Business support device, business support method and business support program

The business support device addresses the challenge of managing numerous anomaly detection results by employing a unified display and search mechanism, facilitating efficient recognition and analysis of desired anomalies across multiple definitions.

JP2025144009APending Publication Date: 2025-10-02OBIC CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024043561
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-19
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing systems struggle to efficiently recognize desired anomalies when numerous detection results are displayed, making it difficult to manage and analyze large volumes of anomaly detection data effectively.

Method used

A business support device that employs a common message layout and table structure to display and search anomaly detection results across multiple alert definitions, allowing for cross-sectional analysis and extraction of desired anomalies using a unified screen format.

Benefits of technology

Facilitates the recognition of desired anomalies even when many are detected, enhancing efficiency and enabling targeted analysis of anomaly detection results without overwhelming the operator.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025144009000001_ABST
    Figure 2025144009000001_ABST
Patent Text Reader

Abstract

To make it easy to recognize a desired abnormality even when many abnormalities are detected.SOLUTION: An alert definition display unit is configured to display an alert definition selection screen for selecting an alert definition of a plurality of alert definitions stored in a first storage unit on a display part. A result data display unit is configured to, of result data stored in a second storage unit by implementing each alert definition, indicating an abnormality of an abnormality detection object and including a determination result, acquire and display the result data including the determination result of the abnormality corresponding to the alert definition selected on the alert definition selection screen. An extraction condition input screen display unit is configured to display, on the display part, an extraction condition input screen allowing for inputting an extraction condition to extract desired result data of the result data on the alert definition selected on the alert definition selection screen. A result data display unit is configured to, when the extraction condition is input via the extraction condition input screen, extract the result data corresponding to the input extraction condition from the second storage unit, and display the result data on the display part.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a business support device, a business support method, and a business support program. [Background technology]

[0002] Patent document 1 (JP Patent Publication No. 2023-134188) discloses an alert AI management device that creates defined groups by grouping audit scenarios based on the nature of the audit content of the alert AI, assigns roles to each group, and appropriately allocates authority to each role, enabling security control.

[0003] This alert AI management device acquires user data for a specific target user. Then, based on the user data, user group member master, user alert definition group relation table, alert AI definition group master, and abnormal value judgment definition table, it identifies the target user's role type, modification authority, and / or alert AI definition for which the target user has viewing authority. This enables security control in alert AI management. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2023-134188 Summary of the Invention [Problem to be solved by the invention]

[0005] Here, in the case of a device that detects anomalies in an anomaly detection target and displays the detection results, if many anomalies are detected, the number of detection results displayed will increase, which can make it difficult to recognize the desired anomaly.

[0006] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a business support device, a business support method, and a business support program that make it easy to recognize desired abnormalities even when many abnormalities are detected, and that can support anomaly detection work for anomaly detection targets. [Means for solving the problem]

[0007] In order to solve the above-mentioned problems and achieve the object, the business support device of the present invention includes: an alert definition display unit that displays, on a display unit, an alert definition selection screen for selecting one or more alert definitions from a plurality of alert definitions stored in a first storage unit; a result data display unit that acquires result data including judgment results of an abnormality corresponding to one or more alert definitions selected on the alert definition selection screen from result data that includes judgment results indicating an abnormality in an anomaly detection target and is stored in a second storage unit by executing each alert definition, and displays the result data on the display unit; and an extraction condition input screen display unit that displays, on the display unit, an extraction condition input screen for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen; and when extraction conditions are input via the extraction condition input screen, the result data display unit extracts result data that corresponds to the input extraction conditions from the second storage unit and displays the result data on the display unit.

[0008] Furthermore, in order to solve the above-mentioned problems and achieve the object, the business support method according to the present invention includes: an alert definition display step in which an alert definition display unit displays, on the display unit, an alert definition selection screen for selecting one or more alert definitions from a plurality of alert definitions stored in a first storage unit; a result data display step in which a result data display unit acquires, from result data including judgment results indicating abnormalities in an anomaly detection target, which is stored in a second storage unit by executing each alert definition, result data including judgment results of abnormalities corresponding to one or more alert definitions selected on the alert definition selection screen, and displays the acquired result data on the display unit; and an extraction condition input screen display step in which an extraction condition input screen display unit displays, on the display unit, an extraction condition input screen for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen; and in the result data display step, when extraction conditions are input via the extraction condition input screen, result data corresponding to the input extraction conditions are extracted from the second storage unit and displayed on the display unit.

[0009] Furthermore, in order to solve the above-mentioned problems and achieve the object, the business support program of the present invention causes a computer to function as: an alert definition display unit that displays, on a display unit, an alert definition selection screen for selecting one or more alert definitions from a plurality of alert definitions stored in a first storage unit; a result data display unit that acquires, from result data that includes judgment results indicating abnormalities in an anomaly detection target and that is stored in a second storage unit by executing each alert definition, result data that includes judgment results of abnormalities corresponding to one or more alert definitions selected on the alert definition selection screen, and displays the acquired result data on the display unit; and an extraction condition input screen display unit that displays, on the display unit, an extraction condition input screen for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen; and when extraction conditions are input via the extraction condition input screen, the result data display unit causes the computer to function so as to extract result data that corresponds to the input extraction conditions from the second storage unit and display the result data on the display unit. [Effects of the Invention]

[0010] The present invention can facilitate the recognition of a desired anomaly even when many anomalies are detected, thereby supporting the anomaly detection work of an anomaly detection target. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a block diagram illustrating a hardware configuration of a task assistance device according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of a layout element storage unit provided in the task assistance device according to the embodiment. [Figure 3] FIG. 3 is a diagram showing an example of a layout configuration of layout elements displayed on a screen in the task support device according to the embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of an alert definition master table provided in the task assistance device according to the embodiment. [Figure 5] FIG. 5 is a diagram showing an example of the first half of a result message template master table provided in the task assistance device according to the embodiment. [Figure 6] FIG. 6 is a diagram showing an example of the second half of the result message template master table provided in the task assistance device according to the embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of an alert execution history detail data table provided in the task support device according to the embodiment. [Figure 8] FIG. 8 is a diagram illustrating a first example of a result message table provided in the task assistance device according to the embodiment. [Figure 9] FIG. 9 is a diagram illustrating a second example of a result message table provided in the task assistance device according to the embodiment. [Figure 10] FIG. 10 is a diagram illustrating a third example of a result message table provided in the task assistance device according to the embodiment. [Figure 11] FIG. 11 is a diagram illustrating a fourth example of a result message table provided in the task assistance device according to the embodiment. [Figure 12]FIG. 12 is a diagram illustrating a fifth example of a result message table provided in the task assistance device according to the embodiment. [Figure 13] FIG. 13 is a diagram illustrating a sixth example of a result message table provided in the task assistance device according to the embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of a determination result table information master table provided in the task assistance device according to the embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a concentrated order transaction analysis result table provided in the business support device according to the embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of a sales discount analysis result table provided in the business support apparatus according to the embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of a purchase lead time analysis result table provided in the business support device according to the embodiment. [Figure 18] FIG. 18 is a flowchart showing the flow of an abnormality display operation of the business support device according to the embodiment of the present invention for accounting data. [Figure 19] FIG. 19 is a diagram showing how an anomaly detection algorithm is executed and the detection result data is input into the determination result table. [Figure 20] FIG. 20 is a diagram showing how an algorithm for detecting an anomaly is executed by the alert definition execution unit, and how data resulting from the detection is stored in a predetermined table. [Figure 21] FIG. 21 is a diagram showing how the display content (message) and the display position on the screen (layout element CD) that are the abnormality detection result are stored in the result message table. [Figure 22] FIG. 22 is a diagram illustrating an example of an execution history of an algorithm for detecting an anomaly. [Figure 23] FIG. 23 is a diagram showing an example of an order concentration transaction analysis result table in which abnormality detection results are stored. [Figure 24] FIG. 24 is a diagram showing an example of a sales discount analysis result table in which abnormality detection results are stored. [Figure 25] FIG. 25 is a diagram illustrating an example of a purchase lead time analysis result table in which abnormality detection results are stored. [Figure 26] FIG. 26 is a diagram showing an example of a result message table in which the display position on the screen (layout element CD) and display content (message) are stored for each alert execution history detail ID and row number of the abnormality determination result. [Figure 27] FIG. 27 is a diagram showing another example of a result message table in which the display position on the screen (layout element CD) and display content (message) are stored for each alert execution history detail ID and row number of the abnormality determination result. [Figure 28] FIG. 28 is a diagram showing an example of an alert list screen displayed by the display control unit. [Figure 29] FIG. 29 is a diagram showing the alert list screen in a state where a desired algorithm has been selected. [Figure 30] FIG. 30 is a diagram showing how alert execution detail data corresponding to the alert definition selected on the alert definition selection screen is obtained from the alert execution history detail table. [Figure 31] FIG. 31 is a diagram showing how the layout element CD (display position) and message (display content) corresponding to the alert definition history detail data are detected from the result message table. [Figure 32] FIG. 32 is a diagram showing an example of an abnormality level selection screen displayed on the alert list screen. [Figure 33] FIG. 33 is a diagram illustrating an example of an alert definition master table showing the algorithm of each alert definition executed for detecting the degree of abnormality. [Figure 34] FIG. 34 is a diagram showing how result data with an abnormality rank of "1" is acquired from the order concentration transaction analysis result table. [Figure 35] FIG. 35 is a diagram showing how result data with an abnormality rank of "1" is acquired from the sales discount analysis result table. [Figure 36]FIG. 36 is a diagram showing how result data with an abnormality rank of "1" is acquired from the purchase lead time analysis result table. [Figure 37] Figure 37 is a diagram showing an example of a message generated based on the result data with an abnormality rank of "1" obtained from the order concentration transaction analysis result table, the sales discount analysis result table, and the purchase lead time analysis result table, and stored in the result message table. [Figure 38] FIG. 38 is a diagram showing how the oldest and latest alert execution histories are detected from the alert execution history detail table. [Figure 39] FIG. 39 is a diagram showing an example of a list of dates between the oldest date of the alert execution history and the latest date of the alert execution history detected from the alert execution history detail table. [Figure 40] FIG. 40 is a diagram showing an example of the scroll bar, slider, and date text data displayed on the date selection screen. [Figure 41] FIG. 41 shows the alert list screen in a state where messages for the date selected on the date selection screen are displayed. [Figure 42] FIG. 42 is a diagram showing how alert execution history data corresponding to the period selected on the date selection screen is obtained from the alert execution history detail table. [Figure 43] FIG. 43 is a diagram showing how messages corresponding to the alert execution history data for the period selected on the date selection screen are stored in the result message table. [Figure 44] FIG. 44 is a diagram showing how the response status message selected on the response status selection screen is displayed on the alert list screen. [Figure 45] FIG. 45 is a diagram showing how the alert execution history detail ID and row number corresponding to the response state selected on the response state selection screen are detected from the concentrated order transaction analysis result table. [Figure 46]FIG. 46 is a diagram showing a state in which the alert execution history detail ID and row number corresponding to the response state selected on the response state selection screen are not detected in the sales discount analysis result table. [Figure 47] FIG. 47 is a diagram showing a state in which the alert execution history detail ID and row number corresponding to the response state selected on the response state selection screen are not detected in the purchase lead time analysis result table. [Figure 48] FIG. 48 is a diagram showing how a message of an alert execution history detail ID and row number corresponding to the response state selected on the response state selection screen is obtained from the result message table. [Figure 49] FIG. 49 is a diagram showing the alert list screen in a state where a desired keyword has been entered into the keyword search screen. [Figure 50] FIG. 50 shows a result message table in a state where the keyword "purchase" has been detected. [Figure 51] FIG. 51 is another diagram showing the result message table in a state where the keyword "purchase" is detected. [Figure 52] FIG. 52 is a diagram showing the alert execution history detail ID and line number of a message containing the keyword "purchase." [Figure 53] FIG. 53 is a diagram showing how messages containing the keyword "purchase" are obtained from the result message table. [Figure 54] FIG. 54 is a diagram showing an example of an alert definition and a field name selected via the alert definition selection screen and the extraction condition input screen when performing a composite search. [Figure 55] FIG. 55 is a diagram showing how the determination result table information ID corresponding to the field name of "accounting year / month" is acquired from the sales discount analysis result table. [Figure 56] FIG. 56 is a diagram showing how the determination result table information ID corresponding to the field name of "accounting year / month" is acquired from the purchase lead time analysis result table. [Figure 57]FIG. 57 is a diagram showing another example of an alert definition and a field name selected via the alert definition selection screen and the extraction condition input screen when performing a composite search. [Figure 58] FIG. 58 is a diagram showing how the determination result table information ID corresponding to the field names "Payee Code" and "Payee Name" is acquired from the concentrated order transaction analysis result table. [Figure 59] FIG. 59 is a diagram showing how the determination result table information ID corresponding to the field names of "Payee Code" and "Payee Name" is acquired from the purchase lead time analysis result table. [Figure 60] FIG. 60 is a diagram showing an example of a pull-down menu for selecting a desired operator. [Figure 61] FIG. 61 is a diagram showing an example of input to the extraction condition input screen, and an example of displaying a message corresponding to the extraction conditions input via the extraction condition input screen and the alert definition selected on the alert definition selection screen. [Figure 62] FIG. 62 is a diagram showing an alert definition selected on the alert definition selection screen in the combined search process using the alert definition selection screen and the extraction condition input screen. [Figure 63] Figure 63 shows how the alert execution history detail ID and row number of the detection result data corresponding to the extraction conditions specified on the extraction condition input screen are obtained from the sales discount analysis result table corresponding to the alert definition selected on the alert definition selection screen. [Figure 64] Figure 64 shows how the alert execution history detail ID and row number of the detection result data corresponding to the extraction conditions specified on the extraction condition input screen are obtained from the purchase lead time analysis result table corresponding to the alert definition selected on the alert definition selection screen. [Figure 65] FIG. 65 is a diagram showing how messages corresponding to the alert execution history detail IDs and row numbers obtained from the sales discount analysis result table and the purchase lead time analysis result table are obtained from the result message table. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, an embodiment in which the present invention is applied to a business support device that detects abnormalities in recorded commercial transactions will be described in detail with reference to the drawings. However, the present invention is not limited to the following embodiment.

[0013] [overview] In recent years, corporate internal control standards have been revised, resulting in increased demand for strengthened controls and monitoring. To prevent various types of fraud in corporate management, the accuracy of detecting anomalies (fraud) can be improved by implementing detection methods tailored to each type of fraud. To efficiently check the results of these anomaly detections, a display format (display screen) is required that allows cross-sectional checking of the results of each anomaly detection.

[0014] On the other hand, if there are many anomaly detection results, displaying them all on one screen will result in too many items being displayed, making it difficult for the operator to recognize them. In this case, it is possible to make it possible to check each anomaly detection result on a screen specialized for each anomaly detection content. However, while this has the advantage of making it easier to narrow down the results by focusing on the specificity of the item, it is inefficient because it requires checking the detection results on a separate screen for each anomaly detection content.

[0015] In contrast, if all anomaly detection results are aggregated and displayed on a single screen, it becomes possible to recognize all detection results on a single screen, improving efficiency. However, because the amount of data becomes enormous, it becomes difficult to recognize the target detection results because the diverse anomaly detection results can only be narrowed down by general common items.

[0016] For these contradictory reasons, it has been difficult to improve efficiency while also addressing the uniqueness of extraction conditions.

[0017] For this reason, the business support device of the embodiment defines a common message layout and displays the abnormality detection results of each alert definition by applying the message layout to the message. This results in a common message layout, making it possible to check the abnormality detection results of each alert definition across the board on a single screen.

[0018] Furthermore, the business support device of the embodiment has a table structure that holds common information for all anomaly detection results, and an area for searching for common information is provided on the screen. This enables cross-sectional searches of anomaly detection results for each alert definition, and even when there are many anomaly determination results, the desired anomaly can be extracted and displayed, making it easier to recognize the desired anomaly.

[0019] In addition, each time an anomaly detection result is extracted using common information, it is possible to select a search item for a specific anomaly detection result, which allows anomaly detection results to be extracted in stages, making it easier to recognize the desired anomaly.

[0020] [Hardware configuration] FIG. 1 shows the hardware configuration of a business support device 1 according to an embodiment. As shown in FIG. 1, the business support device 1 according to the embodiment includes a storage unit 2, a control unit 3, a communication interface unit 4, and an input / output interface unit 5. An input device 6 and an output device 7 are connected to the input / output interface unit 5. The output device 7 corresponds to a display unit such as a monitor device (including a home television), a printing device, or a speaker device. The input device 6 may be a keyboard device, a mouse device, a microphone device, or a monitor device that cooperates with a mouse device to achieve a pointing device function. The communication interface unit 4 is connected to a network, such as a wide area network like the Internet or a private network like a LAN (Local Area Network).

[0021] A storage device such as a ROM (Read Only Memory), a RAM (Random Access Memory), an HDD (Hard Disk Drive), or an SSD (Solid State Drive) can be used as the storage unit 2. The storage unit 2 stores a task support program that makes it easier to recognize a desired anomaly even when many anomalies are detected, and that supports anomaly detection tasks for anomaly detection targets.

[0022] The storage unit 2 also has a layout element storage unit 11, an alert definition master table 12, a result message template master table 13, a result message table 14, and an alert execution history detail table 15, each of which is a storage area. The storage unit 2 also has a determination result table information master table 16, a determination result table 17, an order concentration transaction analysis result table 18, a sales discount analysis result table 19, and a purchase lead time analysis result table 20, each of which is a storage area.

[0023] As shown in Fig. 2, the layout element storage unit 11 includes a layout element code (layout element CD), a layout element category, and a layout element name that are uniquely assigned to each layout element when a screen is displayed on the output device 7, which is an example of a display unit. The layout element category is information that indicates the type or display form of an object displayed in each layout element. For example, the layout element category of the "header icon" whose layout element CD is "LC1" is "image," and the layout element category of the "header title" whose layout element CD is "LC2" is "text." Furthermore, the layout element categories of the "execution status" whose layout element CD is "LC11" and the "detection date" whose layout element CD is "LC12" are "fixed," indicating that the display content is fixed.

[0024] FIG. 3 shows the display positions of the objects of each layout element CD on the screen. In FIG. 3, the positions of "LC1," "LC12," "LC2," etc. indicate the display positions of the layout elements of the corresponding layout element CD on the screen. The display positions in FIG. 3 indicate the display positions of each layout element corresponding to the display form of the first result data in the result data display area shown in FIG. 28. Details will be described later with reference to FIG. 28. The layout data (see FIG. 3) indicating the display positions of each layout element on the screen is stored in the storage unit 2.

[0025] Information indicating each algorithm used for anomaly detection is stored in the alert definition master table 12. Specifically, as shown in Fig. 4, the alert definition master table 12 stores an alert definition name, an algorithm, and a determination result table name, each associated with a uniquely assigned alert definition code (alert definition CD).

[0026] In the example shown in Figure 4, the algorithm for detecting anomalies in the alert definition CD for "AL1" is the "interquartile range" algorithm, and the name of the alert definition is "Order Concentration Transaction Analysis." The "Order Concentration Transaction Analysis Result Table 18" is specified as the storage destination for the anomaly determination results.

[0027] The algorithm for detecting anomalies in the alert definition CD for "AL2" is the "interquartile range" algorithm, and the alert definition name is "Sales Discount Analysis." The "Sales Discount Analysis Result Table 19" is specified as the storage destination for the anomaly determination results.

[0028] The algorithm for detecting anomalies in the alert definition CD for "AL3" is the "rule" algorithm that indicates the analysis of purchase lead time, and the alert definition name is "Purchase Lead Time Analysis."The "Purchase Lead Time Analysis Result Table 20" is specified as the storage destination for the anomaly determination results.

[0029] 5 and 6, the result message template master table 13 stores template values ​​for each of the above-mentioned alert definitions CD and layout elements CD. FIG. 5 is a diagram showing an example of the first half of the result message template master table 13. FIG. 6 is a diagram showing an example of the second half of the result message template master table 13.

[0030] Specifically, the example shown in Figure 5 shows a setting in which, when an abnormality is detected using the "interquartile range" algorithm, which is the alert definition CD for "AL1," the layout element for "abnormal image" is displayed in the on-screen display position of the layout element CD for "LC1," and the layout elements for "alert definition CD" and "alert definition name" are displayed in the on-screen display position of the layout element CD for "LC2."

[0031] Furthermore, the example shown in Figure 5 shows a setting where, when an anomaly is detected using the "interquartile range" algorithm, which is the alert definition CD for "AL2," the layout elements "Alert definition CD" and "Alert definition name" are displayed in the on-screen display position of the layout element CD for "LC2." The example shown in Figure 5 also shows a setting where a layout element for "Box and Whisker Plot Icon Image," which illustrates the minimum, maximum, quartiles, interquartile range, and outliers of the "Interquartile Range," is displayed in the on-screen display position of the layout element CD for "LC4."

[0032] 7, the alert execution history detail table 15 stores the execution history of the anomaly detection algorithm to which the above-mentioned alert definition CD is added. When the anomaly detection algorithm is executed, the control unit 3 automatically assigns an alert execution history detail identification number (alert execution history detail ID) and stores it in the alert execution history detail table 15 in association with the alert definition number and update date added to the executed algorithm.

[0033] Figures 8 to 13 are diagrams showing an example of the result message table 14. Figures 8 to 13 show successive result message tables 14. As shown in Figures 8 to 13, in the result message table 14, a layout element (message) and a layout element CD to be displayed on the screen are set for each of the above-mentioned alert execution history detail IDs and row numbers that are generated each time an anomaly detection algorithm is executed.

[0034] For example, the example shown in Figure 8 is an example in which, for an alert execution history detail ID of "AEM1" and a row number of "1," the result message table 14 specifies that the layout elements for the image of "Abnormal Image" through the text data of "Detected" are to be displayed at the display positions on the screen of the layout elements CD of "LC1" through "LC10."

[0035] Similarly, the example shown in Figure 13 is an example in which, for an alert execution history detail ID of "AEM6" and a row number of "6," the result message table 14 specifies the display of layout elements for the image of "Abnormal image" through the text data layout element for "Different from the specified LT by 10" at the display positions on the screen of the layout elements CD of "LC1" to "LC10."

[0036] The determination result table information master table 16 is a master that manages information obtained from the abnormality determination results of each alert definition, and as shown in FIG. 14, the alert definition CD, determination result table information ID, and column name are stored in association with each other. The alert definition CD is an ID managed in the alert definition master table 12 shown in FIG. 4. The determination result table information ID is an ID uniquely assigned to the determination result table information. The column name is information that manages the column names of the determination result table 17 (order concentration transaction analysis result table 18 to purchase lead time analysis result table 20).

[0037] In addition, the judgment result table information ID (RT1 to RT5) in each alert definition CD (AL1 to AL3) is the "Alert execution history detail ID to judgment result status", which is a common item for each alert definition CD (AL1 to AL3).

[0038] The determination result table 17 includes an order concentration transaction analysis result table 18, a sales discount analysis result table 19, and a purchase lead time analysis result table 20, each of which is a storage area.

[0039] As shown in Figure 15, order concentration transaction analysis result table 18 stores the alert execution history detail ID, line number, judgment result, abnormality rank, judgment result status, minimum accounting year and month, maximum accounting year and month, payee code, payee name, person in charge CD, person in charge name, and number of purchases, each associated with the other. Of these, the "judgment result" is the abnormality judgment result obtained by executing the order concentration transaction analysis algorithm, and is entered as either "abnormal" or "normal."

[0040] The "row number" is a consecutive number assigned for each alert execution history detail ID when an alert determination is executed and the determination result is stored in the order concentration transaction analysis result table 18. The result message is obtained or the determination result is identified using a combination of the "alert definition history detail ID" and the "row number."

[0041] "Abnormality rank" is information that indicates the abnormality detection result by classifying it into four levels according to the degree of abnormality, for example, no abnormality, high abnormality, medium abnormality, and low abnormality. This abnormality rank is input as "0" if there is no abnormality, and as "3" if the degree of abnormality is high. Furthermore, this abnormality rank is input as "2" if the degree of abnormality is medium, and as "1" if the degree of abnormality is low.

[0042] The "judgment result status" indicates the response status for the abnormality detection result. If the judgment result is "normal," this "judgment result status" will be "no response required," but if the judgment result is "abnormal," a status corresponding to the current response status will be selected and entered from "not responded," "responding," "on hold," and "response completed."

[0043] As shown in Figure 16, the sales discount analysis result table 19 stores the alert execution history detail ID, line number, judgment result, abnormality rank, judgment result status, accounting year / month, person in charge CD, net sales amount, net discount amount, and discount rate, each associated with the other. The "judgment result," "abnormality rank," and "judgment result status" are as described above.

[0044] 17, the purchase lead time analysis result table 20 stores the alert execution history detail ID, line number, judgment result, abnormality rank, judgment result status, accounting year and month, purchase number, purchase order number, purchase date, order date, payee code, payee name, supplier code, supplier name, product code, and product name, each associated with the other. The "judgment result," "abnormality rank," and "judgment result status" are as described above.

[0045] [Functional configuration of business support device] Next, the control unit 3 executes the business support program stored in the storage unit 2, thereby functioning as an alert definition execution unit 21, a result data generation unit 22, a display control unit 23, an alert definition display unit 24, a result data display unit 25, and an extraction condition input screen display unit 26, as shown in Fig. 1. Furthermore, by executing the business support program, the control unit 3 functions as an abnormality level selection screen display unit 27, a date selection screen display unit 28, a response status selection screen display unit 29, and a keyword search screen display unit 30.

[0046] The alert definition execution unit 21 executes the anomaly detection algorithm stored in the alert definition master table 12 shown in Fig. 4. The result data generation unit 22 generates result data indicating the anomaly determination result based on the execution result of the algorithm by the alert definition execution unit 21 (anomaly determination result). Then, the result data generation unit 22 stores the anomaly detection data in the order concentration transaction analysis result table 18, the sales discount analysis result table 19, or the purchase lead time analysis result table 20 (see Figs. 15 to 17) corresponding to the algorithm executed by the alert definition execution unit 21.

[0047] The display control unit 23 is equipped with an alert definition display unit 24 to a keyword search screen display unit 30, and controls the display of each screen described below. That is, the alert definition display unit 24 displays, on the display unit (output device 7), an alert definition selection screen (see FIG. 28) for selecting one or more alert definitions from among the multiple alert definitions stored in the first storage unit (the alert definition master table 12 in FIG. 4).

[0048] The result data display unit 25 acquires result data including the judgment results of abnormalities corresponding to one or more alert definitions selected on the alert definition selection screen (see Figure 29) from the result data including judgment results indicating abnormalities in the abnormality detection targets stored in the second memory unit (the order concentration transaction analysis result table 18 in Figure 15, the sales discount analysis result table 19 in Figure 16, or the purchase lead time analysis result table 20 in Figure 17) by executing each alert definition, and displays the result data on the display unit.

[0049] The extraction condition input screen display unit 26 displays on the display unit an extraction condition input screen (see FIG. 28) for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen (see FIG. 29).

[0050] When extraction conditions are input via the extraction condition input screen (see Figures 54 and 57), the result data display unit 25 extracts the result data corresponding to the input extraction conditions from the second memory unit (the order concentration transaction analysis result table 18 in Figure 15, the sales discount analysis result table 19 in Figure 16, or the purchase lead time analysis result table 20 in Figure 17) and displays it on the display unit.

[0051] In addition, the result data generation unit 22 refers to the third memory unit (the result message table in Figures 8 to 13) in which display content information (messages in Figures 8 to 13) indicating the display content to be displayed on the display unit is stored based on the execution result of the alert definition, selects one or more pieces of display content information corresponding to the execution result, generates result data, and stores it in the second memory unit (the order concentration transaction analysis result table 18 in Figure 15, the sales discount analysis result table 19 in Figure 16, or the purchase lead time analysis result table 20 in Figure 17).

[0052] The extraction condition input screen display unit 26 displays an extraction condition input screen (see Figure 28) on the display unit, which includes a field name input field for inputting the desired search item, an input field for the desired search value, and an operator selection field for specifying the search for a value equal to the search value, a value greater than the search value, or a value smaller than the search value.

[0053] Each result data (see Figures 15 to 17) stored in the second memory unit (order concentration transaction analysis result table 18 in Figure 15, sales discount analysis result table 19 in Figure 16, or purchase lead time analysis result table 20 in Figure 17) includes abnormality degree information that indicates, in stages, the degree of abnormality that serves as the judgment result for the abnormality detection target. The abnormality degree selection screen display unit 27 displays, on the display unit, an abnormality degree selection screen (see Figure 32) for selecting one or more desired degrees of abnormality from the degrees of abnormality. The result data display unit 25 displays, on the display unit, the result data corresponding to the degree of abnormality selected via the abnormality degree selection screen from the result data stored in the second memory unit.

[0054] Furthermore, each piece of result data stored in the second storage unit includes date information (such as the accounting year and month shown in FIGS. 15 to 17). Date selection screen display unit 28 displays a date selection screen on the display unit for selecting a desired date. Result data display unit 25 displays on the display unit result data corresponding to the date selected via the date selection screen from among the result data stored in the second storage unit (order concentration transaction analysis result table 18 in FIG. 15, sales discount analysis result table 19 in FIG. 16, or purchase lead time analysis result table 20 in FIG. 17).

[0055] The date selection screen display unit 28 also generates a scroll bar corresponding to the period from the earliest date information to the latest date information among the date information included in the result data, and displays it on the display unit (see FIG. 41). The date selection screen display unit 28 also initially displays a slider, which is scrolled along the scroll bar, at a position on the scroll bar corresponding to a date a predetermined period before the latest date (see FIG. 40). The date selection screen display unit 28 also displays the date corresponding to the position on the scroll bar of the scrolled slider and the latest date as text information on the display unit (see FIG. 40). The rightmost position (terminal position) on the scroll bar, where the latest date is initially displayed, can also be changed. When the terminal position on the scroll bar is changed, the terminal position will indicate a date going back from the latest date depending on the amount of operation. The result data display unit 25 displays result data on the display unit corresponding to the period from the date corresponding to the position on the slider's scroll bar to the latest date (see FIG. 41).

[0056] Furthermore, each result data stored in the second memory unit (order concentration transaction analysis result table 18 in FIG. 15, sales discount analysis result table 19 in FIG. 16, or purchase lead time analysis result table 20 in FIG. 17) includes response status information (determination result status in FIGS. 15 to 17) indicating at least the response status of responded or not responded, which is the response status for the determination result. Response status selection screen display unit 29 displays on the display unit a response status selection screen for selecting a desired response status (see FIG. 44). Result data display unit 25 displays on the display unit result data corresponding to the response status selected via the response status selection screen from the result data stored in the second memory unit (see FIG. 44).

[0057] Furthermore, the keyword search screen display unit 30 displays on the display unit a keyword search screen for inputting a desired keyword contained in desired result data from among the result data stored in the second storage unit (see FIG. 49). The result data display unit 25 displays on the display unit the result data stored in the second storage unit that includes the keyword input via the keyword search screen (see FIG. 49).

[0058] [Abnormal display operation] Next, an explanation will be given of an abnormality display operation of accounting data in the business support device 1 of the embodiment. The control unit 3 of the business support device 1 of the embodiment operates based on a business support program stored in the storage unit 2, thereby functioning as an alert definition execution unit 21 to a keyword search screen display unit 30, and executing an abnormality detection process in step S1 and an alert list screen display process in step S2 shown in FIG.

[0059] In this example, the alert definition execution unit 21 to the keyword search screen display unit 30 are described as being implemented as software based on a business support program. However, some or all of the alert definition execution unit 21 to the keyword search screen display unit 30 may be implemented as hardware. In either case, the same effects as those described below can be obtained.

[0060] (Abnormality detection processing) First, in the anomaly detection process of step S1, the alert definition execution unit 21 executes an algorithm for anomaly detection set in the alert definition master table 12 shown in FIG. 19(a) at a predetermined timing, such as late at night or the end of the month. The result data generation unit 22 references the determination result table information master table 16 shown in FIG. 19(b) and recognizes the items of common information and alert definition specific information shown in FIG. 19(c). Then, the result data generation unit 22 inputs the anomaly detection result data obtained by the alert definition execution unit 21 executing the algorithm into each item of the determination result table 17 recognized from the determination result table information master table 16.

[0061] Specifically, as shown in Fig. 20(a), this is an example in which the algorithm for "interquartile range" with the alert definition name of "order concentration transaction analysis" is executed by the alert definition execution unit 21. In this case, as shown in Fig. 20(b), the result data generation unit 22 stores the date on which the algorithm was executed and the alert definition CD of the executed algorithm in the alert execution history detail table 15 in association with the automatically assigned alert execution history detail ID and row number.

[0062] In this case, the result data generation unit 22 inputs and stores various data of the items recognized from the judgment result table information master table 16 into the order concentration transaction analysis result table 18, which is the judgment result table corresponding to the executed algorithm, as shown in Figure 20(c).

[0063] Next, the result data generation unit 22 refers to the result message template master table 13 shown in Fig. 21(a) and the determination result table information master table 16 shown in Fig. 21(b), and recognizes the layout element CD (display position on the screen) and template value (display content) corresponding to the alert definition CD (AL1) of the executed algorithm. In addition, the result data generation unit 22 acquires the anomaly detection result corresponding to the template value (display content) to be displayed at the display position indicated by the layout element CD corresponding to the alert definition CD (AL1) from the order concentration transaction analysis result table 18 shown in Fig. 20(c).

[0064] Furthermore, the result data generation unit 22 generates messages to be displayed at each display position on the screen indicated by the layout element CD, based on the abnormality detection results acquired from the order concentration transaction analysis result table 18 and the template values ​​recognized from the result message template master table 13. Then, the result data generation unit 22 stores the generated messages in the result message table 14 in association with the alert execution history detail ID, line number, and layout element CD (display position), as shown in FIG. 21(c).

[0065] As a result, for each execution history of the anomaly detection algorithm, information indicating the display position on the screen (layout element CD) and the “message” to be displayed at each display position are stored in the result message table 14.

[0066] In this way, the alert definition execution unit 21 executes the algorithm for anomaly detection set in the alert definition master table 12. Furthermore, the result data generation unit 22 stores the anomaly detection results in the order concentration transaction analysis result table 18, the sales discount analysis result table 19, and the purchase lead time analysis result table 20, and also stores the display position on the screen (layout element CD) and display content (message) in the result message table 14 for each alert execution history.

[0067] In addition, each time the alert definition execution unit 21 executes an algorithm for anomaly detection, the result data generation unit 22 stores the execution history of each algorithm in the alert execution history detail table 15, as shown in FIG. 22. The example shown in FIG. 22 illustrates an example in which the alert definition CD executes the algorithms "AL1 (order concentration transaction analysis)," "AL2 (sales discount analysis)," and "AL3 (purchase lead time analysis result table)" as the first execution between October 1, 2023 and October 1, 2023. In addition, the example shown in FIG. 22 illustrates an example in which the alert definition CD executes the algorithms "AL1 (order concentration transaction analysis)," "AL2 (sales discount analysis)," and "AL3 (purchase lead time analysis)" as the second execution between November 1, 2023 and December 1, 2023.

[0068] Furthermore, when the alert definition execution unit 21 executes the algorithm with the alert definition CD "AL1 (order concentration transaction analysis)", the result data generation unit 22 stores the abnormality detection result, which is the execution result, in the order concentration transaction analysis result table 18 as shown in FIG. 23. Similarly, when the alert definition execution unit 21 executes the algorithm with the alert definition CD "AL2 (sales discount analysis)", the result data generation unit 22 stores the abnormality detection result, which is the execution result, in the sales discount analysis result table 19 as shown in FIG. 24. Similarly, when the alert definition execution unit 21 executes the algorithm with the alert definition CD "AL3 (purchase lead time analysis)", the result data generation unit 22 stores the abnormality detection result, which is the execution result, in the purchase lead time analysis result table 20 as shown in FIG. 25.

[0069] Furthermore, when the alert definition execution unit 21 executes the anomaly detection algorithm, the result data generation unit 22 generates various "messages" based on the anomaly detection results stored in the order concentration transaction analysis result table 18, the sales discount analysis result table 19, and the purchase lead time analysis result table 20, as shown in Figures 26 and 27, and stores these in the result message table 14 together with the display position on the screen (layout element CD), the alert execution history detail ID, and the line number. As a result, the result message table 14 stores messages indicating the anomaly detection results generated each time the anomaly detection algorithm is executed, together with the alert execution history detail ID and the line number.

[0070] (Alert list screen display processing) Next, the display process of the alert list screen in step S2 will be described. Fig. 28 shows the alert list screen on which various messages are displayed by the display control unit 23 at the display positions indicated by the layout element CD stored in the result message table 14 together with the alert execution history detail ID and line number.

[0071] As shown in FIG. 28, the alert list screen includes an alert definition selection screen that displays a list of the alert definition names of the alert definitions stored in the alert definition master table 12 described with reference to FIG. 4, and allows a desired alert definition to be selected.

[0072] In addition, the alert list screen includes an abnormality level selection screen that allows the user to select the desired abnormality level from the abnormality level levels stored in the order concentration transaction analysis result table 18, the sales discount analysis result table 19, and the purchase lead time analysis result table 20, as shown in Figures 23 to 25.

[0073] The alert list screen also includes a date selection screen that allows the user to select the abnormality detection results for a desired date based on the "update date" of the alert execution history detail table 15 shown in FIG.

[0074] In addition, as shown in Figures 23 to 25, the alert list screen has a response status selection screen that allows the user to select the detection result of the desired response status based on the judgment result status stored in the order concentration transaction analysis result table 18, the sales discount analysis result table 19, and the purchase lead time analysis result table 20.

[0075] The alert list screen also includes a keyword search screen that allows a search for detection results that include the input keyword.

[0076] The alert list screen also includes an extraction condition input screen that enables the display of detection results for desired items input as extraction conditions.

[0077] The alert list screen also has a result data display area, which is a display area for detection results. This result data display area displays the layout element CD (display position) and layout element classification (display type) stored in the layout element storage unit 11 shown in Fig. 2, and the "message (detection result of abnormality)" stored for each alert execution history detail ID and row number in the result message table 14 shown in Figs. 26 and 27.

[0078] In other words, the result data display area displays the abnormality detection results stored in the result message table 14 in the layout shown in FIG.

[0079] [Specific display format] (Displaying a message indicating an abnormality in the desired algorithm) Next, the operation of displaying the detection results of an anomaly in a desired algorithm will be described. In this case, the operator operates the pull-down menu on the alert definition selection screen of the alert list screen, as shown in FIG. 29. When this operation is performed, the alert definition display unit 24 displays a pull-down menu for selecting the desired alert definition from "AL1 Order Concentration Transaction Analysis," "AL2 Sales Discount Analysis," and "AL3 Purchase Lead Time Analysis," as shown in FIG. 29. The operator selects the desired alert definition based on the pull-down menu. Here, as an example, it is assumed that the alert definition "AL1 Order Concentration Transaction Analysis" has been selected.

[0080] When the alert definition "AL1 Order Concentration Transaction Analysis" is selected, the alert definition display unit 24 refers to the alert execution history detail table 15 based on the alert definition CD of "AL1" as shown in Figure 30, and obtains the alert definition history detail data of "AEM1" and "AEM4", which are the execution history of the algorithms of the alert definition CD of "AL1".

[0081] Next, the alert definition display unit 24 refers to the result message table 14 and detects the layout element CD (display position) and message (display content) corresponding to each alert definition history detail data of "AEM1" and "AEM4", as shown in Figure 31.

[0082] Next, the result data display unit 25 displays the "messages" corresponding to the alert definition history detail data of "AEM1" and "AEM4" detected from the result message table 14 at the display positions on the result data display area indicated by the layout element CD, as shown in Fig. 29. This makes it possible to display the anomaly detection result message corresponding to the alert definition selected by the operator in the result data display area.

[0083] Specifically, as shown in FIG. 29, the result data display unit 25 displays each message together with a triangular icon whose display color corresponds to the degree of abnormality.

[0084] 29, the result data display unit 25 displays, in the top row of the result data display area, various messages such as "LC1 (header icon)," "LC12 (detection date)," "LC2 (header title)," "LC3 (header message)," and "LC11 (execution status)" shown in Fig. 3. In addition, the result data display unit 25 displays, in the second row, various messages such as "LC4 (main icon)," "LC5 (main message)," "LC6 (definition label)," "LC7 (detailed message)," "LC8 (data label)," "LC9 (data content)," and "LC10 (data message)."

[0085] In addition, from the third row onwards, the result data display unit 25 displays various messages such as "LC1 (header icon)", "LC12 (detection date)", "LC2 (header title)", "LC3 (header message)", and "LC11 (execution status)" shown in Figure 3.

[0086] In the example of Figure 29, the top row of the result data display area displays an abnormality level image (a triangular icon with a display color corresponding to the abnormality level: LC1), detection date (LC12), header title (alert definition CD and alert definition name: LC2), accounting period (header message: LC3), person in charge name, payee name, header message, and execution status (not supported: execution status: LC11).

[0087] In addition, the example in Figure 29 is an example in which various messages are displayed in the second row of the result data display area: "Box and whisker icon image (LC4: main icon)," which illustrates the minimum, maximum, quartiles, interquartile range, and outliers of the "interquartile range" algorithm; "Main message (LC5: Person in charge 1, payee 1 detected)," "LC6 (Definition label; Calculation method; Interquartile range (range magnification 1.5x, upper test))," "LC7 (Detailed message: Automatically detected because the number of purchase vouchers for payee 1 is abnormally higher than for other persons in charge)," "LC8 (Data label: Number of purchases from 2022 / 9 to 2023 / 9)," "LC9 (Data content: 100 items)," and "LC10 (Data message: Detected)."

[0088] In this example, the result data display unit 25 automatically displays the second line of the message following the top line. However, the result data display unit 25 may display the second line of the message in response to an operation by the operator to specify the display, such as a cursor pointing operation or a mouse click operation.

[0089] (Displaying a message with the desired abnormality level) Next, the operation of displaying the detection results of the desired abnormality level will be described. The abnormality level selection screen display unit 27 displays the abnormality level selection screen shown in Fig. 32 on the alert list screen. As an example, on this abnormality level selection screen, the abnormality level selection screen display unit 27 displays a red triangular icon image, a yellow triangular icon image, and a blue triangular icon image, along with check boxes for selecting one or more icon images, adjacent to each icon image.

[0090] The color of each icon image indicates the level of abnormality, with red icon images being icon images with a high level of abnormality. Yellow icon images are icon images with a medium level of abnormality, and blue icon images are icon images with a low level of abnormality. The operator inputs a check mark (R) into the check box of the icon image with the abnormality level they wish to display in the result data display area. In this example, it is assumed that a check mark has been input into the check box of the blue icon image.

[0091] In order to select all abnormality levels, a check mark may be input into all check boxes, or a check mark may be input into any one or two check boxes.

[0092] Next, in this example, the result data display unit 25 obtains the detection data of the abnormality rank corresponding to the blue icon image with a check mark entered in the checkbox from the order concentration transaction analysis result table 18 shown in Figure 34, the sales discount analysis result table 19 shown in Figure 35, and the purchase lead time analysis result table 20 shown in Figure 36, which store the detection data obtained by executing each algorithm for abnormality detection shown in Figure 33.

[0093] That is, in this example, the abnormality degree rank corresponding to the designated blue icon image is an abnormality degree rank of "1." The abnormality degree rank corresponding to the red icon image is an abnormality degree rank of "3," and the abnormality degree rank corresponding to the yellow icon image is an abnormality degree rank of "2." The result data display unit 25 acquires the alert execution history detail ID and row number of the result data with an abnormality degree rank of "1," which are shown in FIGS. 34 to 36.

[0094] Next, as shown in Fig. 37, the result data display unit 25 obtains a message corresponding to the obtained "alert execution history detail ID" and "row number" from the result message table 14, and displays it in the result data display area as shown in Fig. 32. This makes it possible to display the message of the abnormality level specified via the abnormality level selection screen in the result data display area.

[0095] (Displaying a message for the desired date) Next, the display operation of the detection results for a desired date will be described. The date selection screen display unit 28 displays a date selection screen shown in Fig. 41 on the alert list screen. Specifically, as shown in Fig. 38, the date selection screen display unit 28 detects the alert execution history for the oldest date and the alert execution history for the latest date from among the alert execution histories stored in the alert execution history detail table 15. In the example of Fig. 38, the alert execution history for "January 1, 2021" is detected as the alert execution history for the oldest date, and the alert execution history for "December 1, 2023" is detected as the alert execution history for the latest date.

[0096] Next, as shown in Fig. 39, the date selection screen display unit 28 creates a list of dates between the oldest date in the alert execution history and the latest date in the alert execution history detected from the alert execution history detail table 15. In the example of Fig. 39, a list from January 2021 (oldest month) to December 2023 (latest month) is shown to have been created.

[0097] Next, based on the created list, the date selection screen display unit 28 generates an image of a scroll bar with a length corresponding to January 2021 (the oldest month) to December 2023 (the latest month), as shown in Figure 40, and displays it on the date selection screen.

[0098] Furthermore, date selection screen display unit 28 sets the right end of this scroll bar to December 2023 (the latest month), and displays a slider that the operator can operate along the scroll bar, with the position on the scroll bar corresponding to December 2022, which is one year before the latest month, as the initial position. Furthermore, date selection screen display unit 28 displays text data for "December 2022," which is the date corresponding to the initial position of the slider on the scroll bar, and text data for "December 2023," which is the date corresponding to the right end of the scroll bar, on the date selection screen, and displays the period from the slider position to the right end of the scroll bar.

[0099] Here, assume that the slider on the date selection screen is operated and the period "November 2023 to December 2023" is specified, as shown in Fig. 41. In this case, the result data display unit 25 refers to the alert execution history detail table 15 as shown in Fig. 42, and detects each of the alert execution history IDs "AEM4 to AEM6" as the alert execution history IDs corresponding to the period "November 2023 to December 2023".

[0100] Next, the result data display unit 25 obtains the message corresponding to the detected alert execution history ID of "AEM4 to AEM6" from the result message table 14, and displays it in the result data display area as shown in Fig. 41. This makes it possible to display the message corresponding to the date selected on the date selection screen in the result data display area.

[0101] (Displaying the desired status message) Next, the operation of displaying a message of a desired response status will be described. The response status selection screen display unit 29 displays a response status selection screen shown in Fig. 44 on the alert list screen. The response status selection screen display unit 29 displays a pull-down menu on this response status selection screen for selecting a response status for the abnormality detection result, such as "Not responded to," "In response," "Response completed," "On hold," "Confirmed," or "No response required."

[0102] The operator selects the response status for which they wish to display a message using this pull-down menu. As an example, let's assume that the response status "Not Handled" is selected from the pull-down menu. When this response status is selected, the result data display unit 25 references the concentrated order transaction analysis result table 18, sales discount analysis result table 19, and purchase lead time analysis result table 20 shown in FIG. 45, and detects the alert execution history detail ID and row number of the result data for which the judgment result status is "Not Handled." In the example of FIGS. 45 to 47, the judgment result status of the result data for row number "1" in the concentrated order transaction analysis result table 18 shown in FIG. 45 is "Not Handled," so the corresponding alert execution history detail ID and row number of "AEM1" are detected.

[0103] Next, the result data display unit 25 obtains the message corresponding to the detected alert execution history detail ID and row number of "AEM1" from the result message table 14 as shown in Fig. 48, and displays it in the result data display area as shown in Fig. 44. This makes it possible to display the message of the response status selected on the response status selection screen in the result data display area.

[0104] (Displaying messages containing desired keywords) Next, the operation of displaying a message containing a desired keyword will be described. The keyword search screen display unit 30 displays a keyword search screen with an input field for a desired keyword on the alert list screen, as shown in Fig. 49. The operator inputs the desired keyword into the keyword input field. As an example, it is assumed that the keyword "purchase" is input into the keyword input field.

[0105] Based on the input keyword, the result data display unit 25 refers to the result message table 14. Then, as shown in Figures 50 and 51, the result data display unit 25 detects messages containing the keyword "purchase" from among the messages of each alert execution history detail ID and row number stored in the result message table 14.

[0106] Next, the result data display unit 25 detects the alert execution history detail ID and line number attached to the message containing the detected keyword "purchase" from the result message table 14. In the example of the result message table 14 in Figures 50 and 51, the alert execution history detail ID and line number of the message containing the keyword "purchase" are Alert execution history detail ID of "AEM1 (see Figure 50)" and row number of "1", The alert execution history detail ID of "AEM3 (see Figure 51)" and the row number of "1", and The alert execution history detail ID is "AEM4 (see Figure 51)" and the line number is "6." Figure 52 shows the alert execution history detail ID and line number of such a message containing the keyword "purchase."

[0107] Next, as shown in Fig. 53, the result data display unit 25 acquires from the result message table 14 the message with the alert execution history detail ID "AEM1" and the line number "1", the message with the alert execution history detail ID "AEM3" and the line number "1", and the message with the alert execution history detail ID "AEM4" and the line number "6", all of which contain the keyword "purchase". Then, as shown in Fig. 49, the result data display unit 25 displays the acquired messages containing the keyword "purchase" in the result data display area. This makes it possible to selectively display messages with the specified keyword.

[0108] (cross-message search behavior) In the above explanation, the alert definition selection screen, anomaly level selection screen, date selection screen, response status selection screen, and keyword search screen are each used individually to select and display a desired message. However, it is also possible to select and display a desired message by selectively using multiple screens, including the extraction condition input screen described below, including the alert definition selection screen, anomaly level selection screen, date selection screen, response status selection screen, keyword search screen, and extraction condition input screen. Below, as an example, we will explain an example in which a cross-sectional message search is possible through a composite search operation that uses the alert definition selection screen and extraction condition input screen in combination.

[0109] In this case, the alert definition display unit 24 displays the above-mentioned alert definition selection screen on the alert list screen, as shown in Fig. 61. Furthermore, the extraction condition input screen display unit 26 displays an extraction condition input screen, which has input fields for the field name, operator, and search value, on the alert list screen, as shown in Fig. 61.

[0110] The operator selects the desired alert definition via the alert definition selection screen as shown in Fig. 54(a). In the example of Fig. 54(a), an alert definition for a sales discount analysis algorithm with the alert definition code "AL2" and an alert definition for a purchase lead time analysis algorithm with the alert definition code "AL3" are selected.

[0111] Next, the extraction condition input screen display unit 26 refers to the sales discount analysis result table 19 and the purchase lead time analysis result table 20 shown in Figures 55 and 56, and compares the judgment result table information of the alert definitions "AL2" and "AL3" selected via the alert definition selection screen. Then, the extraction condition input screen display unit 26 obtains the judgment result table information IDs having the same column names, and displays them as options selectable by the operator in a pull-down menu of field names on the extraction condition input screen.

[0112] In the examples of Figures 55 and 56, the extraction condition input screen display unit 26 obtains the judgment result table information ID of "RT6" associated with the column name of "fiscal year / month" from the sales discount analysis result table 19 and the purchase lead time analysis result table 20, respectively, and displays it as an option in the pull-down menu of field names on the extraction condition input screen.

[0113] Next, when the operator selects "Fiscal Year / Month" from the pull-down menu and enters an operator and search value, the result data display unit 25 extracts result data that matches the specified "Fiscal Year / Month" conditions from the sales discount analysis result table 19 with the alert definition "AL2" and the purchase lead time analysis result table 20 with the alert definition "AL3."

[0114] In this way, by narrowing down and selecting only the columns that are common to multiple selected alert definitions using the pull-down menu on the extraction condition input screen display section 26, it is possible to perform a cross-sectional search using the "fiscal year / month" column that is common between search items for the detection results of specific abnormalities in different alert definition judgment results.

[0115] The same applies if another alert definition is selected on the alert definition selection screen and another field name is selected on the extraction condition input screen.

[0116] That is, as shown in Figure 57(a), an alert definition for an algorithm for order concentration transaction analysis with alert definition code "AL1" and an alert definition for an algorithm for purchase lead time analysis with alert definition code "AL3" are selected on the alert definition selection screen.

[0117] 58 and 59, and compares the judgment result table information of the alert definitions "AL1" and "AL3" selected via the alert definition selection screen. The extraction condition input screen display unit 26 then obtains the judgment result table information IDs having the same column names and displays them as options selectable by the operator in the field name pull-down menu on the extraction condition input screen.

[0118] In the examples of Figures 58 and 59, the extraction condition input screen display unit 26 obtains the judgment result table information IDs "RT8," "RT9," "RT11," and "RT12" associated with the column names "Payee Code" and "Payee Name" from the sales discount analysis result table 19 and the purchase lead time analysis result table 20, respectively, and displays them as options in the pull-down menu of field names on the extraction condition input screen.

[0119] Next, when the operator selects "Payee Code" and "Payee Name" from the pull-down menu and enters an operator and search value, the result data display unit 25 extracts result data that matches the specified "Payee Code" and "Payee Name" conditions from the order concentration transaction analysis result table 18 with the alert definition "AL1" and the purchase lead time analysis result table 20 with the alert definition "AL3" (see Figures 62 to 65).

[0120] In addition, the "Add Condition" and "X" buttons on the extraction condition input screen display section 26 shown in Figure 49 allow the input or deletion of multiple combinations of field names, operators, and search values. Therefore, if multiple field names apply, such as the above-mentioned "Payee Code" and "Payee Name," it is possible to specify condition expressions for multiple field names simultaneously (on multiple lines). In this way, by combining the alert definitions selected on the alert definition selection screen and adding conditions by the operator, it is possible to dynamically change the extraction items of the extraction conditions and perform an "advanced search."

[0121] Next, we will explain how to input the desired search value and desired operator on the extraction condition input screen. As shown in Figure 60, input the desired search value and select the desired operator. The operator selection field is a field where you can select whether to search for values ​​greater than the input search value, or whether to search for values ​​greater than the input search value.

[0122] The operator selection field is a pull-down menu. The extraction condition input screen display unit 26 displays a pull-down menu in the operator selection field, for example, "less than (search value)," "less than or equal to (search value)," "not equal to (search value)," "equal to (search value)," "greater than (search value)," and "greater than or equal to (search value)."

[0123] The operator inputs the desired search value and selects the desired operator based on this pull-down menu. Figure 61 shows an example in which the operator selects "Fiscal Year / Month" as the field name, inputs the fiscal year / month of "September 2023" as the search value, and selects the operator "equal to" the fiscal year / month of "September 2023."

[0124] In this way, when the desired alert definition is selected and the desired extraction conditions are entered, the result data display unit 25, as shown in Figure 62, refers to the sales discount analysis result table 19 shown in Figure 63 based on the selected alert definition code of "AL2", and obtains the alert definition history detail ID of "AEM2" where the "fiscal year and month" entered and selected on the extraction condition input screen is "equal" to "September 2023".

[0125] Similarly, as shown in Figure 62, the result data display unit 25 refers to the purchase lead time analysis result table 20 shown in Figure 64 based on the selected alert definition code of "AL3", and obtains the alert definition history detail ID of "AEM3" where the "accounting year and month" entered and selected on the extraction condition input screen is "equal" to "September 2023".

[0126] Next, the result data display unit 25 refers to the result message table 14 as shown in FIG. 65 based on the alert definition history detail ID and row number of "AEM2" acquired from the sales discount analysis result table 19 and the alert definition history detail ID and row number of "AEM3" acquired from the purchase lead time analysis result table 20. Then, the result data display unit 25 acquires messages corresponding to the alert definition history detail ID and row number of "AEM2" and the alert definition history detail ID and row number of "AEM3" from the result message table 14, and displays them in the result data display area as shown in FIG.

[0127] This allows messages corresponding to the results of a combined search performed using the alert definition selection screen and the extraction input screen to be displayed in the result data display area, thereby enabling cross-sectional message searches.

[0128] [Effects of the embodiment] As is clear from the above description, the task support device 1 according to the embodiment can achieve the following effects.

[0129] 1. Define a common message layout and display the abnormality determination results for each alert definition in accordance with the message layout. This allows the abnormality determination results for each alert definition to be displayed in a message format with a common layout, making it easier to visually check the abnormality determination results for each alert definition across multiple screens.

[0130] 2. All fraud detection results are structured as a table that holds common information, and the desired information can be searched and displayed via an area for searching common information. Therefore, even when there are many judgment results, the desired information can be extracted and displayed, making it easier for operators to recognize the desired abnormality judgment results, etc.

[0131] 3. After searching for anomaly detection results using common information, it is possible to further search for the desired detection results by selecting search items specialized for specific anomaly detection results. This allows anomaly detection results to be searched in stages, making it easier for operators to recognize the desired anomaly detection results.

[0132] [Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This invention can contribute to improving business efficiency and promoting appropriate management decisions by companies, thereby contributing to the achievement of goals "8" and "9" of the SDGs.

[0133] Furthermore, this invention can contribute to reducing waste and promoting paperless and electronic systems, thereby contributing to the achievement of SDGs goals 12, 13, and 15.

[0134] Furthermore, the present invention can contribute to strengthening control and governance, thereby contributing to the achievement of goal 16 of the SDGs.

[0135] [Other embodiments] The present invention can be implemented in various different forms other than the above-described embodiments within the scope of the technical concept described in the claims.

[0136] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically may be performed manually, or all or part of the processes described as being performed manually may be performed automatically using a known method or the like.

[0137] Furthermore, the processing procedures, control procedures, specific names, registered data for each process, information including parameters such as search conditions, screen examples, and database configurations shown in the specification or drawings may be changed as desired unless otherwise specified.

[0138] Furthermore, the components of the business support device 1 shown in the figure are conceptual functional components and do not necessarily have to have the physical configuration shown in the figure. For example, all or any part of the processing functions of the business support device 1, particularly the processing functions performed by the control unit 3, may be realized by a program interpreted and executed by the control unit 3 (CPU: Central Processing Unit), or may be realized by hardware using wired logic.

[0139] The program is recorded on a non-transitory computer-readable recording medium containing programmed instructions for causing the information processing device to execute the processes described in the embodiments, and is mechanically read by the business support device 1 as needed. That is, a computer program is recorded in the storage unit 2, such as a ROM or HDD, for working with an OS (Operating System) to give instructions to a control unit 3 (CPU) and perform various processes. The computer program is loaded into RAM, expanded, and executed by the control unit 3 as appropriate.

[0140] In addition, the business support program of this business support device 1 may be stored in another server device connected to the business support device 1 via any network, and all or part of it may be downloaded and executed as needed.

[0141] Furthermore, the business support program for executing the processes described in the embodiments may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product.

[0142] Here, the "recording medium" can be any "portable physical medium" such as a memory card, a USB (Universal Serial Bus) memory, an SD (Secure Digital) card, a flexible disk, a magneto-optical disk, a ROM, an EPROM (Erasable Programmable Read Only Memory), an EEPROM (registered trademark) (Electrically Erasable and Programmable Read Only Memory), a CD-ROM (Compact Disk Read Only Memory), an MO (Magneto-Optical Disk), a DVD (Digital Versatile Disk), and a Blu-ray (registered trademark) Disc.

[0143] Furthermore, a "program" is a data processing method written in any language or description method, regardless of the format, such as source code or binary code.

[0144] It should be noted that a "program" is not necessarily limited to a single structure, but includes a structure that is distributed as multiple modules or libraries, and a structure that achieves its function by working together with other programs, such as an OS.

[0145] Furthermore, the specific configuration for reading the recording medium in the task support device 1 of the embodiment, the reading procedure, and the installation procedure after reading can be any known configuration or procedure.

[0146] The memory unit 2 is a storage means such as a memory device such as RAM or ROM, a fixed disk device such as a hard disk, a flexible disk, or an optical disk, and stores various programs, tables, databases, web page files, etc. used for various processes or providing websites.

[0147] The business support device 1 may be configured as an information processing device such as a known personal computer or a workstation, or may be configured as an information processing device connected to any peripheral device. The information processing device may be implemented with software (including programs or data) that realizes the processes described in the embodiments.

[0148] Furthermore, the specific forms of distribution and integration of the devices are not limited to those shown in the drawings, and all or part of them can be functionally or physically distributed or integrated in any unit depending on various additions or functional loads. In other words, the above-mentioned embodiments can be selectively implemented by combining them in any way. [Industrial Applicability]

[0149] The present invention is suitable for application to anomaly detection work for anomaly detection targets in various industries such as the construction industry, the chemical industry, and the real estate industry. [Explanation of symbols]

[0150] 1 Business support equipment 2 Storage section 3. Control Unit 4. Communication interface section 5 Input / output interface section 6 Input Devices 7 Output Devices 11 Layout element storage unit 12 Alert Definition Master Table 13 Result Message Template Master Table 14 Result Message Table 15 Alert Execution History Detail Table 16 Judgment result table information master table 17 Judgment result table 18 Order concentration transaction analysis results table 19 Sales Discount Analysis Result Table 20 Purchase lead time analysis results table 21 Alert definition execution part 22 Result data generation unit 23 Display control unit 24 Alert definition display section 25 Result data display section 26 Extraction condition input screen display section 27 Abnormality level selection screen display 28 Date selection screen display section 29 Response status selection screen display 30 Keyword search screen display section

Claims

1. an alert definition display unit that displays an alert definition selection screen on a display unit for selecting one or more alert definitions from among the plurality of alert definitions stored in the first storage unit; a result data display unit that acquires, from result data including determination results indicating an abnormality in an abnormality detection target that are stored in a second storage unit by executing each of the alert definitions, result data including determination results of an abnormality corresponding to one or more of the alert definitions selected on the alert definition selection screen, and displays the result data on the display unit; and an extraction condition input screen display unit that displays on the display unit an extraction condition input screen for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen, when the extraction conditions are input via the extraction condition input screen, the result data display unit extracts the result data corresponding to the input extraction conditions from the second storage unit and displays the result data on the display unit; A business support device characterized by the above.

2. a result data generation unit that refers to a third storage unit that stores display content information indicating display content to be displayed on the display unit based on the execution result of the alert definition, selects one or more pieces of display content information corresponding to the execution result, generates the result data, and stores the result data in the second storage unit; 2. The business support device according to claim 1, wherein:

3. the extraction condition input screen display unit displays the extraction condition input screen on the display unit, the extraction condition input screen including a field name input field for inputting a desired search item, an input field for a desired search value, and an operator selection field for specifying a search for a value equal to the search value, a value greater than the search value, or a value smaller than the search value; 3. The business support device according to claim 1 or 2, wherein:

4. each of the result data stored in the second storage unit includes abnormality degree information indicating, in stages, an abnormality degree that is a determination result of the abnormality detection target; an abnormality level selection screen display unit that displays an abnormality level selection screen on the display unit for selecting one or more desired abnormality levels from the abnormality levels, the result data display unit displays, on the display unit, result data corresponding to the degree of abnormality selected via the abnormality degree selection screen, from the result data stored in the second storage unit; 4. The business support device according to claim 3, wherein:

5. Each of the result data stored in the second storage unit includes date information, a date selection screen display unit that displays a date selection screen on the display unit for selecting a desired date; the result data display unit displays, on the display unit, the result data corresponding to the date selected via the date selection screen, from the result data stored in the second storage unit; 5. The business support device according to claim 4, wherein:

6. the date selection screen display unit generates a scroll bar corresponding to the period from the earliest date information to the latest date information among the date information included in the result data, and displays the scroll bar on the display unit, and initially displays a slider that is scrolled along the scroll bar at a position on the scroll bar that corresponds to the date a predetermined period before the latest date, and also displays the date that corresponds to the position on the scroll bar of the slider that is scrolled and the latest date as text information on the display unit; the result data display unit displays, on the display unit, the result data corresponding to a period from a date corresponding to the position of the slider on the scroll bar to the latest date; 6. The business support device according to claim 5,

7. Each of the result data stored in the second storage unit includes correspondence status information indicating a correspondence status of at least correspondence or non-correspondence, which is a correspondence status with respect to the determination result, and a response state selection screen display unit that displays a response state selection screen on the display unit for selecting a desired response state; the result data display unit displays, on the display unit, result data corresponding to the corresponding state selected via the corresponding state selection screen from the result data stored in the second storage unit; 7. The business support device according to claim 6, wherein:

8. a keyword search screen display unit that displays on the display unit a keyword search screen for inputting a desired keyword included in desired result data among the result data stored in the second storage unit, the result data display unit displays, on the display unit, the result data that includes the keyword input via the keyword search screen, from the result data stored in the second storage unit; 8. The business support device according to claim 7, wherein:

9. an alert definition display step in which the alert definition display unit displays an alert definition selection screen on the display unit for selecting one or more alert definitions from the plurality of alert definitions stored in the first storage unit; a result data display step in which a result data display unit acquires, from result data including determination results indicating an abnormality in an abnormality detection target that are stored in a second storage unit by executing each of the alert definitions, result data including determination results of an abnormality corresponding to one or more of the alert definitions selected on the alert definition selection screen, and displays the result data on the display unit; an extraction condition input screen display step in which an extraction condition input screen display unit displays, on the display unit, an extraction condition input screen for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen, in the result data display step, when the extraction conditions are input via the extraction condition input screen, the result data corresponding to the input extraction conditions is extracted from the second storage unit and displayed on the display unit; A business support method characterized by the above.

10. Computer, an alert definition display unit that displays an alert definition selection screen on a display unit for selecting one or more alert definitions from among the plurality of alert definitions stored in the first storage unit; a result data display unit that acquires, from result data including determination results indicating an abnormality in an abnormality detection target that are stored in a second storage unit by executing each of the alert definitions, result data including determination results of an abnormality corresponding to one or more of the alert definitions selected on the alert definition selection screen, and displays the result data on the display unit; and an extraction condition input screen display unit that displays on the display unit an extraction condition input screen for inputting extraction conditions for extracting desired result data from the result data of the alert definition selected on the alert definition selection screen, the result data display unit causes the computer to function such that, when the extraction conditions are input via the extraction condition input screen, the result data corresponding to the input extraction conditions is extracted from the second storage unit and displayed on the display unit; A business support program that features:

Citation Information

Patent Citations

  • Alert ai management device, alert ai management method, and alert ai management program

    JP2023134188A