Analysis method and analysis system
The analysis method and system address the lack of detailed information in communication systems by acquiring and analyzing control messages to detect anomalies and identify their causes, enhancing anomaly detection and system analysis.
Patent Information
- Application Number
- JP2024043909
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-10-02
AI Technical Summary
In communication systems with autonomous and distributed communication devices, the network orchestrator lacks detailed information for detecting anomalies and analyzing their causes, as existing technologies rely solely on comparing time-series statistical values with threshold values.
An analysis method and system that acquires control messages, generates metrics data and event data from these messages, and uses a learning model to detect anomalies and identify their causes based on statistical and historical information.
Enables effective anomaly detection and cause identification in communication systems by acquiring necessary information, allowing for appropriate anomaly detection and system analysis.
Smart Images

Figure 2025144232000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to analytical methods and systems. [Background technology]
[0002] Conventionally, there have been technologies relating to anomaly detection and cause analysis for communication systems. An example of a related technology is the invention disclosed in Patent Document 1 below.
[0003] The following Patent Document 1 discloses a detection device having a calculation unit that calculates a group of time-series statistical values relating to the communication quality of a monitoring target by referring to a specific log for specific traffic involving the monitoring target for communication quality, and a detection unit that detects deterioration of the communication quality of the monitoring target by comparing the group of time-series statistical values calculated by the calculation unit with a threshold value relating to deterioration of the communication quality of the monitoring target. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent Publication No. 2015-165636 Summary of the Invention [Problem to be solved by the invention]
[0005] In a communication system, multiple communication devices operate in an autonomous and distributed manner. Therefore, even the network orchestrator does not grasp the information exchanged between multiple communication devices operating in an autonomous and distributed manner.
[0006] Furthermore, in the technology described in the above-mentioned Patent Document 1, deterioration of communication quality of a monitored object is detected by comparing a time-series statistical value group relating to the communication quality of the monitored object with a threshold value. However, in order to detect an abnormality in a communication system and analyze the cause, more detailed information may be required.
[0007] The present disclosure has been made in consideration of the above-mentioned problems, and one exemplary purpose thereof is to provide a technology that can acquire information necessary for detecting an anomaly in a communication system and perform anomaly detection in an appropriate manner. [Means for solving the problem]
[0008] An analysis method according to an exemplary aspect of the present disclosure includes acquiring control messages exchanged between a plurality of communication devices included in a communication system, generating metrics data, which is statistical information for each type of control message, based on the control messages, generating event data, which is historical information for the control messages, based on the control messages, and detecting an abnormality in the communication system based on the metrics data and the event data.
[0009] An analysis system according to an exemplary aspect of the present disclosure includes an acquisition means for acquiring control messages exchanged between a plurality of communication devices included in a communication system, a metrics data generation means for generating metrics data, which is statistical information for each type of control message, based on the control messages, an event data generation means for generating event data, which is historical information for the control messages, based on the control messages, and a detection means for detecting the occurrence of an abnormality in the communication system based on the metrics data and the event data. [Effects of the Invention]
[0010] According to an exemplary aspect of the present disclosure, an exemplary effect is achieved in that information necessary for detecting an anomaly in a communication system can be acquired, and an anomaly can be suitably detected. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a block diagram illustrating a configuration example of an analysis system according to the present disclosure. [Figure 2] FIG. 10 is a flowchart illustrating a processing procedure of the analysis system according to the present disclosure. [Figure 3] 1 is a block diagram illustrating a configuration example of an analysis system according to the present disclosure. [Figure 4] FIG. 1 is a diagram illustrating an example of a BGP template. [Figure 5] FIG. 10 is a diagram illustrating an example of a fixed phrase of OSPF. [Figure 6] A figure showing an example of a control message of a 5G core. [Figure 7] FIG. 10 is a diagram illustrating an example of learning data. [Figure 8] FIG. 1 is a diagram illustrating anomaly detection using a learning model. [Figure 9] FIG. 10 is a diagram illustrating an example of training data and inference data. [Figure 10] FIG. 10 is a diagram illustrating the identification of the cause of a system abnormality. [Figure 11] FIG. 1 illustrates an example of a communication system. [Figure 12] FIG. 1 is a diagram for explaining how to identify the cause of an abnormality in a communication system. [Figure 13] FIG. 1 is a block diagram illustrating a configuration of a computer that functions as an analysis system according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0012] The following are examples of embodiments of the present invention. However, the present invention is not limited to the exemplary embodiments shown below, and various modifications are possible within the scope of the claims. For example, embodiments obtained by appropriately combining the technical means employed in the exemplary embodiments shown below may also be included in the scope of the present invention. Furthermore, embodiments obtained by appropriately omitting some of the technical means employed in the exemplary embodiments shown below may also be included in the scope of the present invention. Furthermore, the effects mentioned in the exemplary embodiments shown below are examples of effects expected in the exemplary embodiments, and do not define the scope of the present invention. In other words, embodiments that do not exhibit the effects mentioned in the exemplary embodiments shown below may also be included in the scope of the present invention.
[0013] First Exemplary Embodiment A first exemplary embodiment, which is one example of an embodiment of the present invention, will be described in detail with reference to the drawings. This exemplary embodiment is the basic form of each exemplary embodiment described later. Note that the scope of application of each technical means employed in this exemplary embodiment is not limited to this exemplary embodiment. That is, each technical means employed in this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure to the extent that no particular technical obstacles arise. Furthermore, each technical means shown in the drawings referred to in describing this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure to the extent that no particular technical obstacles arise.
[0014] (Configuration of analysis system 1) The configuration of analysis system 1 will be described with reference to FIG. 1. FIG. 1 is a block diagram showing an example configuration of analysis system 1. Analysis system 1 is applicable to systems such as AIops (Artificial Intelligence for IT Operations), and as shown in FIG. 1, includes an acquisition unit 11, a metrics data generation unit 12, an event data generation unit 13, and a detection unit 14. A system including analysis system 1, communication devices 2-1 and 2-2, and communication network 3 will be referred to as a communication system. Furthermore, communication network 3 is a network through which analysis system 1 collects information from communication devices 2-1 and 2-2, and the network formed by communication devices 2-1 and 2-2 is considered to exist separately.
[0015] The acquisition unit 11, the metrics data generation unit 12, the event data generation unit 13, and the detection unit 14 are configured to be able to communicate via a communication network 3, for example. Here, the specific configuration of the communication network 3 does not limit this exemplary embodiment, but for example, a wireless LAN (Local Area Network), a wired LAN, a WAN (Wide Area Network), a public line network, a mobile data communication network, or a combination of these networks can be used.
[0016] The acquisition unit 11, metrics data generation unit 12, event data generation unit 13, and detection unit 14 may be implemented in one device or in separate devices. Furthermore, each unit may be distributed and located on the cloud (i.e., on the communication network 3). For example, when implemented on the cloud or separate devices, information from each unit is sent and received via the communication network 3 to proceed with processing.
[0017] The acquisition unit 11 acquires control messages exchanged between a plurality of communication devices 2-1 and 2-2 included in the communication system. The communication devices 2-1 and 2-2 are devices such as switches capable of communicating via a communication network 3, NFs (Network Functions) in 5G (fifth generation mobile communication systems), etc., and are devices that operate in an autonomous and distributed manner while exchanging control messages between the plurality of devices.
[0018] Control messages are messages defined in various control protocols, such as Link Layer Discovery Protocol (LLDP), Open Shortest Path First (OSPF), Link Aggregation Control Protocol (LACP), and Border Gateway Protocol (BGP), which are protocols used between switches, Network Configuration Protocol (Netconf), Simple Network Management Protocol (SNMP), OpenFlow, and external BGP (eBGP), which are control protocols used by controllers, Synchronous Ethernet (SyncEther) and Ethernet Operations, Administration, and Maintenance (EtherOAM), which are network-level protocols spanning multiple devices, and communication between NFs in a 5G core.
[0019] The acquisition unit 11 may receive control messages from, for example, mirror ports set in the communication devices 2-1 and 2-2, or may receive control messages from agents placed in the communication devices 2-1 and 2-2. An agent is a software module that moves on a network and automatically and efficiently sends and receives information specified by a user.
[0020] When a mirror port is set in the communication devices 2-1 and 2-2, the mirror port copies packets flowing through the network and transmits the copied packets to the acquisition unit 11. When an agent is placed in the communication devices 2-1 and 2-2, the agent may collect packets flowing through the network and create metrics data and event data, which will be described later.
[0021] The metrics data generator 12 generates metrics data, which is statistical information for each type of control message, based on the control message. The metrics data is statistical information such as the number of transmissions per hour, the number of receptions per hour, the average length of transmitted packets, the average length of received packets, the average interval between packets, the average interval between received packets, the number of parameters in the message, etc.
[0022] Furthermore, the metrics data may be statistical information not based on control messages, such as CPU usage, memory usage, disk write, disk read, network transfer volume, and network reception volume. This metrics data is used to detect abnormalities in devices such as servers.
[0023] The event data generator 13 generates event data, which is history information of a control message, based on the control message. The event data is log data of parameters and the like included in the control message. As will be described later, the event data can be generated by using a template prepared for each control message of the control protocol.
[0024] The detection unit 14 detects the occurrence of an abnormality in the communication system based on the metrics data and event data. For example, the detection unit 14 detects the occurrence of an abnormality in the communication system using a learning model that has been trained on metrics data and event data generated from control messages under normal conditions. For example, a learning model trained by unsupervised learning can be used as the learning model.
[0025] The detection unit 14 generates metrics data and event data as inference data from control messages collected, for example, every four hours, and sequentially inputs the metrics data and event data at each time into a learning model. Then, by detecting data at a time when the network state is different from normal, the occurrence of an abnormality in the communication system is detected. For example, the detection unit 14 may input the inference data into a trained learning model and determine that the state is normal if the correlation with normal data is high, or conversely, determine that the state is abnormal if the correlation with normal data is low.
[0026] (Effects of Analysis System 1) As described above, in the analysis system 1, the metrics data generator 12 generates metrics data, which is statistical information for each type of control message, based on the control message. The event data generator 13 generates event data, which is historical information about the control message, based on the control message. Therefore, the detector 14 can acquire the metrics data and event data necessary for detecting anomalies in the communication system and perform anomaly detection appropriately.
[0027] (Analysis method flow) The flow of the analysis method S1 will be described with reference to Fig. 2. Fig. 2 is a flow diagram showing the flow of the analysis method S1. As shown in Fig. 2, the analysis method S1 includes steps S11 to S14.
[0028] First, the acquisition unit 11 acquires control messages exchanged between a plurality of communication devices 2-1 and 2-2 included in the communication system (S11). The communication devices 2-1 and 2-2 are devices such as switches that can communicate via the communication network 3, NFs in 5G, etc., and are devices that operate in an autonomous and distributed manner while exchanging control messages between a plurality of devices. The control messages are messages defined in various control protocols.
[0029] Next, the metrics data generator 12 generates metrics data, which is statistical information for each type of control message, based on the control message (S12). The metrics data is statistical information such as the number of transmissions per hour, the number of receptions per hour, the average length of transmitted packets, the average length of received packets, the average interval between packets, the average interval between received packets, the number of parameters in the message, etc.
[0030] Next, the event data generator 13 generates event data, which is history information of the control message, based on the control message (S13). The event data is log data of parameters and the like included in the control message. As will be described later, the event data can be generated by using a template prepared for each control message of the control protocol.
[0031] The detection unit 14 detects the occurrence of an abnormality in the communication system based on the metrics data and event data (S14). For example, the detection unit 14 detects the occurrence of an abnormality in the communication system using a learning model that has been trained on metrics data and event data generated from control messages under normal conditions. For example, a learning model trained by unsupervised learning can be used as the learning model.
[0032] (Effect of analysis method) As described above, in analysis method S1, the metrics data generator 12 generates metrics data, which is statistical information for each type of control message, based on the control message. The event data generator 13 then generates event data, which is historical information about the control message, based on the control message. Therefore, the detector 14 can acquire the metrics data and event data necessary for detecting anomalies in the communication system and perform anomaly detection appropriately.
[0033] Second Exemplary Embodiment A second exemplary embodiment, which is one example of an embodiment of the present invention, will be described in detail with reference to the drawings. Components having the same functions as those described in the above exemplary embodiment will be assigned the same reference numerals, and their description will be omitted as appropriate. The scope of application of each technical means employed in this exemplary embodiment is not limited to this exemplary embodiment. That is, each technical means employed in this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure, to the extent that no particular technical obstacles arise. Furthermore, each technical means shown in each drawing referenced to explain this exemplary embodiment can also be employed in other exemplary embodiments included in the present disclosure, to the extent that no particular technical obstacles arise.
[0034] (Configuration of analysis system 1A) The configuration of analysis system 1A will be described with reference to Fig. 3. Fig. 3 is a block diagram showing the configuration of analysis system 1A. Analysis system 1A includes an acquisition unit 11, a metrics data generation unit 12, an event data generation unit 13, a detection unit 14, an identification unit 15, and an estimation unit 16. Note that a system including analysis system 1A, communication devices 2-1 and 2-2, and communication network 3 is referred to as a communication system.
[0035] The acquisition unit 11, the metrics data generation unit 12, the event data generation unit 13, the detection unit 14, the identification unit 15, and the estimation unit 16 are configured to be able to communicate via a communication network 3, for example. Here, the specific configuration of the communication network 3 does not limit the present exemplary embodiment, but for example, a wireless LAN, a wired LAN, a WAN, a public line network, a mobile data communication network, or a combination of these networks can be used.
[0036] The acquisition unit 11, metrics data generation unit 12, event data generation unit 13, detection unit 14, identification unit 15, and estimation unit 16 may be implemented in one device or in separate devices. Furthermore, each unit may be distributed and located on the cloud (i.e., on the communication network 3). For example, when implemented on the cloud or separate devices, information from each unit is transmitted and received via the communication network 3 to proceed with processing.
[0037] The acquisition unit 11 acquires control messages exchanged between a plurality of communication devices 2-1 and 2-2 included in the communication system. The communication devices 2-1 and 2-2 are devices such as switches that can communicate via a communication network 3, NFs in 5G, etc., and are devices that operate in an autonomous and distributed manner while exchanging control messages between the plurality of devices.
[0038] The metrics data generator 12 generates metrics data, which is statistical information for each type of control message, based on the control message. The metrics data is statistical information such as the number of transmissions per hour, the number of receptions per hour, the average length of transmitted packets, the average length of received packets, the average interval between packets, the average interval between received packets, the number of parameters in the message, etc.
[0039] When the control protocol is BGP, the acquisition unit 11 collects statistical information for the past three hours at one-hour intervals, for example. The metrics data generation unit 12 then aggregates control messages sent and received during one-minute intervals. Hereinafter, control messages are also simply referred to as messages.
[0040] For example, the metrics data generation unit 12 generates metrics data such as the number of times the message "OPEN" was sent and received, the number of times the message "UPDATE" was sent, the number of times it was received, the number of deleted routes, and the number of times it was updated, the number of times the message "NOTIFICATION" was sent and received, the number of times the message "KEEPALIVE" was sent and received, the transmission interval for each communication partner, and the reception interval for each communication partner.
[0041] When the control protocol is OSPF, the acquisition unit 11 collects statistical information for the past three hours at one-hour intervals, for example. The metrics data generation unit 12 then aggregates control messages sent and received at one-minute intervals. For example, the metrics data generation unit 12 generates the following metrics data: the number of "HELLO" messages sent, the number of "HELLO" messages received, the transmission interval, the reception interval, and the number of neighbor exchanges per hour; the number of "DBD" messages received and the number of LSA headers received; the number of "LSR" messages sent, the number of "LSA" messages received, the number of LSAs requested (requested), and the number of LSA types requested (requested); the number of "LSU" messages sent, the number of "LSU" messages received, the number of LSAs and the number of LSA types; and the number of "LSAck" messages sent, the number of "LSAck" messages received, and the number of LSA headers.
[0042] When the control protocol is 5G Core, the acquisition unit 11 aggregates messages related to the service operations of each NF, such as the Access and Mobility Function (AMF) and the Session Management Function (SMF). The metrics data generation unit 12 generates metrics data such as the number of messages sent and received for each service operation per hour.
[0043] Based on a control message, the event data generator 13 generates event data, which is history information of the control message. The event data is log data of parameters and the like included in the control message. The event data generator 13 may also generate event data by extracting parameters using a template prepared for each control protocol.
[0044] FIG. 4 is a diagram showing examples of fixed phrases (template sentences) for each type of BGP message. The message "OPEN" is a message for starting a BGP session. As shown in FIG. 4, for example, an AS (Autonomous System) number is written in "*", and the event data generation unit 13 can obtain the AS number by referring to AS<*> in the message "OPEN". The event data generation unit 13 can obtain other parameters in the same way.
[0045] The message "UPDATE" is a message used to notify routing information. The message "NOTIFICATION" is a message for notifying the other party of a protocol error. The message "KEEPALIVE" is a message for confirming that the BGP session is valid. The event data generation unit 13 can acquire the parameters of each message by referring to these fixed phrases.
[0046] Figure 5 is a diagram showing an example of an OSPF template text. The upper diagram in Figure 5 shows an example of a template text for each type of OSPF message. The message "Hello" is a message used to search for neighboring routers, determine the designated router, etc. The message "DBD" is an abbreviation for Database Description, and is a message that summarizes and notifies the contents of the topology database when forming an adjacency. The message "LSR" is an abbreviation for Link State Request, and is a message that requests additional LSA (topology information) in the final stage of forming an adjacency.
[0047] The message "LSU" is an abbreviation for Link State Update, and is a message that notifies LSA (topology information). The message "LSA" is an abbreviation for Link State Ack, and is an acknowledgment message for a link state update packet. The event data generator 13 can acquire the parameters of each message by referring to these fixed phrases.
[0048] The bottom diagram in Figure 5 shows examples of template text for each type of LSA information contained in an LSU. A "Router LSA" is information about router interfaces within an area. A "Network LSA" is information about a multi-access network to which multiple routers are connected. A "Network Summary LSA" is route information (next hop, metric, etc.) to networks outside the area (but within the AS).
[0049] "ASBR Summary LSA" is route information to an AS Border Router (ASBR) outside the area. "AS External LSA" is route information to an AS outside. "NSSA External LSA" is route information to an AS outside. The event data generation unit 13 can obtain parameters for each type of LSA information by referring to these template messages.
[0050] 6 is a diagram showing AMF Service Operations, which is an example of a 5G core control message. The event data generator 13 extracts parameters included in the message using a template sentence created so that parameters of the payload of the Service Operations message can be extracted.
[0051] The detection unit 14 detects the occurrence of an abnormality in the communication system based on the metrics data and event data. For example, the detection unit 14 detects the occurrence of an abnormality in the communication system using a learning model that has learned metrics data and event data generated from control messages under normal conditions.
[0052] (Server abnormality detection) First, we will briefly explain server anomaly detection. Figure 7 is a diagram showing an example of learning data used when creating a learning model. The upper diagram in Figure 7 shows an example of metrics data, which includes statistical information such as time, CPU utilization (CPU_Utilization), memory utilization (Memory_Utilization), disk write (Disk_Write), disk read (Disk_Read), network transfer volume (Network_TX), and network reception volume (Network_RX).
[0053] The bottom diagram in Figure 7 shows an example of event data, which is event data used to monitor whether any abnormalities have occurred on the server (Host A). This event data includes the syslog and application log of the server (Host A). When analyzing multiple servers (Hosts), data should be prepared for each server (Host). Note that data from a period when the system is operating normally is used as learning data.
[0054] Metrics data and event data from the same time period are input into the learning model and learning is performed. When analyzing multiple servers (hosts), the learning model is trained using data prepared for each server (host).
[0055] Fig. 8 is a diagram schematically illustrating anomaly detection using a learning model. Learning model 4 is a trained learning model that has been trained using the metrics data and event data in normal times shown in Fig. 7. As shown in Fig. 8, detection unit 14 inputs metrics data and event data at the same time during the detection period into learning model 4, thereby determining whether the server is normal or abnormal at that time.
[0056] (Detection of abnormalities in communication systems) 9 is a diagram showing another example of learning data when creating a learning model. Metrics data 5-1 is OSPF metrics data as learning data, and includes statistical information such as the time, the number of "HELLO" transmissions, the number of "HELLO" exchange neighbors, and the number of "LSU" LSAs.
[0057] The event data 5-2 is OSPF event data as learning data, and includes the time and parameters of exchanged messages. Similar to the learning method of the learning model explained using Fig. 7, a learned learning model is created by having the learning model learn the metrics data 5-1 and the event data 5-2.
[0058] Metrics data 6-1 is OSPF metrics data as inference data, and includes the same type of data as metrics data 5-1. Event data 6-2 is OSPF event data as inference data, and includes the same type of data as event data 5-2. As with the anomaly detection method described using Figure 8, by inputting metrics data 6-1 and event data 6-2 into a learning model, it is determined whether the communication system is normal or abnormal at that time.
[0059] The identifying unit 15 identifies the cause of the abnormality in the communication system based on at least one of the metrics data and the event data.
[0060] (Identifying the cause of server abnormalities) First, we will briefly explain how to identify the cause of a server abnormality. For example, when the performance index of a certain system application deteriorates, the identification unit 15 identifies the server that is causing the abnormality. The identification unit 15 uses the average response time of requests to the system, the number of processes per hour, etc. as numerical data representing the performance index of the system application.
[0061] Figure 10 is a diagram that shows a model of identifying the cause of a system anomaly. Metrics data 5-3 is the same as the metrics data shown in the upper diagram of Figure 8, and data including the period before and after the anomaly occurred is used. Event data 6-3 is the same as the event data shown in the lower diagram of Figure 8, and data including the period before and after the anomaly occurred is used.
[0062] For example, if the numerical data representing a performance index is "Latency," the identifying unit 15 identifies a device (HostB) having metrics data that indicates behavior that has a strong causal relationship with fluctuations in "Latency" as the cause of the anomaly. For example, a weight is set for each piece of metrics data, and the identifying unit 15 calculates the score of each device in the period before and after the anomaly occurs, and identifies the device with the highest score as the cause of the anomaly. For example, the score can be calculated by multiplying each piece of metrics data by a weight and adding the results together.
[0063] (Identifying the cause of communication network abnormalities) 11 is a diagram showing an example of a communication system in which devices P to U communicate with each other via communication devices A to F. It is assumed that the communication devices A to F communicate with each other using OSPF.
[0064] Fig. 12 is a diagram for explaining how to identify the cause of an abnormality in a communication system. A case will be described in which a device (not shown) separately monitors the communication system and detects an increase in communication delay between devices P to R. The metrics data shown in the upper diagram of Fig. 12 is metrics data that includes the period before and after the increase in communication delay, and includes the time, the latency between P and R, and statistical information for communication devices A to F.
[0065] The event data shown in the lower diagram of FIG. 12 is event data including a period before and after an increase in communication latency, and includes time and log information of messages from devices A to F. For example, if the numerical data representing a performance index is "Latency," the identifying unit 15 identifies a communication device having statistical information indicating behavior that has a strong causal relationship with fluctuations in "Latency," such as communication device D, as the cause of the abnormality. For example, a weight is set for each piece of statistical information, and the identifying unit 15 calculates a score for each communication device and identifies device D with the highest score as the cause of the abnormality. Note that the identifying unit 15 may refer to event data including a period before and after an increase in communication latency to identify the communication path in which the abnormality is occurring.
[0066] If a control message is encrypted, the estimation unit 16 estimates the type of the control message based on at least the packet size and frequency of the control message. Even if the control message is encrypted, the header portion is not encrypted, so the type of the control message can be determined from the port number, etc.
[0067] For example, BGP's "KEEPALIVE" is only a header, whereas BGP's "UPDATE" contains data on the route information to be updated. Also, the body of "Route-refresh" is fixed length, and TCP is closed immediately after "NOTIFICATION." The estimation unit 16 can determine the type of control message from these differences.
[0068] When a control message is encrypted, the estimation unit 16 may estimate the type of the encrypted control message using a learning model that has been trained using at least the packet size, frequency, and type of the unencrypted control message as training data.
[0069] (Effects of Analysis System 1A) As described above, in the analysis system 1A, the metrics data generator 12 generates metrics data, which is statistical information for each type of control message, based on the control message. Therefore, the identifier 15 can acquire the metrics data necessary to identify the cause of an abnormality in the communication system, and can suitably identify the cause of the abnormality in the communication system.
[0070] Furthermore, in the analysis system 1A, when a control message is encrypted, the estimation unit 16 estimates the type of the control message based on at least the packet size and frequency of the control message. Therefore, even if the control message is encrypted, the type of the control message can be suitably estimated.
[0071] Furthermore, in the analysis system 1A, when a control message is encrypted, the estimation unit 16 estimates the type of the encrypted control message using a learning model that has been trained using at least the packet size, frequency, and type of the unencrypted control message as training data. Therefore, the estimation unit 16 can suitably estimate the type of the control message even when the control message is encrypted.
[0072] In the analysis system 1A, the event data generator 13 generates event data by extracting parameters using a template prepared for each control protocol. Therefore, the event data generator 13 can easily generate event data for each control protocol.
[0073] [Software implementation example] Some or all of the functions of the analysis systems 1 and 1A may be realized by hardware such as an integrated circuit (IC chip), or by software.
[0074] In the latter case, the analysis systems 1 and 1A are realized by, for example, a computer that executes instructions of a program, which is software that realizes each function. An example of such a computer (hereinafter referred to as computer C) is shown in Fig. 13. Fig. 13 is a block diagram showing the hardware configuration of computer C that functions as the analysis systems 1 and 1A.
[0075] The computer C includes at least one processor C1 and at least one memory C2. The memory C2 stores a program P for causing the computer C to operate as each of the above systems. In the computer C, the processor C1 reads and executes the program P from the memory C2, thereby realizing each function of the above analysis systems 1 and 1A.
[0076] The processor C1 may be, for example, a central processing unit (CPU), a graphic processing unit (GPU), a digital signal processor (DSP), a micro processing unit (MPU), a floating point number processing unit (FPU), a physics processing unit (PPU), a tensor processing unit (TPU), a quantum processor, a microcontroller, or a combination thereof. The memory C2 may be, for example, a flash memory, a hard disk drive (HDD), a solid state drive (SSD), or a combination thereof.
[0077] The computer C may further include a RAM (Random Access Memory) for expanding the program P during execution and for temporarily storing various data. The computer C may also include a communication interface for transmitting and receiving data to and from other devices. The computer C may also include an input / output interface for connecting input / output devices such as a keyboard, mouse, display, and printer.
[0078] Furthermore, the program P can be recorded on a non-transitory tangible recording medium M that can be read by the computer C. Such a recording medium M can be, for example, a tape, a disk, a card, a semiconductor memory, or a programmable logic circuit. The computer C can acquire the program P via such a recording medium M. The program P can also be transmitted via a transmission medium. Such a transmission medium can be, for example, a communication network or broadcast waves. The computer C can also acquire the program P via such a transmission medium.
[0079] [Appendix 1] This disclosure includes the techniques described in the following appendices. However, the present invention is not limited to the techniques described in the following appendices, and various modifications are possible within the scope of the claims.
[0080] (Appendix 1) Obtaining control messages exchanged between a plurality of communication devices included in a communication system; generating metrics data, which is statistical information for each type of the control message, based on the control message; generating event data that is history information of the control message based on the control message; detecting an occurrence of an abnormality in the communication system based on the metrics data and the event data. Analysis method.
[0081] (Appendix 2) The analysis method further comprises: and identifying a cause of the abnormality in the communication system based on at least one of the metrics data and the event data. Analytical method described in Appendix 1.
[0082] (Appendix 3) The analysis method further comprises: If the control message is encrypted, estimating the type of the control message based on at least the packet size and frequency of the control message. The analytical method described in Appendix 1 or 2.
[0083] (Appendix 4) In estimating the type of the control message, If the control message is encrypted, the type of the encrypted control message is estimated using a learning model that has been trained using at least the packet size, frequency, and type of the unencrypted control message as training data. Analytical method described in Appendix 3.
[0084] (Appendix 5) In generating the event data, generating the event data by extracting parameters using a template prepared for each control protocol; The analytical method described in Appendix 1 or 2.
[0085] (Appendix 6) an acquisition means for acquiring control messages exchanged among a plurality of communication devices included in the communication system; a metrics data generating means for generating metrics data, which is statistical information for each type of the control message, based on the control message; an event data generating means for generating, based on the control message, event data that is history information of the control message; a detection means for detecting an occurrence of an abnormality in the communication system based on the metrics data and the event data, Analysis system.
[0086] (Appendix 7) The analysis system further comprises: an identification unit that identifies a cause of an abnormality in the communication system based on at least one of the metrics data and the event data; 10. The analytical system of claim 6.
[0087] (Appendix 8) The analysis system further comprises: an estimation means for estimating a type of the control message based on at least a packet size and a frequency of the control message when the control message is encrypted; 8. The analytical system of claim 6 or 7.
[0088] (Appendix 9) The estimation means If the control message is encrypted, the type of the encrypted control message is estimated using a learning model that has been trained using at least the packet size, frequency, and type of the unencrypted control message as training data. 9. The analytical system of claim 8.
[0089] (Appendix 10) The event data generating means generating the event data by extracting parameters using a template prepared for each control protocol; 8. The analytical system of claim 6 or 7.
[0090] (Appendix 11) A control program for causing a computer to operate as the analysis system according to any one of Supplementary Notes 6 to 10, the control program causing the computer to function as each of the means. [Explanation of symbols]
[0091] 1,1A Analysis System 2-1, 2-2 Communication equipment 3. Communication Network 4. Learning Model 11 Acquisition Department 12 Metrics Data Generation Unit 13 Event data generation unit 14. Detection unit 15 Specific section 16 Estimation part
Claims
1. Obtaining control messages exchanged between a plurality of communication devices included in a communication system; generating metrics data, which is statistical information for each type of the control message, based on the control message; generating event data that is history information of the control message based on the control message; detecting an occurrence of an abnormality in the communication system based on the metrics data and the event data. Analysis method.
2. The analysis method further comprises: and identifying a cause of the abnormality in the communication system based on at least one of the metrics data and the event data. The analytical method according to claim 1 .
3. The analysis method further comprises: If the control message is encrypted, estimating the type of the control message based on at least the packet size and frequency of the control message. The analytical method according to claim 1 or 2.
4. In estimating the type of the control message, If the control message is encrypted, the type of the encrypted control message is estimated using a learning model that has been trained using at least the packet size, frequency, and type of the unencrypted control message as training data. The analytical method according to claim 3.
5. In generating the event data, generating the event data by extracting parameters using a template prepared for each control protocol; The analytical method according to claim 1 or 2.
6. an acquisition means for acquiring control messages exchanged among a plurality of communication devices included in the communication system; a metrics data generating means for generating metrics data, which is statistical information for each type of the control message, based on the control message; an event data generating means for generating, based on the control message, event data that is history information of the control message; a detection means for detecting an occurrence of an abnormality in the communication system based on the metrics data and the event data, Analysis system.
7. The analysis system further comprises: an identification unit that identifies a cause of an abnormality in the communication system based on at least one of the metrics data and the event data; The analysis system according to claim 6 .
8. The analysis system further comprises: an estimation means for estimating a type of the control message based on at least a packet size and a frequency of the control message when the control message is encrypted; The analysis system according to claim 6 or 7.
9. The estimation means If the control message is encrypted, the type of the encrypted control message is estimated using a learning model that has been trained using at least the packet size, frequency, and type of the unencrypted control message as training data. The analysis system according to claim 8 .
10. The event data generating means generating the event data by extracting parameters using a template prepared for each control protocol; The analysis system according to claim 6 or 7.
Citation Information
Patent Citations
Detecting device, detecting method, and detecting program
JP2015165636A