본문 바로가기
  • Home

Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework

  • Journal of Internet of Things and Convergence
  • Abbr : JKIOTS
  • 2026, 12(4), 10
  • Publisher : The Korea Internet of Things Society
  • Research Area : Engineering > Computer Science > Internet Information Processing
  • Received : July 6, 2026
  • Accepted : August 20, 2026
  • Published : August 31, 2026

Lee, Hyung Woo 1

1한신대학교

Accredited

ABSTRACT

In recent Internet of Things (IoT) environments, the increasing interconnection of devices, services, network protocols, and operational entities has significantly increased both the volume and heterogeneity of security log data. In such environments, conventional rule-based anomaly detection and single-event-oriented analysis are limited in their ability to capture the continuity of multi-stage attacks and the behavioral context at the session level. In particular, attacks such as port scanning, account takeover attempts, command-and-control activities, and data exfiltration can be more effectively identified by analyzing adjacent event flows and recurrent behavioral patterns within a session rather than individual log events in isolation. To address this challenge, this paper proposes a Session Context-Aware BERT architecture that combines semantic representation, contextual window analysis, and session-level behavior aggregation within a BERT-based framework. The proposed method analyzes neighboring contexts within ranges of 1, 2, and 3 centered on the current event and automatically determines anomaly status by integrating Session Context-Aware indicators such as average decision margin, anomalous event ratio, destination diversity, and suspicious pattern density. In addition, explicit file-level and line-level labels are constructed to complement the limitations of conventional label estimation methods and to enable a comparative evaluation of detection performance. Experimental results show that the incorporation of contextual information improves network event classification performance and that session-level information contributes effectively to the identification of anomalous network behaviors.

Journal Copyright Policy

No CCL information provided

Citation status

* References for papers published after 2025 are currently being built.