From Machine Learning to LogBERT: A Survey of Web Log Anomaly Detection for APT and Botnet Threats

Authors

  • Sajad Bshar Mussin Altmimi Computer Department, College of Education for Pure Sciences, Wasit University, 52001 Al-Kut, Wasit, Iraq, https://orcid.org/0009-0003-9201-7810
  • Esraa Saleh Alomari Computer Department, College of Education for Pure Sciences, Wasit University, 52001 Al-Kut, Wasit, Iraq

DOI:

https://doi.org/10.71229/7tzh0144

Keywords:

Log Anomaly Detection, LogBERT, Web Access Logs, Advanced Persistent Threat (APT), BlackEnergy, Self-Supervised Learning

Abstract

 

Automated log analysis has become a cornerstone of cybersecurity operations, yet research on log-based anomaly detection remains scattered across different modalities, learning paradigms, and threat models. This survey brings together work on log anomaly detection-spanning signature-based and classical unsupervised methods, deep sequential models, and BERT/LogBERT self-supervision-with a particular focus on botnet and advanced persistent threat (APT) identification in web server environments, using Black Energy as a representative APT/botnet case study. Prior work is organised into four categories: supervised, unsupervised, deep learning, and hybrid/BERT-based approaches. We compare the datasets, underlying assumptions, and limitations across these categories, and identify a specific research gap at the intersection of LogBERT-style self-supervision, session-aggregated web access logs, and Black Energy-class behavioral indicators. Three problems in particular stand out: a mismatch between methodology and data modality, a lack of threat-specific evaluation, and the absence of public benchmarks-each of which is substantiated in detail in Section 4.7. This paper's contribution is threefold: a comprehensive literature synthesis covering more than 75 peer-reviewed studies published between 2016 and 2025, organised into the four methodological categories described above; a master synthesis matrix (Table 7, split as Tables 7a–7e) summarizing the qualitative advantages and limitations of each approach; and a formal gap analysis that confines its claims strictly to the reviewed corpus. No empirical results, new detection methods, or experimental validation are presented here. Instead, this work aims to situate future empirical research within the gaps it identifies.

References

[1] Siwach, M., & Mann, S. (2022). Anomaly detection for web log data analysis: A review. Journal of Algebraic Statistics, 13(1), 129–148

[2] Landauer, M., Wurzenberger, M., Skopik, F., Hotwagner, W., & Höld, G. (2023). AMiner: A modular log data analysis pipeline for anomaly-based intrusion detection. Digital Threats: Research and Practice, 4(1), Article 12 https://doi.org/10.1145/3567675

[3] Landauer, M., Onder, S., Skopik, F., & Wurzenberger, M. (2023). Deep learning for anomaly detection in log data: A survey. Machine Learning with Applications, 12, Article 100470 https://doi.org/10.1016/j.mlwa.2023.100470

[4] Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), Article 15 https://doi.org/10.1145/1541880.1541882

[5] He, S., Zhu, J., He, P., & Lyu, M. R. (2016). Experience report: System log analysis for anomaly detection. In Proceedings of the IEEE 27th Int. Symp. Software Reliability Engineering (ISSRE), 2016 (pp. 207–218) https://doi.org/10.1109/ISSRE.2016.21

[6] Biswas, H. (2024). Malware trend in smart grid cyber security. In Proceedings of the IEEE Region 10 Symposium (TENSYMP), 2024 (pp. 1–5) https://doi.org/10.1109/TENSYMP61132.2024.10752141

[7] Khan, R., Maynard, P., McLaughlin, K., Laverty, D., & Sezer, S. (2016). Threat analysis of BlackEnergy malware for synchrophasor based real-time control and monitoring in smart grid. In Proceedings of the 4th Int. Symp. ICS & SCADA Cyber Security Research (ICS-CSR), BCS (pp. 53–63) https://doi.org/10.14236/ewic/ICS2016.7

[8] Koay, A. M. Y., Ko, R. K. L., Hettema, H., & Radke, K. (2022). Machine learning in industrial control system (ICS) security: current landscape, opportunities and challenges. Journal of Intelligent Information Systems, 60, 377–405 https://doi.org/10.1007/s10844-022-00753-1

[9] Dairi, A., Harrou, F., Bouyeddou, B., Senouci, S.-M., & Sun, Y. (2020). Semi-supervised deep learning-driven anomaly detection schemes for cyber-attack detection in smart grids. in Artificial Intelligence Techniques for a Scalable Energy Transition, Springer

[10] Wu, Y., Sun, Y., Huang, C., Jia, P., & Liu, L. (2019). Session-based webshell detection using machine learning in web logs. Security and Communication Networks, vol., Art. no. 3093809, 2019 https://doi.org/10.1155/2019/3093809

[11] Baazeem, R. M. (2023). Cybersecurity: Botnet threat detection across the seven-layer ISO-OSI model using machine learning techniques. Computing and Informatics, 42(5), 1060–1090 https://doi.org/10.31577/cai20235

[12] He, P., Zhu, J., Zheng, Z., & Lyu, M. R. (2017). Drain: An online log parsing approach with fixed depth tree. In Proceedings of the IEEE Int. Conf. Web Services (ICWS), 2017 (pp. 33–40) https://doi.org/10.1109/ICWS.2017.13

[13] J. Zhu et al. (2019). Tools and benchmarks for automated log parsing. In Proceedings of the IEEE/ACM 41st Int. Conf. Software Engineering: Software Engineering in Practice (ICSE-SEIP), 2019 (pp. 121–130) https://doi.org/10.1109/ICSE-SEIP.2019.00021

[14] Nipa, N. A., Bouguila, N., & Patterson, Z. (2025). A comparative study of log-based anomaly detection methods in real-world system logs. In Proceedings of the 10th Int. Conf. Internet of Things, Big Data and Security (IoTBDS) (pp. 141–152) https://doi.org/10.5220/0013367000003944

[15] Lee, Y., Kim, J., & Kang, P. (2023). LAnoBERT: System log anomaly detection based on BERT masked language model. Applied Soft Computing, 146, Article 110689 https://doi.org/10.1016/j.asoc.2023.110689

[16] Guo, H., Yuan, S., & Wu, X. (2021). LogBERT: Log anomaly detection via BERT. In Proceedings of the Int. Joint Conf. Neural Networks (IJCNN), 2021 (pp. 1–8) https://doi.org/10.1109/IJCNN52387.2021.9534113

[17] Nguyen, M. T. A., Tong, V., Souihi, S. B., & Souihi, S. (2023). Deep learning in NLP for anomalous HTTP requests detection. In Proceedings of the 19th Int. Conf. Network and Service Management (CNSM), 2023 (pp. 1–8) https://doi.org/10.23919/CNSM59352.2023.10327888

[18] Chen, S., & Liao, H. (2022). BERT-Log: Anomaly detection for system logs based on pre-trained language model. Applied Artificial Intelligence, 36(1), Article 2145642 https://doi.org/10.1080/08839514.2022.2145642

[19] Almodovar, C., Sabrina, F., Karimi, S., & Azad, S. (2024). LogFiT: Log anomaly detection using fine-tuned language models. IEEE Trans. Netw. Service Manag., 21(2), 1715–1731 https://doi.org/10.1109/TNSM.2024.3358730

[20] Guan, W., Cao, J., Qian, S., Gao, J., & Ouyang, C. (2025). LogLLM: Log-based anomaly detection using large language models. arXiv:2411.08561

[21] Han, X., Yuan, S., & Trabelsi, M. (2023). LogGPT: Log anomaly detection via GPT. arXiv preprint, Utah State University / Nokia Bell Labs

[22] Du, M., Li, F., Zheng, G., & Srikumar, V. (2017). DeepLog: Anomaly detection and diagnosis from system logs through deep learning. In Proceedings of the ACM SIGSAC Conf. Computer and Communications Security (CCS), 2017 (pp. 1285–1298) https://doi.org/10.1145/3133956.3134015

[23] Lin, Y. (2024). Advancing log anomaly detection by deep log modeling. Master's thesis, University of Alberta

[24] ATT&CK, MITRE (n.d.). BlackEnergy. software entry S0089. [Online]. Available: * https://attack.mitre.org/software/S0089/

[25] S. Huang et al. (2064). HitAnomaly: Hierarchical transformers for anomaly detection in system log. IEEE Trans. Netw. Service Manag., 17(4), –2077 https://doi.org/10.1109/TNSM.2020.3034647

[26] Zhu, J., He, S., He, P., Liu, J., & Lyu, M. R. (2023). Loghub: A large collection of system log datasets for AI-driven log analytics. In Proceedings of the IEEE 34th Int. Symp. Software Reliability Engineering (ISSRE), 2023 (pp. 355–366) https://doi.org/10.1109/ISSRE59848.2023.00071

[27] Oliner, A., & Stearley, J. (2007). What supercomputers say: A study of five system logs. In Proceedings of the 37th Annu. IEEE/IFIP Int. Conf. Dependable Systems and Networks (DSN) (pp. 575–584) https://doi.org/10.1109/DSN.2007.103

[28] Long et al. (2024). A deep learning-based approach for anomaly detection in cloud system logs. Journal of Cloud Computing, 13, Article 5 https://doi.org/10.1186/s13677-023-00574-9

[29] Benova, L., & Hudec, L. (2024). Comprehensive analysis and evaluation of anomalous user activity in web server logs. Sensors, 24(3), Article 746 https://doi.org/10.3390/s24030746

[30] Seyyar, Y. E., Yavuz, A. G., & Ünver, H. M. (2022). An attack detection framework based on BERT and deep learning. IEEE Access, 10, 68633–68644 https://doi.org/10.1109/ACCESS.2022.3185748

[31] García-Teodoro, P., Díaz-Verdejo, J., Maciá-Fernández, G., & Vázquez, E. (2009). Anomaly-based network intrusion detection: Techniques, systems and challenges. Computers & Security, 28(1-2), 18–28 https://doi.org/10.1016/j.cose.2008.08.003

[32] Liu, F. T., Ting, K. M., & Zhou, Z.-H. (2008). Isolation forest. In Proceedings of the Eighth IEEE Int. Conf. Data Mining (ICDM), 2008 (pp. 413–422) https://doi.org/10.1109/ICDM.2008.17

[33] Benova, L., & Hudec, L. (2023). Web server load prediction and anomaly detection from hypertext transfer protocol logs. International Journal of Electrical and Computer Engineering (IJECE), 13(5), 5165–5178 https://doi.org/10.11591/ijece.v13i5.pp5165-5178

[34] Le, V.-H., & Zhang, H. (2021). Log-based anomaly detection without log parsing. In Proceedings of the 36th IEEE/ACM Int. Conf. Automated Software Engineering (ASE) (pp. 492–504) https://doi.org/10.1109/ASE51524.2021.9678773

[35] W. Meng et al. (2019). LogAnomaly: Unsupervised detection of sequential and quantitative anomalies in unstructured logs. In Proceedings of the 28th Int. Joint Conf. Artificial Intelligence (IJCAI) (pp. 4739–4745)

[36] Farzad, A., & Gulliver, T. A. (2020). Unsupervised log message anomaly detection. ICT Express, 6(3), 229–237 https://doi.org/10.1016/j.icte.2020.06.003

[37] Zhao, Z., Xu, C., & Li, B. (2021). A LSTM-based anomaly detection model for log analysis. Journal of Intelligent Manufacturing / related Springer venue

[38] V. A. Skazin et al. (2021). Detection of network anomalies in log files using machine learning methods. IOP Conf. Ser.: Mater. Sci. Eng., 1069, Article 012021 https://doi.org/10.1088/1757-899X/1069/1/012021

[39] Huang, S., Liu, Y., Fung, C., Wang, H., Yang, H., & Luan, Z. (2023). Improving log-based anomaly detection by pre-training hierarchical transformers. IEEE Trans. Computers, 72(9), 2656–2667 https://doi.org/10.1109/TC.2023.3257518

[40] Lv, D., Luktarhan, N., & Chen, Y. (2021). ConAnomaly: Content-based anomaly detection for system logs. Sensors, 21(18), Article 6125 https://doi.org/10.3390/s21186125

[41] Xie, Y., Zhang, H., & Babar, M. A. (2022). LogGD: Detecting anomalies from system logs with graph neural networks. In Proceedings of the IEEE Int. Conf. related to software/log analysis, [Sources: LogGD PDF]

[42] Li, Z., Shi, J., & Leeuwen, M. van (2023). Graph neural networks-based log anomaly detection and explanation. arXiv preprint, Leiden University (Logs2Graphs)

[43] C. Duan et al. (2025). LogAction: Consistent cross-system anomaly detection through logs via active domain adaptation. In Proceedings of the 40th IEEE/ACM Int. Conf. Automated Software Engineering (ASE) (pp. 700–712) https://doi.org/10.1109/ASE63991.2025.00064

[44] A. Vaswani et al. (2017). Attention is all you need. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS) (pp. 5998–6008)

[45] Devlin, J., Chang, M.-W., Lee, K., & Toutanova, K. (2019). BERT: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the NAACL-HLT (pp. 4171–4186) https://doi.org/10.18653/v1/N19-1423

[46] Liu, S., Deng, L., Xu, H., & Wang, W. (2023). LogBD: A log anomaly detection method based on pretrained models and domain adaptation. Applied Sciences, 13(13), Article 7739 https://doi.org/10.3390/app13137739

[47] L. D. Manocchio et al. (2024). FlowTransformer: A transformer framework for flow-based network intrusion detection systems. Expert Systems with Applications, 241, Article 122564 https://doi.org/10.1016/j.eswa.2023.122564

[48] Wang, S., Jiang, R., Wang, Z., & Zhou, Y. (2024). Deep learning-based anomaly detection and log analysis for computer networks. Journal of Information and Computing, 2(2), 34–63 https://doi.org/10.30211/JIC.202402.005

[49] Wu, Z., Zhang, H., Wang, P., & Sun, Z. (2022). RTIDS: A robust transformer-based approach for intrusion detection system. IEEE Access, 10, 64395–64415 https://doi.org/10.1109/ACCESS.2022.3182333

[50] Karlsen, E., Luo, X., Zincir-Heywood, N., & Heywood, M. (2024). Benchmarking large language models for log analysis, security, and interpretation. Journal of Network and Systems Management

[51] Le, V.-H., & Zhang, H. (2022). Log-based anomaly detection with deep learning: How far are we? In Proceedings of the 44th Int. Conf. Software Engineering (ICSE) (pp. 1356–1367) https://doi.org/10.1145/3510003.3510155

[52] Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In Proceedings of the IEEE Symp. Security and Privacy, 2010 (pp. 305–316) https://doi.org/10.1109/SP.2010.25

[53] Velasco-Mata, J., González-Castro, V., Fidalgo, E., & Alegre, E. (2023). Real-time botnet detection on large network bandwidths using machine learning. Scientific Reports, 13, Article 4282 https://doi.org/10.1038/s41598-023-31260-0

[54] Xin, Q. (2026). Self-supervised log anomaly detection with LogBERT-style transformers: Full empirical evaluation on a reproducible SynHDFS benchmark. JEECS (Journal of Electrical Engineering and Computer Sciences), 11(1), 23–35

[55] Hu, C., Sun, X., Dai, H., Zhang, H., & Liu, H. (2023). Research on log anomaly detection based on Sentence-BERT. Electronics, 12(17), Article 3580 https://doi.org/10.3390/electronics12173580

[56] Seyyar, Y. E., Yavuz, A. G., & Ünver, H. M. (2022). Detection of web attacks using the BERT model. In Proceedings of the 30th Signal Processing and Communications Applications Conf. (SIU), 2022 (pp. 1–4) https://doi.org/10.1109/SIU55565.2022.9864721

[57] Zhong, M., Zhou, Y., & Chen, G. (2021). A security log analysis scheme using deep learning algorithm for IDSs in social network. Security and Communication Networks, vol., Art. no. 5546331, 2021 https://doi.org/10.1155/2021/5546331

[58] Balasubramanian, P., Seby, J., & Kostakos, P. (2024). Transformer-based LLMs in cybersecurity: An in-depth study on log anomaly detection and conversational defense mechanisms. University of Oulu

[59] Ma, Z., Chen, A. R., Kim, D., & et al. (2024). LLMParser: An exploratory study on using large language models for log parsing. Concordia University / University of Alberta

[60] Sallah, A., Alaoui, E. A. Abdellaoui, Agoujil, S., & et al. (2024). Fine-tuned understanding: Enhancing social bot detection with transformer-based classification. IEEE Access, 12, 113456–113470 https://doi.org/10.1109/ACCESS.2024.3440657

[61] Liang, F., & Liu, J. (2024). EDSLog: Efficient log anomaly detection method based on dataset partitioning. In Proceedings of the related Springer LNCS conference, Inner Mongolia University

[62] Malik, A. S., Shahzad, M. K., & Hussain, M. (2023). A forensic framework for webmail threat detection using log analysis. In Proceedings of the related Springer conference, NUST, Pakistan

[63] Liu, T.-J., Lin, T.-S., & Chen, C.-W. (2023). An ensemble machine learning botnet detection framework based on noise filtering. Feng Chia University, Taiwan

[64] Guastalla, M., Li, Y., Hekmati, A., & Krishnamachari, B. (2024). Application of large language models to DDoS attack detection. In Proceedings of the related Springer conference, University of Southern California

[65] Saad, A. M. S. E. (2023). Leveraging graph neural networks for botnet detection. Texas A&M University-Corpus Christi

[66] Luftensteiner, S., & Praher, P. (2023). Log file anomaly detection based on process mining graphs. In Proceedings of the related Springer conference, Software Competence Center Hagenberg

[67] Zhang, B., Zhang, H., Le, V.-H., Moscato, P., & Zhang, A. (2023). Semi-supervised and unsupervised anomaly detection by mining numerical workflow relations from system logs. Automated Software Engineering, 30, Article 4 https://doi.org/10.1007/s10515-022-00370-w

[68] Shih, W. -C., Yang, C.-T., Jiang, C.-T., & Kristiani, E. (2023). Implementation and visualization of a netflow log data lake system for cyberattack detection using distributed deep learning. The Journal of Supercomputing, 79, 4983–5012 https://doi.org/10.1007/s11227-022-04802-y

[69] Arshad, S., Abbaspour, M., Kharrazi, M., & Sanatkar, H. (2011). An anomaly-based botnet detection approach for identifying stealthy botnets. In Proceedings of the related IEEE conference

[70] Y. Duan et al. (2024). LogEDL: Log anomaly detection via evidential deep learning. Applied Sciences, 14(16), Article 7055 https://doi.org/10.3390/app14167055

[71] Yang, Z., & Harris, I. G. (2024). LogLLaMA: Transformer-based log anomaly detection with LLaMA. University of California, Irvine

[72] Zhou, Y., Chen, Y., Rao, X., Zhou, Y., Li, Y., & Hu, C. (2024). Leveraging large language models and BERT for log parsing and anomaly detection. Mathematics, 12(17), Article 2758 https://doi.org/10.3390/math12172758

[73] Li, M., Sun, M., Li, G., Han, D., & Zhou, M. (2023). MDFULog: Multi-feature deep fusion of unstable log anomaly detection model. Applied Sciences, 13(4), Article 2237 https://doi.org/10.3390/app13042237

[74] Ocansey, I. T., Bhattacharya, R., & Sen, T. (2024). LogTinyLLM: Tiny large language models based contextual log anomaly detection. University of Texas at El Paso / ISI Kolkata

[75] Balasubramanian, P., Kankanamge, D., Gilman, E., & Oussalah, M. (2024). AnomalyExplainerBot: Explainable AI for LLM-based anomaly detection using BERTViz & Captum. University of Oulu

fig 2

Downloads

Published

2026-09-08

Issue

Section

Original Articles

How to Cite

From Machine Learning to LogBERT: A Survey of Web Log Anomaly Detection for APT and Botnet Threats. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(4), 196-216. https://doi.org/10.71229/7tzh0144

Similar Articles

41-50 of 58

You may also start an advanced similarity search for this article.