IP Library Granted Patent US 12,542,783
Granted Patent B2
US 12,542,783 · App. 18/551,720 · Granted Feb 3, 2026

Communication system, anomaly detection apparatus, anomaly detection method, and program

Inventors: Masahiro Shiraishi (Tokyo, JP); Hiroki Nagayama (Tokyo, JP); Tomoaki Washio (Tokyo, JP); Asami Miyajima (Tokyo, JP)
Assignee: NTT, Inc.
H04L63/101H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,783
App. No.
18/551,720
Granted
Feb 3, 2026
Kind
B2
Abstract

A communication system that performs communication among a plurality of nodes by a broker-less type publishing/subscribing model, includes: a computer including a memory and a processor configured to, in a case where a network configuration of the communication system changes, detect an anomaly of the communication system based on configuration information indicating the network configuration and at least one of a predefined white list or black list.

Claims (26)

1 . A communication system that performs communication among a plurality of nodes by a broker-less type publishing/subscribing model, the communication system comprising:

a computer including a memory and a processor configured to

in a case where a network configuration of the communication system changes, detect an anomaly of the communication system based on configuration information indicating the network configuration and at least one of a predefined white list or black list,

wherein the configuration information comprises multi-level relationship information between nodes extracted from communication traffic in the broker-less type publishing/subscribing model, and

the communication system further comprises a configuration management unit configured to perform network configuration control in response to detection of the anomaly,

wherein the configuration information is information in which, using first relationship information indicating a relationship among the nodes regarding transmission and reception of the communication, second relationship information indicating a relationship among the nodes regarding a belonging domain and whether the nodes are on a publisher side or on a subscriber side, and third relationship information indicating a relationship among the nodes regarding a topic to be published and subscribed, the first relationship information and the second relationship information are associated with each other by IP addresses and port numbers, and the second relationship information and the third relationship information are associated with each other by identifiers used in the broker-less type publishing/subscribing model.

2 . The communication system according to claim 1 , wherein the white list is information in which a condition for determining a normality is defined for a tree represented by one or more IP addresses held by each of the nodes, one or more port numbers corresponding to the IP addresses, identifiers corresponding to the IP addresses and the port numbers, and topic names corresponding to the identifiers,

the black list is information in which a condition for determining an anomaly is defined for a tree represented by one or more IP addresses held by each of the nodes, one or more port numbers corresponding to the IP addresses, identifiers corresponding to the IP addresses and the port numbers, and topic names corresponding to the identifiers, and

the processor detects an anomaly of the communication system by determining an anomaly of the communication system based on the configuration information and at least one of the white list or the black list.

3 . An anomaly detection apparatus that detects an anomaly of a communication system that performs communication among a plurality of nodes by a broker-less type publishing/subscribing model, the anomaly detection apparatus comprising:

a memory; and

a processor configured to

in a case where a network configuration of the communication system changes, detect an anomaly of the communication system based on configuration information indicating the network configuration and at least one of a predefined white list or black list,

wherein the configuration information comprises multi-level relationship information between nodes extracted from communication traffic in the broker-less type publishing/subscribing model, and

the communication system comprises a configuration management unit configured to perform network configuration control in response to detection of the anomaly,

wherein the configuration information is information in which, using first relationship information indicating a relationship among the nodes regarding transmission and reception of the communication, second relationship information indicating a relationship among the nodes regarding a belonging domain and whether the nodes are on a publisher side or on a subscriber side, and third relationship information indicating a relationship among the nodes regarding a topic to be published and subscribed, the first relationship information and the second relationship information are associated with each other by IP addresses and port numbers, and the second relationship information and the third relationship information are associated with each other by identifiers used in the broker-less type publishing/subscribing model.

4 . The anomaly detection apparatus according to claim 3 , wherein the configuration information is information in which, using first relationship information indicating a relationship among the nodes regarding transmission and reception of the communication, second relationship information indicating a relationship among the nodes regarding a belonging domain and whether the nodes are on a publisher side or on a subscriber side, and third relationship information indicating a relationship among the nodes regarding a topic to be published and subscribed, the first relationship information and the second relationship information are associated with each other by IP addresses and port numbers, and the second relationship information and the third relationship information are associated with each other by identifiers used in the broker-less type publishing/subscribing model.

5 . The anomaly detection apparatus according to claim 4 , wherein the white list is information in which a condition for determining a normality is defined for a tree represented by one or more IP addresses held by each of the nodes, one or more port numbers corresponding to the IP addresses, identifiers corresponding to the IP addresses and the port numbers, and topic names corresponding to the identifiers,

the black list is information in which a condition for determining an anomaly is defined for a tree represented by one or more IP addresses held by each of the nodes, one or more port numbers corresponding to the IP addresses, identifiers corresponding to the IP addresses and the port numbers, and topic names corresponding to the identifiers, and

the processor detects an anomaly of the communication system by determining an anomaly of the communication system based on the configuration information and at least one of the white list or the black list.

6 . An anomaly detection method performed by an anomaly detection apparatus that includes a memory and a processor to detect an anomaly of a communication system that performs communication among a plurality of nodes by a broker-less type publishing/subscribing model, the anomaly detection method comprising:

in a case where a network configuration of the communication system changes, detecting an anomaly of the communication system based on configuration information indicating the network configuration and at least one of a predefined white list or black list,

wherein the configuration information comprises multi-level relationship information between nodes extracted from communication traffic in the broker-less type publishing/subscribing model, and

the anomaly detection method further comprises performing, by the communication system including a configuration management unit, network configuration control in response to detection of the anomaly,

wherein the configuration information is information in which, using first relationship information indicating a relationship among the nodes regarding transmission and reception of the communication, second relationship information indicating a relationship among the nodes regarding a belonging domain and whether the nodes are on a publisher side or on a subscriber side, and third relationship information indicating a relationship among the nodes regarding a topic to be published and subscribed, the first relationship information and the second relationship information are associated with each other by IP addresses and port numbers, and the second relationship information and the third relationship information are associated with each other by identifiers used in the broker-less type publishing/subscribing model.

7 . A non-transitory computer-readable recording medium having computer-readable instructions stored thereon, which, when executed, cause a computer including a memory and processor to function as the anomaly detection apparatus according to claim 3 .

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072473/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: SHIRAISHI, MASAHIRO; NAGAYAMA, HIROKI; WASHIO, TOMOAKI; MIYAJIMA, ASAMI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 064983/0990 →
Continuity (1)
Related Publication 20240056451A1 · Feb 15, 2024
References Cited (12)
US 7882253B2 · Pardo-Castellote · 2011 [cited by examiner]
US 7886180B2 · Jin · 2011 [cited by examiner]
US 11509654B2 · Schmidt · 2022 [cited by examiner]
US 20110295923A1 · de Campos Ruiz · 2011 [cited by examiner]
US 20110307789A1 · Karenos · 2011 [cited by examiner]
US 20140282889A1 · Ishaya · 2014 [cited by examiner]
US 20150039734A1 · King · 2015 [cited by examiner]
US 20150097697A1 · Laval · 2015 [cited by examiner]
US 20160050261A1 · Mcdaid · 2016 [cited by examiner]
US 20190044976A1 · Smith · 2019 [cited by examiner]
US 20210286346A1 · Braun · 2021 [cited by examiner]
DDS Foundation “What's in the DDS Standard?”, Internet [retrieved on Sep. 20, 2023] (the Internet) <URL: https://www.dds-foundation.org/omg-dds-standard/>. [cited by applicant]