IP Library › Granted Patent US 11,797,413
Granted Patent B2
US 11,797,413 · App. 17/684,656 · Granted Oct 24, 2023

Anomaly detection method, system, and program

Inventor: Ryosuke Togawa (Tokyo, JP)
Assignee: NEC CORPORATION
G06F11/3082G06F11/076G06F11/0772G06F11/3075
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,413
App. No.
17/684,656
Filed
Mar 2, 2022
Granted
Oct 24, 2023
Kind
B2
Art Unit
2113
USPC
714/47.1
Abstract

The present invention provides an anomaly detection method, an anomaly detection system, and an anomaly detection program that can detect an anomaly at high accuracy by using log output quantity distributions generated for to different aggregate units and different devices. An anomaly detection system according to one example embodiment of the present invention has: a reference distribution, which is a time-series distribution of a log output quantity acquisition unit that acquires a plurality of distributions generated for each device that outputs logs and for each unit of a time range in which logs are aggregated; and an anomaly detection unit that detects an anomaly by using the plurality of distributions.

Claims (51)

1. An anomaly detection method comprising:

acquiring a plurality of reference data including a number of log outputs of different devices with respect to different aggregate units;

acquiring target data including a number of log outputs of a target device with respect to a first aggregate unit included in the different aggregate units;

determining a first reference data, among the plurality of reference data, based on similarity between the target data and each of the plurality of reference data; and

detecting that the target device has an anomaly based on the first reference data and the target data.

2. The anomaly detection method according to claim 1 , wherein

the plurality of reference data is in various time ranges.

3. The anomaly detection method according to claim 1 , wherein

an anomaly degree is calculated based on the first reference data and the target data, and

the target device is detected as having the anomaly when the anomaly degree is higher than a predetermined threshold.

4. The anomaly detection method according to claim 1 , wherein

the target data include time-series distribution of number of log outputs.

5. The anomaly detection method according to claim 1 , wherein

the similarity is related to a correlation coefficient.

6. The anomaly detection method according to claim 1 , wherein

the deciding is performed based on a correlation coefficient.

7. The anomaly detection method according to claim 1 , wherein

each of the plurality of reference data is a time-series distribution of an output quantity generated based on a rule of aggregating previously output logs according to a predetermined time range.

8. The anomaly detection method according to claim 1 further comprising

displaying a notification indicating that the anomaly is detected.

9. An anomaly detection system comprising:

a memory storing one or more instructions; and

one or more processors configured to execute the one or more instructions to:

acquire a plurality of reference data including a number of log outputs of different devices with respect to different aggregate units;

acquire target data including a number of log outputs of a target device with respect to a first aggregate unit included in the different aggregate units;

determine a first reference data, among the plurality of reference data, based on similarity between the target data and each of the plurality of reference data; and

detect that the target device has an anomaly based on the first reference data and the target data.

10. The anomaly detection system according to claim 9 , wherein

the plurality of reference data is in various time ranges.

11. The anomaly detection system according to claim 9 , wherein

an anomaly degree is calculated based on the first reference data and the target data, and

the one or more processors detect that the target device has the anomaly when the anomaly degree is higher than a predetermined threshold.

12. The anomaly detection system according to claim 9 , wherein

the target data include time-series distribution of number of log outputs.

13. The anomaly detection system according to claim 9 , wherein

the similarity is related to a correlation coefficient.

14. The anomaly detection system according to claim 9 , wherein

the detection is performed based on a correlation coefficient.

15. The anomaly detection system according to claim 9 , wherein

each of the plurality of reference data is a time-series distribution of an output quantity generated based on a rule of aggregating previously output logs according to a predetermined time range.

16. The anomaly detection system according to claim 9 , wherein the one or more processors is further configured to execute the one or more instructions to:

display a notification indicating that the anomaly is detected.

17. A non-transitory computer-readable storage medium in which an anomaly detection program is stored, the anomaly detection program causing a computer to:

acquire a plurality of reference data including a number of log outputs of different devices with respect to different aggregate units;

acquire target data including a number of log outputs of a target device with respect to a first aggregate unit included in the different aggregate units;

determine a first reference data, among the plurality of reference data, based on similarity between the target data and each of the plurality of reference data; and

detect that the target device has an anomaly based on the first reference data and the target data.

18. The non-transitory computer-readable storage medium according to claim 17 , wherein

each of the plurality of reference data is a time-series distribution of an output quantity generated based on a rule of aggregating previously output logs according to a predetermined time range.

19. The non-transitory computer-readable storage medium according to claim 17 , wherein the anomaly detection program further causes a computer to:

display a notification indicating that the anomaly is detected.

Continuity (2)
Continuation 16470281
Related Publication 20220188209A1 · Jun 16, 2022