@article{ART003374524},
author={Lee, Hyung Woo},
title={Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework},
journal={Journal of Internet of Things and Convergence},
issn={2466-0078},
year={2026},
volume={12},
number={4},
pages={10}
TY - JOUR
AU - Lee, Hyung Woo
TI - Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework
JO - Journal of Internet of Things and Convergence
PY - 2026
VL - 12
IS - 4
PB - The Korea Internet of Things Society
SP - 10
EP -
SN - 2466-0078
AB - In recent Internet of Things (IoT) environments, the increasing interconnection of devices, services, network protocols, and operational entities has significantly increased both the volume and heterogeneity of security log data. In such environments, conventional rule-based anomaly detection and single-event-oriented analysis are limited in their ability to capture the continuity of multi-stage attacks and the behavioral context at the session level. In particular, attacks such as port scanning, account takeover attempts, command-and-control activities, and data exfiltration can be more effectively identified by analyzing adjacent event flows and recurrent behavioral patterns within a session rather than individual log events in isolation. To address this challenge, this paper proposes a Session Context-Aware BERT architecture that combines semantic representation, contextual window analysis, and session-level behavior aggregation within a BERT-based framework. The proposed method analyzes neighboring contexts within ranges of 1, 2, and 3 centered on the current event and automatically determines anomaly status by integrating Session Context-Aware indicators such as average decision margin, anomalous event ratio, destination diversity, and suspicious pattern density. In addition, explicit file-level and line-level labels are constructed to complement the limitations of conventional label estimation methods and to enable a comparative evaluation of detection performance. Experimental results show that the incorporation of contextual information improves network event classification performance and that session-level information contributes effectively to the identification of anomalous network behaviors.
KW - Session Context Awareness;Anomaly Detection;Network Security Log Analysis;Internet of Things Security;Multi-stage Attack Detection;BERT
DO -
UR -
ER -
Lee, Hyung Woo. (2026). Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework. Journal of Internet of Things and Convergence, 12(4), 10.
Lee, Hyung Woo. 2026, "Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework", Journal of Internet of Things and Convergence, vol.12, no.4 10.
Lee, Hyung Woo "Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework" Journal of Internet of Things and Convergence 12.4 10 (2026) : 10.
Lee, Hyung Woo. Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework. 2026; 12(4), 10.
Lee, Hyung Woo. "Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework" Journal of Internet of Things and Convergence 12, no.4 (2026) : 10.
Lee, Hyung Woo. Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework. Journal of Internet of Things and Convergence, 12(4), 10.
Lee, Hyung Woo. Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework. Journal of Internet of Things and Convergence. 2026; 12(4) 10.
Lee, Hyung Woo. Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework. 2026; 12(4), 10.
Lee, Hyung Woo. "Security Log Anomaly Detection Mechanism using Session Context-Aware BERT Framework" Journal of Internet of Things and Convergence 12, no.4 (2026) : 10.