IP Library Granted Patent US 12,406,208
Granted Patent B2
US 12,406,208 · App. 16/481,672 · Granted Sep 2, 2025

Anomaly detection method using an autoencoder learning from data items collected by measuring devices

Inventors: Yasuhiro Ikeda (Musashino, JP); Yusuke Nakano (Musashino, JP); Keishiro Watanabe (Musashino, JP); Keisuke Ishibashi (Musashino, JP); Ryoichi Kawahara (Musashino, JP)
Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
G06N20/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,208
App. No.
16/481,672
Granted
Sep 2, 2025
Kind
B2
Abstract

A feature value generation device includes a generator configured to generate vectors whose elements are feature values of data items collected at a plurality of timings from a target of anomaly detection, so as to normalize or standardize the vectors based on a set of predetermined vectors; a learning unit configured to learn the predetermined vectors so as to output a learning result; and a detector configured to detect, for each of the vectors normalized or standardized by the generator, an anomaly based on said each of the vectors and the learning result. The set of predetermined vectors is a set of vectors with which no anomaly is detected by the detector, and the set of vectors is updated in accordance with no anomaly being detected by the detector.

Claims (14)

1. A feature value generation device comprising:

processing circuitry configured to

generate vectors whose elements are feature values of data items collected at each of a plurality of timings, which are each upon an elapse of a predetermined time interval that is not greater than three minutes, from a target of anomaly detection, so as to perform normalization on the vectors, after a predetermined amount of vectors are stored, based on a set of predetermined vectors, the target being a system including a plurality of measuring devices that sample the data items within the system, the feature value generation device being connected to each of the plurality of measuring devices and the processing circuitry is configured to collect the data items from the measuring devices, wherein within the predetermined time interval the feature values are collected at sub-intervals such that a plurality of data items for a particular type of data item are collected at each of the plurality of timings and the normalization of the vectors includes at each of the plurality of timings, dividing each of the collected data items for a particular type of data item by a maximum value of the particular type of data item that is collected occurs during the respective timing;

generate an autoencoder that learns the predetermined vectors so as to output a learning result by duplicating a respective vector into two, applying one of the two vectors to the input layer to the autoencoder, and applying the other of the two vectors to the output layer, to execute learning so as to output the learning result; and

for each of the plurality of timings, detect, for each of the vectors normalized, an anomaly based on said each of the vectors and the learning result,

wherein the set of predetermined vectors is a set of vectors, stored as learning data in a learning data storage, with which no anomaly is detected by the processing circuitry, and for each of the plurality of timings, the entire set of vectors stored in the learning data storage based on the most recent collected vectors when no anomaly is detected by the processing circuitry and the entire set of vectors is not stored in the learning data storage based on the most recent collected vectors when an anomaly is detected by the processing circuitry based on a most recent learning result output by the autoencoder.

2. The feature value generation device as claimed in claim 1 , wherein the system is a network that is constituted with multiple nodes being connected with each other, in which packets are transmitted and received between the nodes to provide predetermined services.

3. The feature value generation device as claimed in claim 2 , wherein the data items to be collected include MIB (Management Information Base) data, flow data by NetFlow, and CPU utilization.

4. A feature value generation method executed by a feature value generation device, the method comprising:

generating vectors whose elements are feature values of data items collected at each of a plurality of timings, which are each upon an elapse of a predetermined time interval that is not greater than three minutes, from a target of anomaly detection, so as to perform normalization on the vectors, after a predetermined amount of vectors are stored, based on a set of predetermined vectors, the target being a system including a plurality of measuring devices that sample the data items within the system, the feature value generation device being connected to each of the plurality of measuring devices and method includes collecting the data items from the measuring devices, wherein within the predetermined time interval the feature values are collected at sub-intervals such that a plurality of data items for a particular type of data item are collected at each of the plurality of timings and the normalization of the vectors includes at each of the plurality of timings, dividing each of the collected data items for a particular type of data item by a maximum value of the particular type of data item that is collected occurs during the respective timing;

generating an autoencoder that learns the predetermined vectors so as to output a learning result by duplicating a respective vector into two, applying one of the two vectors to the input layer to the autoencoder, and applying the other of the two vectors to the output layer, to execute learning so as to output the learning result; and

for each of the plurality of timings, detecting, for each of the vectors normalized, an anomaly based on said each of the vectors and the learning result,

wherein the set of predetermined vectors is a set of vectors, stored as learning data in a learning data storage, with which no anomaly is detected, and for each of the plurality of timings, the entire set of vectors stored in the learning data storage based on the most recent collected vectors when no anomaly is detected and the entire set of vectors is not stored in the learning data storage based on the most recent collected vectors when an anomaly is detected based on a most recent learning result output by the autoencoder.

5. A non-transitory computer-readable recording medium having a program stored thereon for causing a computer to execute the feature value generation method as claimed in claim 4 .

Assignments (2)
CHANGE OF NAME Recorded Aug 11, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072416/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2019
From: IKEDA, YASUHIRO; NAKANO, YUSUKE; WATANABE, KEISHIRO; ISHIBASHI, KEISUKE; KAWAHARA, RYOICHI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 049888/0738 →
Priority Claims (1)
JP 2017-017920 · Feb 2, 2017 · national
Continuity (1)
Related Publication 20190392350A1 · Dec 26, 2019
References Cited (19)
US 8682824B2 · Shibuya · 2014 [cited by examiner]
US 20130024415A1 · Herzog · 2013 [cited by applicant]
US 20170026250A1 · Hu · 2017 [cited by examiner]
US 20190297520A1 · Vedam · 2019 [cited by examiner]
JP 2007329329A · 2007 [cited by applicant]
JP 2014525096A · 2014 [cited by applicant]
Sakurada, Mayu, and Takehisa Yairi. “Anomaly detection using autoencoders with nonlinear dimensionality reduction.” Proceedings of the MLSDA 2014 2nd workshop on machine learning for sensory data analysis. 2014. https:/… [cited by examiner]
Limthong, Kriangkrai. “Real-time computer network anomaly detection using machine learning techniques.” Journal of Advances in Computer Networks 1.1 (2013): 126-133. (Year: 2013). https://www.researchgate.net/profile/Kr… [cited by examiner]
Zolotukhin, Mikhail, et al. “Analysis of HTTP requests for anomaly detection of web attacks.” 2014 IEEE 12th International Conference on Dependable, Autonomic and Secure Computing. IEEE, 2014. https://ieeexplore.ieee.or… [cited by examiner]
Duong, Nguyen Ha, and Hoang Dang Hai. “A semi-supervised model for network traffic anomaly detection.” 2015 17th International Conference on Advanced Communication Technology (ICACT). IEEE, 2015. https://ieeexplore.ieee… [cited by examiner]
Breitbart, Yuri, et al. “Efficiently monitoring bandwidth and latency in IP networks.” Proceedings IEEE Infocom 2001. Conference on Computer Communications. Twentieth Annual Joint Conference of the IEEE Computer and Com… [cited by examiner]
D. Liu, C. - H. Lung, N. Seddigh and B. Nandy, “Network Traffic Anomaly Detection Using Adaptive Density-Based Fuzzy Clustering, ” 2014 IEEE 13th International Conference on Trust, Security and Privacy in Computing and … [cited by examiner]
[Item U continued] https://ieeexplore.IEEE.org/document/7011333 (Year: 2014). [cited by examiner]
Salem, Maher, and Ulrich Buehler. “Mining techniques in network security to enhance intrusion detection systems.” arXiv preprint arXiv:1212.2414 (2012). https://arxiv.org/ftp/arxiv/papers/1212/1212.2414.pdf (Year: 2012). [cited by examiner]
Wazid, Mohammad, and Ashok Kumar Das. “An efficient hybrid anomaly detection scheme using K-means clustering for wireless sensor networks.” Wireless Personal Communications 90 (2016): 1971-2000. https://link.springer.co… [cited by examiner]
International Search Report issued on Dec. 19, 2017 in PCT/JP2017/040104 filed in Nov. 7, 2017. [cited by applicant]
Sakurada, M. et al., “Dimensionality Reduction with the Autoencoder for Anomaly Detection of Spacecrafts”, The 28 [cited by applicant]
Banerjee, A. et al., “A Support Vector Method for Anomaly Detection in Hyperspectral Imagery”, IEEE Transactions on Geoscience and Remote Sensing, vol. 44, No. 8, Aug. 2006, pp. 2282-2291. [cited by applicant]
Muteki, K., “Process Monitoring Development Utilizing Plant Data-Multivariate Analysis Applications (Consideration on operating support utilizing plant data)—(Concept of user-oriented operating support and utilization o… [cited by applicant]