Anomaly detection support device, anomaly detection support method, and anomaly detection support program

The anomaly detection support device addresses the challenge of tracking anomaly responses by managing and displaying detection results, allowing for comment registration and similarity determinations, enhancing the efficiency and clarity of corrective actions.

JP2026069664APending Publication Date: 2026-04-23OBIC CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
OBIC CO LTD
Filing Date
2026-02-19
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing systems for detecting anomalies in business data do not facilitate easy checking of the status of responses to detected anomalies, leading to delayed corrective actions and potential misunderstandings among multiple personnel.

Method used

An anomaly detection support device that manages and displays anomaly detection results, allows for registering and reviewing comments, and performs similarity determinations to update response statuses, enabling multiple users to input comments and track comment history.

Benefits of technology

Enables easy checking of anomaly response statuses, detailed documentation of corrective actions, and reduces the risk of redundant responses by distinguishing similar anomalies, thus improving the efficiency of corrective actions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026069664000001_ABST
    Figure 2026069664000001_ABST
Patent Text Reader

Abstract

To provide an anomaly detection support device, an anomaly detection support method, and an anomaly detection support program that allow a person in charge to easily check the status of responses to anomalies detected in business data. [Solution] The anomaly detection support device according to this embodiment includes a display control means that controls the display of an alert screen, and on the alert screen, refers to the judgment result data to display a list of anomaly detection results in the list display area, and at the same time refers to the judgment result comment data to display the corresponding status of each anomaly detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an abnormality detection support device, an abnormality detection support method, and an abnormality detection support program.

Background Art

[0002] For example, systems for detecting abnormalities in business data are on the increase. Depending on the content of the detected abnormality, it may have a serious impact on the business, so a mechanism that enables prompt and accurate corrective action is necessary. Conventionally, as a system for detecting abnormalities, there is, for example, Patent Document 1.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, Patent Document 1 does not describe anything regarding the case where, when an abnormality in business data is detected, a person in charge can easily check the status of the response to the abnormality.

[0005] The present invention has been made in view of the above, and an object thereof is to provide an abnormality detection support device, an abnormality detection support method, and an abnormality detection support program that enable a person in charge to easily check the status of the response to an abnormality when an abnormality in business data is detected.

Means for Solving the Problems

[0006] To solve the above-mentioned problems and achieve the objective, the present invention provides an anomaly detection support device comprising a control unit that displays anomaly detection results for business data, wherein the control unit is configured to manage the results of anomaly detection and is capable of accessing judgment result data including execution ID, line number, anomaly judgment result, detection target, detection date and time, definition name, and summary message, and judgment result comment data including comment ID, execution ID, execution line number, comment content, response status indicating the response status, update user, and update date and time, and controls the display of an alert screen, and on the alert screen, refers to the judgment result data to display a list of anomaly detection results in a list display area, and at that time refers to the judgment result comment data to display the response status of each anomaly detection result.

[0007] Furthermore, according to one aspect of the present invention, the response status may include: response required, confirmed, in progress, pending, completed, or no response required.

[0008] Furthermore, according to one aspect of the present invention, the control unit may further include a comment processing means for registering comments entered by the person in charge regarding the abnormality detection result of the target on the alert screen into the judgment result comment data.

[0009] Furthermore, according to one aspect of the present invention, the comment may be configured to allow multiple users to input it multiple times.

[0010] Furthermore, according to one aspect of the present invention, the comment processing means may refer to the judgment result comment data and display a history of comments for the target anomaly detection result.

[0011] Furthermore, according to one aspect of the present invention, the control unit is configured to access a default value update condition details master in which a default value update condition ID, condition detail No., and similarity determination conditions are registered in association with each other, and a default value update condition master in which a default value update condition ID, default value update condition name, execution ID, execution line number, and a status indicating no action required are registered in association with each other, and the determination result data includes a similarity determination result, and the control unit is configured to provide a similarity determination means that performs a similarity determination on the target anomaly detection result with an existing anomaly detection result according to the similarity determination conditions registered in the default value update condition details master, and if similarity is determined, updates the similarity determination result of the determination result data to "True", and updates the response status of the determination result comment data to no action required according to the status of the default value update condition master.

[0012] Furthermore, in order to solve the above-mentioned problems and achieve the objectives, the present invention provides an anomaly detection support method executed by an information processing device equipped with a control unit, wherein the control unit is for managing the results of anomaly detection and is configured to access judgment result data including execution ID, line number, anomaly judgment result, detection target, detection date and time, definition name, and summary message, and judgment result comment data including comment ID, execution ID, execution line number, comment content, response status indicating the response status, update user, and update date and time, and the control unit controls the display of an alert screen, and on the alert screen, it refers to the judgment result data to display a list of anomaly detection results in a list display area, and at that time refers to the judgment result comment data to display the response status of each anomaly detection result.

[0013] Furthermore, in order to solve the above-mentioned problems and achieve the objective, the present invention is an anomaly detection support program for execution by an information processing device equipped with a control unit, wherein the control unit is for managing the results of anomaly detection and is configured to access judgment result data including execution ID, line number, anomaly judgment result, detection target, detection date and time, definition name, and summary message, and for managing comments registered for anomaly detection and is configured to access judgment result comment data including comment ID, execution ID, execution line number, comment content, response status indicating the response status, update user, and update date and time, and the control unit controls the display of an alert screen, and on the alert screen, it refers to the judgment result data to display a list of anomaly detection results in a list display area, and at that time, it refers to the judgment result comment data to display the response status of each anomaly detection result, and the present invention is an anomaly detection support program for executing a display control step. [Effects of the Invention]

[0014] According to the present invention, when an anomaly is detected in business data, the person in charge can easily check the status of the response to the anomaly. [Brief explanation of the drawing]

[0015] [Figure 1] Figure 1 is a diagram illustrating problem 1 of the present invention. [Figure 2] Figure 2 is a diagram illustrating problem 2 of the present invention. [Figure 3] Figure 3 is a diagram illustrating problem 3 of the present invention. [Figure 4] Figure 4 is a diagram illustrating problem 4 of the present invention. [Figure 5] Figure 5 is a diagram illustrating problem 5 of the present invention. [Figure 6] Figure 6 is a block diagram showing an example of the configuration of the anomaly detection support device according to this embodiment. [Figure 7] Figure 7 shows an example of the configuration of the default value update condition master. [Figure 8] FIG. 8 is a diagram showing a configuration example of a default value update condition detail master. [Figure 9] FIG. 9 is a diagram showing a configuration example of an abnormality determination definition master. [Figure 10] FIG. 10 is a diagram showing a configuration example of a determination result data column information master. [Figure 11] FIG. 11 is a diagram showing a configuration example of a default value update history table. [Figure 12] FIG. 12 is a diagram showing a configuration example of determination result data. [Figure 13] FIG. 13 is a diagram showing a configuration example of determination result comment data. [Figure 14] FIG. 14 is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 15] FIG. 15 is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 16A] FIG. 16A is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 16B] FIG. 16B is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 17] FIG. 17 is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 18A] FIG. 18A is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 18B] FIG. 18B is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 19A] FIG. 十九A is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 19B] FIG. 19B is a diagram for explaining a specific example of the processing of the control unit of the abnormality detection support device according to the present embodiment. [Figure 20]Figure 20 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 21] Figure 21 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 22] Figure 22 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 23] Figure 23 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 24] Figure 24 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 25] Figure 25 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 26] Figure 26 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 27] Figure 27 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 28] Figure 28 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 29] Figure 29 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Figure 30] Figure 30 is a diagram illustrating a specific example of the processing performed by the control unit of the anomaly detection support device according to this embodiment. [Modes for carrying out the invention]

[0016] Embodiments of the present invention will be described in detail with reference to the drawings. However, the present invention is not limited to these embodiments.

[0017] [1. Overview] The outline of this invention will be explained in the following order: background, problems, and solutions.

[0018] (1-1. Background) Recently, there has been an increasing trend towards systems that detect anomalies in business data. Depending on the nature of the detected anomaly, it could have a significant impact on business operations, so a mechanism that allows for quick and accurate corrective action is necessary. Therefore, anomaly detection support devices must implement not only the logic for detecting anomalies, but also a flow for correcting the detected anomalies. The following three points are important requirements for the flow for correcting detected anomalies.

[0019] • The person in charge of corrective actions should be able to easily check the status of the response to the anomaly. • Register the details of the corrective actions taken. • The ability to manage and review past corrective actions.

[0020] (1-2. Issues / measures) The problems 1 to 5 of the present invention and the measures to address them will be explained with reference to Figures 1 to 5. Figures 1 to 5 are diagrams that illustrate the problems 1 to 5 of the present invention, the measures to address them, and an overview of their functions.

[0021] (1) Task 1 One challenge is the time-consuming process of checking the latest status of responses to detected anomalies. Specifically, when correcting and managing detected anomalies, it is necessary to know the latest response status of the anomaly. Therefore, if checking the latest status is time-consuming, subsequent corrective actions will also be delayed. For example, checking the status of an anomaly while corrective actions are being taken requires communication with those involved in the corrective actions, which adds to the time and effort required for status confirmation. For this reason, a mechanism is needed to quickly and easily check the latest status of the response to detected anomalies.

[0022] As a countermeasure, the present invention includes a function to set a "response status" representing the response status for each anomaly detection result, and to change the response status according to the response status. Furthermore, it includes a function to display the response status for each anomaly detection result on the list screen of the anomalies that have occurred.

[0023] This allows corrective action personnel to quickly check the status of responses to anomalies.

[0024] (2) Task 2 There is a challenge in that corrective actions for anomalies need to be registered and managed in detail. Specifically, when checking the specific details of corrective actions for detected anomalies, statuses such as "in progress" or "completed" are insufficient. Furthermore, it is difficult for people other than those responsible for corrective actions to accurately grasp the current status of anomaly responses, and if there are multiple people responsible for corrective actions, misunderstandings may occur among them. For example, for an anomaly with the status "in progress," it is unclear "what" actions have been taken and "to what extent." Therefore, a mechanism is needed that allows the details of corrective actions to be registered in a comment format.

[0025] As a countermeasure, the present invention incorporates a function to register comments for each anomaly detection result.

[0026] This allows for detailed documentation of each anomaly detection result, making it possible to manage corrective actions at a fine-grained level.

[0027] (3) Task 3 One challenge is that, assuming a scenario where multiple people work together to correct a single anomaly, each person needs to be able to register comments multiple times. Specifically, when multiple people work together to correct a detected anomaly, each person needs to be able to register details of their actions and interactions with other people in the comments section.

[0028] For example, if User1 is responsible for implementing the corrective action and User2 is responsible for verifying the corrective action, the following comments could be used in this way.

[0029] User1 will provide details of the corrective action in the comments. User2 commented that they had confirmed User1's corrective actions. • The exchange between User1 and User2 is also included in the comments.

[0030] Therefore, a system is needed that allows multiple corrective officers to register comments multiple times for a single anomaly.

[0031] As a countermeasure, the present invention incorporates a function that allows multiple personnel to register comments multiple times for each anomaly detection result.

[0032] This allows multiple personnel to handle the task of correcting anomalies.

[0033] (4) Task 4 One challenge is the need to be able to review the comment history registered in the past. Specifically, when checking past corrective actions for a particular anomaly, it is necessary to check not only the most recent comments but also the comment history registered in the past. If the comment history cannot be reviewed, it becomes difficult to manage past corrective actions. For example, if there is an anomaly that has been left uncorrected, it is necessary to review the past comment history to determine the cause of the neglect. Therefore, a mechanism to review the comment history registered in the past is necessary.

[0034] As a countermeasure, this invention incorporates a function that enables the management of comment history.

[0035] This makes it possible to manage past corrective actions and control fraudulent data manipulation.

[0036] (5) Task 5 If similar anomalies are repeatedly detected, there is a risk that corrective action will be hindered. Specifically, when anomaly detection is performed regularly, If an anomaly that has already occurred is not addressed, there is a possibility that a similar anomaly may be detected again, making it difficult to distinguish between an anomaly similar to a previously occurred one and a newly occurring anomaly. This increases the risk of having to address the same anomaly multiple times, and the volume of anomaly notifications becomes enormous, increasing the risk of missing more important anomalies.

[0037] For example, if there is an anomaly ART001 that takes several days to correct, and automatic anomaly detection is performed daily, then if similar anomalies (ART002, ART003, ART004, etc.) repeatedly occur before the correction of ART001 is completed, it becomes difficult to determine whether ART002, ART003, ART004, etc. require correction. Therefore, a mechanism is needed to distinguish whether a newly occurring anomaly is similar in content to an existing anomaly or not.

[0038] As a countermeasure, the present invention incorporates a function that, if it is determined that the result is similar to an existing anomaly detection result, updates the corresponding status of the anomaly detection result to the corresponding status set in the master.

[0039] This reduces the risk of having to respond to the same anomaly multiple times, decreases the number of anomaly notifications, and reduces the risk of missing more important anomalies.

[0040] The anomaly detection support device of the present invention is applicable to all industries and sectors.

[0041] [2. Structure] Referring to Figure 6, an example of the configuration of the anomaly detection support device 100 according to this embodiment will be described. Figure 6 is a block diagram showing an example of the configuration of the anomaly detection support device 100.

[0042] The anomaly detection support device 100 is a commercially available desktop personal computer. However, the anomaly detection support device 100 is not limited to stationary information processing devices such as desktop personal computers, but may also be portable information processing devices such as commercially available notebook personal computers, PDAs (Personal Digital Assistants), smartphones, and tablet personal computers.

[0043] The anomaly detection support device 100 comprises a control unit 102, a communication interface unit 104, a storage unit 106, and an input / output interface unit 108. Each component of the anomaly detection support device 100 is connected to communicate via any communication path.

[0044] The communication interface unit 104 connects the anomaly detection support device 100 to the network 300 via communication devices such as routers and wired or wireless communication lines such as dedicated lines, enabling communication between them. The communication interface unit 104 has the function of communicating data with other devices via communication lines. Here, the network 300 has the function of connecting the anomaly detection support device 100, the server 200, the business system 400, and the terminal device 500 so that they can communicate with each other, and is, for example, the internet or a LAN (Local Area Network).

[0045] The business system 400 is configured to communicate data with the anomaly detection support device 100 via the network 300. The business system 400 generates various types of business data, such as cost data, manufacturing data, order data, purchase order data, procurement data, sales data, and journal entry data. The anomaly detection unit 102a of the anomaly detection support device 100 performs automatic anomaly detection of this business data.

[0046] Terminal devices 500... are terminal devices used by, for example, User1, User2, User3, etc. Terminal devices 500... are configured to communicate data with the anomaly detection support device 100 via the network 300. For example, User1, User2, User3, etc. use terminal devices 500... to access the anomaly detection support device 100 and check the status of the anomaly detection results and enter comments on the alert screen provided by the anomaly detection support device 100.

[0047] The input / output interface unit 108 is connected to an input device 112 and an output device 114. The output device 114 can be a monitor (including a home television), a speaker, or a printer. The input device 112 can be a keyboard, a mouse, a microphone, or a monitor that works in conjunction with the mouse to provide pointing device functionality. In the following, the output device 114 may be referred to as the monitor 114, and the input device 112 as the keyboard 112 or mouse 112. Also, the display of information on the monitor 114 and the user's operation of the input device 112 may be referred to as "user operation via UI".

[0048] The memory unit 106 stores various databases, tables, and files. The memory unit 106 also stores computer programs that work in cooperation with the OS (Operating System) to give instructions to the CPU (Central Processing Unit) to perform various processes. As the memory unit 106, for example, memory devices such as RAM (Random Access Memory) and ROM (Read Only Memory), fixed disk devices such as hard disks, flexible disks, and optical disks can be used.

[0049] The storage unit 106 stores the default value update condition master 106a, the default value update condition detail master 106b, the abnormality judgment definition master 106c, the judgment result data column information master 106d, the default value update history table 106e, the judgment result data, the judgment result comment data, etc. Figure 7 shows an example of the configuration of the default value update condition master 106a. Figure 8 shows an example of the configuration of the default value update condition detail master 106b. Figure 9 shows an example of the configuration of the abnormality judgment definition master 106c. Figure 10 shows an example of the configuration of the judgment result data column information master 106d. Figure 11 shows an example of the configuration of the default value update history table 106e. Figure 12 shows an example of the configuration of the judgment result data. Figure 13 shows an example of the configuration of the judgment result comment data.

[0050] The default value update condition master 106a is a master for managing the response status and comments to be updated for anomaly detection results that are determined to be similar to existing anomaly detection results. As shown in Figure 7, the default value update condition master 106a can be composed of tables that associate and register the default value update condition ID, default value update condition name, execution ID, execution line number, status type, status, comment copy, default comment addition, and default comment content. In the example shown in the figure, the first row contains the default value update condition ID "UC001", default value update condition name "Default value update condition A", execution ID "EX002", execution line number "1", status type "Fixed value", status "No action required", comment copy "False", default comment addition "True", and default comment content "Automatically updated".

[0051] The default value update condition details master 106b is a master for managing the conditions used to determine whether a newly detected anomaly is similar to an existing anomaly detection result. As shown in Figure 8, the default value update condition details master 106b can be composed of tables that associate and register default value update condition IDs, condition detail numbers, similarity determination conditions (result table information ID, comparison operator, determination value type, and determination value), etc. In the example shown in the figure, the first row has default value update condition ID "UC001", condition detail number "1", result table information ID "Fiscal year", comparison operator "=", determination value type "Same value as the original anomaly", and the second row has default value update condition ID "UC001", condition detail number "2", result table information ID "Product name", comparison operator "=", determination value type "Same value as the original anomaly".

[0052] The Anomaly Judgment Definition Master 106c is a master for managing the definitions of anomalies in business data. As shown in Figure 9, the Anomaly Judgment Definition Master 106c can be composed of tables that register and associate anomaly judgment definition IDs, anomaly judgment definition names, etc. In the example shown in the figure, the first row contains the anomaly judgment definition ID "JD001" and the anomaly judgment definition name "Inventory Turnover Alert". The Anomaly Judgment Definition Master 106c, other than the Anomaly Judgment Definition ID, is not related to this application, so a detailed explanation is omitted.

[0053] The judgment result data column information master 106d is a master for managing information (header name, type, etc.) of the table columns of the judgment result data. As shown in Figure 10, the judgment result data column information master 106d can be composed of tables that register the abnormal judgment definition ID, column number, column, column name, type, and type name in association. In the example shown in the figure, the first row contains the abnormal judgment definition ID "JD001", column number "1", column "AlertDefinitionID", column name "Abnormal Judgment Definition ID", type "string", and type name "Character".

[0054] The default value update history table 106e is a table for managing the conditions actually used to determine which items are subject to default value updates during a default value update. As shown in Figure 11, the default value update history table 106e may include a default value update history ID, execution ID, execution line number, and default value update condition ID. In the example shown in the figure, the first row contains default value update history ID "UH001", execution ID "EX002", execution line number "1", and default value update condition ID "UC001".

[0055] The judgment result data is a table used to manage the results of anomaly detection in business data. The judgment result data may include the following: anomaly judgment definition ID, execution ID, line number, judgment result, anomaly rank, fiscal year, fiscal year and month, product name, inventory turnover rate, whether it is a similar judgment result, detection date and time, definition name, summary message, detection target, detection method, threshold, judgment method, and lower limit. The "anomaly rank" is a ranking of the degree of anomaly based on the calculated value of the anomaly judgment method used when the automatic anomaly judgment was executed. In the example shown in the figure, the first row contains the following information: Anomaly Judgment Definition ID "JD001", Execution ID "EX001", Row Number "1", Judgment Result "True", Anomaly Rank "3", Fiscal Year "2022", Fiscal Year and Month "2022 / 11", Product Name "Product Name A", Inventory Turnover Rate "0.36", Similarity Judgment Result "False", Detection Date and Time "2022 / 11 / 1 01:02:03", Definition Name "Inventory Turnover Alert", Summary Message "Product A has been detected", Detected Target "2022 / 11 Product A 0.36", Detection Method "Interquartile Range", Threshold "1.5 times the normal range", Judgment Method "Values ​​smaller than the lower limit are judged as anomaly", Lower Limit "0.83".

[0056] The judgment result comment data is data used to manage comments registered in response to anomalies. As shown in Figure 13, the judgment result comment data may include comment ID, execution ID, execution line number, comment content, response status, update user, and update date and time. In the example shown in the figure, the first line contains comment ID "CM001", execution ID "EX001", execution line number "1", response status "Requires Action", update user "Automatic Execution", and update date and time "2022 / 11 / 1 01:02:03".

[0057] The control unit 102 is a CPU or similar component that comprehensively controls the anomaly detection support device 100. The control unit 102 has internal memory for storing control programs such as the OS, programs that define various processing procedures, and required data, and executes various information processing based on these stored programs.

[0058] The control unit 102 is configured to access the default value update condition master 106a, default value update condition detail master 106b, abnormality judgment definition master 106c, judgment result data column information master 106d, default value update history table 106e, judgment result data, judgment result comment data, etc., which are stored in the storage unit 106. Note that the default value update condition master 106a, default value update condition detail master 106b, abnormality judgment definition master 106c, judgment result data column information master 106d, default value update history table 106e, judgment result data, and judgment result comment data may be located elsewhere (for example, on the server 200), as long as the control unit 102 can access them.

[0059] Functionally, the control unit 102 comprises an anomaly detection unit 102a, a similarity determination unit 102b, a comment processing unit 102c, and a screen display control unit 102d.

[0060] The control unit 102 is equipped with a function to add comments and response status to the anomaly detection result, and a similarity determination function.

[0061] The anomaly detection unit 102a automatically detects anomalies in various business data generated by the business system 400 according to the anomaly judgment definition master 106c, etc., and registers the anomaly detection result as judgment result data in the storage unit 106.

[0062] The screen display control unit 102d controls the display and input of various screens. For example, the screen display control unit 102d controls the display and input of an alert screen, and on the alert screen, it refers to the judgment result data to display a list of anomaly detection results in the list display area, and at that time, it refers to the judgment result comment data to display the response status of each anomaly detection result. The response status may include "requires action," "confirmed," "in progress," "on hold," "response completed," or "no action required."

[0063] The comment processing unit 102c registers comments entered by the person in charge regarding the target anomaly detection result in the judgment result comment data on the alert screen. The comment processing unit 102c may also be configured to allow multiple people to enter comments multiple times. The comment processing unit 102c may also refer to the judgment result comment data to display the history of comments regarding the target anomaly detection result.

[0064] The similarity determination unit 102b performs a similarity determination on the target anomaly detection result with existing anomaly detection results according to the similarity determination conditions set in the default value update condition details master 106b. If similarity is determined, the similarity determination result of the determination result data is updated to "True," and the corresponding status of the determination result comment data is updated to "No action required" according to the status of the default value update condition master 106a.

[0065] [3. Specific examples] Referring to Figures 14 to 30, a specific example of the processing of the control unit 102 of the anomaly detection support device 100 in this embodiment will be described. Figures 14 to 30 are diagrams illustrating a specific example of the processing of the control unit 102 of the anomaly detection support device 100 in this embodiment.

[0066] (3-1. Comment function) Refer to Figures 14 to 20 to explain the comment function on the alert screen. Refer to Figure 14 to explain the overview of the comment function on the alert screen. Figure 14 is a diagram that explains the overview of the comment function on the alert screen.

[0067] The alert screen consists of two screens: the alert list screen (initial screen) and the alert details screen. The "alert list screen" allows you to view detected anomalies in a list format, and you can check the response status for each anomaly detection result on the list screen. The "alert details screen" is for viewing the details of the detected anomaly.

[0068] It is possible to register comments regarding anomalies and to check past comment history. This is the situation. The following three operations will be explained.

[0069] 1. When one person in charge writes details of the corrective action taken for the anomaly in the comments (User001 is in charge) 1.1 Operations on the Alert List Screen Set the "Response Status" to indicate how the anomaly was handled. 1.2 Operations on the Alert Details Screen Register a comment for each anomaly detection result.

[0070] 2. When registering a comment for an anomaly that has already been registered by another user (User002 is in charge). 2.1 Operations on the Alert Details Screen Multiple users can register comments for each anomaly detection result.

[0071] 3. When the administrator confirms that the issue has been resolved (User003 is responsible for this) 3.1 Operations on the Alert Details Screen You can manage and review your past comment history.

[0072] Figure 15 illustrates a scenario where one person (User001) writes detailed comments about corrective actions taken for an anomaly. In Figure 15, (A) shows an example of the alert list screen, and also indicates which columns of the judgment result data and judgment comment data are referenced to extract the data.

[0073] As shown in (A), the alert list screen includes an area for specifying extraction conditions, an area for displaying a list of anomaly detection results, and a comment button.

[0074] The extraction criteria specification area includes an input field for the corresponding status and a display button. When you specify a corresponding status and press the display button, the judgment result data and judgment result comment data corresponding to the specified corresponding status are extracted and displayed in the judgment result list display area. Specifically, the system retrieves the execution ID corresponding to the specified response status from the judgment result comment data, and extracts the judgment result data using the retrieved execution ID and execution line number as keys. In the judgment result list display area, each process (per execution ID and per execution line number) in the abnormal judgment execution is displayed as one detail. If no extraction conditions are specified, all judgment results are displayed. The example shown in Figure 15 illustrates the case where no extraction conditions are specified.

[0075] In the anomaly detection results list display area, each item displays the definition name of the judgment result data, the detection date and time, a summary message, the response status indicating the status of the anomaly response, the number of comments in the judgment result comment data, the user who updated the latest comment and the update date and time. The number of comments is calculated by aggregating the number of comments for each execution ID and execution line number of the judgment result comment data. Records with no comments are excluded from the aggregation. For example, in the example shown in the figure, the first item displays the definition name "Inventory Turnover Alert", detection date and time "2022 / 11 / 1 01:02:03", summary message "Product A has been detected", response status "Requires Action", and number of comments "0". Additionally, the second detail shows the definition name "Inventory Turnover Alert", detection date and time "2022 / 11 / 2 01:02:03", summary message "Product A has been detected", response status "In progress", number of comments "2", update user "User002", and update date and time "2022 / 11 / 2 12:22:32".

[0076] In this way, it is possible to set a status according to the status of handling the anomaly, such as "Action Required" or "Handling in Progress," and the status of each anomaly detection result can be checked on the alert list screen. A background color can be set for each status; for example, the background color can be set as follows: "Action Required" is red, "Confirmed" is green, "Handling in Progress" is blue, "On Hold" is yellow, "Completed" is navy blue, and "No Action Required" is gray. The background color can be specified in advance as a fixed value. In this way, the status of each anomaly detection result can be easily checked in this embodiment.

[0077] Next, we will explain the operation on the alert details screen with reference to Figures 16A and 16B. Figures 16A and 16B are diagrams to explain the operation on the alert details screen. (A) shows an example of the alert list screen, (B) shows an example of the alert details screen, and (C) shows an example of the display when a comment is entered in the corresponding comment area of ​​the alert details screen. Furthermore, they show which columns of the judgment result data and judgment comment data are being referenced to extract data.

[0078] As shown in (A), clicking on the target anomaly detection result in the anomaly detection result list display area of ​​the alert list screen will display the alert details screen as shown in (B). The alert details screen displays the details of the anomaly detection result and the response / comment area.

[0079] The details of the anomaly detection result are displayed by extracting data such as the accounting year and month, product name, inventory turnover rate, detection target, detection method, threshold, reflection method, and lower limit from the judgment result data, using the execution ID and execution line number corresponding to the clicked anomaly detection result as keys.

[0080] The response / comment area displays the latest response status, comment update history, and comment input field, using the execution ID and execution line number as keys to reference the judgment result comment data. The latest response status displays the latest updater, update date, response status, and comment status. In this example, the "response status" in the latest response status is "Requires Action".

[0081] The comment update history displays the latest comments and history if comments exist in the judgment result comment data. The comment input field allows you to select the corresponding status and has an add button for registering comments. When you select the corresponding status in the comment input field, enter a comment, and press the add button, new judgment result comment data corresponding to the input content will be registered.

[0082] As shown in (C), when User1 selects the response status "In Progress" in the comment input field, enters the comment "Changed the sales amount of sales slip A001 from 10,000 yen to 1,000 yen", and presses the Add button, for example, the following will be newly registered in the judgment result comment data: Comment ID "CM004", Execution ID "EX001", Execution line number "1", Comment content "Changed the sales amount of sales slip A001 from 10,000 yen to 1,000 yen", Response status "In Progress", Updating user "User001", Update date and time "2022 / 11 / 9 20:21:00".

[0083] In this way, details of the response can be registered in comment format for each anomaly detection result, allowing for detailed recording of the actions taken by the person in charge. This makes it possible to manage corrective actions at a fine granularity.

[0084] Referring to Figure 17, we will explain how to toggle the display of the "Correspondence / Comment Area" by pressing the comment button. Figure 17 is a diagram illustrating how to toggle the display of the "Correspondence / Comment Area" by pressing the comment button, with (A) showing the state before pressing the comment button and (B) showing the state after pressing the comment button. You can toggle the display of the "Correspondence / Comment Area" by pressing the comment button. In (A), when you press the comment button, the "Correspondence / Comment Area" becomes hidden as shown in (B). Also, in (B), when you press the comment button, the "Correspondence / Comment Area" becomes visible as shown in (A).

[0085] Referring to Figures 18A and 18B, we will explain the case where a comment is registered for an anomaly that has already been commented on by another user (User002 is in charge). Figures 18A and 18B are diagrams to explain the case where a comment is registered for an anomaly that has already been commented on by another user (User002 is in charge). (A) shows the state after User001 has registered a comment (the state after User001 has registered a comment in Figure 16(C)), and (B) shows the state after User002 has registered further comments. In addition, the referenced judgment result data and the referenced and registered judgment comment data are also shown. This section describes the operations after selecting an anomaly detection result from the alert list screen.

[0086] As shown in (A), the details of the anomaly detection result show the response status as "In Progress" and the number of comments as "1". In the response / comment area, the latest response status is shown as follows: latest updater "User001", update date "2022 / 11 / 9 20:21:00", response status "In Progress", and comment "Changed the sales amount of sales slip A001 from 10,000 yen to 1,000 yen". In addition, the comment update history shows "User001 2022 / 11 / 9 20:21:00 In Progress Changed the sales amount of sales slip A001 from 10,000 yen to 1,000 yen".

[0087] Here, as shown in (B), if User002 selects the response status "In Progress" in the comment input field, enters the comment "Confirmed corrective action by User001", and presses the add button, then, for example, the following will be newly registered in the judgment result comment data: comment ID "CM005", execution ID "EX001", execution line number "1", response status "In Progress", updating user "User002", comment content "Confirmed corrective action by User001", and update date and time "2022 / 11 / 10 20:54:00".

[0088] In this way, multiple personnel can register comments for each anomaly detection result. Specifically, multiple personnel can register comments multiple times for each anomaly detection result, allowing each person to register details of their response. In addition, it is possible to register the communication between personnel in the comments, making it possible to leave a detailed record of corrective actions that become complex when multiple personnel are involved. This enables multiple personnel to handle the task of correcting anomalies.

[0089] Referring to Figures 19A and 19B, we will explain the case where an administrator (handled by User003) confirms an anomaly that has been resolved. Figures 19A and 19B are diagrams that illustrate the case where an administrator (handled by User003) confirms an anomaly that has been resolved. (A) shows the state after User002 has registered a comment (the state after User002 registered a comment in Figure 18(B)), and (B) shows the state after User003 has registered further comments. In addition, the referenced judgment result data and the referenced and registered judgment comment data are also shown. This section describes the operations after selecting an anomaly detection result from the alert list screen.

[0090] As shown in (A), the details of the anomaly detection result show the response status as "In Progress" and the number of comments as "2". In the response / comments area, the latest response status is shown as follows: latest updater "User002", update date "2022 / 11 / 10 20:54:00", response status "In Progress", and comment "Confirming corrective action by User001". In addition, the comment update history shows the comments "User002, 2022 / 11 / 10 20:54:00, In Progress, Confirming corrective action by User001" and "User001 2022 / 11 / 9 20:21:00 In Progress Changed the sales amount of sales slip A001 from 10,000 yen to 1,000 yen" in chronological order.

[0091] Here, as shown in (B), if User003 selects the response status "Response Completed" in the comment input field, enters the comment "This abnormal response will be closed", and presses the add button, then, for example, the following will be newly registered in the judgment result comment data: comment ID "CM006", execution ID "EX001", execution line number "1", response status "Response Completed", updating user "User003", comment content "This abnormal response will be closed", and update date and time "2022 / 11 / 11 20:35:00".

[0092] In this way, it is possible to manage and review the history of past comments. Specifically, it is possible to manage the history of comments registered in the past for each anomaly detection result, and to review the history of previously registered comments. The comment history displays the name of the person who made the update and the date and time of the update, so it is possible to check "who" made the comment and "when". This makes it possible to manage past corrective actions and control fraudulent data manipulation.

[0093] (3-2. Similarity determination function) The similarity determination function will be explained with reference to Figures 20 to 30. Here, we will explain the mechanism for determining similarity between detected anomaly detection results and past anomaly detection results. The function that updates the response status and comments pre-configured in the master for anomaly detection results determined to be similar to existing anomaly detection results is called "default value update".

[0094] Let's explain an example of the tasks we envision here. For example, at the end of the month, we perform anomaly detection on inventory turnover. The end of the month is often the time for closing accounting, and it is common to check for any accounting anomalies at the same time as closing the accounts. Also, if anomalies in inventory turnover are detected for the same product within the same fiscal year, there will be multiple anomalies for the same key item, which may cause confusion for the person in charge. Therefore, if an anomaly with the same key is detected again, the anomaly in question will be considered "under corrective action," and the anomaly detection result will be changed to "no action required."

[0095] The following explains an example of the conditions for similarity detection: (1) the fiscal year matches, and (2) the product names match. If similarity is detected, the following will be automatically registered in the detection result comment data: comment content "Automatically updated", response status "No action required", and update user "Automatic execution". In addition, the details of the anomaly detection result on the alert list screen will display the response status "No action required".

[0096] Referring to Figure 20, an example of setting the default value update condition master 106a and default value update condition detail master 106b will be explained. In order to perform the above assumed business, data will be set in the default value update condition master 106a and default value update condition detail master 106b.

[0097] In this instance, we confirmed the anomaly detection result for "Execution ID=EX002, Execution Line Number=1," and assumed that a master record has been provided in preparation for similar anomalies being detected in the future.

[0098] Figure 20(A) shows an example of data settings for the default value update condition master 106a. The default value update condition master 106a includes fields for default value update condition ID, default value update condition name, execution ID, execution line number, status type, status, whether to copy comments, whether to add default comments, and default comment content. The execution ID and execution line number are used to specify the source anomaly detection result (judgment result data). The "corresponding status" is used to specify the corresponding status of the similarly judged anomaly detection result. The "status type" is expected to be either a "fixed value" or the "same value as the judgment source". The behavior when "same value as the judgment source" is set will be described later. "Whether to copy comments", "Whether to add default comments", and "default comment content" are used to control the comments of similarly judged anomaly detection results. The "Whether to copy comments" option will be described later.

[0099] In the example shown in the figure, the following settings are configured: Default value update condition ID "UC001", Default value update condition name "Default value update condition A", Execution ID "EX002", Execution line number "1", Status type "Fixed value", Status "No action required", Copy comment "False", Add default comment "True", Default comment content "Updated automatically".

[0100] Figure 20(B) shows an example of data settings for the default value update condition detail master 106b. The default value update condition details master 106b includes fields for default value update condition ID, condition detail no., result table information ID, comparison operator, judgment value type, and judgment value. The conditions for similarity determination are specified using "Result Table Information ID," "Comparison Operator," "Judgment Value Type," and "Judgment Value." A fixed value can also be specified for "Judgment Value Type," in which case the fixed value is entered in "Judgment Value."

[0101] In the example shown in the figure, the first row has the default value update condition ID "UC001", condition detail no. "1", result table information ID "Fiscal Year", comparison operator "=", and judgment value type "Same value as the original anomaly", and the second row has the default value update condition ID "UC001", condition detail no. "2", result table information ID "Product Name", comparison operator "=", and judgment value type "Same value as the original anomaly".

[0102] Regarding the default value update condition master 106a, it is possible to apply one default value update condition to multiple anomaly detection results, and Figure 20(C) shows an example of applying one default value update condition to multiple anomaly detection results. In the example shown in the figure, default value update condition ID "UC001" and default value update condition name "default value update condition A" are applied to execution ID "EX002" and execution line number "1", execution ID "EX001" and execution line number "1", and execution ID "EX001" and execution line number "1".

[0103] The records in the default value update condition master 106a and default value update condition detail master 106b are provided after confirming the detected anomaly judgment result, depending on the need for similarity judgment. Furthermore, the records in the default value update condition master 106a and default value update condition detail master 106b are examples of settings configured for anomaly detection regarding inventory turnover rate. The actual contents of the records will vary depending on the items set for each anomaly judgment definition (settings in the judgment result data column information master 106d) and the conditions used for similarity judgment. In the following explanation, it is assumed that the execution of anomaly detection has already been completed.

[0104] Refer to Figure 21 to explain how to perform similarity determination. Figure 21 is a diagram illustrating how to perform similarity determination. (A) shows an example of determination result data, and (B) shows determination result comment data. Similarity determination is performed on anomaly detection results with the same "anomaly determination definition ID". If the "anomaly determination definition ID" is different, similarity determination is not performed because the types of anomaly determination definitions are different.

[0105] For example, in (A) and (B), the first row of the judgment result data and the first and second rows of the judgment result comment data show previously detected anomaly detection results, while the second row of the judgment result data shows the anomaly detection result created as a result of the current anomaly detection. The anomaly judgment definition ID "JD001" in the second row of the judgment result data is the same as in the first row, so a similarity judgment is performed with the first row. In this case, the fiscal year and product name match, so the similarity judgment result is "True".

[0106] On the other hand, as shown in (C), if the anomaly detection definition IDs are different, similarity detection will not be performed. Furthermore, if the anomaly detection definition IDs are different, similarity detection will not be performed even if the fiscal year and product name match.

[0107] The mechanism of similarity determination will be explained with reference to Figures 22 to 24. Figures 22 to 24 are diagrams illustrating the mechanism of similarity determination. Similarity determination is performed in the following order.

[0108] 1. Perform similarity determination according to the conditions registered in the default value update condition details master 106b. 2. Register a comment according to the settings registered in the default value update condition master 106a. 3. Update the response status for anomaly detection results that have been determined to be similar.

[0109] The following describes these processes in detail. (1. Similarity determination is performed according to the conditions registered in the default value update condition details master 106b.) If similar anomaly detection results are determined, the information of the similarity determination history is newly registered in the default value update history table 106e.

[0110] In Figure 22, in the default value update condition details master 106b, the similarity determination condition is the fiscal year. The values ​​for = and **product name** are set to the same value as the original anomaly. The first row of the judgment result data, with execution ID "EX002" and row number "1", has fiscal year "2022" and product name "product A". The current anomaly detection result, with execution ID "EX003" and row number "1", has fiscal year "2022" and product name "product A", matching the similarity judgment condition, updating the similarity judgment result to "True", and registering it as a new entry in the default value update history table 106e. In the example shown in the figure, default value update history ID "UH001", execution ID "EX003", execution row number "1", and default value update condition ID "UC001" are newly registered.

[0111] (2. Register comments according to the settings registered in the default value update condition master 106a) In Figure 23, the default value update condition master 106a is set to "True" for adding a default comment, and the default comment content is "Automatically updated". If a similarity is determined, according to this setting, the judgment result comment data is registered with the comment content "Automatically updated", the response status "Requires action (initial value when an anomaly is detected)", and the update user "Automatic execution".

[0112] In this way, it becomes possible to automatically distinguish whether a newly occurring anomaly is similar in content to an existing anomaly or not.

[0113] (3. Update the response status for anomaly detection results that have been determined to be similar.) The "Response Status" of records that have been determined to be similar anomalies is updated to the status set in the default value update condition detail master 106b.

[0114] In Figure 24, the default value update condition details master 106b is set to the status "No action required". In accordance with this setting, the response status of the judgment comment data is updated from "Requires action" to "No action required".

[0115] In this way, it is possible to automatically distinguish whether a newly occurring anomaly is similar in content to an existing anomaly. If the anomaly detection result is determined to be similar to an existing anomaly detection result, the response status is updated to "No action required." Therefore, the response status can be updated automatically without the person in charge having to update it manually. This reduces the risk of having to respond to the same anomaly multiple times, decreases the number of anomaly notifications, and reduces the risk of missing more important anomalies.

[0116] Next, referring to Figures 25 to 27, we will explain how the alert list screen and alert details screen display similar anomaly detection results. Additional functionality has been added to each screen for anomaly detection results that have been determined to be similar.

[0117] In Figure 25, in the anomaly detection result list display area of ​​the alert list screen, if the similarity judgment result of the judgment result data is "True", the corresponding status is displayed according to the status of the default value update condition master 106a in Figure 24, and a similarity information icon is also displayed. The similarity information icon is displayed only when it is determined that the result is similar to an existing anomaly detection result. For example, when the mouse hovers over the similarity information icon, a message indicating that the result is similar to an existing anomaly is displayed, such as "The corresponding status has been updated due to the similarity judgment. Please check the similarity judgment result for details." This makes it possible to confirm the similarity of existing anomaly detection results from the alert list screen.

[0118] Clicking on an anomaly detection result displays an alert details screen, such as the one shown in Figure 26. The Action / Comment area displays the "Check Similarity Judgment Results" button and the similarity judgment date and time. The "Check Similarity Judgment Results" button is only displayed for an anomaly detection result that has been determined to "No Action Required" based on the similarity judgment. When the "Check Similarity Judgment Results" button is pressed, the screen transitions to the similarity judgment result details screen. The similarity judgment date and time displays the update date and time of the judgment result data.

[0119] Refer to Figure 27 to explain the Similarity Result Details screen. Figure 27 is a diagram showing an example of the Similarity Result Details screen. When the "Confirm Similarity Result" button is pressed in Figure 26, the Similarity Result Details screen shown in Figure 27 is displayed. The Similarity Result Details screen displays (1) the anomaly detection result that was determined to be similar to the existing anomaly detection result, (2) the original anomaly detection result, (3) the conditions used in the similarity determination, and (4) the settings and values ​​used in the default value update.

[0120] Refer to Figure 28 to explain the function for copying the corresponding status and comment when similar anomaly detection results are determined.

[0121] The similarity detection function also allows for a setting that "copies the latest response status and comment from the original anomaly to an anomaly that has been determined to be similar." This is intended for use in operations where an anomaly detection result that has been determined to already exist, but is not treated as "no action required," is kept as an anomaly detection result that requires action. This can be controlled by setting the default value update condition master 106a.

[0122] In Figure 28, by setting the status type to "Update to the same value as the source" in the default value update condition master 106a, the latest corresponding status, the same as the source, can be registered as the corresponding status in the judgment result comment data. Also, by setting whether to copy comments to "True" in the default value update condition master 106a, the comments from the source can be registered as the comment content in the judgment result comment data.

[0123] Referring to Figures 29 and 30, we will explain the case where multiple default value update conditions are set for a single anomaly detection result. The similarity judgment function makes it possible to associate multiple default value update condition masters 106a with a single anomaly detection result. This may be used in operations where the default value update process is branched depending on the content of the anomaly detection result.

[0124] For example, in an inventory turnover alert, let's explain how to branch the conditions for updating the default value based on the "degree of deviation from the inventory turnover threshold." For instance, if the "degree of deviation from the inventory turnover threshold" exceeds a certain value, the response status of similarly determined anomaly detection results will be set to "requires action" (treated as a new anomaly). In addition to the conditions of "fiscal year" and "product name," a condition of "anomaly severity rank" will be added.

[0125] In Figure 29, the default value update condition master 106a allows multiple default value update condition IDs to be associated with the same anomaly detection result. In the example shown in the figure, the default value update condition IDs "UC001" and "UC002" are set for execution ID "EX002" and execution line number "1". For "UC001", the status is set to "No action required", and for "UC002", the status is set to "Action required".

[0126] In the default value update condition detail master 106b, both "UC001" and "UC002" have three similarity judgment conditions set. For detail condition NO "3" of "UC002", the result table information ID is set to "abnormality rank", the comparison operator to "≧", the judgment value type to "fixed value", and the judgment value to "3". Since the abnormality rank of the judgment result data is "3" (the product name and fiscal year are the same as the source of the judgment), the corresponding status of the judgment result comment data is updated to "requires action".

[0127] The anomaly rank is calculated based on how far the detected anomaly deviates from the threshold. A higher rank number indicates a greater degree of deviation from the threshold. Figure 30 shows an example of calculating the anomaly rank for products A, B, and C based on the degree of deviation of the inventory turnover rate from the threshold.

[0128] As described above, according to this embodiment, the display control unit 102d controls the display of the alert screen, and on the alert screen, it refers to the judgment result data to display a list of anomaly detection results in the list display area, and at that time, it refers to the judgment result comment data to display the response status of each anomaly detection result. Therefore, when an anomaly is detected in business data, the person in charge can easily check the response status to the anomaly.

[0129] [4. Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This embodiment can contribute to improving operational efficiency and promoting appropriate management decisions within companies, thereby contributing to SDGs Goals 8 and 9.

[0130] Furthermore, this embodiment can contribute to reducing waste and promoting paperless and digital processes, thereby contributing to SDGs Goals 12, 13, and 15.

[0131] Furthermore, this embodiment can contribute to strengthening control and governance, thereby enabling contributions to SDG Goal 16.

[0132] [5. Other Embodiments] In addition to the embodiments described above, the present invention may be implemented in various different embodiments within the scope of the technical idea described in the claims.

[0133] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by known methods.

[0134] Furthermore, the processing procedures, control procedures, specific names, information including parameters such as registration data and search conditions for each process, screen examples, and database configuration shown in this specification and in the drawings may be changed at will unless otherwise specified.

[0135] Furthermore, with respect to the anomaly detection support device 100, each component shown in the diagram is a functional concept and does not necessarily need to be physically configured as shown.

[0136] For example, the processing functions of the anomaly detection support device 100, particularly those performed by the control unit, may be implemented in whole or in part by a CPU and a program interpreted and executed by the CPU, or they may be implemented as wired logic hardware. The program is recorded on a non-temporary computer-readable recording medium containing programmed instructions for the information processing device to execute the processing described in this embodiment, and is mechanically read by the anomaly detection support device 100 as needed. That is, a storage unit such as ROM or HDD (Hard Disk Drive) contains a computer program that works in cooperation with the OS to give instructions to the CPU and perform various processing tasks. This computer program is executed by being loaded into RAM and works in cooperation with the CPU to constitute the control unit.

[0137] Furthermore, this computer program may be stored on an application program server connected to the anomaly detection support device 100 via any network, and it is possible to download all or part of it as needed.

[0138] Furthermore, the program for executing the processing described in this embodiment may be stored on a non-temporary computer-readable recording medium, or it may be configured as a program product. Here, "recording medium" includes any "portable physical medium" such as memory cards, USB (Universal Serial Bus) memory, SD (Secure Digital) cards, flexible disks, magneto-optical disks, ROMs, EPROMs (Erasable Programmable Read Only Memory), EEPROMs (Registered Trademark) (Electrically Erasable and Programmable Read Only Memory), CD-ROMs (Compact Disk Read Only Memory), MOs (Magneto-Optical disks), DVDs (Digital Versatile Disks), and Blu-ray (Registered Trademark) Discs.

[0139] Furthermore, "program" refers to a data processing method described in any language or writing method, regardless of its format, such as source code or binary code. Note that "program" is not necessarily limited to a single, monolithic structure; it also includes distributed structures consisting of multiple modules or libraries, and those that work in cooperation with other programs, such as an operating system, to achieve their functions. Regarding the specific configuration and reading procedures for reading the recording medium in each device shown in the embodiments, as well as the installation procedures after reading, well-known configurations and procedures can be used.

[0140] The various databases stored in the memory unit are storage means such as RAM, ROM, other memory devices, hard disks, flexible disks, and optical disks, and store various programs, tables, databases, and web page files used for various processes and website provision.

[0141] Furthermore, the anomaly detection support device 100 may be configured as an information processing device such as a known personal computer or workstation, or as an information processing device to which any peripheral device is connected. Alternatively, the anomaly detection support device 100 may be implemented by installing software (including programs or data, etc.) that enables the processing described in this embodiment onto the device.

[0142] Furthermore, the specific forms of distribution and integration of the devices are not limited to those shown in the illustration, and all or part of them can be configured by functionally or physically distributing and integrating them in any unit according to various additions or functional loads. In other words, the embodiments described above may be implemented in any combination, or the embodiments may be implemented selectively. [Explanation of Symbols]

[0143] 100 Anomaly detection support device 102 Control Unit 102a Anomaly detection unit 102b Similarity determination section 102c Comment Processing Unit 102d Screen display control unit 104 Communication Interface Section 106 Storage section 106a Default value update condition master 106b Default Value Update Conditions Details Master 106c Anomaly detection definition master 106d Judgment Result Data Column Information Master 106e Default Value Update History Table 108 Input / Output Interface Section 112 Input device 114 Output device 200 servers 300 Networks 400 Business Systems 500 terminal devices

Claims

[Claim 1] An anomaly detection support device comprising a control unit and displaying anomaly detection results for business data, The control unit, This is for managing the results of anomaly detection, and includes judgment result data such as execution ID, line number, anomaly judgment result, detection target, detection date and time, definition name, and summary message. This system manages comments registered in response to anomaly detection, and includes judgment result comment data such as comment ID, execution ID, execution line number, comment content, response status indicating the status of the response, update user, and update date and time. It is configured to be accessible, The system includes a display control means that controls the display of an alert screen, and on the alert screen, refers to the judgment result data to display a list of anomaly detection results in a list display area, and at the same time refers to the judgment result comment data to display the corresponding status of each anomaly detection result. The control unit, The default value update condition details master, which is registered by associating the default value update condition ID, condition detail No., and similarity judgment condition, A default update condition master is registered by associating the default update condition ID, default update condition name, execution ID, execution line number, and status indicating that no action is required. It is configured to be accessible, The aforementioned judgment result data includes similarity judgment results, An anomaly detection support device characterized by comprising a similarity determination means that, in accordance with the similarity determination conditions registered in the default value update condition details master, performs a similarity determination on the target anomaly detection result with an existing anomaly detection result, updates the similarity determination result of the determination result data to "True" if similarity is determined, and updates the correspondence status of the determination result comment data to "no correspondence required" in accordance with the status of the default value update condition master.

Citation Information

Patent Citations

  • Abnormality monitoring assisting device, program and method thereof

    JP2021165998A