhang, “OMLog: Online Log Anomaly Detection for Evolving System With Meta-Learning,” IEEE Internet of Things Journal, vol. 12, no. 15, pp. 30142–30155, Aug. 2025, doi: 10.1109/JIOT.2025.3569628.
    [21] J. Qi, Z. Luan, S. Huang, C. Fung, H. Yang, and D. Qian, “SpikeLog: Log-Based Anomaly Detection via Potential-Assisted Spiking Neuron Network,” IEEE Transactions on Knowledge and Data Engineering, vol. 36, no. 12, pp. 9322–9335, Feb. 2024, doi: 10.1109/TKDE.2023.3347695.
    [22] B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-Efficient Learning of Deep Networks from Decentralized Data,” in Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, PMLR, Apr. 2017, pp. 1273–1282. Accessed: Jun. 26, 2026. [Online]. Available: https://proceedings.mlr.press/v54/mcmahan17a.html
    [23] 楊強, 黃安埠, 劉洋, and 陳天健, 聯邦學習實戰, 初版. 中華人民共和國: 電子工業, 2021.
    [24] P. Kairouz et al., “Advances and Open Problems in Federated Learning,” Found. Trends Mach. Learn., vol. 14, no. 1–2, pp. 1–210, Jun. 2021, doi: 10.1561/2200000083.
    [25] Y. Zhao, M. Li, L. Lai, N. Suda, D. Civin, and V. Chandra, “Federated Learning with Non-IID Data,” 2018, doi: 10.48550/arXiv.1806.00582.
    [26] Tian Li, Anit Kumar Sahu, Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith, “Federated Optimization in Heterogeneous Networks,” in Third Conference on Machine Learning and Systems, USA: MLSys, Mar. 2020. [Online]. Available: https://mlsys.org/Conferences/2020/Schedule?showEvent=1406
    [27] C. M. Lonvick, “The BSD Syslog Protocol,” Internet Engineering Task Force, Request for Comments RFC 3164, Aug. 2001. doi: 10.17487/RFC3164.
    [28] R. Gerhards, “The Syslog Protocol,” Internet Engineering Task Force, Request for Comments RFC 5424, Mar. 2009. doi: 10.17487/RFC5424.
    [29] “Log File Formats.” Accessed: Aug. 05, 2025. [Online]. Available: https://web.archive.org/web/20210224022111/http://publib.boulder.ibm.com/tividd/td/ITWSA/ITWSA_info45/en_US/HTML/guide/c-logs.html#common
    [30] “Extended Log File Format.” Accessed: Aug. 05, 2025. [Online]. Available: https://www.w3.org/TR/WD-logfile.html
    [31] H. S. Thompson and C. Lilley, “XML Media Types,” Internet Engineering Task Force, Request for Comments RFC 7303, Jul. 2014. doi: 10.17487/RFC7303.
    [32] “Implementing ArcSight Common Event Format (CEF) - Version 27.” Accessed: Aug. 05, 2025. [Online]. Available: https://www.microfocus.com/documentation/arcsight/arcsight-smartconnectors-25.1/cef-implementation-standard/
    [33] “IBM QRadar Security Intelligence Platform.” Accessed: Aug. 05, 2025. [Online]. Available: https://www.ibm.com/docs/zh-tw/dsm?topic=leef-overview
    [34] T. Bray, “The I-JSON Message Format,” Internet Engineering Task Force, Request for Comments RFC 7493, Mar. 2015. doi: 10.17487/RFC7493.
    [35] L. Ren et al., “Research on relay setting attack defense in power systems based on a three-layer optimization model,” Front. Energy Res., vol. 12, Nov. 2024, doi: 10.3389/fenrg.2024.1502078.
    [36] Stuart J. Russell and Peter Norvig, Artificial Intelligence: A Modern Approach, 4/e. USA: Pearson FT Press, 2020.
    [37] T. F. Authors, “Flower: Advance Collaborative Superintelligence.” Accessed: Jul. 07, 2026. [Online]. Available: https://flower.ai/
    [38] L. Zhu, Z. Liu, and S. Han, “Deep leakage from gradients,” in Proceedings of the 33rd International Conference on Neural Information Processing Systems, Red Hook, NY, USA: Curran Associates Inc., 2019, pp. 14774–14784. Accessed: Jul. 06, 2026. [Online]. Available: https://dl.acm.org/doi/10.5555/3454287.3455610
    [39] “Secure Aggregation Protocols,” Flower. Accessed: Jun. 26, 2026. [Online]. Available: https://flower.ai/docs/framework/explanation-ref-secure-aggregation-protocols.html
    [40] E. Farooq, M. Milano, and A. Borghesi, “Federated LSTM autoencoders for time series anomaly detection in production-scale HPC systems,” Knowledge-Based Systems, vol. 334, p. 115043, Feb. 2026, doi: 10.1016/j.knosys.2025.115043.
    [41] H. Pan et al., “IPMN Risk Assessment Under Federated Learning Paradigm,” in 2025 IEEE 22nd International Symposium on Biomedical Imaging (ISBI), Apr. 2025, pp. 1–5. doi: 10.1109/ISBI60581.2025.10980733.
    [42] R. Darwish, M. Abdelsalam, S. Khorsandroo, and K. Roy, “FedP3E: Privacy-Preserving Prototype Exchange for Non-IID IoT Malware Detection in Cross-Silo Federated Learning,” Jul. 09, 2025, arXiv: arXiv:2507.07258. doi: 10.48550/arXiv.2507.07258.
    [43] E. Khramtsova, C. Hammerschmidt, S. Lagraa, and R. State, “Federated Learning For Cyber Security: SOC Collaboration For Malicious URL Detection,” in 2020 IEEE 40th International Conference on Distributed Computing Systems (ICDCS), Jan. 2020, pp. 1316–1321. doi: 10.1109/ICDCS47774.2020.00171.

    無法下載圖示 全文公開日期 2031/08/19
    QR CODE
    :::