IP Library Granted Patent US 12,457,065
Granted Patent B2
US 12,457,065 · App. 18/716,699 · Granted Oct 28, 2025

Anomaly detection device, anomaly detection method, and anomaly detection program

Inventor: Yuki Yamanaka (Musashino, JP)
Assignee: NTT, Inc.
H04L1/24H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,065
App. No.
18/716,699
Granted
Oct 28, 2025
Kind
B2
Abstract

An abnormality detection device includes processing circuitry configured to input a normal packet to a Bidirectional Encoder Representations from Transformers (BERT) model learned using the normal packet, and acquire a size of Attention for each byte portion when encoding of the normal packet is performed, sample an important byte portion of the normal packet based on the size of the Attention of each byte portion of the normal packet acquired, and rewrite the sampled important byte portion to a random byte to generate a pseudo-abnormal packet, and determine a threshold value of an abnormality degree for detecting an abnormal packet based on the abnormality degree of the generated pseudo-abnormal packet group and normal packet group.

Claims (16)

1. An abnormality detection device comprising:

processing circuitry configured to:

input a normal packet to a Bidirectional Encoder Representations from Transformers (BERT) model learned using the normal packet, and acquire a size of Attention for each byte portion when encoding of the normal packet is performed;

sample an important byte portion of the normal packet based on the size of the Attention of each byte portion of the normal packet acquired, and rewrite the sampled important byte portion to a random byte to generate a pseudo-abnormal packet; and

determine a threshold value of an abnormality degree for detecting an abnormal packet based on the abnormality degree of the generated pseudo-abnormal packet group and normal packet group.

2. The abnormality detection device according to claim 1 , wherein the processing circuitry is further configured to determine the threshold value of the abnormality degree by an F1 optimization method.

3. The abnormality detection device according to claim 1 , wherein the processing circuitry is further configured to detect a packet as an abnormal packet in a case where the abnormality degree of the packet to be detected exceeds the threshold value.

4. The abnormality detection device according to claim 1 , wherein the processing circuitry is further configured to generate the pseudo-abnormal packet by randomly sampling an important byte portion of the normal packet based on the size of the Attention of each byte portion of the acquired normal packet, and rewriting the randomly sampled important byte portion to a random byte.

5. An abnormality detection method executed by an abnormality detection device, the abnormality detection method comprising:

inputting a normal packet to a Bidirectional Encoder Representations from Transformers (BERT) model learned using the normal packet, and acquiring a size of Attention for each byte portion when encoding of the normal packet is performed;

sampling an important byte portion of the normal packet based on the size of the Attention of each byte portion of the normal packet acquired, and rewriting the sampled important byte portion to a random byte to generate a pseudo-abnormal packet; and

determining a threshold value of an abnormality degree for detecting an abnormal packet based on the abnormality degree of the generated pseudo-abnormal packet group and normal packet group.

6. A non-transitory computer-readable recording medium storing therein an abnormality detection program that causes a computer to execute a process comprising:

inputting a normal packet to a Bidirectional Encoder Representations from Transformers (BERT) model learned using the normal packet, and acquiring a size of Attention for each byte portion when encoding of the normal packet is performed;

sampling an important byte portion of the normal packet based on the size of the Attention of each byte portion of the normal packet acquired, and rewriting the sampled important byte portion to a random byte to generate a pseudo-abnormal packet; and

determining a threshold value of an abnormality degree for detecting an abnormal packet based on the abnormality degree of the generated pseudo-abnormal packet group and normal packet group.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2024
From: YAMANAKA, YUKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 067631/0535 →
Continuity (1)
Related Publication 20250038899A1 · Jan 30, 2025
References Cited (4)
US 20220182434A1 · Walters · 2022 [cited by examiner]
US 20230030341A1 · Koh · 2023 [cited by examiner]
US 20240106766A1 · Wang · 2024 [cited by examiner]
Yamanaka et al., “Utilizing BERT for Feature Extraction of Packet Payload”, The 35th Annual Conference of the Japanese Society for Artificial Intelligence, 1F2-GS-10a-04, 2021, pp. 1-3 (3 pages including English Abstrac… [cited by applicant]