IP Library › Granted Patent US 11,288,161
Granted Patent B2
US 11,288,161 · App. 16/470,281 · Granted Mar 29, 2022

Anomaly detection method, system, and program

Inventor: Ryosuke Togawa (Tokyo, JP)
Assignee: NEC CORPORATION
G06F11/3082G06F11/076G06F11/0772G06F11/3075
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,288,161
App. No.
16/470,281
Filed
Jun 17, 2019
Granted
Mar 29, 2022
Kind
B2
Art Unit
2113
USPC
714/47.1
Abstract

The present invention provides an anomaly detection method, an anomaly detection system, and an anomaly detection program that can detect an anomaly at high accuracy by using log output quantity distributions generated for to different aggregate units and different devices. An anomaly detection system according to one example embodiment of the present invention has: a reference distribution, which is a time-series distribution of a log output quantity acquisition unit that acquires a plurality of distributions generated for each device that outputs logs and for each unit of a time range in which logs are aggregated; and an anomaly detection unit that detects an anomaly by using the plurality of distributions.

Claims (28)

1. An anomaly detection method, the method comprising:

acquiring, from a plurality of devices, a plurality of target logs, each including a plurality of distributions generated for each of the plurality of devices that outputs logs;

grouping the plurality of target logs according to a time range and a format of each of the plurality of target logs;

detecting an anomaly in a group of target logs by using a plurality of reference distributions corresponding to the time range and the format of the group of the target logs; and

displaying the anomaly in the group of target logs on a display;

wherein each of the plurality of reference distributions is a time-series distribution of an output quantity in at least one format generated based on a rule of aggregating logs output in the past according to a predetermined time range.

2. The anomaly detection method according to claim 1 , further comprises generating an analysis target distribution that is a time-series distribution of an output quantity of a target log included in the group of target logs,

wherein the acquiring the plurality of target logs including the plurality of distributions further comprises selecting a reference distribution that is most similar to the analysis target distribution from the plurality of reference distributions, and

wherein the detecting the anomaly further comprises detecting the anomaly in the group of the target logs by comparing the analysis target distribution with the reference distribution.

3. The anomaly detection method according to claim 2 , wherein the acquiring the plurality of target logs including the plurality of distributions further comprises calculating a similarity between the analysis target distribution and each of the plurality of reference distributions and selecting, as the reference distribution, a distribution having the similarity that is greater than or equal to a predetermined threshold.

4. The anomaly detection method according to claim 2 , wherein the detecting the anomaly further comprises calculating an anomaly degree of the analysis target distribution with respect to the reference distribution as a reference and detecting the anomaly when the anomaly degree is out of a predetermined normal range.

5. The anomaly detection method according to claim 1 , wherein the anomaly is detected by extracting at least one distribution among the plurality of distributions deviating from the plurality of reference distributions as an abnormal distribution.

6. The anomaly detection method according to claim 5 , wherein a similarity between the plurality of distributions is calculated, and a distribution deviating from the plurality of distributions is extracted based on the similarity between the plurality of distributions.

7. The anomaly detection method according to claim 5 , wherein the anomaly is detected by extracting, as an abnormal device, a device among the plurality of devices in which a quantity of the abnormal distribution or a ratio of the abnormal distribution is greater than or equal to a predetermined threshold.

8. The anomaly detection method according to claim 1 , wherein the grouping of the plurality of target logs is performed according to a predetermined length of the time range.

9. A non-transitory computer-readable storage medium in which an anomaly detection program is stored, the anomaly detection program causing a computer to:

acquire, from a plurality of devices, a plurality of target logs, each including a plurality of distributions generated for each of the plurality of devices that outputs logs;

grouping the plurality of target logs according to a time range and a format of each of the plurality of target logs;

detect an anomaly in a group of target logs by using a plurality of reference distributions corresponding to the time range and the format of the group of the target logs; and

displaying the anomaly in the group of target logs on a display;

wherein each of the plurality of reference distributions is a time-series distribution of an output quantity in at least one format generated based on a rule of aggregating logs output in the past according to a predetermined time range.

10. An anomaly detection system comprising:

one or more processors configured to:

acquire, from a plurality of devices, a plurality of target logs, each including a plurality of distributions generated for each of the plurality of devices that outputs logs;

grouping the plurality of target logs according to a time range and a format of each of the plurality of target logs;

detect an anomaly in a group of target logs by using a plurality of reference distributions corresponding to the time range and the format of the group of the target logs; and

displaying the anomaly in the group of target logs on a display;

wherein each of the plurality of reference distributions is a time-series distribution of an output quantity in at least one format generated based on a rule of aggregating logs output in the past according to a predetermined time range.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2019
From: TOGAWA, RYOSUKE
To: NEC CORPORATION
Reel/Frame 049481/0559 →
Continuity (1)
Related Publication 20200089590A1 · Mar 19, 2020
Cited By (1)
US 12,748,674