Information processing system

The information processing system efficiently identifies and analyzes user interactions with web services by monitoring and extracting relevant operation histories, reducing the time needed to generate analysis reports.

JP2026061011APending Publication Date: 2026-04-09CANON DENSHI KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing systems require significant time to understand the characteristics of each web service and generate analysis reports, as they need to record and analyze operation logs for user interactions, which is inefficient and time-consuming.

Method used

An information processing system with operation monitoring, recording, and extraction means to identify and analyze user interactions with web services, allowing for rapid identification of relevant operation histories and generating reports based on specified web access destinations.

Benefits of technology

Reduces the time required to investigate and analyze URLs for specific web services, enabling easier understanding of user tasks, thereby improving efficiency in generating analysis reports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026061011000001_ABST
    Figure 2026061011000001_ABST
Patent Text Reader

Abstract

This reduces the time required to research and analyze URLs for specific web services, making it easier to understand what tasks users were performing while using those web services. [Solution] The system includes an operation monitoring means for monitoring user operations on an information processing device, an operation recording means for recording the operations monitored by the operation monitoring means as an operation history, a web access recording means for monitoring the user's use of web services on the information processing device and recording it as a web access history, a first extraction means for extracting from the web access history entries that match a specified web access destination, a second extraction means for extracting from the operation history entries that match the period during which the web access extracted by the first extraction means was performed as a target operation history, and an output means for outputting results based on the target operation history based on the specified web access destination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing system for analyzing operation logs.

Background Art

[0002] When considering business improvement by corporate managers, there are cases where services are used to collect the usage status of various web services and application usage status using the Internet as operation logs, and generate reports after analysis. Also, when grasping the actual usage of a specific web service, it is effective to use the above-mentioned log collection and analysis service.

[0003] As an operation specific to a web service, there are cases where the function is switched for each URL, such as file upload by accessing a certain URL, video viewing by accessing a certain URL, and comment sending by accessing a certain URL.

[0004] When providing an analysis report specialized for a specific web service in a log collection and analysis service, it is common to understand the above-mentioned operation specific to the web service and report the web access log. However, since it takes time to understand the characteristics of each web service, it takes time to provide an analysis report to end users.

[0005] First, for a specific web service, in order to investigate its characteristics, the functions are classified for each URL. However, depending on the web service, classification may also be based on the transmitted data. Next, logs are collected for the URLs accessed by users as the actual usage situation. By combining the collected logs with the above classification, it is analyzed what operations the users have performed with the web service. Finally, by reporting the analysis results, it is a common analysis method to grasp the actual usage of a specific web service.

[0006] Furthermore, as described in Patent Document 1, there is a method that records the task associated with the user's clipboard paste operation, along with the window title and URL at that time, and then analyzes the task being performed. [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Patent No. 5353208 [Overview of the project] [Problems that the invention aims to solve]

[0008] However, since the system records information necessary for analysis (window title, URL, etc.) as soon as the user operates their personal computer (PC), it is necessary to understand in advance what information is needed and to devise a method for acquiring the logs. [Means for solving the problem]

[0009] Therefore, in the present invention, Operation monitoring means for monitoring the operation of an information processing device by a user, An operation recording means that records the operations monitored by the aforementioned operation monitoring means as an operation history, A web access recording means that monitors the user's use of web services on the information processing device and records it as web access history, A first extraction means extracts from the aforementioned web access history entries that match the specified web access destination, A second extraction means extracts from the operation history that matches the period during which the WEB access extracted by the first extraction means was performed, as the target operation history. Based on the specification of a web access destination, an output means outputs the results based on the aforementioned target operation history. It is characterized by having the following features. [Effects of the Invention]

[0010] According to the present invention, it is possible to reduce the time required to investigate and analyze URLs for a specific web service, and to easily understand what tasks users were performing while using the web service. [Brief explanation of the drawing]

[0011] [Figure 1] System configuration diagram of the information processing system according to the present invention [Figure 2] Example of operation history 10G in client terminal device 10 [Figure 3] An example of 20GB of operation history collected by a server device, corresponding to 10GB of operation history. [Figure 4] Flowchart for analyzing a specific web service [Figure 5] Examples of compatible databases [Figure 6] Example of generating a report on the usage status of a specific web service. [Modes for carrying out the invention]

[0012] <System Configuration Diagram> First, the information processing system configuration according to this embodiment will be explained using the system configuration diagram in Figure 1. As shown in Figure 1, the information processing system according to this embodiment has a computer, i.e., an information processing device, and each information processing device is connected to a network 30. The network 30 may be connected to the Internet. Hereinafter, this information processing device will be referred to as a client terminal device 10. There may be multiple client terminal devices 10. Furthermore, the client terminal device 10 can be any device that is capable of executing the various processes described later, which are performed by information processing devices such as PCs and mobile terminal devices.

[0013] Furthermore, in this embodiment, it is assumed that there are multiple client terminal devices 10, and that each is connected via the network 30.

[0014] <Client terminal device> In the client terminal device 10, the arithmetic unit 10B is a microprocessor (e.g., CPU). The arithmetic unit 10B starts the operating system (OS) stored in the storage device 10C according to a boot program such as a BIOS stored in the ROM of memory 10E, and then starts various programs according to the OS or user operations. This storage device 10C stores computer programs and data that cause the arithmetic unit 10B to execute various processes described later as being performed by the OS or this device. This computer program includes the client program 10F and the operation history 10G on the client terminal device 10. The computer programs and data stored in the storage device 10C are loaded into the ROM of memory 10E as appropriate according to the control of the arithmetic unit 10B and become the target of processing by the arithmetic unit 10B. The OS is, for example, Windows®, MacOS®, Linux®, iOS®, Android®, etc. The storage device 10C is a hard disk drive (HDD) or solid state drive (SSD), etc., and stores the OS as well as the client program 10F that runs on the client terminal device 10. The input / output device (hereinafter referred to as I / O device) 10A is an input / output interface for connecting to a pointing device (such as a mouse) or a keyboard, or a display incorporating a touch panel. The keyboard may be a software keyboard. The I / O device 10A may also be a voice input unit including a microphone, which recognizes the operator's voice input using a voice recognition function and transmits the recognized voice to the arithmetic unit 10B. The I / O device 10A also functions as a user interface (UI) for displaying information. The network interface (hereinafter referred to as network I / F) 10D is an interface with the network 30 and is a communication circuit for communicating with other information processing devices (for example, other client terminal devices 10, etc.). The arithmetic unit 10B may send request packets to, for example, an external web service on the internet via the network I / F 10D.

[0015] The client program 10F is a program for monitoring data, programs, etc. of the client terminal device 10. For example, it has a function (operation monitoring means) for monitoring operations such as file operations (copying, moving, renaming, etc.) and program startup performed by a user operating the client terminal device 10 via the I / O device 10A. Also, the client program 10F stores the above-mentioned file operations, program startups, etc. in the storage device 10C (operation storage means) as operation histories. Further, the operation monitoring means similarly has a function for monitoring access by a user operating the client terminal device 10 to external WEB services via the I / O device 10A. Similar to the operation history, the access history to the WEB service is stored in the storage device 10C (WEB access storage means).

[0016] <Server device> In the server device 20, the arithmetic unit 2OB is a microprocessor (e.g., CPU). The arithmetic unit 20C starts the operating system (OS) stored in the storage device 20C according to a boot program such as BIOS stored in the ROM of the memory 20E, and further starts various programs according to the OS or user operations. The storage device 20C stores an OS, a computer program and data for causing the arithmetic unit 20B to execute each process described later as operations of this device. This computer program includes a server program 20F.

[0017] The server program 20F is a program for managing data, programs, etc. of the server device 20. For example, it has functions such as recording data received from the client terminal device 10 in the storage device 20C and calculating arbitrary data by the arithmetic unit 20B. Also, the server program 20F has a function for analyzing the operation history 20G and generating a report.

[0018] Computer programs and data stored in the storage device 20C are loaded into the RAM of the memory 20E as appropriate, according to the control of the arithmetic unit 20B, and become subject to processing by the arithmetic unit 20B. The operating system may be, for example, Windows®, MacOS®, Linux®, iOS®, or Android®.

[0019] The storage device 20C is a hard disk drive (HDD) or solid-state drive (SSD), and stores the OS as well as server programs 20F that run on the server device 20. The network interface 20D is an interface to the network 30 and is a communication circuit for communicating with other information processing devices (for example, the client terminal device 10). The arithmetic unit 20B has functions such as receiving request packets sent from the network interface 10D of the client terminal device 10 via the network interface 20D. For this reason, the storage device 20G stores operation history 20G, which includes the operation history 10G of the client terminal device 10 and packets obtained from the network interface 20D.

[0020] Figure 2 shows an example of the operation history recorded by the client program 10F. Figure 2 shows an example of the operation history 10G for file operations performed on the client terminal device 10. As an example, Figure 2 records the PC name of the client terminal device 10, the username of the user who performed the operation, the date and time of the operation, the operation type (such as file operation or active window), the operation details, the window title of the process on which the operation was performed, the process name, and the target of the operation. Note that "OPEN" and "WRITE" recorded as operation details correspond to opening and writing to the target file, respectively. In addition, for operations where the operation type is "active window," it corresponds to the window with the title recorded as the window title becoming active.

[0021] The information to be recorded may include information not shown in Figure 2 (for example, the number of keyboard keystrokes acquired via I / O device 10A, and information recorded periodically such as the mouse pointer movement distance).

[0022] Figure 3 shows an example of 20G of operation history collected by the server device 20, corresponding to 10G of operation history from the client terminal device 10, where a browser was launched and web services were accessed. As an example, Figure 3 shows a table that has been extracted and saved from the 20G of operation history, limited to web service access (for example, operation logs with specific processes or network access), and shows that the PC name of the client terminal device 10, the username of the user who performed the operation, the date and time of the operation, the operation type, the HTTP method, and the accessed URL are recorded.

[0023] <Processing flow> The client program 10F transmits the operation history 10G acquired by the client terminal device 10 to the server device 20, and the server program 20F stores it as operation history 20G. In the following explanation, operation history 20G is exemplified as being the same as in Figure 2. The server program 20F starts analyzing operation history 20G at any time.

[0024] Figure 4 shows a flowchart for analyzing a specific web service.

[0025] First, the analysis of a specific web service is started at any time (S1000). The timing can be a predetermined date and time, or it can be specified by the user. Also, at the start of the analysis, the user specifies the "text content keywords" to be used for the analysis. These are selected from those registered in the corresponding database, which will be described later. At this time, multiple keywords may be grouped together and specified by the user. The server program 20F obtains operation logs, including access to the web service, from the operation history 20G (S1001). The URL of the web service to be analyzed is extracted using the domain name portion of the access destination URL included in the operation log (S1002).

[0026] Next, logs related to file operations are obtained from the operation history 20G (S1003). In addition, the corresponding database of "work details" and "text content keywords" stored in the server's storage device 20C is obtained (S1004), and file operations containing the relevant file name are extracted as target operation history from the operation history during the period in which access to a specific web service was performed.

[0027] Figure 5 shows an example of a correspondence database for "work content" and "text content keywords." While the system provides initial values ​​for this database, users are free to modify them. "Text content keywords" indicate characters included in the file name of the relevant file operation history and are used when extracting from the operation history 20G (S1005). "Work content" in the correspondence database is registered as a file related to "text content keywords," indicating what kind of work the user is expected to be doing. Here, the "text content keywords" corresponding to "work content" can be any information related to the operation history 20G, such as the window title, process name, clipboard contents during a copy operation, or keyboard input. If information other than the file name is used, the operation history handled in S1003 and S1004 will also be modified accordingly.

[0028] For example, when using copy operation history, the "text content keywords" are used when extracting from the 20G of operation history based on whether they are included in the content of the relevant copy operation history. In addition, the "work content" in the corresponding database indicates what kind of work is expected to be done by the user operation related to the copy content. Similarly, when using keyboard operation history, the "text content keywords" are used when extracting from the 20G of operation history based on whether they are included in the input text string determined from the relevant keyboard operation history. In addition, the "work content" in the corresponding database indicates what kind of work is expected to be done by the user operation related to the input text string.

[0029] Next, the operation history related to file operations extracted is matched with the access date and time of the operation history related to the web service under analysis (S1006), and the content of the work performed by the user while using the web service under analysis is estimated (S1007). At this time, the operation logs extracted are those included in the period in which the operation history including access to a specific web service was performed. This period can be set as appropriate, and it may be the operation logs included in a predetermined time before and after the operation history in question, or it may be the operation logs only during the period in which the operation history was performed continuously. The number of occurrences of this work content is aggregated for each user (S1008), and a report on the usage status of the web service under analysis is generated (S1009).

[0030] Let's explain a specific example using the tables shown in Figures 2, 3, and 5. Assume a scenario where a specific web service is analyzed using http: / / sample2.co.jp / and the "text content keywords" are management meetings, business partners, security procedures, and security regulations. In this case, first, operation logs IDs 201 to 205 are extracted from the 20G of operation history shown in Figure 3 (S1002). Next, for the period during which these operation logs were executed, operation logs containing the string "management meeting" as the target of the operation are extracted from the 20G of operation history shown in Figure 2. In this case, IDs 2002 and 2003 are extracted (S1006). These two IDs are considered to have performed work related to confidential information, corresponding to the "text content keywords" of management meetings shown in Figure 5, and the count of occurrences is tallied (2 times in this case). Subsequently, operation logs containing the strings "business partners," "security procedures," and "security regulations" as the target of the operation are extracted, and the occurrence count of each operation log is aggregated for each "work content."

[0031] Figure 6 shows an example of a report outputting the usage status of the analyzed web service. When analyzing access to the analyzed web service with "text content keywords" set to "management meeting," "business partners," "security measures procedures," and "security regulations," the frequency of occurrence of "work content" from the corresponding operation logs can be aggregated for each user to determine how the analyzed web service is being used and to understand the actual usage. The report content can be aggregated by PC name, by work content, or by text content keyword, rather than by user, as long as it allows users to understand their actual usage. Alternatively, instead of the frequency of occurrence, the cumulative work time from the start and end times of the extracted operation history can be used.

[0032] In this figure, the title "User-Specific Usage Status of File Storage Web Service 'Information Leakage'" is displayed at the top. This indicates that an analysis related to "information leakage" was performed when the file storage web service was selected as the web service to be analyzed (specific web service). In this case, instead of entering "text content keywords" in S1000 in Figure 4, it is also possible to configure the server device 20 to allow selection of the analysis target theme using an I / O device (selection means) that can input / output to it, and then respond when "information leakage" is selected. By selecting the analysis target theme, it is possible to configure the system so that the "text content keywords" associated with it are automatically selected. In this example, when "information leakage" is selected, it is possible to configure the system so that "management meeting," "business partners," "security countermeasures procedures," and "security regulations" are automatically selected.

[0033] The embodiments described above describe a method for extracting matching results by specifying a target web service and either text content keywords or a target theme. The present invention is not limited to this, and for example, only the target web service may be specified, and all operation logs corresponding to the period during which that target web service was running may be extracted from the operation history 20G. In this case, the output of the analysis results may be to identify the "work content" by referring to the corresponding database in Figure 5 for the extracted operation logs, and output a report of the aggregated number of times for each work content. At this time, it may also be possible to configure the system to allow selection of whether or not to aggregate for each user.

[0034] (Other embodiments) The present invention can also be realized by supplying a program that implements the functions of the above-described embodiment to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (for example, an ASIC) that implements one or more functions. [Explanation of Symbols]

[0035] 10 Client terminal devices 10A Input / Output Devices (I / O Devices) 10B calculation unit 10C storage device 10D Network Interface 10E Memory 10F Client Program 10G Operation History 20 Server Devices 20A Input / Output Devices (I / O Devices) 20B Arithmetic unit 20C storage device 20D Network Interface 20E Memory 20F Client Program 20G Operation History

Claims

1. Operation monitoring means for monitoring the operation of an information processing device by a user, An operation storage means that stores the operations monitored by the operation monitoring means as an operation history, A web access storage means that monitors user access to web services on the information processing device and stores it as a history of access to web services, A first extraction means extracts from the aforementioned access history that matches the specified access destination, A second extraction means extracts from the operation history that matches the period during which the access history extracted by the first extraction means was performed, as the target operation history. Based on the specified access destination, an output means outputs the results based on the aforementioned target operation history. An information processing system characterized by comprising the following features.

2. The system has a correspondence database in which information regarding the operation history is associated with the work performed. The information processing system according to claim 1, characterized in that the output means outputs the work content as a result by referring to the corresponding database.

3. The aforementioned corresponding database contains strings included in the operation history as information related to the operation history, The information processing system according to claim 2, characterized in that the second extraction means extracts the target operation history when the specified keyword matches the string.

4. It has a selection method that allows you to select the target theme, The information processing system according to claim 3, characterized in that the second extraction means extracts the target operation history as the specified keywords, using a plurality of keywords stored in association with the target theme input by the selection means.

Citation Information

Patent Citations

  • Information transmission system

    JP1978053208A