Anomaly detection management device, anomaly detection management method, and anomaly detection management program
Patent Information
- Application Number
- JP2025023670
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2026-08-27
AI Technical Summary
【0014】 本発明によれば、俯瞰的な状態の確認を容易にすることができるという効果を奏する。また、本発明によれば、俯瞰的な状態を確認するために、3つのグラフで状況を表現し、出力する異常検知判定結果の共通項目をもとに分割することができるという効果を奏する。また、本発明によれば、確認するグラフを3つに絞ることで、システム内部で集計でき、時間の短縮につなげることができるという効果を奏する。また、本発明によれば、共通項目を自動で判別するため、異常検知判定結果の俯瞰的な集計を容易にすることができるという効果を奏する。また、本発明によれば、異常検知判定結果および周辺データ(対応ステータス等)を横断的に集計·図表で確認することができるという効果を奏する。また、本発明によれば、異常検知判定結果の俯瞰的な表示により対応状況を迅速に確認でき、統制監査の素早く行えると共に利用者の負荷低減に繋げることができるという効果を奏する。また、本発明によれば、共通項目を自動で判別し、それに沿って異常検知判定結果を分割することで、アラート定義を横断した集計や分析を容易にすることができるという効果を奏する。
Smart Images

Figure 2026137512000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an abnormality detection management device, an abnormality detection management method, and an abnormality detection management program.
Background Art
[0002] Patent Document 1 discloses a configuration in which the results of fraudulent transactions detected using a fraud detection application for recorded transaction data are visually displayed using graphs and Gantt charts.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the invention described in Patent Document 1, there is a problem that the abnormality detection determination results for performing an overview analysis cannot be aggregated according to the selected output conditions and output units.
[0005] The present invention has been made in view of the above problems, and an object thereof is to provide an abnormality detection management device, an abnormality detection management method, and an abnormality detection management program capable of confirming abnormality detection determination results in an overview state such as the number of occurrences, response status, or retention status when performing control audits.
Means for Solving the Problems
[0006] To solve the above-mentioned problems and achieve the objective, the anomaly detection management device according to the present invention is an anomaly detection management device comprising a storage unit and a control unit, wherein the storage unit includes an execution ID that identifies the execution of an anomaly detection judgment for a company's transactions, comment content for the anomaly detection judgment result, a response status for the anomaly detection judgment result and a data update date and time, a judgment result table for each alert definition that includes the execution ID, an anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result, the response status, a judgment item and a table update date and time, and the alert definition and the judgment result table. The system includes a business storage means for storing a judgment result data column item master that is set by associating it with the column names set therein, and the control unit is characterized by including a filter means for displaying selectable output conditions and output units based on the judgment result data column item master, and when the output conditions and output units are selected, a filter means for acquiring the selected output conditions and the selected output units, and an analysis output means for aggroing target data from the judgment result comment data and the judgment result table according to the selected output conditions, and displaying a Gantt chart showing the progress of the response status of the anomaly detection judgment result for each selected output unit based on the target data.
[0007] Furthermore, in the anomaly detection management device according to the present invention, the analysis output means further divides the anomaly detection judgment results into groups for each selected output unit based on the target data, and displays a bar graph comparing the number of days of response in each group.
[0008] Furthermore, in the anomaly detection management device according to the present invention, the analysis output means is further characterized in that, based on the target data, it divides the anomaly detection judgment results into groups for each selected output unit and displays a bar graph comparing the number of anomaly detection judgment results in each group.
[0009] Furthermore, in the anomaly detection management device according to the present invention, the output conditions are characterized by being an output period and / or an alert definition.
[0010] Furthermore, in the abnormality detection management device according to the present invention, the output unit is characterized by being the judgment item.
[0011] Furthermore, the anomaly detection management device according to the present invention is characterized in that the determination items are business establishment, department, person in charge, sales amount, business partner, and / or number of cases.
[0012] Furthermore, the anomaly detection management method according to the present invention is an anomaly detection management method to be executed by an anomaly detection management device comprising a storage unit and a control unit, wherein the storage unit includes an execution ID that identifies the execution of an anomaly detection judgment for a company's transactions, comment content for the anomaly detection judgment result, a response status for the anomaly detection judgment result and data update date and time set in association with judgment result data, a judgment result table for each alert definition that includes the execution ID, an anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result, the response status, judgment items and table update date and time set in association with each alert definition, and columns set in the alert definition and the judgment result table. The system includes a business memory means for storing a master of judgment result data column items set by associating names, and is characterized by including a filter step executed in the control unit which allows the selection of output conditions and output units based on the master of judgment result data column items, and when the output conditions and output units are selected, a filter step which obtains the selected output conditions and the selected output units, and an analysis output step which aggregates target data from the judgment result comment data and the judgment result table according to the selected output conditions, and displays a Gantt chart showing the progress of the response status of the anomaly detection judgment results for each of the selected output units based on the target data.
[0013] Furthermore, the anomaly detection management program according to the present invention is an anomaly detection management program to be executed by an anomaly detection management device comprising a storage unit and a control unit, wherein the storage unit includes an execution ID that identifies the execution of an anomaly detection judgment for a company's transactions, comment content for the anomaly detection judgment result, a response status for the anomaly detection judgment result and data update date and time set in association with judgment result comment data, a judgment result table for each alert definition that includes the execution ID, an anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result, the response status, a judgment item and a table update date and time set in association with the alert definition and the judgment result table. The system includes a business storage means for storing a judgment result data column item master that is set by associating the selected column names, and the control unit is characterized in that it displays the output conditions and output units in a selectable manner based on the judgment result data column item master, and when the output conditions and output units are selected, it executes a filter step to obtain the selected output conditions and the selected output units, and an analysis output step to aggregate target data from the judgment result comment data and the judgment result table according to the selected output conditions, and to display a Gantt chart showing the progress of the response status of the anomaly detection judgment results for each of the selected output units based on the target data. [Effects of the Invention]
[0014] The present invention has the effect of making it easy to check the status from an overview perspective. Furthermore, the present invention has the effect of representing the situation with three graphs to check the status from an overview perspective, and dividing the output anomaly detection judgment results based on common items. Furthermore, the present invention has the effect of making it possible to aggregate data within the system by narrowing down the number of graphs to check to three, thereby saving time. Furthermore, the present invention has the effect of making it easy to aggregate anomaly detection judgment results from an overview perspective because common items are automatically identified. Furthermore, the present invention has the effect of making it possible to check anomaly detection judgment results and surrounding data (response status, etc.) across aggregated data and charts. Furthermore, the present invention has the effect of making it possible to quickly check the response status by displaying anomaly detection judgment results from an overview perspective, thereby enabling quick control audits and reducing the burden on users. Furthermore, the present invention has the effect of making it easy to aggregate and analyze alert definitions across aggregated data by automatically identifying common items and dividing the anomaly detection judgment results accordingly. [Brief explanation of the drawing]
[0015] [Figure 1] Figure 1 is a block diagram showing an example of the configuration of an anomaly detection management device in an embodiment. [Figure 2] Figure 2 shows an example of business data in the embodiment. [Figure 3] Figure 3 shows an example of business data in the embodiment. [Figure 4] Figure 4 shows an example of business data in the embodiment. [Figure 5] Figure 5 shows an example of business data in the embodiment. [Figure 6] Figure 6 is a flowchart showing an example of the processing of the anomaly detection management device in the embodiment. [Figure 7] Figure 7 shows an example of the prerequisite processing in the embodiment. [Figure 8]FIG. 8 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 9] FIG. 9 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 11] FIG. 11 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 12] FIG. 12 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 13] FIG. 13 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 14] FIG. 14 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 15] FIG. 15 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 16] FIG. 16 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 17] FIG. 17 is a diagram showing an example of the abnormality detection management process in the embodiment. [Figure 18] FIG. 18 is a diagram showing an example of the abnormality detection management process in the embodiment. BEST MODE FOR CARRYING OUT THE INVENTION
[0016] Embodiments of the present invention will be described in detail based on the drawings. Note that the present invention is not limited to these embodiments.
[0017] [1. Overview] First, the overview of the present invention will be described.
[0018] In recent years, corporate internal control standards have been revised, leading to increased demand for strengthened controls and monitoring. To prevent fraud in corporate management, corrective actions are necessary, including detection tailored to the type of fraud. To improve detection accuracy, detection methods must be defined according to the type of fraud. Furthermore, to facilitate corrective actions, it is necessary to be able to save and analyze anomaly detection results (detection results) in accordance with the defined detection methods.
[0019] On the other hand, when conducting a control audit, it is effective to review the detection results in an overview manner (number of occurrences, response status, and delay status). However, when reviewing detection results in an overview manner, it is necessary to aggregate the scattered detection results and adapt them to the format defined for each detection method. In order to minimize the impact on corporate management, it is necessary to conduct control audits quickly, so it is important to quickly aggregate and analyze the detection results.
[0020] Previously, when conducting a comprehensive analysis, it was necessary to aggregate the detection results. However, because the detection results, including surrounding data, were scattered, this aggregation process was time-consuming. Furthermore, since the format of the detection results differed for each alert definition, it was necessary to standardize the format and aggregate the results when analyzing them across different systems.
[0021] Therefore, in this embodiment, it is necessary to define alert definitions individually for various types of fraud to make appropriate judgments. Since the alert definitions are defined according to the type of fraud, the format of the judgment results differs (although there are some common parts). When performing audit work, it is necessary to take an overview and analyze the detection results to confirm whether there are any fraudulent activities or activities of concern (number of occurrences, response status, status of delays).
[0022] Therefore, in this embodiment, the purpose of analysis is to check the progress of each detection result from the perspective of "Are there any detection results that have not been addressed?" or "How many days have passed until the address has been addressed?" and to identify those that are stalled or taking an unusually long time compared to others. To achieve this, a mechanism is provided to output a Gantt chart that shows the progress of the addressing status for each detection result.
[0023] Furthermore, in this embodiment, the detection results are divided into arbitrary groups based on the criteria of "how many detection results have not been addressed?" or "how many days have taken on average to address?", and the mechanism is provided to divide the detection results by arbitrary common items and output a bar graph comparing the number of days to address each group, with the purpose of analysis to identify those that are stalled or taking an abnormally long time compared to others.
[0024] Furthermore, in this embodiment, with the aim of analyzing whether "the number of anomaly detections is high in a particular group," the detection results are divided into arbitrary groups, and a mechanism is provided to divide the detection results by arbitrary common items and output a bar graph comparing the number of anomaly detection results in each group.
[0025] [2. Structure] An example of the configuration of the anomaly detection management device 100 according to this embodiment will be described with reference to Figures 1 to 5. Figure 1 is a block diagram showing an example of the configuration of the anomaly detection management device 100 in this embodiment.
[0026] As shown in Figure 1, the anomaly detection management device 100 is a commercially available desktop personal computer. However, the anomaly detection management device 100 is not limited to stationary information processing devices such as desktop personal computers, but may also be portable information processing devices such as commercially available notebook personal computers, PDAs (Personal Digital Assistants), smartphones, and tablet personal computers.
[0027] The anomaly detection management device 100 comprises a control unit 102, a communication interface unit 104, a storage unit 106, and an input / output interface unit 108. Each part of the anomaly detection management device 100 is connected to communicate via any communication path.
[0028] The communication interface unit 104 connects the anomaly detection management device 100 to the network 300 via communication devices such as routers and wired or wireless communication lines such as dedicated lines, enabling communication between them. The communication interface unit 104 has the function of communicating data with other devices via communication lines. Here, the network 300 has the function of connecting the anomaly detection management device 100 and the server 200 so that they can communicate with each other, and is, for example, the Internet or a LAN (Local Area Network).
[0029] The input / output interface unit 108 is connected to an input device 112 and an output device 114. The output device 114 can be a monitor (including a touch panel), a speaker, or a printer. The input device 112 can be a keyboard, a mouse, a microphone, or a monitor that works in conjunction with a mouse to provide pointing device functionality. In the following, the output device 114 may be referred to as the monitor 114 or printer 114, and the input device 112 may be referred to as the keyboard 112 or mouse 112.
[0030] The storage unit 106 stores various databases, tables, and files. The storage unit 106 also stores computer programs that work in cooperation with the OS (Operating System) to give instructions to the CPU (Central Processing Unit) to perform various processes. The storage unit 106 can be, for example, a memory device such as RAM (Random Access Memory) or ROM (Read Only Memory), a fixed disk device such as a hard disk, a flexible disk, or an optical disk. The storage unit 106 includes a business database 106a.
[0031] The business database 106a stores the company's business data. Here, the business database 106a may store execution IDs that identify the execution of anomaly detection judgments for the company's transactions, comment content for the anomaly detection judgment results, judgment result comment data set by associating the response status and data update date and time for the anomaly detection judgment results, a judgment result table set by associating the execution ID, anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result for each alert definition, judgment items and table update date and time, and a judgment result data column item master set by associating the column names set in the alert definition and judgment result table. Here, the judgment items may be business location, department, person in charge, sales amount, customer, and / or number. The business database 106a may also store an alert definition master in which alert definitions are set. Furthermore, the business database 106a may store target data, output files, Gantt charts, and / or bar graphs.
[0032] Here, an example of business data in this embodiment will be described with reference to Figures 2 to 5. Figures 2 to 5 are diagrams showing an example of business data in this embodiment.
[0033] As shown in Figure 2, this embodiment includes an alert definition master that links an alert definition ID for uniquely managing alert definitions, an alert definition for managing the names of alert definitions, and a judgment result table for storing the judgment results when an alert definition is executed (see Japanese Patent Publication No. 2022-170223).
[0034] As shown in Figure 3, this embodiment includes a judgment result data column item master that associates an alert definition ID for uniquely managing alert definitions, a column number which is a number for uniquely managing data within the same alert definition, and a column name which manages the names of the columns (see Japanese Patent Publication No. 2022-170223).
[0035] As shown in Figure 4, this embodiment includes a judgment result table for each alert definition (see Japanese Patent Publication No. 2022-170223). Here, the judgment result table may be set with associated information such as the execution ID generated when the judgment is executed, an abnormality flag that manages whether the judgment is abnormal or not, the current response status, business office, department, person in charge, customer, number of cases, sales amount, and / or update date and time.
[0036] As shown in Figure 5, in this embodiment, the system includes a comment ID that uniquely manages comment data for managing comments registered in response to anomalies, an execution ID that uniquely manages detection executions and identifies the detection execution to which the comment data is linked, a number that uniquely manages the anomaly detection judgment result (detection result) within the detection execution and identifies the detection result to which the comment data is linked, the comment content, the response status that manages the response status associated with the comment, the update user, and the update date and time, all linked to judgment result comment data (see Japanese Patent Application Publication No. 2024-95366).
[0037] Returning to Figure 1, the control unit 102 is a CPU or similar component that comprehensively controls the anomaly detection management device 100. The control unit 102 has internal memory for storing control programs such as the OS, programs that define various processing procedures, and required data, and executes various information processing based on these stored programs. Functionally, the control unit 102 comprises a filter unit 102a and an analysis output unit 102b.
[0038] The filter unit 102a sets the filtering settings for the output. Here, the filter unit 102a may display the output conditions and output units in a selectable format based on the judgment result data column item master, and if the output conditions and output units are selected, it may acquire the selected output conditions and selected output units. Here, the output conditions may be the output period and / or the alert definition. The output units may be judgment items. The filter unit 102a may also display an output setting dialog in which the output conditions and output units can be selected.
[0039] The analysis output unit 102b outputs analysis data. Here, the analysis output unit 102b may aggregate target data from the judgment result comment data and the judgment result table according to the selected output conditions, and based on the target data, display a Gantt chart showing the progress of the response status of the anomaly detection judgment result for each selected output unit. Alternatively, the analysis output unit 102b may divide the anomaly detection judgment result into groups for each selected output unit based on the target data and display a bar graph comparing the number of response days for each group. Alternatively, the analysis output unit 102b may divide the anomaly detection judgment result into groups for each selected output unit based on the target data and display a bar graph comparing the number of anomaly detection judgment results for each group. Furthermore, the analysis output unit 102b may output the analysis data (audio output and / or print output).
[0040] [3. Specific examples] A specific example of this embodiment will be described with reference to Figures 6 to 18.
[0041] [Anomaly detection and management processing] Now, with reference to Figure 6, an example of the anomaly detection management process in this embodiment will be described. Figure 6 is a flowchart showing an example of the processing of the anomaly detection management device 100 in this embodiment.
[0042] As shown in Figure 6, the filter unit 102a displays the output conditions and output units on the output device 114 so that they can be selected based on the judgment result data column item master. When the user selects the output period and the output conditions, which are alert definitions, and the output units, which are judgment items, via the input device 112, the selected output conditions and selected output units are acquired (step SA-1).
[0043] Then, the analysis output unit 102b aggregates target data from the judgment result comment data and the judgment result table according to the selected output conditions, and based on the target data, displays a Gantt chart on the output device 114 showing the progress of the response status of the anomaly detection judgment result for each selected output unit (step SA-2).
[0044] Then, the analysis output unit 102b divides the anomaly detection judgment results into groups for each selected output unit based on the target data, and displays a bar graph comparing the number of days required for each group on the output device 114 (step SA-3).
[0045] Then, the analysis output unit 102b displays a bar graph comparing the number of anomaly detection results in each group on the output device 114 (step SA-4), and terminates the process.
[0046] Now, with reference to Figure 7, an example of the prerequisite processing in this embodiment will be described. Figure 7 is a diagram showing an example of the prerequisite processing in this embodiment.
[0047] As shown in Figure 7, in this embodiment, the abnormality detection result is saved by performing an abnormality detection determination (step SB-1) (see Japanese Patent Publication No. 2022-170223 and Japanese Patent Publication No. 2023-064481).
[0048] As shown in Figure 7, in this embodiment, the anomaly detection result can be viewed from the analysis screen, and comments and response status can be changed (step SB-2) (see Japanese Patent Publication No. 2024-095366).
[0049] Furthermore, an example of the anomaly detection management process in this embodiment will be described with reference to Figures 8 to 18. Figures 8 to 18 are diagrams showing an example of the anomaly detection management process in this embodiment.
[0050] As shown in Figure 8, in this embodiment, by executing operational status analysis processes A to D, it is possible to comprehensively aggregate and review anomaly detection judgment results and surrounding data in charts and graphs.
[0051] As shown in Figure 9, in the operational status analysis process A of this embodiment, the filter unit 102a performs data extraction and setting of output units (filtering). As shown in Figure 9, in the operational status analysis process A of this embodiment, the user can select the output period and the alert definition to be output as output conditions, thereby narrowing down the anomaly detection judgment results. Multiple alert definitions can be selected, and if none are selected, all existing data will be extracted. Also, as shown in Figure 9, in the operational status analysis process A of this embodiment, the division unit of the graphs for operational status analysis processes B, C, and D is set using the output unit selected by the user. In this embodiment, the data list set in the common items combo box is changed according to the selection state of the alert definition combo box, but the "Execution ID", "Execution Row Number", "Anomaly Flag", and "Update Date and Time" columns are excluded.
[0052] As shown in Figure 10, in the operational status analysis process A of this embodiment, if the user has not specified an alert definition combo box, common items are displayed from the table columns of all alert definitions. If the user has specified an alert definition combo box (for example, if Alert001 and Alert002 are specified), common items are displayed from the table columns of the specified alert definitions.
[0053] Furthermore, as shown in Figure 11, in the operational status analysis process B of this embodiment, a Gantt chart is output that shows the progress of the response status for each anomaly detection judgment result (detection result).
[0054] Here, as shown in Figure 12, in the operational status analysis process B of this embodiment, (1) the judgment result comment data (for example, the detection result for execution ID=EX1002, execution line number=1) is referenced, (2) only the data where the response status has changed is obtained, (3) the record is referenced from the judgment result table, (4) the number of days from the judgment execution date until the status changes to each response status is calculated from (2) and (3), and (5) a Gantt chart is created from (4). Furthermore, as shown in Figure 12, in the operational status analysis process B of this embodiment, (5-1) the period from the judgment execution date when the status changes to "In Progress" (=1 day) to the day before the next response status: "Completed" (=9 days) is filled in.
[0055] As shown in Figure 13, in the operational status analysis process B of this embodiment, (6) a Gantt chart is created for each abnormal flag set to TRUE in the detection results, and it is divided and displayed according to the group selected in the output unit - common item combo box of the operational status analysis process A (for example, by department). Here, as shown in Figure 13, in the operational status analysis process B of this embodiment, (6-1) "Are there any detection results that have not been addressed?" and "How many days have passed until the address is completed? (How much is there a delay at each status?)" become easier to see, and the overall length and the tendency of areas that tend to get stuck can be visually grasped by the output unit (for example, by department).
[0056] Furthermore, as shown in Figure 14, in the operational status analysis process C of this embodiment, the detection result data is divided by the common item selected in the output unit - common item combo box of the operational status analysis process A, and a bar graph comparing the number of days of response in each group is output.
[0057] Here, as shown in Figure 15, in the operational status analysis process C of this embodiment, (1) only records from the detection results where "abnormal flag is TRUE" and "response status is completed" or "response status is not required" are referenced. In this embodiment, in order to aggregate the average number of days until the response is completed, responses completed and responses not required may be defined as completed.
[0058] Then, as shown in Figure 16, in the operational status analysis process C of this embodiment, (2) the data linked to the judgment result data obtained in (1) from the judgment result comment data is referenced and the data that is marked as "Completed" or "No action required" is matched with the execution ID and execution line number of (1) and the column of the judgment result comment data.
[0059] Then, as shown in Figure 16, in the operational status analysis process C of this embodiment, the number of days until each detection result becomes "response completed" or "no response required" is calculated from the data of (3)(1) and (2), and (4)(3) is divided into groups selected in the output unit - common item combo box of the operational status analysis process A (for example, by department), and the number of cases is displayed as a bar graph.
[0060] Furthermore, as shown in Figure 17, in the operational status analysis process D of this embodiment, the detection results are divided by the common item selected in the output unit - common item combo box of the operational status analysis process A, and a bar graph comparing the number of anomaly detection judgment results in each group is output.
[0061] Here, as shown in Figure 18, in the operational status analysis process D of this embodiment, (1) only the records with "abnormal flag: TRUE" from the detection results are referred to, and (2) (1) is divided into groups selected in the output unit - common item combo box of the operational status analysis process A (for example, by department), and the number of records is displayed as a bar graph.
[0062] As shown in Figures 14 to 18, in this embodiment, both the average response time and the number of anomaly detection results are in the order of "Department 11 < Department 12 < Department 21," indicating that "Department 21" has a particularly high number of anomaly detections and bottlenecks, and therefore requires higher priority in addressing these issues.
[0063] [4. Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This embodiment can contribute to improving operational efficiency and promoting appropriate management decisions by companies, thereby contributing to SDGs Goals 8 and 9.
[0064] Furthermore, this embodiment can contribute to reducing waste and promoting paperless and digital processes, thereby contributing to SDGs Goals 12, 13, and 15.
[0065] Furthermore, this embodiment can contribute to strengthening control and governance, thereby enabling contributions to SDG Goal 16.
[0066] [5. Other Embodiments] In addition to the embodiments described above, the present invention may be implemented in various different embodiments within the scope of the technical idea described in the claims.
[0067] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically by known methods.
[0068] Furthermore, the processing procedures, control procedures, specific names, information including parameters such as registration data and search conditions for each process, screen examples, and database configuration shown in this specification and in the drawings may be changed at will unless otherwise specified.
[0069] Furthermore, with respect to the anomaly detection management device 100, each component shown in the diagram is a functional concept and does not necessarily need to be physically configured as shown.
[0070] For example, the processing functions of the anomaly detection management device 100, particularly those performed by the control unit 102, may be implemented entirely or partially by a CPU and a program interpreted and executed by the CPU, or they may be implemented as wired logic hardware. The program is recorded on a non-temporary computer-readable recording medium containing programmed instructions for the information processing device to execute the processing described in this embodiment, and is mechanically read by the anomaly detection management device 100 as needed. That is, a storage unit such as ROM or HDD (Hard Disk Drive) stores a computer program that works in cooperation with the OS to give instructions to the CPU and perform various processing tasks. This computer program is executed by being loaded into RAM and works in cooperation with the CPU to constitute the control unit.
[0071] Furthermore, this computer program may be stored on an application program server connected to the anomaly detection management device 100 via any network, and it is possible to download all or part of it as needed.
[0072] Furthermore, the program for executing the processing described in this embodiment may be stored on a non-temporary computer-readable recording medium, or it may be configured as a program product. Here, "recording medium" includes any "portable physical medium" such as memory cards, USB (Universal Serial Bus) memory, SD (Secure Digital) cards, flexible disks, magneto-optical disks, ROMs, EPROMs (Erasable Programmable Read Only Memory), EEPROMs (Registered Trademark) (Electrically Erasable and Programmable Read Only Memory), CD-ROMs (Compact Disk Read Only Memory), MOs (Magneto-Optical disks), DVDs (Digital Versatile Disks), and Blu-ray (Registered Trademark) Discs.
[0073] Furthermore, "program" refers to a data processing method described in any language or writing method, regardless of its format, such as source code or binary code. Note that "program" is not necessarily limited to a single, monolithic structure; it also includes distributed structures consisting of multiple modules or libraries, and those that work in cooperation with other programs, such as an operating system, to achieve their functions. Regarding the specific configuration and reading procedures for reading the recording medium in each device shown in this embodiment, as well as the installation procedures after reading, well-known configurations and procedures can be used.
[0074] The various databases stored in the memory unit 106 include memory devices such as RAM and ROM, fixed disk devices such as hard disks, flexible disks, and optical disks, and store various programs, tables, databases, and web page files used for various processes and website provision.
[0075] Furthermore, the anomaly detection management device 100 may be configured as a known personal computer or workstation or other information processing device, or as an information processing device to which any peripheral devices are connected. Alternatively, the anomaly detection management device 100 may be implemented by installing software (including programs or data, etc.) on the device that enables the processing described in this embodiment.
[0076] Furthermore, the specific forms of distribution and integration of the devices are not limited to those shown in the figures, and all or part of them can be configured by functionally or physically distributing and integrating them in any unit according to various additions or functional loads. In other words, the embodiments described above may be implemented in any combination, or the embodiments may be implemented selectively. [Industrial applicability]
[0077] This invention is useful in various industries, including the construction, real estate, and chemical industries, which have implemented accounting and accounts receivable / payable systems. [Explanation of Symbols]
[0078] 100 Anomaly detection and management device 102 Control Unit 102a Filter section 102b Analysis Output Unit 104 Communication Interface Section 106 Storage section 106a Business Database 108 Input / Output Interface Section 112 Input device 114 Output device 200 servers 300 Networks
Claims
1. An anomaly detection management device comprising a memory unit and a control unit, The aforementioned storage unit is A business storage means that stores an execution ID that identifies the execution of an anomaly detection judgment for a company's transactions, a judgment result comment data set by associating the content of the comment for the anomaly detection judgment result, the response status and data update date and time for the anomaly detection judgment result, a judgment result table set by associating the execution ID, an anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result for each alert definition, the response status, the judgment item and the table update date and time, and a judgment result data column item master set by associating the column names set in the alert definition and the judgment result table. Equipped with, The control unit, Based on the judgment result data column item master, the output conditions and output units are displayed in a selectable format, and when the output conditions and output units are selected, a filter means is provided to acquire the selected output conditions and the selected output units. An analysis output means that aggregates target data from the judgment result comment data and the judgment result table according to the selection output conditions, and displays a Gantt chart showing the progress of the response status of the anomaly detection judgment result for each selection output unit based on the target data, An anomaly detection and management device characterized by being equipped with the following features.
2. The aforementioned analysis output means is Furthermore, the anomaly detection management device according to claim 1 is characterized in that, based on the target data, the anomaly detection judgment results are divided into groups for each selected output unit, and a bar graph is displayed comparing the number of days of response in each group.
3. The aforementioned analysis output means is Furthermore, the anomaly detection management device according to claim 1 is characterized in that, based on the target data, the anomaly detection judgment results are divided into groups for each selected output unit, and a bar graph is displayed comparing the number of anomaly detection judgment results in each group.
4. The aforementioned output conditions are: An anomaly detection management device according to claim 1 or 2, characterized in that it is an output period and / or the alert definition.
5. The aforementioned output unit is, The abnormality detection management device according to claim 1 or 2, characterized in that the determination item is as described above.
6. The aforementioned determination items are: An anomaly detection management device according to claim 1 or 2, characterized in that the information includes business locations, departments, personnel in charge, sales figures, business partners, and / or the number of cases.
7. An anomaly detection management method to be executed by an anomaly detection management device comprising a memory unit and a control unit, The aforementioned storage unit is A business storage means that stores an execution ID that identifies the execution of an anomaly detection judgment for a company's transactions, a judgment result comment data set by associating the content of the comment for the anomaly detection judgment result, the response status and data update date and time for the anomaly detection judgment result, a judgment result table set by associating the execution ID, an anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result for each alert definition, the response status, the judgment item and the table update date and time, and a judgment result data column item master set by associating the column names set in the alert definition and the judgment result table. Equipped with, The control unit is executed as follows: Based on the judgment result data column item master, the output conditions and output units are displayed in a selectable format, and if the output conditions and output units are selected, a filter step is performed to obtain the selected output conditions and the selected output units. An analysis output step which aggregates target data from the judgment result comment data and the judgment result table according to the selection output conditions, and displays a Gantt chart showing the progress of the response status of the anomaly detection judgment result for each selection output unit based on the target data, An anomaly detection and management method characterized by including the following.
8. An anomaly detection management program to be executed by an anomaly detection management device comprising a memory unit and a control unit, The aforementioned storage unit is A business storage means that stores an execution ID that identifies the execution of an anomaly detection judgment for a company's transactions, a judgment result comment data set by associating the content of the comment for the anomaly detection judgment result, the response status and data update date and time for the anomaly detection judgment result, a judgment result table set by associating the execution ID, an anomaly flag indicating whether or not there is an anomaly in the anomaly detection judgment result for each alert definition, the response status, the judgment item and the table update date and time, and a judgment result data column item master set by associating the column names set in the alert definition and the judgment result table. Equipped with, In the control unit, Based on the judgment result data column item master, the output conditions and output units are displayed in a selectable format, and if the output conditions and output units are selected, a filter step is performed to obtain the selected output conditions and the selected output units. An analysis output step which aggregates target data from the judgment result comment data and the judgment result table according to the selection output conditions, and displays a Gantt chart showing the progress of the response status of the anomaly detection judgment result for each selection output unit based on the target data, An anomaly detection management program to execute this.
Citation Information
Patent Citations
A transaction platform where a system includes other systems
JP2024545943A