Abnormal input detection model training method and abnormal input detection method

By combining the abnormal input detection model training method with the hidden Markov chain model and YARA rules, the detection problem of malicious user behavior in the remote desktop system is solved, which improves security and efficiency and reduces alert fatigue.

CN120750558APending Publication Date: 2025-10-03INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510769527.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

There is a security threat in remote desktop systems where malicious users can carry out malicious behaviors through remote desktops. Traditional user behavior auditing methods require a lot of storage space and manpower costs, and traditional intrusion detection systems cannot detect abnormal behaviors of pixels and keyboard and mouse input data.

Method used

An abnormal input detection model training method is adopted. By obtaining abnormal input text and background information, it is converted into an alarm sequence. The hidden Markov chain model is used for detection. The keyboard input data and clipboard data are combined, and the abnormal input text is matched using YARA rules. The text is then deployed to a virtual machine for detection.

Benefits of technology

It achieves precise matching of abnormal text, reduces alert fatigue, can identify multi-stage attacks, and improves the security and efficiency of remote desktop systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750558A_ABST
    Figure CN120750558A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network security, and particularly relates to an abnormal input detection model training method and an abnormal input detection method. Obtaining an abnormal input text and abnormal input background information corresponding to the abnormal input text; converting the abnormal input text and the abnormal input background information into an alarm sequence; and inputting the alarm sequence into an invisible Markov chain to obtain a trained abnormal input detection model. Deploying the abnormal input detection model to a virtual machine; and detecting a terminal connected to the virtual machine through the abnormal input detection model to realize abnormal input detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and specifically relates to an abnormal input detection model training method and an abnormal input detection method. Background Art

[0002] Remote desktops are highly valued for both entertainment and office use. Security requirements are high in office settings, and auditing user behavior is essential for both security audits and security protection. Furthermore, user operations on remote desktops are directly related to information security and work efficiency. Auditing user behavior not only provides managers with a comprehensive monitoring perspective but also effectively regulates user behavior. When users know their operations are recorded and traceable, they are more likely to comply with corporate information security policies and avoid security risks caused by improper operations. At the same time, audit data provides managers with intuitive feedback on user behavior, facilitating the timely identification of irregular operations and targeted training and corrections, thereby reducing the occurrence of improper behavior at the source and creating a safe, efficient, and standardized remote work environment.

[0003] Remote desktop user behavior auditing is achieved by deploying a security audit system in the remote desktop system. Generally speaking, the system should have monitoring and replay functions. When the user uses the remote desktop, the monitoring function is activated to monitor the user's activities; when the user is not using the remote desktop, the replay function is activated to replay the user's various activities during use. The administrator can use this to determine whether the user has performed malicious behavior. For example, the method proposed by Cui et al. in the paper "The design and implementation of remote desktop access audit system". The system designed in this paper can be used for the three command-type transmission protocols RDP, VNC, and X11. It is deployed in the form of a physical bypass gateway without changing the original network topology. It includes five modules, among which the more critical ones are the agent module, the monitoring and replay module, and the monitoring and replay plug-in module:

[0004] (1) Proxy Module: As the core component of the system, the proxy module is responsible for proxying, forwarding, monitoring, recording, and saving all user operations on the remote desktop system. In addition, it is also responsible for establishing and maintaining the connection with the remote desktop system.

[0005] (2) Monitoring and replay module: This module extracts the data required for monitoring and replay from the storage space and passes it to the monitoring and replay plug-in. This module also has an authentication module to verify the legitimacy of the replay and monitoring requests.

[0006] (3) Monitoring and replay plug-ins: The monitoring plug-in is used to monitor ongoing remote desktop sessions in real time, and the replay plug-in replays ended remote desktop sessions according to the needs of security auditors.

[0007] In addition, in order to adapt to different remote desktop protocols, the system has customized a data format for storing remote desktop image data. This data format refers to the data format transmitted by the RDP protocol.

[0008] Deploy a network intrusion detection system at the network edge to monitor network traffic from remote desktops, analyze network protocols, extract protocol information, and generate traffic statistics. Based on predefined rules, it identifies potential attacks in network traffic and generates alerts.

[0009] User behavior auditing systems can protect against security threats such as malicious users performing malicious actions through remote desktops, but they also have some significant limitations and challenges.

[0010] (1) User behavior auditing requires complete recording and replay of user behavior on remote desktops. However, a large number of remote desktops are often deployed in remote desktop systems, which requires a large amount of space to store the behavior information of all remote desktops deployed in the system.

[0011] (2) User behavior auditing relies on manual auditing by administrators. Auditing remote desktops deployed in all systems requires a lot of manpower costs and may lead to alarm fatigue due to the excessive number of events that need to be audited. That is, security operators are unable to respond to alarms due to the large number of alarms they handle every day.

[0012] (3) Traditional data transmission methods transmit application data across the network. Intrusion detection systems, based on pattern matching, can detect abnormal behavior in network traffic. However, in a remote desktop architecture, the network transmits pixel and keyboard input data, not application data. Traditional intrusion detection systems cannot detect abnormal behavior through network traffic. Summary of the Invention

[0013] The present invention aims to address the security threat of malicious users carrying out malicious behaviors through the remote desktop in a remote desktop system, and provides a method for training an abnormal input detection model, which includes the following steps:

[0014] Acquire abnormal input text and abnormal input background information corresponding to the abnormal input text;

[0015] Converting the abnormal input text and the abnormal input background information into an alarm sequence;

[0016] The alarm sequence is input into a hidden Markov chain to obtain a trained abnormal input detection model.

[0017] Furthermore, the abnormal input text is obtained by the following method:

[0018] Capture keyboard input data and clipboard data;

[0019] Restoring the input data to user input text, performing anomaly matching on the user input text through YARA, and outputting the anomaly input text;

[0020] The clipboard data is detected by a remote desktop component, and another abnormal input text is output.

[0021] Furthermore, the abnormal input text includes:

[0022] The names of common network security tools, malicious codes, and PowerShell commands.

[0023] Furthermore, the abnormal input background information is obtained by the following method:

[0024] Retrieve the current window handle through the GetForegroundWindow function to get the user's current window;

[0025] The program corresponding to the current window is used as the abnormal input background information.

[0026] Furthermore, the abnormal input text and the abnormal input background information are converted into an alarm sequence through an alarm flow manager.

[0027] Furthermore, in response to the alarm flow manager receiving a set number of the abnormal input texts and the abnormal input background information, the alarm sequence is input into a hidden Markov chain.

[0028] The present invention also provides a method for detecting abnormal input, the steps of which include:

[0029] Deploy the above abnormal input detection model to the virtual machine;

[0030] The abnormal input detection model is used to detect the terminal connected to the virtual machine to achieve abnormal input detection.

[0031] Furthermore, a management platform is provided to be connected to the host machine where the virtual machine is located; the management platform is used to receive the detection result of the abnormal input detection model.

[0032] The present invention also provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the above method.

[0033] The present invention also provides a storage medium storing a computer program, wherein the computer program implements the above method when executed by a computer.

[0034] The beneficial effects of the present invention are as follows:

[0035] (1) This method proposes a user input anomaly detection technology that combines text anomaly and security context detection. This technology can accurately match abnormal text and detect the software applicable to the user's current input. Combining these two dimensions, it can accurately locate the user's abnormal input behavior. This solves the security threat of malicious users carrying out malicious behavior through the remote desktop in the vGTP remote desktop system, and strengthens the security of the vGTP remote desktop system.

[0036] (2) This method is more efficient than the security audit system method and will not cause alarm fatigue due to excessive information that needs to be audited.

[0037] (3) This method uses a hidden Markov chain model to detect user input anomalies. In the hidden Markov chain model, the abnormal text and security context are combined as the observed state, and the stage of the user's abnormal input behavior is used as the hidden state. The evaluation and prediction problems of the hidden Markov chain are used to detect abnormal user input behavior. The use of the hidden Markov mechanism can not only reduce the problem of misidentifying suspicious normal behavior as abnormal behavior, but also identify the attacker's current attack stage in the case of multi-stage attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 Schematic diagram of the remote desktop architecture relationship according to a specific embodiment of the present invention.

[0039] Figure 2 This is a schematic diagram of implementing a malicious behavior model according to a specific embodiment of the present invention.

[0040] Figure 3 The flowchart of the training abnormal input detection model according to the specific embodiment of the present invention.

[0041] Figure 4 The flowchart of collecting abnormal input text according to a specific embodiment of the present invention.

[0042] Figure 5 The flowchart of collecting abnormal behavior background information according to a specific embodiment of the present invention. DETAILED DESCRIPTION

[0043] The present invention will be described in further detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0044] Remote desktop usually consists of four components: 1) Virtual machine: the virtualization device of the remote desktop system. 2) Host machine: the server that installs the virtualization platform and hosts the virtual machine. 3) Terminal: the device for users to connect to the remote desktop system, including zero terminal, thin terminal with remote desktop app installed, and fat terminal with remote desktop app installed. 4) Protocol part: the protocol used by the server and client to communicate. The architectural relationship of remote desktop is as follows Figure 1 shown.

[0045] Compared with traditional desktops, the security advantage of remote desktops is that all application data processing occurs on the host side. The terminal used by the user does not process or save application data, nor does it transmit application data on the network. When used properly, application data will not be leaked during transmission, nor will local data be lost due to terminal attacks. However, remote desktops also face new security risks, such as abnormal user input, that is, security threats caused by malicious users entering and executing malicious code on the remote desktop. Figure 2 As shown in Figure 1, a malicious user can use remote desktop to carry out malicious activities. The malicious user can start the malicious tool by entering the name or instructions of the malicious tool through the command line. VM1 executes the malicious tool to attack VM2, VM3 or the server.

[0046] The first aspect of this embodiment discloses a method for training an abnormal input detection model, wherein the model takes an alarm sequence converted from abnormal input text and abnormal input background information as input, such as Figure 3 shown.

[0047] In this embodiment, a method for collecting abnormal input text is disclosed. The specific process is as follows: Figure 4 As shown, it includes (1) collecting keyboard input data: obtaining the user's keyboard input data by capturing the input data of the virtual machine keyboard driver. (2) collecting shared clipboard data: obtaining the user's shared clipboard data by capturing the virtual machine's shared clipboard driver. (3) restoring user input text: restoring the user input text on the remote desktop based on the collected keyboard input data. (4) matching abnormal input text rules: using YARA to match the user input text with the user's shared clipboard data. When abnormal input text is matched, a warning is issued and the type of abnormal input text is indicated.

[0048] This method further discloses a method for collecting keyboard input data. By capturing input data from a virtual machine keyboard driver, user keyboard input data is obtained. Keyboard driver input data is expressed in the form of a keycode. A keycode typically refers to a unique numeric code assigned to each key on a keyboard. In computer programming and hardware, when a user presses a key on a keyboard, the operating system receives a specific digital signal, which is the keycode for that key.

[0049] This method further discloses a method for restoring user input text. The user input text restoration is based on the collected keyboard input data. The collected keyboard input data exists in the form of keycodes, so it needs to be processed to obtain the user input text. Typically, the keycode is detected to determine what text the user has entered. In this method, an example is used to illustrate the text restoration method in more detail:

[0050] In one example, the keycodes collected are 65, 66, 67, and 68. These numbers represent the keycode values ​​for the letters A, B, C, and D, respectively. Scanning from front to back, detecting 65 means the user entered A, detecting 66 means the user entered B, and so on. The keycodes represent the input text ABCD.

[0051] In special cases, that is, when the user enters a key combination, it is necessary to pay extra attention to the key state corresponding to the keycode, that is, whether the key is in the press state or the release state. In another example, the keycodes collected are 16 (press), 186, and 16 (release). Among them, 16 is the keycode of the "shift" key, and 186 is the keycode of the ";" key. Detecting key 16 in the press state means that the "shift" key is pressed; then detecting key 186 means that the ";" key is pressed, and the combination of the "shift" key and the ";" key is input:, so the user currently enters a ":". Finally, detecting 16 (release) means that the "shift" key is released, which also means that the key combination input is completed. In summary, the collected keycode indicates that the user has entered a symbol ":".

[0052] In this method, a method for matching abnormal input text rules is further disclosed, and abnormal text rule matching is performed using YARA. YARA is a tool for malware research and detection. It uses YARA rules to describe the patterns and characteristics of malware or other suspicious files. The rules used are called YARA rules. The rule syntax is similar to C language. Each rule starts with the rule keyword, followed by the unique identifier of the rule. The rule content generally consists of two parts: string definition (strings) and condition (condition). The string definition has three forms: hexadecimal string, text string and regular expression. In this method, text string is used. The condition is an expression based on Boolean logic. In addition to strings and condition, there is another part, namely, meta field, which is used to provide metadata information about the rule, including the description, label, product, category, and hazard level of the rule.

[0053] Let's use an example to introduce the rules and explain in more detail how YARA works:

[0054]

[0055] The meaning of this rule is to detect the file my_text_string. If it is detected that the file contains the string it is malicious code, an alarm will be issued.

[0056] This method uses the names of common network security tools, malicious code, and PowerShell commands to create YARA rules. The input is the restored user input text, and the output is an abnormal text alert. This method defines ten alert types: active scanning software, passive sniffing software, malicious documents, malicious URLs, penetration PowerShell scripts, information collection PowerShell scripts, impact PowerShell scripts, execution PowerShell scripts, malicious code, and malicious web page code.

[0057] In this embodiment, a method for collecting abnormal input background information is disclosed, such as Figure 5 In order to reduce the overhead caused by the detection logic, the present invention triggers the abnormal input background information detection logic only when a warning of abnormal input text appears. The present invention uses a method of system call to perform abnormal input background information detection.

[0058] The background information of abnormal input refers to the software that the user is using when the abnormal text alarm is triggered. In this method, five types of abnormal input background information are defined, namely, input using document software, input using shell or console software, input using browser software, input using programming software, and input using other software.

[0059] In the Windows environment, a window object is identified by a unique value called a window handle (HWND). Therefore, the foreground application currently in use can be determined by obtaining the window handle. Windows provides the GetForegroundWindow function to retrieve the handle of the foreground window, which is the window currently in use. In the C language environment, this function is defined as HWND GetForegroundWindow(), and the return value type is HWND.

[0060] In this model training method, the collected abnormal input text and abnormal input background information are processed for alarm processing. The purpose of alarm processing is to pre-process the alarm information passed from the abnormal text input detection component and send it to the detection model. The alarm information received by the detection model is in the form of an alarm plus the alarm background information, and the output is an alarm sequence. For example, the abnormal text input detection component issues a malicious code input alarm, and the abnormal input background information detection component detects that the background information of the alarm is input using a Word document. Then, the content received by the alarm stream manager should be malicious code input using a Word document. The following provides an example of an alarm sequence:

[0061] Malicious_PowerShell_initial_accessAdministrator: Command Prompt

[0062] Malicious_PowerShell_initial_accessAdministrator: Command Prompt

[0063] Malicious_PowerShell_initial_accessAdministrator: Command Prompt

[0064] After receiving a certain number of alert sequences, they are forwarded to the detection model. This is because a single anomalous input does not necessarily indicate an attack, so multiple anomalous inputs must be evaluated together. Specifically, when the malicious input detection system receives n alerts, it sends them to the detection model. n is a user-defined value that represents the maximum number of alerts to be processed and can be anywhere from 6 to 15.

[0065] In this embodiment, a Markov chain is used as a model to detect malicious input. First, the Markov chain is introduced.

[0066] A Markov chain describes the process of transitioning from one state to another in a series of discrete events. This process satisfies the Markov property, which states that the current state depends only on the state at the previous moment and is independent of states further in advance. Markov chains are categorized as explicit and implicit. The explicit Markov chain refers to a Markov chain where the current state can be directly observed, while the implicit Markov chain refers to a chain where the current state cannot be directly observed and the response state can only be indirectly observed. Generally speaking, unobservable system states are called implicit states, while observable results are called observed results.

[0067] Hidden Markov chain has three important matrices, which describe a hidden Markov chain:

[0068] (1) State transition matrix: The state transition matrix is ​​a matrix that represents the probability of each state transferring to the next state. It is usually represented by A. In the matrix, the i-th row and j-th column a ij represents the probability of transitioning from the i-th state to the j-th state.

[0069] (2) Observation probability matrix: The observation probability matrix represents the probability of observing each observation result in a given hidden state, generally represented by B. In the matrix, row i and column l are i (l) represents the probability of observing the observation result l given the hidden state i.

[0070] (3) Steady-state matrix: The steady-state matrix, also known as the initial state probability matrix, defines the probability of the system's initial state and is generally represented by π. In this vector, the mth row represents the probability that the initial hidden state is m.

[0071] Hidden Markov chains have three basic problems:

[0072] (1) Probability calculation problem: Given model parameters λ = (A, B, Π) and an observation sequence y, calculate the probability P(y|λ) of observing y given the model parameters λ. This is also called the evaluation problem. This problem is solved using either a forward or backward algorithm.

[0073] (2) Prediction problem: Given model parameters λ = (A, B, Π) and an observation sequence y, calculate the hidden state sequence x that maximizes P(x|y,λ). The Viterbi algorithm is used to solve this problem.

[0074] (3) Learning problem: Given an observation sequence y, find the system parameter λ that makes the probability P(x|λ) of the sequence appear. This problem is solved using the Baum-Welch algorithm based on the EM algorithm.

[0075] Existing knowledge representation hidden Markov chain models have demonstrated excellent performance in analyzing time series data and handling multi-stage attacks. They are robust and flexible, capable of identifying the current attack stage and predicting future attack behavior. In remote desktop systems, malicious user input behavior often exhibits multi-stage temporal characteristics. Therefore, the present invention employs a hidden Markov chain model. In this hidden Markov chain model, the received alert content represents the observation result, and the attack tactic represents the hidden state.

[0076] This paper draws on the 14 tactics of the ATT&CK framework and the common steps of RDP protocol lateral movement attacks. To better meet the purpose of detecting malicious input from remote desktop users, this paper categorizes malicious input behaviors into four tactics: "reconnaissance," "resource exploitation," "execution," and "normal." In a hidden Markov model, these four tactics represent hidden states.

[0077] In this embodiment, the training process of the malicious input detection model is further disclosed. The input of the malicious input detection model is an alarm sequence, and the output is whether malicious input has occurred.

[0078] The goal of model training is to calculate the parameter λ corresponding to each attack type. To achieve this, a complete set of malicious input behaviors, encompassing various tactics, was simulated on a remote desktop. Alert sequences were collected to form a training set, which was then used to train the model. The main process of model training involves calculating the parameters λ = {A, B, Π} of the hidden Markov chain, where A is the state transition matrix, B is the observation probability matrix, and Π is the steady-state vector. Through model training, a list of model parameters Λ = {λ1, λ2, …, λn} is obtained, where each λ corresponds to a malicious input model.

[0079] For an alarm sequence, this invention preprocesses it using character matching. This involves character matching using two dictionaries: a text alarm dictionary and a background information dictionary. This matching is then mapped to a number between 0 and 49. This is because this solution allows for 50 possible combinations of text alarms and background information. For the training set, the corresponding hidden state (i.e., tactic) for each explicit state (i.e., the aforementioned 50 combinations) is known. Therefore, in the training set, each explicit state is mapped to a hidden state.

[0080] The present invention utilizes statistical methods to train the state transfer probability matrix and the observation probability matrix.

[0081] For the state transition probability matrix, the number of times a hidden state in the training set transitions to other hidden states is counted to calculate the state transition probability matrix. It should be noted that the transition from other states to state 1 (i.e., reconnaissance tactics) is not counted. This is based on the consideration that malicious users will not complete other actions before conducting reconnaissance. The specific calculation formula is as follows

[0082]

[0083] Among them, λ ij is the number of times hidden state i is transferred to hidden state j, and N is the total number of hidden states.

[0084] For the observation probability matrix, the probability of the visible state corresponding to a certain hidden state in the training set is counted, and the observation probability matrix is ​​calculated based on this. It should be noted that due to the characteristics of the HMM, the observation probability matrix cannot contain any zeros, otherwise the result will be a negative infinity error when executing the HMM evaluation problem. Therefore, the matrix needs to be smoothed. Laplace smoothing is selected for processing, that is, a smoothing amount is added to all the visible state times corresponding to a certain hidden state, and then the probability of occurrence is calculated. The specific calculation formula is as follows:

[0085]

[0086] Among them, Ω i (l) represents the number of times the explicit state l appears when the hidden state i is in the state i; M is the total number of explicit states, and δ is the smoothing amount.

[0087] For the initial state probability matrix Π, set Π = [1, 0, 0, 0], that is, the initial state of the malicious input behavior is considered to be reconnaissance.

[0088] The second aspect of this embodiment discloses an abnormal input detection method, which deploys a trained abnormal input detection model to a virtual machine, and detects terminals connected to the virtual machine through the abnormal input detection model to identify attacks.

[0089] The purpose of attack identification is to determine whether the terminal has malicious input behavior. It is based on the evaluation problem of hidden Markov chains. The input of attack identification is the received alarm sequence Y and the model parameter list Λ = {λ1, λ2, ..., λn}. The steps are as follows:

[0090] (1) Using the forward algorithm, calculate P(O|λi) under different model parameters.

[0091] (2) Compare P(O|λi) and find the model parameter λk that maximizes it.

[0092] (3) P(O|λk) is compared with a pre-designed threshold. If it is greater than the threshold, it is considered that malicious input has occurred and the current malicious input conforms to the attack pattern represented by λk, and a malicious input behavior alarm is issued. If it is less than the threshold, it is marked as pending and submitted to manual review.

[0093] The purpose of attack phase determination is to identify the user's current malicious input phase, allowing administrators to understand the intelligence the attacker may possess and better defend against attacks. This is based on the prediction problem of hidden Markov chains. The input for attack phase determination is the received alert sequence Y and the model parameter λk. The steps are as follows:

[0094] a. Use the Viterbi algorithm to calculate the most likely hidden state sequence X

[0095] b. Based on X, that is, the currently received alarm information, determine the current malicious input stage.

[0096] After completing the malicious input detection, the detection results will be submitted to the remote desktop management platform. The detection results include malicious input behavior alerts and the stages of malicious input that have been carried out.

Claims

1. A method for training an abnormal input detection model, comprising the following steps: Acquire abnormal input text and abnormal input background information corresponding to the abnormal input text; Converting the abnormal input text and the abnormal input background information into an alarm sequence; The alarm sequence is input into a hidden Markov chain to obtain a trained abnormal input detection model.

2. The method according to claim 1, characterized in that The abnormal input text is obtained by the following method: Capture keyboard input data and clipboard data; The input data is restored to user input text, anomaly matching is performed on the user input text and the clipboard data, and the abnormal input text is output.

3. The method according to claim 2, characterized in that The abnormal input text includes: The names of common network security tools, malicious codes, and PowerShell commands.

4. The method according to claim 1, wherein The abnormal input background information is obtained by the following method: Retrieve the current window handle through the GetForegroundWindow function to get the user's current window; The program corresponding to the current window is used as the abnormal input background information.

5. The method according to claim 1, wherein The exception input text and the exception input context information are converted into an alarm sequence by an alarm flow manager.

6. The method according to claim 5, characterized in that In response to the alarm flow manager receiving a set number of the abnormal input texts and the abnormal input background information, the alarm sequence is input into a hidden Markov chain.

7. A method for detecting abnormal input, comprising the steps of: Deploying the abnormal input detection model described in any one of claims 1 to 6 to a virtual machine; The abnormal input detection model is used to detect the terminal connected to the virtual machine to achieve abnormal input detection.

8. The method according to claim 7, characterized in that A management platform is set up to be connected to the host machine where the virtual machine is located; the management platform is used to receive the detection result of the abnormal input detection model.

9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, the computer program being configured to be executed by the processor, the computer program comprising instructions for executing the method according to any one of claims 1 to 8.

10. A storage medium storing a computer program, wherein when the computer program is executed by a computer, the method according to any one of claims 1 to 8 is implemented.