IP Library › Granted Patent US 12,524,292
Granted Patent B2
US 12,524,292 · App. 18/566,582 · Granted Jan 13, 2026

Analysis device, analysis method, and analysis program

Inventors: Masanori Shinohara (Tokyo, JP); Takaaki Koyama (Tokyo, JP); Yukio Nagafuchi (Tokyo, JP); Makiko Aoyagi (Tokyo, JP); Yasuhiro Teramoto (Tokyo, JP)
Assignee: NTT, Inc.
G06F11/0787G06F11/0709
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,292
App. No.
18/566,582
Granted
Jan 13, 2026
Kind
B2
Abstract

An analysis server accumulates an alert of communication determined not to be normal communication on the basis of a model indicating a feature of normal communication in a storage unit. Then, the analysis server performs clustering of alerts obtained by excluding an alert having a different category variable from communication data used for learning of the model from the accumulated alerts by using a feature amount of communication included in the alert. Thereafter, the analysis server determines, for each cluster generated by clustering, whether or not the cluster includes the same type of alert. Then, the analysis server outputs a result of clustering and a determination result as to whether or not each cluster includes the same type of alert.

Claims (29)

1 . An analysis device comprising:

a memory; and

a processor coupled to the memory and programmed to execute a process comprising:

accumulating alerts of communication determined not to be normal communication on a basis of a model as trained predicts a feature of normal communication;

performing clustering of the accumulated alerts according to respective feature amounts of communications as described in respective accumulated alerts of the accumulated alerts, wherein a feature amount of communication of an alert comprises an address of a device as a part of the communication, a duration of a session of the communication, and a volume of transmitted data in the communication;

determining, for each cluster of clusters generated by the clustering, whether or not said each cluster comprises a plurality of alerts indicating a same type of alert, wherein the same type of alert represents over detection of an alert based on normalcy of operating the device associated with the plurality of alerts; and

outputting a result of the clustering and a determination result as to whether or not said each cluster of the clusters comprises the plurality of alerts indicating the same type of alert.

2 . The analysis device according to claim 1 , wherein

the process further comprises, excluding, based on a comparison between a learning feature amount of communication used for learning of the model and the feature amount of communication of the alert, the alert from the clustering operation, wherein the feature amount of communication further comprises an IP address of a terminal device of the communication, a transmission source IP address of a session, a transmission destination IP address of the session, a transmission destination port number of the session, and a protocol number.

3 . The analysis device according to claim 1 , wherein

the performing clustering of the accumulated alerts performs clustering by using at least one of a forward-direction total byte quantity, a forward-direction total packet quantity, a reverse-direction total byte quantity, and a reverse-direction total packet quantity among feature amounts of communication included in the alert.

4 . The analysis device according to claim 1 , wherein

the performing clustering of the accumulated alerts performs clustering by calculating, for each terminal device, a difference between a value of a feature amount of communication used for learning of the model and a value of a feature amount of the communication included in the alert, and using a value obtained by converting the value of the difference of the feature amount into a logarithmic scale.

5 . The analysis device according to claim 1 , wherein

the determining determines that, for each of the generated clusters, a cluster in which a ratio of a number of alerts constituting the cluster to a number of all alerts is equal to or greater than a predetermined threshold value is a cluster including an alert of a same type of alert.

6 . The analysis device according to claim 1 , wherein

the process further comprises calculating, for each of the generated clusters, how many terminal devices that are targets of an alert are included in the cluster, and the determining determines that a cluster in which the calculated number is equal to or less than a predetermined threshold value is a cluster including an alert of a same type of alert.

7 . The analysis device according to claim 1 , wherein

the process further comprises creating a scatter diagram of the generated clusters, calculates a density of the clusters using an area of clusters on the scatter diagram and a number of alerts included in the clusters, and the determining determines that a cluster whose calculated density is equal to or greater than a predetermined threshold value is a cluster including a same type of alert.

8 . An analysis method executed by an analysis device, the analysis method comprising:

accumulating alerts of communication determined not to be normal communication on a basis of a model as trained predicts a feature of normal communication;

performing clustering of the accumulated alerts according to respective feature amounts of communications as described in respective accumulated alerts of the accumulated alerts, wherein a feature amount of communication of an alert comprises an address of a device as a part of the communication, a duration of a session of the communication, and a volume of transmitted data in the communication;

determining, for each cluster of clusters generated by the clustering, whether or not said each cluster comprises a plurality of alerts indicating a same type of alert, wherein the same type of alert represents over detection of an alert based on normalcy of operating the device associated with the plurality of alerts; and

outputting a result of the clustering and a determination result as to whether or not said each cluster of the clusters comprises the plurality of alerts indicating the same type of alert.

9 . A non-transitory computer readable storage medium having stored therein an analysis program causing a computer to execute a process comprising the steps of:

accumulating alerts of communication determined not to be normal communication on a basis of a model as trained predicts a feature of normal communication;

performing clustering of accumulated alerts according to respective feature amounts of communications as described in respective accumulated alerts of the accumulated alerts, wherein a feature amount of communication of an alert comprises an address of a device as a part of the communication, a duration of a session of the communication, and a volume of transmitted data in the communication;

determining, for each cluster of clusters generated by the clustering, whether or not said each cluster comprises a plurality of alerts indicating a same type of alert, wherein the same type of alert represents over detection of an alert based on normalcy of operating the device associated with the plurality of alerts; and

outputting a result of the clustering and a determination result as to whether or not said each cluster of the clusters comprises the plurality of alerts indicating the same type of alert.

Assignments (2)
CHANGE OF NAME Recorded Oct 3, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 073007/0308 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2023
From: SHINOHARA, MASANORI; KOYAMA, TAKAAKI; NAGAFUCHI, YUKIO; AOYAGI, MAKIKO; TERAMOTO, YASUHIRO
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 065739/0667 →
Continuity (1)
Related Publication 20240256376A1 · Aug 1, 2024
References Cited (14)
US 11539595B1 · Hatton · 2022 [cited by examiner]
US 20130179220A1 · Notani · 2013 [cited by examiner]
US 20150117174A1 · Alber · 2015 [cited by examiner]
US 20150318021A1 · Nishimura · 2015 [cited by examiner]
US 20160364467A1 · Gupta · 2016 [cited by examiner]
US 20190260793A1 · Stockdale · 2019 [cited by examiner]
US 20210160270A1 · Minami et al. · 2021 [cited by applicant]
US 20210326744A1 · Israel · 2021 [cited by examiner]
US 20220141185A1 · Tyou et al. · 2022 [cited by applicant]
JP 2020005184A · 2020 [cited by applicant]
JP 2020135655A · 2020 [cited by applicant]
NOZOMI Networks (2020) “Data Sheet: Guardian; Industrial Strenghth OT and IoT Security and Visibility” [online] Accessed on May 25, 2021, website: <URL : https://www.exclusive-networks.com/fr/wp-content/uploads/ites/17/… [cited by applicant]
Meng et al. (2018) “An Effective High Threating Alarm Mining Method for Cloud Security Management”, IEEE Access, vol. 6, pp. 22634-22644, XP011683213. [cited by applicant]
Dingbang Xu (2006) “Correlation Analysis of Intrusion Alerts”, Thesis; North Carolina State University, Jan. 1, 2006 (Jan. 1, 2006), pp. 1-194, XP055903232. [cited by applicant]