Skip to main content

2022 | OriginalPaper | Buchkapitel

The Analysis of Online Event Streams: Predicting the Next Activity for Anomaly Detection

verfasst von : Suhwan Lee, Xixi Lu, Hajo A. Reijers

Erschienen in: Research Challenges in Information Science

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Anomaly detection in process mining focuses on identifying anomalous cases or events in process executions. The resulting diagnostics are used to provide measures to prevent fraudulent behavior, as well as to derive recommendations for improving process compliance and security. Most existing techniques focus on detecting anomalous cases in an offline setting. However, to identify potential anomalies in a timely manner and take immediate countermeasures, it is necessary to detect event-level anomalies online, in real-time. In this paper, we propose to tackle the online event anomaly detection problem using next-activity prediction methods. More specifically, we investigate the use of both ML models (such as RF and XGBoost) and deep models (such as LSTM) to predict the probabilities of next-activities and consider the events predicted unlikely as anomalies. We compare these predictive anomaly detection methods to four classical unsupervised anomaly detection approaches (such as Isolation forest and LOF) in the online setting. Our evaluation shows that the proposed method using ML models tends to outperform the one using a deep model, while both methods outperform the classical unsupervised approaches in detecting anomalous events.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
3.
Zurück zum Zitat Burattin, A., Sperduti, A., van der Aalst, W.M.P.: Heuristics miners for streaming event data. arXiv preprint arXiv:1212.6383 (2012) Burattin, A., Sperduti, A., van der Aalst, W.M.P.: Heuristics miners for streaming event data. arXiv preprint arXiv:​1212.​6383 (2012)
6.
Zurück zum Zitat Guo, H., Meamari, E., Shen, C.C.: Blockchain-inspired event recording system for autonomous vehicles. In: 2018 1st IEEE international conference on hot information-centric networking (HotICN), pp. 218–222. IEEE (2018) Guo, H., Meamari, E., Shen, C.C.: Blockchain-inspired event recording system for autonomous vehicles. In: 2018 1st IEEE international conference on hot information-centric networking (HotICN), pp. 218–222. IEEE (2018)
7.
Zurück zum Zitat Hulten, G., Spencer, L., Domingos, P.: Mining time-changing data streams. In: Proceedings of the seventh ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 97–106 (2001) Hulten, G., Spencer, L., Domingos, P.: Mining time-changing data streams. In: Proceedings of the seventh ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 97–106 (2001)
8.
Zurück zum Zitat Khatuya, S., Ganguly, N., Basak, J., Bharde, M., Mitra, B.: Adele: anomaly detection from event log empiricism. In: IEEE INFOCOM 2018-IEEE Conference on Computer Communications, pp. 2114–2122. IEEE (2018) Khatuya, S., Ganguly, N., Basak, J., Bharde, M., Mitra, B.: Adele: anomaly detection from event log empiricism. In: IEEE INFOCOM 2018-IEEE Conference on Computer Communications, pp. 2114–2122. IEEE (2018)
10.
Zurück zum Zitat Kolozali, S., Bermudez-Edo, M., Puschmann, D., Ganz, F., Barnaghi, P.: A knowledge-based approach for real-time IoT data stream annotation and processing. In: 2014 IEEE International Conference on Internet of Things (iThings), and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom), pp. 215–222. IEEE (2014) Kolozali, S., Bermudez-Edo, M., Puschmann, D., Ganz, F., Barnaghi, P.: A knowledge-based approach for real-time IoT data stream annotation and processing. In: 2014 IEEE International Conference on Internet of Things (iThings), and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom), pp. 215–222. IEEE (2014)
11.
Zurück zum Zitat Leontjeva, A., Conforti, R., Di Francescomarino, C., Dumas, M., Maggi, F.M.: Complex symbolic sequence encodings for predictive monitoring of business processes. In: Motahari-Nezhad, H.R., Recker, J., Weidlich, M. (eds.) BPM 2015. LNCS, vol. 9253, pp. 297–313. Springer, Cham (2015). https://doi.org/10.1007/978-3-319-23063-4_21CrossRef Leontjeva, A., Conforti, R., Di Francescomarino, C., Dumas, M., Maggi, F.M.: Complex symbolic sequence encodings for predictive monitoring of business processes. In: Motahari-Nezhad, H.R., Recker, J., Weidlich, M. (eds.) BPM 2015. LNCS, vol. 9253, pp. 297–313. Springer, Cham (2015). https://​doi.​org/​10.​1007/​978-3-319-23063-4_​21CrossRef
13.
Zurück zum Zitat Maisenbacher, M., Weidlich, M.: Handling concept drift in predictive process monitoring. SCC 17, 1–8 (2017) Maisenbacher, M., Weidlich, M.: Handling concept drift in predictive process monitoring. SCC 17, 1–8 (2017)
14.
Zurück zum Zitat Nguyen, H.T.C., Lee, S., Kim, J., Ko, J., Comuzzi, M.: Autoencoders for improving quality of process event logs. Expert Syst. Applicat. 131, 132–147 (2019)CrossRef Nguyen, H.T.C., Lee, S., Kim, J., Ko, J., Comuzzi, M.: Autoencoders for improving quality of process event logs. Expert Syst. Applicat. 131, 132–147 (2019)CrossRef
15.
Zurück zum Zitat Nolle, T., Luettgen, S., Seeliger, A., Mühlhäuser, M.: Binet: multi-perspective business process anomaly classification. Inf. Syst. 103 (2022). Article no. 101458 Nolle, T., Luettgen, S., Seeliger, A., Mühlhäuser, M.: Binet: multi-perspective business process anomaly classification. Inf. Syst. 103 (2022). Article no. 101458
16.
Zurück zum Zitat Paszke, A., et al.: Pytorch: an imperative style, high-performance deep learning library. In: Advances in Neural Information Processing Systems, vol. 32, pp. 8026–8037 (2019) Paszke, A., et al.: Pytorch: an imperative style, high-performance deep learning library. In: Advances in Neural Information Processing Systems, vol. 32, pp. 8026–8037 (2019)
17.
Zurück zum Zitat Pedregosa, F., et al.: Scikit-learn: machine learning in python. J. Mach. Learn. Res. 12, 2825–2830 (2011) Pedregosa, F., et al.: Scikit-learn: machine learning in python. J. Mach. Learn. Res. 12, 2825–2830 (2011)
18.
Zurück zum Zitat Sani, M.F., van Zelst, S.J., van der Aalst, W.M.P.: Improving process discovery results by filtering outliers using conditional behavioural probabilities. In: Teniente, E., Weidlich, M. (eds.) BPM 2017. LNBIP, vol. 308, pp. 216–229. Springer, Cham (2018). https://doi.org/10.1007/978-3-319-74030-0_16 Sani, M.F., van Zelst, S.J., van der Aalst, W.M.P.: Improving process discovery results by filtering outliers using conditional behavioural probabilities. In: Teniente, E., Weidlich, M. (eds.) BPM 2017. LNBIP, vol. 308, pp. 216–229. Springer, Cham (2018). https://​doi.​org/​10.​1007/​978-3-319-74030-0_​16
19.
Zurück zum Zitat Savickas, T., Vasilecas, O.: Belief network discovery from event logs for business process analysis. Comput. Ind. 100, 258–266 (2018). Article no. 101458 Savickas, T., Vasilecas, O.: Belief network discovery from event logs for business process analysis. Comput. Ind. 100, 258–266 (2018). Article no. 101458
20.
Zurück zum Zitat Tavares, G.M., Ceravolo, P., Da Costa, V.G.T., Damiani, E., Junior, S.B.: Overlapping analytic stages in online process mining. In: 2019 IEEE International Conference on Services Computing (SCC), pp. 167–175. IEEE (2019) Tavares, G.M., Ceravolo, P., Da Costa, V.G.T., Damiani, E., Junior, S.B.: Overlapping analytic stages in online process mining. In: 2019 IEEE International Conference on Services Computing (SCC), pp. 167–175. IEEE (2019)
21.
Zurück zum Zitat Teinemaa, I., Dumas, M., Rosa, M.L., Maggi, F.M.: Outcome-oriented predictive process monitoring: review and benchmark. ACM Trans. Knowl. Discov. Data (TKDD) 13(2), 1–57 (2019). 101458 Teinemaa, I., Dumas, M., Rosa, M.L., Maggi, F.M.: Outcome-oriented predictive process monitoring: review and benchmark. ACM Trans. Knowl. Discov. Data (TKDD) 13(2), 1–57 (2019). 101458
22.
Zurück zum Zitat Vertuam Neto, R., Tavares, G., Ceravolo, P., Barbon, S.: On the use of online clustering for anomaly detection in trace streams. In: XVII Brazilian Symposium on Information Systems, pp. 1–8 (2021) Vertuam Neto, R., Tavares, G., Ceravolo, P., Barbon, S.: On the use of online clustering for anomaly detection in trace streams. In: XVII Brazilian Symposium on Information Systems, pp. 1–8 (2021)
23.
Zurück zum Zitat van Zelst, S.J., Fani Sani, M., Ostovar, A., Conforti, R., La Rosa, M.: Filtering spurious events from event streams of business processes. In: Krogstie, J., Reijers, H.A. (eds.) CAiSE 2018. LNCS, vol. 10816, pp. 35–52. Springer, Cham (2018). https://doi.org/10.1007/978-3-319-91563-0_3 van Zelst, S.J., Fani Sani, M., Ostovar, A., Conforti, R., La Rosa, M.: Filtering spurious events from event streams of business processes. In: Krogstie, J., Reijers, H.A. (eds.) CAiSE 2018. LNCS, vol. 10816, pp. 35–52. Springer, Cham (2018). https://​doi.​org/​10.​1007/​978-3-319-91563-0_​3
Metadaten
Titel
The Analysis of Online Event Streams: Predicting the Next Activity for Anomaly Detection
verfasst von
Suhwan Lee
Xixi Lu
Hajo A. Reijers
Copyright-Jahr
2022
DOI
https://doi.org/10.1007/978-3-031-05760-1_15