arXiv

NLLog: Lightweight, Explainable SOC Anomaly Detection via Log-to-Language Rewriting

Title: NLLog: A Lightweight, Explainable Approach to SOC Anomaly Detection Through Log-to-Language Transformation

Abstract: While system-generated logs are the foundation of security monitoring, their rigid, template-driven structure often impedes both automated processing and human understanding. To address this, we introduce NLLog (Natural-Language Log), a streamlined pipeline that transforms parsed templates into structured WHO-WHAT-SEVERITY sentences through deterministic rewriting. This process is followed by pooling with term-frequency-inverse-document-frequency (TF-IDF) weighting, session classification via tree ensembles, and the back-projection of evidence using TreeSHAP to facilitate analyst review.

Evaluations on the Hadoop Distributed File System (HDFS) and Blue Gene/L (BGL) datasets demonstrate that NLLog outperforms two reproduced baselines that adhere to the same protocol. Furthermore, across the HDFS, BGL, and AIT Alert Data Set, the system maintains low false-positive rates and operates with latency on commodity hardware, making it well-suited for security operations center (SOC) triage. Ablation studies focusing on coverage, sparse versus dense representations, faithfulness, and adversarial scenarios reveal that fallback adequacy varies by corpus. Additionally, an enrollment-time coverage check can identify refinement needs prior to deployment. Ultimately, the combination of an auditable, deterministic rewrite mechanism with lightweight dense encoding offers a quantifiable representation layer for log-based anomaly detection and triage.


Source: arXiv Generated at: 2026-06-04 00:00:00 UTC

Related Articles

Zurich Insurance Expands Data-Center Offering Beyond the US
Bloomberg

Zurich Insurance Expands Data-Center Offering Beyond the US

Zurich Insurance Group is expanding its data center insurance products internationally, extending coverage beyond the Un...

Emerging-Market Stocks Fall as Broadcom Miss Disrupts AI Trade
Bloomberg

Emerging-Market Stocks Fall as Broadcom Miss Disrupts AI Trade

Broadcom’s earnings miss triggered a sell-off in AI stocks, dragging down emerging-market equities. This disruption high...

Revolut Co-Founder, CTO Vlad Yatsenko to Step Down From Role
Bloomberg

Revolut Co-Founder, CTO Vlad Yatsenko to Step Down From Role

Revolut co-founder and CTO Vlad Yatsenko is stepping down from his executive role. The resignation marks a significant l...

Netflix Top Tech Exec Stone on Integrating AI
Bloomberg

Netflix Top Tech Exec Stone on Integrating AI

Netflix’s top tech exec discusses integrating AI to enhance content discovery and production efficiency.

Microsoft’s AI Chief Says Anthropic Models Are Too Expensive
Bloomberg

Microsoft’s AI Chief Says Anthropic Models Are Too Expensive

Microsoft AI CEO Mustafa Suleyman criticized Anthropic’s models as too expensive. Meanwhile, Microsoft plans to allow us...

Ramp Notches $44 Billion Valuation in New Funding Round
Bloomberg

Ramp Notches $44 Billion Valuation in New Funding Round

RAMP secured a $44 billion valuation in its latest funding round. CEO Eric Glyman attended the 2026 Reagan National Econ...