Abnormal management device, abnormal management method, and abnormal management system
The abnormality management device addresses uneven signal distribution by learning a probability model to set thresholds for abnormality detection, enhancing resource efficiency in load balancing systems.
Patent Information
- Application Number
- JP2025094596
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Conventional load balancing methods fail to evenly distribute signals due to differences in hardware resources among devices, leading to inefficiencies in resource usage.
An abnormality management device that uses maximum likelihood estimation to learn a probability model from normal data, deriving a threshold for abnormality determination based on the posterior probability of packet distribution to manage bias in signal processing.
Effectively manages the bias in signal processing by setting thresholds for abnormality detection, ensuring equal distribution and efficient resource utilization across devices.
Smart Images

Figure 0007706675000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an abnormality management device, an abnormality management method, and an abnormality management system.
Background Art
[0002] Conventionally, as a technique for distributing signals to a plurality of devices to disperse the load, a load balancer using the round-robin method is known. For example, Patent Document 1 discloses a system that instructs an edge router to change the destination server to a standby server group according to the load status of an operation system server group, and evenly distributes signals to the standby server group of the changed destination using a load balancer.
[0003] However, depending on differences in the hardware resources of the devices to which the signals are distributed, etc., packets may not be evenly distributed to the devices to which the signals are distributed due to processing delays or losses on the device side of the distribution destination. Under such circumstances, since there is a risk that the resource usage efficiency of the entire system will decrease, a technique for detecting the bias in the signal processing amount is desired.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] According to the conventional technology, it has been difficult to appropriately manage the bias in the signal processing amount.
[0006] The present invention has been made to solve the above-described problems, and an object thereof is to appropriately manage the bias in the signal processing amount.
Means for Solving the Problems
[0007] In order to solve the above problems, an abnormality management device according to the present invention uses, as teacher data, normal data indicating the number of normal packets allocated to each device for each time period, and learns, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that the number of packets allocated to each device for each time period is normal. A derivation unit configured to derive a probability distribution of abnormal data indicating the number of abnormal packets allocated to each device in the time period based on the posterior probability for each device in each time period estimated by the learned probability model, the probability distribution of the normal data for each device based on the normal data, and the prior probability of being normal. And a setting unit configured to set, as a threshold for abnormality determination of the number of packets allocated to each device, the number of packets corresponding to a value of the probability distribution at which the probability distribution of the normal data for each device in each time period and the probability distribution of the abnormal data are equal.
[0008] Further, in the abnormality management device according to the present invention, the set threshold may be further configured to be notified to a control device that allocates packets to each device.
[0009] Further, in the abnormality management device according to the present invention, a collection unit configured to collect the normal data indicating the number of normal packets allocated to each device by the control device for each time period is further provided, and the learning unit may use the normal data collected by the collection unit as the teacher data.
[0010] In order to solve the above-described problems, an abnormality management method according to the present invention includes a learning step of learning, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that the number of packets assigned to each device for each time period is normal, using normal data indicating the number of normal packets assigned to each device for each time period as teacher data; a derivation step of deriving a probability distribution of abnormal data indicating the number of abnormal packets assigned to each device in the time period, based on the posterior probability for each device for each time period estimated by the learned probability model, the probability distribution of the normal data for each device estimated based on the normal data, and a prior probability of being normal; and a setting step of setting, as a threshold value for abnormality determination of the number of packets assigned to each device, the number of packets corresponding to a value of the probability distribution at which the probability distribution of the normal data for each device for each time period and the probability distribution of the abnormal data are equal.
[0011] Further, the abnormality management method according to the present invention may further include a notification step of notifying a control device that distributes packets to each device of the set threshold value.
[0012] Further, the abnormality management method according to the present invention may further include a collection step of collecting the normal data indicating the number of normal packets distributed by the control device to each device for each time period, and in the learning step, the normal data collected in the collection step may be used as the teacher data.
[0013] In order to solve the above problems, an abnormality management system according to the present invention is an abnormality management system including the above-described abnormality management device and a control device, wherein the control device is configured to obtain, as the number of packets to be managed, the number of packets distributed to each device for each time period, an acquisition unit configured to perform an abnormality determination on the number of packets to be managed distributed to each device for each time period based on the threshold value, and a determination unit configured to, when it is determined by the determination unit that the number of packets to be managed distributed to any one of the devices is abnormal, identify the device and output an alarm based on the determination result.
Effect of the Invention
[0014] According to the present invention, based on the posterior probability for each device for each time period estimated by the learned probability model, the probability distribution of the normal data for each device estimated based on the normal data, and the prior probability of being normal, a probability distribution of abnormal data indicating the number of abnormal packets distributed to each device for each time period is derived. Therefore, the bias in the signal processing amount can be appropriately managed.
Brief Description of the Drawings
[0015]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Embodiments for Carrying Out the Invention
[0016] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to FIGS. 1 to 7.
[0017] [Configuration of Abnormality Management System] First, with reference to FIG. 1, an overview of an abnormality management system including an abnormality management device 1, a traffic control device (control device) 2, and a counter device (device) 3 according to an embodiment of the present invention will be described.
[0018] The abnormality management system according to the present embodiment is provided in a mobile communication network compliant with 3G, 4G / LTE, 5G, 6G, etc. or a network using a fixed line. As shown in FIG. 1, the abnormality management device 1 is connected to the traffic control device 2 via a network NW such as a LAN, WAN, or the Internet. The abnormality management system sets a threshold for determining an abnormality in the number of packets distributed from the traffic control device 2 to each counter device 3 and performs an abnormality determination.
[0019] As shown in FIG. 2, the traffic control device 2 is communicably connected to a plurality of counter devices 3 and distributes the received packets to the plurality of counter devices 3 based on a preset distribution criterion. As an example, the traffic control device 2 distributes packets to the plurality of counter devices 3 in turn equally in theory by the round-robin method. However, when a packet processing delay or the like occurs on the counter device 3 side, packet transmission waits and retransmissions may occur, and the packet distribution may not be equal.
[0020] A plurality of traffic control devices 2 can be provided, and each traffic control device 2 is uniquely identified by identification information such as an IP address or a MAC address. Also, in the case of a plurality of traffic control devices 2, a threshold for abnormality determination is set for each traffic control device 2.
[0021] The traffic control device 2 can be realized by, for example, the AMF (Access and Mobility Management Function) provided in the core network or a load balancer. The AMF is a functional node in the control plane that manages the registration and wireless connection of user terminals. The load balancer is a device provided in the user plane for traffic distribution. When the anomaly management system is provided in a fixed-line network, the traffic control device 2 can be realized by an edge router, a load balancer, or the like. The functional blocks and hardware configuration of the traffic control device 2 will be described later.
[0022] The counterpart device 3 receives the packets distributed by the traffic control device 2. In the present embodiment, N (N is an integer of 2 or more) counterpart devices 3 are provided. When the traffic control device 2 is configured by the AMF, the counterpart device 3 is realized by the UDM (Unified Data Management) provided in the core network. The UDM is a functional node that manages subscriber information in the core network, performs mobility management of user terminals, and the like. Specifically, the AMF distributes the packets transmitted from the user terminal via the base station and transmits them to a plurality of UDMs. When the anomaly management system is provided in a fixed-line network, the counterpart device 3 is realized by a CDN (Content Delivery Network) node, a web server group, or the like.
[0023] The opposing device 3 can be realized by a computer including a processor, a main memory device, a communication interface, an auxiliary storage device, and input / output I / O, and a program for controlling these hardware resources. Each opposing device 3 is identified by an opposing device ID (i = 1, 2, ···, N) such as an IP address or a MAC address. In the present embodiment, at least one of the plurality of opposing devices 3 has hardware resources with a capacity different from that of other devices. Therefore, in the opposing device 3 with fewer resources than other opposing devices 3, the processing of received packets may be delayed, and a situation where the buffer becomes full may occur. As a result, as described above, a situation may occur in which the distribution of packets from the traffic control device 2 is not equal among all the opposing devices 3.
[0024] Fig. 3(a) is a diagram for explaining the normal data and abnormal data of the number of packets distributed by the traffic control device 2 to the opposing device 3. In Fig. 3(a), the number of packets distributed to one of the plurality of opposing devices 3 (for example, the opposing device 3 with the opposing device ID "1") is shown. The dotted line value in Fig. 3(a) indicates the normal data a1, which is the number of normal packets distributed to the opposing device 3. The normal number of packets means the number of packets distributed to the opposing device 3 with the opposing device ID "1" for each set time period (for example, in units of 10 minutes) according to the distribution standard set by the traffic control device 2 and within the range of the distribution standard.
[0025] On the other hand, the solid line number of packets shown in Fig. 3(a) indicates that, depending on the time period, a larger number of packets than the number of packets distributed during normal times are distributed to the opposing device 3. For example, it can be seen that in the time period t1, a larger number of packets than the normal number of packets are distributed to the opposing device 3 with the opposing device ID "1". Thus, the solid line number of packets indicates the abnormal data b1 in which the number of packets distributed to the opposing device 3 is abnormal.
[0026] Abnormal data is the number of packets that deviate from the range of the number of packets sorted according to the set sorting criteria that are regarded as normal. For example, in the round-robin method, theoretically, it is evenly sorted to each opposing device 3, and the normal data in this case is the number of packets sorted in a range that can be regarded as equal or approximately equal to each opposing device 3. On the other hand, abnormal data is the number of packets when the number of packets that deviate from the range that can be regarded as equal or approximately equal is sorted from the traffic control device 2 to the opposing device 3 due to reasons such as differences in the hardware resources of each opposing device 3.
[0027] [Function Blocks of the Abnormality Management Device] Next, the function blocks of the abnormality management device 1 according to the present embodiment will be described with reference to the block diagram of FIG. 1. As shown in FIG. 1, the abnormality management device 1 includes a collection unit 10, a learning unit 11, a derivation unit 12, a setting unit 13, a notification unit 14, and a storage unit 15. The abnormality management device 1 performs learning based on normal data and sets a threshold value for abnormality determination.
[0028] The collection unit 10 collects normal data indicating the number of normal packets sorted by the traffic control device 2 to each opposing device 3 in each time zone. The collection unit 10 collects data on the number of packets transmitted by the traffic control device 2 to each opposing device 3 per unit time (for example, 10 minutes) according to a predetermined sorting criterion for a certain period (for example, one month). Since the number of packets sorted from the traffic control device 2 and transmitted to each opposing device 3 is extremely small for abnormal data, it is assumed that it can be treated as normal data.
[0029] The learning unit 11 uses the normal data indicating the number of normal packets sorted to each opposing device 3 for each time zone as teacher data, and learns the parameters of the probability model that outputs the posterior probability that the number of packets sorted to each opposing device 3 for each time zone is normal by maximum likelihood estimation. The learning unit 11 learns the probability model by maximum likelihood estimation using normal data in a situation where abnormal data is scarce. Also, in the present embodiment, the learning unit 11 constructs a probability model for each opposing device 3.
[0030] Here, let x be the number of packets allocated to a certain opposing device 3 at a certain observation point during a certain time period. Also, as shown in the following equation (1), let the probability density function (probability distribution) of normal data be ρ d (x), and the probability density function (probability distribution) of abnormal data be ρ g (x), respectively.
Equation
[0031] In the above equation (1), y = 1 indicates the normal class, and y = 0 indicates the abnormal class. Therefore, ρ d (x) shows the appearance tendency of the number of packets x allocated when belonging to the normal class y = 1, and ρ g (x) shows the appearance tendency of the number of packets x allocated when belonging to the abnormal class y = 0. Here, in (b) of FIG. 3, the horizontal axis represents the number of packets allocated to one certain opposing device 3 (for example, the opposing device 3 with opposing device ID "1"), and the vertical axis represents the probability distribution. The probability distribution in (b) of FIG. 3 corresponds to the normal data a1 and abnormal data b1 (black circle data points) at time period t1 in (a) of FIG. 3, and shows the probability distribution (probability density function) a2 of normal data and the probability distribution (probability density function) b2 of abnormal data. In the example of (b) of FIG. 3, the probability distributions of both normal data and abnormal data follow a normal distribution.
[0032] The density ratio γ(x) of the probability density function in the above equation (1) is represented by the following equation (2).
Equation
[0033]
Equation
[0034] Here, assuming π = ρ(y = 1), the above equation (3) can be further expressed by the following equation (4). [Number] As shown in the above equation (4), the density ratio γ(x) is equivalent to obtaining the ratio of posterior probabilities based on the observed value x. However, the posterior probability ρ(y = 1|x) of being normal (y = 1) has a large number of observed values x, while there are almost no observed values x of the posterior probability ρ(y = 0|x) of being abnormal (y = 0), so it is difficult to calculate the posterior probability of being abnormal (y = 0).
[0035] Therefore, first, we will find the posterior probability ρ(y = 1|x) of being normal (y = 1) where there are a large number of data of the allocated number of packets x. Assuming that the posterior probability ρ(y = 1|x) of normal data follows a normal distribution, it is defined as shown in the following equation (5). [Number] In the above equation (5), f(x n ) is an estimated value that is the output by the probability model, σ 2 is the variance of the error, and t is the observed correct signal, that is, normal data.
[0036] Furthermore, if the output f(x n ) of the probability model is represented by a linear combination, it can be expressed as in the following equation (6). [Number] In the above formula (6), w m is the parameter of the model corresponding to the degree m, and x n is the observed value at the nth time zone. Also, the maximum likelihood estimate of the above formula (6) is shown by the following formula (7).
[0037] [Number] In the above formula (7), Φ is the matrix of the feature vector x of all the observed data. t n is the vector t n =(t1, ···, t N ) T representing the number of packets of the correct answer (normal data) at each observation point x. Furthermore, in the above formula (7), Φ is represented by the following formula (8).
[0038] [Number] That is, Φ is an N×M matrix in which the feature vectors Φ(x n ) obtained from each observation point are arranged as rows for N observation points x n .
[0039] Furthermore, the average of the error between the allocated packet number f(x n ) estimated based on the learned parameter w and the actual normal allocated packet number t n (teacher signal) is the variance σ 2 of the normal distribution shown by the following formula (9). [Number]
[0040] Thus, when the probability model represented by the linear combination estimates the posterior probability that the allocated packet number for the input x is normal, it is assumed that each observed value t follows a normal distribution with the estimated value f(x n ) of the probability model as the mean. For all data (xn ,t n By performing maximum likelihood estimation for (), the parameters w of the probability model and the variance σ of the error are estimated. 2 Also, from the definition formula of the normal distribution in the above formula (5), the probability distribution (density function) ρ of normal data is obtained. d (x) is obtained.
[0041] Here, when approximately estimating the posterior probability ρ(y = 1|x) of normal data, ρ(y = 1|x) ≒ q w It has the relationship of (y = 1|x). Based on the estimated value q of the posterior probability that the number of input packets x is normal w (y = 1|x), cross-entropy is defined as the loss function U as shown in the following formula (10).
Equation
[0042] The convergence value (minimum value) of the loss function U in the above formula (10) is represented by the following formula (11).
Equation
[0043] The derivation unit 12 transforms the above formula (11) into the following formula (12) to derive the probability distribution (density function) ρ of abnormal data g (x).
Equation
[0044] In the above formula (12), the probability distribution (density function) ρ of normal data d (x) is calculated from the normal data collected by the collection unit 10. Also, since the prior probability π of normal data is much larger than the prior probability (1 - π) of abnormal data, it can be set to 0.99, for example. Furthermore, for the observed value x, the log-likelihood lnq when y = 1 w(y = 1|x) is obtained by maximum likelihood estimation based on a large amount of normal data (teacher signals) as shown in the above equations (6) to (9). Thus, even when there is little abnormal data, the probability distribution of abnormal data can be obtained from normal data.
[0045] The derivation unit 12 derives an estimated value q of the posterior probability for each opposing device 3 for each time period, which is estimated by the probability model learned by the learning unit 11. w (y = 1|x), the probability distribution (density function) ρ of normal data for each opposing device 3 estimated based on normal data d (x), and the prior probability π of being normal, based on which the probability distribution (density function) ρ of abnormal data indicating the number of abnormal packets distributed to each opposing device 3 for each time period is derived. g (x). The derivation unit 12 derives the probability distribution ρ of abnormal data for each of the plurality of opposing devices 3. g (x).
[0046] The setting unit 13 sets, as the threshold for abnormality determination of the number of packets distributed to each opposing device 3, the number of packets corresponding to the value of the probability distribution at which the probability distribution of normal data and the probability distribution of abnormal data for each opposing device 3 for each time period are equal. As shown in FIG. 3(b), the setting unit 13 sets, as the threshold for the number of packets distributed in time period t1 for the opposing device 3 with opposing device ID “1”, the number of packets at the intersection of the probability distribution of normal data a2 and the probability distribution of abnormal data b2 in time period t1. The setting unit 13 sets a threshold for abnormality determination for each time period for each opposing device 3. Further, when a plurality of traffic control devices 2 are provided, the setting unit 13 sets a threshold for abnormality determination for each time period for each opposing device 3 for each traffic control device 2.
[0047] The abnormality determination condition based on the threshold set by the setting unit 13 is represented by the following equation (13). x i,t > θ i,t ···(13) In the above formula (13), i is the index of the opposing device 3 connected to the traffic control device 2 (i = 1, 2, …, N), t is the time period (e.g., in 10 - minute units), and x i,t is the number of packets allocated from the traffic control device 2 to the opposing device 3(i) in the time period t, and θ i,t represents the abnormality determination threshold value at this time.
[0048] The notification unit 14 notifies the traffic control device 2 that distributes packets to each opposing device 3 of the set threshold value. The notification unit 14 notifies the traffic control device 2 of the threshold value for the abnormality determination of the allocated packet number via the network NW. When there are multiple traffic control devices 2, the threshold value set for each traffic control device 2 is notified to each traffic control device 2.
[0049] The storage unit 15 stores the threshold value for abnormality determination set by the setting unit 13.
[0050] [Function Blocks of Traffic Control Device] As shown in FIG. 1, the traffic control device 2 includes an acquisition unit 20, a communication unit 21, a determination unit 22, an alarm unit 23, and a storage unit 24. The traffic control device 2 performs abnormality determination on the allocated packet number of the management target.
[0051] The acquisition unit 20 acquires, as the packet number of the management target, the number of packets allocated to each opposing device 3 for each time period. The acquisition unit 20 acquires, for each set time period, the number of packets transmitted to each opposing device 3 that is counted and recorded in the log file in its own device as the packet number of the management target. Also, the acquisition unit 20 similarly acquires the normal data used by the abnormality management device 1 as teacher data. When acquiring the packet number as teacher data, for example, data for one month is acquired. Also, the acquired packet number data is associated with the time period and the identification information of the opposing device 3.
[0052] The communication unit 21 transmits the teacher data of the normal data acquired by the acquisition unit 20 to the abnormality management device 1 via the network NW. Also, the communication unit 21 receives the threshold value for abnormality determination notified from the abnormality management device 1.
[0053] The determination unit 22 performs an abnormality determination on the number of packets to be managed allocated to each opposing device 3 for each time zone based on the threshold value. The threshold value is the threshold value notified by the notification unit 14 of the abnormality management device 1. The determination unit 22 determines that an abnormality has occurred when the allocated packet number for each opposing device 3 and for each time zone exceeds the threshold value according to the abnormality determination condition of the above formula (13). When the allocated packet number for each time zone to be managed for each opposing device 3 is equal to or less than the threshold value, the determination unit 22 determines that the packet number allocated to these opposing devices 3 is normal. For example, in the time zone t1, when the number of packets of the opposing device 3 with i = 1 among the packets allocated and transmitted to a plurality of opposing devices 3 exceeds the threshold value, the determination unit 22 determines that an abnormality has occurred. The determination result includes information on the time zone in which the abnormality determination was made and the opposing device ID of the opposing device 3.
[0054] When the determination unit 22 determines that the number of packets to be managed allocated to any of the opposing devices 3 is abnormal, the warning unit 23 identifies the opposing device 3 and outputs a warning based on the determination result. The warning unit 23 can display that an abnormality has occurred on the display device 207 or indicator of its own device. Also, the warning unit 23 may transmit a warning to an external management server. The warning unit 23 can cause the display device 207 to display the opposing device ID of the opposing device 3 to which an abnormal number of packets were allocated together with the warning.
[0055] The storage unit 24 stores the number of packets allocated to each opposing device 3 for each time zone. Also, the storage unit 24 stores the threshold value for each time zone notified by the notification unit 14 of the abnormality management device 1.
[0056] [Hardware Configuration of Abnormality Management Device] Next, an example of the hardware configuration for realizing the abnormality management device 1 having the above-described functions will be described with reference to FIG. 4.
[0057] As shown in FIG. 4, the abnormality management device 1 can be realized, for example, by a computer including a processor 102, a main storage device 103, a communication interface 104, an auxiliary storage device 105, and an input / output I / O 106 connected via a bus 101, and by a program that controls these hardware resources. Further, the abnormality management device 1 includes a display device 107.
[0058] The processor 102 is realized by a CPU, a GPU, an FPGA, an ASIC, or the like.
[0059] In the main storage device 103, programs for the processor 102 to perform various controls and calculations are stored in advance. The functions of the abnormality management device 1 such as the collection unit 10, the learning unit 11, the derivation unit 12, and the setting unit 13 shown in FIG. 1 are realized by the processor 102 and the main storage device 103.
[0060] The communication interface 104 is an interface circuit for network-connecting the abnormality management device 1 and various external electronic devices. At least a part of the notification unit 14 is realized by the communication interface 104.
[0061] The auxiliary storage device 105 is composed of a readable and writable storage medium and a drive device for reading and writing various information such as programs and data to and from the storage medium. As the storage medium, a semiconductor memory such as a hard disk or a flash memory can be used in the auxiliary storage device 105.
[0062] The auxiliary storage device 105 has a program storage area for storing an abnormality management program. Also, the auxiliary storage device 105 has a program storage area for storing a learning program for learning the probability model executed by the abnormality management device 1. The storage unit 15 described with reference to FIG. 1 is realized by the auxiliary storage device 105. Furthermore, for example, it may have a backup area for backing up the above-described data, programs, and the like.
[0063] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.
[0064] The display device 107 is composed of an organic EL display, a liquid crystal display, or the like.
[0065] [Hardware Configuration of Traffic Control Device] Next, an example of the hardware configuration for realizing the traffic control device 2 having the above-described functions will be described with reference to FIG. 5.
[0066] As shown in FIG. 5, the traffic control device 2 can be realized, for example, by a computer including a processor 202, a main storage device 203, a communication interface 204, an auxiliary storage device 205, and an input / output I / O 206 connected via a bus 201, and a program for controlling these hardware resources. Furthermore, the traffic control device 2 includes a display device 207. The traffic control device 2 has the same configuration as the abnormality management device 1, and the description of the corresponding configuration is omitted.
[0067] Each function of the traffic control device 2, such as the acquisition unit 20, the determination unit 22, and the alarm unit 23 shown in FIG. 1, is realized by the processor 202 and the main storage device 203.
[0068] Each time the communication interface 204 distributes and transmits packets to each counterpart device 3, it increments a counter indicating the number of transmitted packets. The counter value is read by the processor 202 at regular intervals. Also, the number of packets is counted for each counterpart device 3 and stored in the main storage device 203, and the processor 202 periodically stores it in the log file of the auxiliary storage device 205.
[0069] The auxiliary storage device 205 has a program storage area for storing an abnormality determination program. The storage unit 24 described in FIG. 1 is realized by the auxiliary storage device 205. Also, the auxiliary storage device 205 has an area for storing a distribution program for distributing packets to the counterpart device 3 according to a predetermined distribution criterion.
[0070] The display device 207 is composed of an organic EL display, a liquid crystal display, etc., and further includes an LED, etc. At least a part of the alarm unit 23 described in FIG. 1 is realized by the display device 207.
[0071] [Operation of Abnormality Management System] Next, the operation of the abnormality management system including the abnormality management device 1 and the traffic control device 2 having the above-described configuration will be described with reference to the sequence of FIG. 6.
[0072] As shown in FIG. 6, first, the acquisition unit 20 of the traffic control device 2 acquires the number of packets distributed to each counterpart device 3 for each time zone (step S1). The acquisition unit 20 of the traffic control device 2 acquires from the log file the number of packets distributed and transmitted to each counterpart device 3 in each time zone over the set period. Since the number of packets acquired in step S1 mostly occupies the ratio of normally distributed packets, it can be treated as normal data. The communication unit 21 of the traffic control device 2 sends the acquired packet number data to the abnormality management device 1 via the network NW.
[0073] Subsequently, the collection unit 10 of the abnormality management device 1 collects normal data for each opposing device 3 from the traffic control device 2 (step S2). Subsequently, the learning unit 11 uses the normal data indicating the number of normal packets allocated to each opposing device 3 for each time period as teacher data, and learns the parameters of the probability model that outputs the posterior probability that the number of packets allocated to each opposing device 3 for each time period is normal by maximum likelihood estimation (step S3).
[0074] After that, the derivation unit 12 derives the probability distribution of the abnormal data (step S4). FIG. 7 is a flowchart for explaining steps S3 and S4 in more detail. As shown in step S30 of FIG. 7, the learning unit 11 uses the normal data as teacher data based on the time series of the allocated packet numbers for each opposing device 3, most of which are normal data, collected in step S2, and the estimated value q of the posterior probability that the number of packets x allocated to each opposing device 3 is normal w (y = 1|x) outputs the parameters w, σ of the probability model 2 by maximum likelihood estimation (step S30).
[0075] In step S30, the learning unit 11 performs learning by maximum likelihood estimation according to the above equations (6) to (9). Also, in step S30, the learning unit 11 obtains the estimated value q of the posterior probability that the number of packets x allocated to each opposing device 3 is normal from the probability model having the parameters w, σ 2 estimated by maximum likelihood estimation w (y = 1|x).
[0076] Furthermore, the learning unit 11 estimates the probability distribution ρ of the normal data for each opposing device 3 for each time period d (x) (normal distribution) based on the number x of normal packets allocated to each opposing device 3 for each time period (step S31).
[0077] Next, the derivation unit 12 substitutes the logarithm of the posterior probability lnq obtained in step S30 into the above equation (12) w (y = 1|x), and the probability distribution ρ of the normal data obtained in step S31 dSubstitute (x) and the prior probability π of normal data (e.g., 0.99) to derive the probability distribution ρ g (x) for each opposing device 3 (step S33).
[0078] Subsequently, the process proceeds to step S5 in FIG. 6. Subsequently, the setting unit 13 determines the probability distribution ρ g (x) of normal data for each opposing device 3 for each time period based on the probability distribution ρ d (x) of abnormal data, and sets the number of packets corresponding to the value of the probability distribution where ρ g (x) of normal data is equal to ρ (x) of abnormal data as the threshold for abnormal determination of the number of packets allocated to each opposing device 3 for each time period (step S5). In step S5, the setting unit 13 sets the threshold for each time period for each opposing device 3.
[0079] Next, the notification unit 14 notifies the traffic control device 2 via the network NW of the threshold for each opposing device 3 and for each time period (step S6). The traffic control device 2 receives the notified threshold and stores it in the storage unit 24. Subsequently, the traffic control device 2 counts the number of packets transmitted and allocated to each opposing device 3 for each time period and stores it in the storage unit 24. The acquisition unit 20 of the traffic control device 2 acquires the number of packets allocated to each opposing device 3 for each time period as the number of packets to be managed (step S7).
[0080] Next, the determination unit 22 of the traffic control device 2 performs an abnormal determination on the number of packets to be managed allocated to each opposing device 3 for each time period based on the threshold notified in step S6 (step S8). The determination unit 22 determines that an abnormality has occurred in the allocation of packets to the opposing device 3 for the time period when the number of allocated packets for each time period exceeds the threshold for each opposing device 3. Next, when it is determined in step S8 that the number of packets to be managed allocated to any of the opposing devices 3 is abnormal, the warning unit 23 identifies the opposing device 3 and outputs a warning based on the determination result (step S9).
[0081] As described above, according to the abnormality management apparatus 1 according to the present embodiment, by learning the parameters of the probability model that outputs the posterior probability that the number of packets distributed to each opposing apparatus 3 for each time zone is normal, using the normal data as teacher data, by maximum likelihood estimation, the posterior probability that the number of packets distributed to each opposing apparatus 3 for each time zone is normal is estimated. Further, based on the estimated value of the posterior probability, the probability distribution of the normal data, and the prior probability of the normal data, the probability distribution of the abnormal data for each opposing apparatus 3 for each time zone is derived. Further, the number of packets corresponding to the value of the probability distribution at which the values of the probability distribution of the abnormal data and the probability distribution of the normal data for each opposing apparatus 3 for each derived time zone are the same is set as the threshold for abnormality determination. Therefore, the bias of the signal processing amount can be appropriately managed.
[0082] Also, according to the abnormality management apparatus 1 according to the present embodiment, since the parameters of the probability model that outputs the posterior probability that the number of packets distributed to the opposing apparatus 3 for each time zone is normal are learned by maximum likelihood estimation using the normal data as teacher data, it is possible to theoretically model using only the normal data.
[0083] Also, according to the abnormality management apparatus 1 according to the present embodiment, the threshold for abnormality determination is set based on the intersection of the probability distribution of the normal data and the probability distribution of the abnormal data. Therefore, the threshold has the explanatory power as a theoretical classification boundary that is the point where normality and abnormality are most equal.
[0084] Also, according to the abnormality management apparatus 1 according to the present embodiment, since abnormality determination is performed using the threshold for each time zone for each opposing apparatus 3, it is possible to identify in which of the plurality of opposing apparatuses 3 the processing abnormality of the distributed packets has occurred. Also, as a result, it is possible to contribute to measures for efficient use of the resource resources of the entire system.
[0085] In addition, according to the abnormality management device 1 according to the present embodiment, since the abnormality determination is performed using the threshold value for each time zone, it is possible to detect the bias of the signal processing amount in real time.
[0086] As described above, the embodiments of the abnormality management device, the abnormality management method, and the abnormality management system of the present invention have been described. However, the present invention is not limited to the described embodiments, and various modifications that can be assumed by those skilled in the art can be made within the scope of the invention described in the claims.
Description of Reference Numerals
[0087] 1... Abnormality management device, 2... Traffic control device, 3... Opposing device, 10... Collection unit, 11... Learning unit, 12... Derivation unit, 13... Setting unit, 14... Notification unit, 15, 24... Storage unit, 20... Acquisition unit, 21... Communication unit, 22... Determination unit, 23... Alarm unit, 101, 201... Bus, 102, 202... Processor, 103, 203... Main storage device, 104, 204... Communication interface, 105, 205... Auxiliary storage device, 106, 206... Input / output I / O, 107, 207... Display device, NW... Network.
Claims
1. A learning unit configured to learn, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that the number of packets assigned to each device for each time period is normal, using normal data indicating the number of normal packets assigned to each device for each time period as teacher data; A derivation unit configured to derive a probability distribution of abnormal data indicating the number of abnormal packets assigned to each device for each time period, based on the posterior probability for each device for each time period estimated by the learned probability model, the probability distribution of the normal data for each device estimated based on the normal data, and the prior probability of being normal; A setting unit configured to set, as a threshold for determining abnormality of the number of packets assigned to each device, the number of packets corresponding to a value of the probability distribution at which the probability distribution of the normal data and the probability distribution of the abnormal data for each device for each time period become equal; An abnormality management device comprising the above.
2. The abnormality management device according to Claim 1, further comprising: A notification unit configured to notify the control device that distributes packets to each device of the set threshold. An abnormality management device comprising the above.
3. The abnormality management device according to Claim 1, further comprising: A collection unit configured to collect the normal data indicating the number of normal packets assigned to each device by the control device for each time period, wherein the learning unit uses the normal data collected by the collection unit as the teacher data. An abnormality management device characterized by the above.
4. A learning step of learning, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that the number of packets assigned to each device for each time period is normal, using normal data indicating the number of normal packets assigned to each device for each time period as teacher data; A derivation step of deriving a probability distribution of abnormal data indicating the number of abnormal packets assigned to each device for each time period, based on the posterior probability for each device for each time period estimated by the learned probability model, the probability distribution of the normal data for each device estimated based on the normal data, and the prior probability of being normal; A setting step of setting, as a threshold value for abnormality determination of the number of packets allocated to each device, the value of the probability distribution at which the probability distribution of the normal data and the probability distribution of the abnormal data for each device for each time zone become equal An abnormality management method comprising the same.
5. In the abnormality management method according to claim 4, Furthermore, a notification step of notifying the control device that distributes packets to each device of the set threshold value An abnormality management method comprising the same.
6. In the abnormality management method according to claim 4, Furthermore, it comprises a collection step of collecting the normal data indicating the number of normal packets distributed to each device by the control device for each time zone, In the learning step, the normal data collected in the collection step is used as the teacher data An abnormality management method characterized by the above.
7. An abnormality management system comprising the abnormality management device according to any one of claims 1 to 3 and a control device, The control device is An acquisition unit configured to acquire, as the number of packets to be managed, the number of packets distributed to each device for each time zone, A determination unit configured to perform abnormality determination of the number of packets to be managed distributed to each device for each time zone based on the threshold value, An alarm unit configured to identify a device and output an alarm based on the determination result when it is determined by the determination unit that the number of packets to be managed distributed to any device is abnormal An abnormality management system comprising the same.
Citation Information
Patent Citations
Learning device, learning method, and program
JP2019070965A
Communication service system and congestion avoidance method
JP2018142848A
Cited By
Abnormality management device and abnormality management method
JP7742001B1
Abnormality management device and abnormality management method
JP7752279B1
Abnormality management device and abnormality management method
JP7762830B1
Abnormality management device and abnormality management method
JP7762832B1
Abnormality management device and abnormality management method
JP7793852B1