Intelligent network security terminal protection capability evaluation model construction method
By constructing an intelligent terminal protection capability evaluation method combining static and dynamic evaluation sub-models, the problem that the existing technology fails to fully consider terminal behavior information is solved, and the accuracy and comprehensive benefits of the evaluation results are improved.
Patent Information
- Application Number
- CN202510563309.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-06-03
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art fails to fully consider the terminal behavior information when evaluating the protection capabilities of the terminal equipment, resulting in inaccurate evaluation results.
By collecting the behavioral information of the device and combining the comprehensive importance of the device, a static and dynamic evaluation sub-model is constructed, combining the risk value of behavioral information and blood kinship analysis, an intelligent network security terminal protection capability evaluation model is constructed.
It improves the accuracy and comprehensive benefits of the evaluation results, ensures that resources are effectively utilized, and improves the robustness and automation capabilities of the model.
Smart Images

Figure CN120090951A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a method for constructing an intelligent evaluation model for the protection ability of network security terminals. Background Art
[0002] With the increasing complexity and diversification of the network, there are more and more terminal devices, and their importance is increasing day by day. However, the evaluation ability of terminal protection is becoming increasingly weak, and the limitations of traditional terminal protection evaluation mechanisms and algorithms are very obvious. Therefore, it is particularly important to study mechanisms and models with strong generalization ability and comprehensive evaluation of the protection ability of terminal devices.
[0003] Currently, the mechanisms for evaluating the terminal security protection ability generally adopt methods such as evaluating the network environment of the terminal device, the protection level of the terminal device itself, and the protection ability of network security devices in the environment where the terminal device is located. When evaluating the protection ability, it is mostly limited to the known protection mechanisms on the device side, lacking the cooperation with the behavior information of the terminal to comprehensively give the evaluation result of the protection ability.
[0004] And some terminal protection ability evaluation mechanisms with terminal behavior information lack generalization ability, universality and are not intelligent enough.
[0005] Therefore, there is an urgent need to provide a solution to solve the above problems. Summary of the Invention
[0006] The purpose of the present invention is to provide a method for constructing an intelligent evaluation model for the protection ability of network security terminals, which solves the problem that the evaluation result is inaccurate due to the lack of consideration of the behavior information of the terminal in the prior art.
[0007] A method for constructing an intelligent evaluation model for the protection ability of network security terminals provided by the present invention adopts the following technical solutions: Collect the evaluation dimensions of device importance and set the index weights of different evaluation dimensions, and calculate the comprehensive importance of the device based on the evaluation dimensions and their index weights; Collect the first-level dimensions for evaluating the security protection ability of the terminal device, divide the first-level dimensions to obtain the corresponding second-level dimensions, set the evaluation weights of the first-level dimensions and the second-level dimensions, score the second-level dimensions, calculate the first-level dimension index values based on the scores and weights of the second-level dimensions, set the thresholds of each first-level index based on the comprehensive importance of the device, calculate the first-level dimension index scores based on the first-level dimension index values and the first-level index thresholds, and calculate the static evaluation total score based on the first-level dimension index scores and their evaluation weights to obtain a static evaluation sub-model; Collect various behavioral information of the device and set corresponding information risk thresholds. Based on the overall importance of the device, set the number and size of the analysis windows, calculate the risk values of the analysis windows, calculate the behavioral information risk value based on the window risk value and the information risk threshold. When the cumulative sum of the behavioral information risk values is greater than 1, perform lineage analysis to draw the behavioral information lineage flow chart and obtain the dynamic evaluation sub-model. Construct a protection ability evaluation model based on the static evaluation sub-model and the dynamic evaluation sub-model, and update the evaluation model based on the self-check cycle and self-check dimension of the model.
[0008] Optionally, in the process of calculating the overall importance of the device based on the evaluation dimension and its index weight, it includes: Score the importance of different evaluation dimensions to obtain importance scores. The scoring methods include but are not limited to AHP, expert scoring, and dimension horizontal comparison scoring. Calculate the original importance of the device based on the index weight and importance score of the evaluation dimension, set an additional importance score for the device based on the device user, and calculate the overall importance of the device based on the original importance of the device and the additional importance score.
[0009] Optionally, in the process of calculating the score of the first-level dimension index based on the first-level dimension index value and the first-level index threshold, it includes: When the first-level dimension index value is less than the first-level index threshold, the score of the first-level dimension index is 0; otherwise, the score of the first-level dimension index is the first-level dimension index value.
[0010] Optionally, in the process of calculating the total static evaluation score based on the score of the first-level dimension index and its evaluation weight, it includes: When there is a situation where the score of one first-level dimension index is 0, the total static evaluation score is 0;
[0011] When the first-level dimension indexes are all non-zero, perform weighted summation based on the score of the first-level dimension index and its evaluation weight to obtain the total static evaluation score.
[0012] Optionally, in the process of calculating the risk value of the analysis window, it includes: Assign values to the content based on whether there is malicious risk in the information content in the analysis window to obtain a window value of a one-dimensional vector. Set weights based on the position of the information content, and perform weighted summation of the value of the information content and the weight to obtain the risk value of a single analysis window.
[0013] Optionally, in the process of calculating the behavioral information risk value based on the window risk value and the information risk threshold, it includes: Calculate the number of windows with behavioral information, set window weights based on the window positions, and perform weighted summation based on the window risk value and its weight to obtain the multi-window risk sum; When the multi-window risk sum is greater than the corresponding information risk threshold, the behavioral information risk is 1; otherwise, it is 0.
[0014] Optionally, before obtaining the dynamic evaluation sub-model, the following steps are included: Set the trigger mechanism and execution period of the dynamic evaluation sub-model; Set the cache mechanism for behavioral information risk value analysis and lineage analysis; Encapsulate the information preprocessing, behavioral information risk value analysis, and lineage analysis processes.
[0015] Optionally, during the process of setting the cache mechanism for behavioral information risk value analysis and lineage analysis, the following steps are included: For the same device, calculate the cosine similarity of all parameters twice based on the similarity method, and determine whether to recalculate the behavioral information risk value and lineage analysis based on the similarity.
[0016] Optionally, during the process of constructing the protection ability evaluation model based on the static evaluation sub-model and the dynamic evaluation sub-model, the following steps are included: Set the update mechanism of the static sub-model and calculate the optimal execution period of the dynamic sub-model; Execute the static evaluation sub-model and the dynamic evaluation sub-model respectively to obtain the total static evaluation score, various behavioral information risk values, and the information lineage flow chart, and fuse the three to obtain the protection ability evaluation model.
[0017] Optionally, during the process of calculating the optimal execution period of the dynamic sub-model, the following steps are included: Randomly give an execution period, execute the dynamic sub-model multiple times based on the execution period to obtain multiple execution results, record the number of times with the same execution result. When the number is not 1, update the execution period until the number is equal to 1 to obtain the optimal execution period.
[0018] The beneficial effects of an intelligent network security terminal protection ability evaluation model construction method provided by the present invention are as follows: 1. Based on the behavioral information risk value, the present invention determines whether lineage analysis is required, which can ensure that limited resources are used for key data or processes; 2. The present invention constructs a static evaluation model by collecting the security protection ability of terminal devices, constructs a dynamic evaluation model by collecting device behavioral information, and improves the accuracy and comprehensive benefits of the model evaluation results through real-time calculation and evaluation of information that does not change frequently and real-time changing information; 3. The present invention proposes a model self-checking mechanism targeted at terminal devices, which can effectively avoid abnormalities or errors in terminal evaluation caused by certain accidental factors or reasons through this mechanism, and improve the robustness of the model.
[0019] 4. The present invention uses machine learning ideas and methods for modeling. In addition to scoring important dimensions of important devices, the evaluation of terminal protection capabilities can be completed automatically and intelligently, improving the automation ability of the evaluation. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a flowchart of a method for constructing a protection capability evaluation model provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art in the field to which the present invention belongs. The words such as "including" used herein mean that the elements or items appearing before this word cover the elements or items listed after this word and their equivalents, without excluding other elements or items.
[0022] The embodiments of the present invention provide an intelligent method for constructing a network security terminal protection capability evaluation model. Refer to Figure 1 , including: S1. Collect the importance evaluation dimensions of devices and set the index weights of different evaluation dimensions, and calculate the comprehensive importance of devices based on the evaluation dimensions and their index weights; S2. Collect the first-level dimensions for evaluating the security protection capabilities of terminal devices, divide the first-level dimensions to obtain corresponding second-level dimensions, set the evaluation weights of the first-level dimensions and the second-level dimensions, score the second-level dimensions, calculate the first-level dimension index values based on the scores and weights of the second-level dimensions, set the thresholds of each first-level index based on the comprehensive importance of the devices, calculate the first-level dimension index scores based on the first-level dimension index values and the first-level index thresholds, and calculate the static evaluation total score based on the first-level dimension index scores and their evaluation weights to obtain a static evaluation sub-model; S3. Collect various behavior information of devices and set corresponding information risk thresholds, set the number and size of analysis windows based on the comprehensive importance of the devices, calculate the risk values of the analysis windows, calculate the behavior information risk values based on the window risk values and the information risk thresholds, and when the cumulative sum of the behavior information risk values is greater than 1, perform pedigree analysis to draw a behavior information pedigree flowchart to obtain a dynamic evaluation sub-model; S4. Construct a protection capability evaluation model based on the static evaluation sub-model and the dynamic evaluation sub-model, and update the evaluation model based on the self-check cycle and self-check dimensions of the model.
[0023] In some embodiments, during the execution of step S1, it includes: S1.1. Collect the evaluation dimensions of device importance; S1.2. Set the index weights for different evaluation dimensions; S1.3. Calculate the comprehensive importance of the device.
[0024] Specifically, during the execution of step S1.1, in the process of collecting the evaluation dimensions of device importance, the evaluation dimensions of device importance include but are not limited to device type, device function, device storage, data types processed, value and sensitivity of the involved data, location in the network where the device is located, connection type of the device, roles and usage frequencies of device users, and dependence of device services.
[0025] Furthermore, when executing step S1.2, set the index weights for different evaluation dimensions according to the relative importance of the evaluation dimensions; for example, different types of terminal devices, including servers, workstations, mobile devices, Internet of Things devices, etc., have different roles in the business, and servers usually carry key business systems, and their importance is higher than that of ordinary office equipment, so their weights need to be set higher.
[0026] Specifically, during the execution of step S1.3, it includes: S1.3.1. Score different evaluation dimensions; S1.3.2. Calculate the original importance of the device based on the scores and weights of different evaluation dimensions; S1.3.3. Modify the original importance of the device to obtain the comprehensive importance of the device.
[0027] Specifically, during the execution of step S1.3.1, score the importance of different evaluation dimensions to obtain importance scores, and the scoring methods include but are not limited to AHP, expert scoring, and cross-dimension horizontal comparison scoring; and each dimension of each device needs to be scored.
[0028] Furthermore, when executing step S1.3.2, calculate the original importance of the device based on the index weights and importance scores of the evaluation dimensions, and the calculation method is to perform weighted summation for each evaluation dimension.
[0029] Furthermore, when executing step S1.3.3, set additional importance scores for the device based on the device users, and calculate the comprehensive importance of the device based on the original importance of the device and the additional importance scores.
[0030] In some embodiments, during the execution of step S2, it includes: S2.1. Construct multi-level evaluation indicators and set corresponding evaluation weights; S2.2. Construct a static evaluation sub - model.
[0031] Specifically, during the execution of step S2.1, it includes: collecting the first - level dimensions for the evaluation of the security protection capabilities of terminal devices, dividing the first - level dimensions to obtain corresponding second - level dimensions, and setting the evaluation weights for the first - level and second - level dimensions.
[0032] Actually, when the first - level dimensions include the technical protection capability dimension, the security management and operation and maintenance dimension, the threat detection and response dimension, the terminal device management dimension, and the security operation dimension.
[0033] Further, the second - level dimensions of the technical protection capability dimension include anti - virus and malware protection, firewall and intrusion detection, data encryption and access control, and kernel - level protection.
[0034] Further, set the evaluation weights for the first - level and second - level dimensions.
[0035] Specifically, during the execution of step S2.2, it includes: scoring the second - level dimensions, calculating the first - level dimension index values based on the scores and weights of the second - level dimensions, setting the threshold for each first - level index based on the comprehensive importance of the device, calculating the first - level dimension index scores based on the first - level dimension index values and the first - level index thresholds, calculating the static evaluation total score based on the first - level dimension index scores and their evaluation weights, and obtaining the static evaluation sub - model.
[0036] Further, during the process of calculating the first - level dimension index scores based on the first - level dimension index values and the first - level index thresholds, it includes: when the first - level dimension index value is less than the first - level index threshold, the first - level dimension index score is 0; otherwise, the first - level dimension index score is the first - level dimension index value.
[0037] Further, during the process of calculating the static evaluation total score based on the first - level dimension index scores and their evaluation weights, it includes: when there is a situation where one of the first - level dimension index scores is 0, the static evaluation total score is 0; when all the first - level dimension index scores are not 0, then perform weighted summation based on the first - level dimension index scores and their evaluation weights to obtain the static evaluation total score.
[0038] In some embodiments, during the execution of step S3, it includes: S3.1. Collect and pre - process the behavior information of the device; S3.2. Set the analysis window; S3.3. Calculate the risk value of the analysis window; S3.4. Calculate the risk value of the behavior information; S3.5. Judge whether blood relationship analysis is required based on the risk value of the behavior information; S3.6. Construct a dynamic evaluation sub - model.
[0039] Specifically, during the execution of step S3.1, it includes: collecting behavior information and preprocessing various types of collected behavior information, including data standardization, normalization related processing logics; the behavior information includes but is not limited to device usage records, device repair records, device operation logs, alarm logs, associated devices of the device, device network topology information, and device traffic information.
[0040] Further, execute step S3.2 to set the number and size of the analysis windows based on the comprehensive importance of the device. The size of the device window, that is, the time domain range of device dynamic analysis; and the number and size of the windows are generally determined by business experts.
[0041] Specifically, during the execution of step S3.3, it includes: performing content assignment based on whether there is malicious risk in the information content in the analysis window to obtain a window value of a one-dimensional vector, setting weights based on the position of the information content, and performing weighted summation of the value of the information content and the weights to obtain a single analysis window risk value.
[0042] For example, when setting weights for each information content in window i, the weight of information content j located at the last position in window i is set to 1, and the weights of information contents in other positions are set to 1 / (d + 1), where d represents the distance between this information content and information content j; (the distance can be represented by the number of intervening elements. For example, in [1, 2, 3, 4, 5, 6, 7], the distance between element 1 and element 7 is 6).
[0043] Actually, during the process of performing content assignment based on whether there is malicious risk in the information content in the analysis window, by collecting in real time malicious or risky IPs, domain names, software vulnerabilities, destructive events, etc. on offline and online networks, forming a real-time blacklist, and sequentially matching the traffic in the window with the real-time blacklist. If a match is found, it is marked as risky and assigned a value of 1, otherwise 0.
[0044] Specifically, during the execution of step S3.4, it includes: calculating the behavior information risk value based on the window risk value and the information risk threshold, calculating the number of windows that the behavior information has, setting window weights based on the window position, and performing weighted summation of the window risk value and its weights to obtain a multi-window risk sum; when the multi-window risk sum is greater than the corresponding information risk threshold, the behavior information risk is 1, otherwise 0.
[0045] Further, execute step S3.5. When the cumulative sum of the behavior information risk values is greater than 1, perform lineage analysis to draw a behavior information lineage flow chart.
[0046] In fact, during the process of blood relationship analysis, first, for the preprocessed behavior information, various types of behavior information are clustered according to the time dimension using a clustering algorithm. The clustering algorithm includes the Kmeans and FCM algorithms. Subsequently, based on a certain type of behavior information with a risk value of 1, window information with risks, the element positions corresponding to the risk points within the window, and other contemporaneous window information are obtained. Starting from the risk point information within a certain window, common graph processing frameworks are used for real-time analysis and calculation, and then a blood relationship flow chart of behavior information is drawn.
[0047] Specifically, during the execution of step S3.6, it includes: setting the trigger mechanism and execution period of the dynamic evaluation sub-model; setting the caching mechanism for behavior information risk value analysis and blood relationship analysis; encapsulating the information preprocessing, behavior information risk value analysis, and blood relationship analysis processes.
[0048] Furthermore, during the process of setting the caching mechanism for behavior information risk value analysis and blood relationship analysis, it includes: for the same device, calculating the cosine similarity of all parameters twice based on the similarity method, and judging whether it is necessary to recalculate the behavior information risk value and blood relationship analysis based on the similarity.
[0049] In some embodiments, during the execution of step S4, it includes: S4.1. Construct a protection ability evaluation model; S4.2. Set the model self-check mechanism.
[0050] Specifically, during the execution of step S4.1, it includes: setting the update mechanism of the static sub-model and calculating the optimal execution period of the dynamic sub-model; respectively executing the static evaluation sub-model and the dynamic evaluation sub-model to obtain the static evaluation total score, various types of behavior information risk values, and the information blood relationship flow chart, and fusing the three to obtain the protection ability evaluation model.
[0051] In fact, the update mechanism of the static sub-model is generally given by business experts, such as when the network topology changes, when it has not been updated for a long time, or when the device importance changes.
[0052] Furthermore, during the process of calculating the optimal execution period of the dynamic sub-model, it includes: randomly giving an execution period, executing the dynamic sub-model multiple times based on the execution period to obtain multiple execution results, recording the number of times the execution results are the same. When the number is not 1, update the execution period until the number is equal to 1 to obtain the optimal execution period.
[0053] Specifically, during the execution of step S4.2, it includes: setting the self-check period, that is, the period for detecting that the model operation has produced conclusions that do not meet expectations, and setting the self-check dimensions, such as the evaluation results of the sub-models are always unchanged or vary greatly, and the evaluation results are significantly different from experience.
[0054] In fact, through the self-checking mechanism, it is found that some parameters of the model do not match the scenario seriously during operation or in different scenarios, thus assisting the operation and maintenance personnel to find the problems existing in the model in a timely manner.
[0055] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention described in the claims. Moreover, the present invention described herein may have other embodiments and can be implemented or realized in various ways.
Claims
1. A method for constructing an intelligent network security terminal protection capability evaluation model, characterized in that: The following steps are involved: Collecting equipment importance evaluation dimensions and setting indicator weights for different evaluation dimensions, and calculating the comprehensive importance of equipment based on the evaluation dimensions and their indicator weights; Collect the first-level dimensions of terminal equipment security protection capability assessment, divide the first-level dimensions to obtain corresponding second-level dimensions, set assessment weights for the first-level dimensions and the second-level dimensions, and score the second-level dimensions. Calculate the first-level dimension index value based on the score of the second-level dimension and its weight, set each first-level index threshold based on the comprehensive importance of the equipment, calculate the first-level dimension index score based on the first-level dimension index value and the first-level indicator threshold, calculate the static assessment total score based on the first-level dimension index score and its assessment weight, and obtain a static assessment sub-model; Collect various types of behavior information of the device and set the corresponding information risk threshold, set the number and size of the analysis window based on the comprehensive importance of the device, calculate the risk value of the analysis window, calculate the behavior information risk value based on the window risk value and the information risk threshold, and when the cumulative sum of the behavior information risk values is greater than 1, perform lineage analysis to draw a behavior information lineage flow chart to obtain a dynamic evaluation sub-model; A protection capability assessment model is constructed based on the static assessment sub-model and the dynamic assessment sub-model, and the assessment model is updated based on the self-inspection cycle and self-inspection dimension of the model.
2. According to claim 1, a method for constructing an intelligent network security terminal protection capability evaluation model is characterized in that: The process of calculating the comprehensive importance of the equipment based on the evaluation dimensions and their indicator weights includes: Scoring the importance of different evaluation dimensions to obtain importance scores. Scoring methods include but are not limited to AHP, expert scoring, and dimension horizontal comparison scoring; The original importance of the equipment is calculated based on the indicator weights of the evaluation dimensions and their importance scores. The additional importance score of the equipment is set based on the equipment users. The comprehensive importance of the equipment is calculated based on the original importance of the equipment and the additional importance score.
3. According to claim 1, a method for constructing an intelligent network security terminal protection capability evaluation model is characterized in that: The process of calculating the first-level dimension indicator score based on the first-level dimension indicator value and the first-level indicator threshold includes: When the first-level dimension indicator value is less than the first-level indicator threshold, the first-level dimension indicator score is 0, otherwise the first-level dimension indicator score is the first-level dimension indicator value.
4. According to claim 1, a method for constructing an intelligent network security terminal protection capability evaluation model is characterized in that: The process of calculating the total static evaluation score based on the first-level dimension indicator scores and their evaluation weights includes: When a first-level dimension indicator scores 0, the total score of the static assessment is 0; When all first-level dimension indicators are not 0, the total static evaluation score is obtained by weighted summing up the first-level dimension indicator scores and their evaluation weights.
5. According to claim 1, a method for constructing an intelligent network security terminal protection capability evaluation model is characterized in that: The process of calculating the risk value of the analysis window includes: Based on whether the information content in the analysis window has malicious risks, the content is assigned a value to obtain a one-dimensional vector window value, and a weight is set based on the position of the information content. The value of the information content and the weight are weighted and summed to obtain a single analysis window risk value.
6. According to claim 1, a method for constructing an intelligent network security terminal protection capability assessment model is characterized in that: The process of calculating the behavior information risk value based on the window risk value and the information risk threshold includes: Calculate the number of windows of the behavior information, set window weights based on window positions, and perform weighted summation based on the window risk values and their weights to obtain a multi-window risk sum; When the multi-window risk sum is greater than the corresponding information risk threshold, the behavior information risk is 1, otherwise it is 0.
7. The method for constructing an intelligent network security terminal protection capability evaluation model according to claim 1, characterized in that: Before obtaining the dynamic evaluation sub-model, include: Set the trigger mechanism and execution cycle of the dynamic evaluation sub-model; Set up a cache mechanism for behavior information risk value analysis and blood relationship analysis; Encapsulation information preprocessing, behavior information risk value analysis, and blood relationship analysis process.
8. The method for constructing an intelligent network security terminal protection capability evaluation model according to claim 7, characterized in that: The process of setting up the cache mechanism for behavior information risk value analysis and blood relationship analysis includes: For the same device, the cosine similarity of all parameters is calculated twice based on the similarity method, and based on the similarity, it is determined whether the behavior information risk value and the blood relationship analysis need to be recalculated.
9. The method for constructing an intelligent network security terminal protection capability evaluation model according to claim 1, characterized in that: The process of constructing the protection capability evaluation model based on the static evaluation sub-model and the dynamic evaluation sub-model includes: Set the update mechanism of the static sub-model and calculate the optimal execution period of the dynamic sub-model; The static assessment sub-model and the dynamic assessment sub-model are executed separately to obtain the static assessment total score, the risk values of various behavioral information, and the information lineage flow chart, and the three are integrated to obtain the protection capability assessment model.
10. The method for constructing an intelligent network security terminal protection capability evaluation model according to claim 9, characterized in that: The process of calculating the optimal execution cycle of the dynamic sub-model includes: An execution cycle is randomly given, and a dynamic sub-model is executed multiple times based on the execution cycle to obtain multiple execution results. The number of times the execution results are the same is recorded. When the number is not 1, the execution cycle is updated until the number is equal to 1, and the best execution cycle is obtained.
Citation Information
Patent Citations
Network security situation analysis model and network security assessment method
CN109246153A
Risk assessment method and device, electronic equipment and computer readable storage medium
CN117240553A
Power distribution equipment waterlogging risk prediction method and system based on neural network
CN117273193A
Fault automatic detection and repair method for self-healing intelligent power line
CN118739184A
Brain dysfunction assessment method, brain dysfunction assessment device, and program thereof
US20160100788A1