Communication Log Analysis Apparatus and Method

JP7686603B2Active Publication Date: 2025-06-02HITACHI LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022099508
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-21
Publication Date
2025-06-02
Estimated Expiration
2042-06-21

AI Technical Summary

Technical Problem

Existing communication log analysis systems struggle with the complexity of machine language and varying data types in communication logs, making it difficult for non-experts to quickly identify failure causes and requiring specialized knowledge to analyze communication logs effectively.

Method used

A communication log analysis device that extracts and displays communication logs with identified time stamps and data types, allowing for the creation of analysis sequences based on user-defined conditions, facilitating easy analysis and visualization of communication sequences.

Benefits of technology

Enables easy analysis of communication logs by non-experts, reducing analysis time and improving the efficiency of failure cause identification by providing clear, data-type-specific analysis sequences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000012_0000
    Figure 00000012_0000
  • Figure 00000013_0000
    Figure 00000013_0000
  • Figure 00000014_0000
    Figure 00000014_0000
Patent Text Reader

Abstract

To facilitate the analysis of a communication log including machine codes of data of a data frame communicated between devices.SOLUTION: A communication log accumulated on a mediation device mediating communication between devices includes a log entry per data frame. The log entry includes a machine code of data of a data frame. The machine code includes a machine code of data representing a data type. A communication log analysis device identifies matters including time, transmission or reception, a transmission destination device or a transmission source device, and a data type of data in a data frame corresponding to the log entry from each log entry of the communication log. The communication log analysis device identifies one or a plurality of subject matters, which is one or a plurality of matters related to the target data type, among the plurality of identified matters, identifies an analysis sequence, which is a communication sequence based on the one or the plurality of identified subject matters, and displays a figure of the analysis sequence.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention generally relates to communication log analysis, and more particularly to communication log analysis that acquires a communication log when a communication failure occurs and plays an auxiliary role in analyzing the cause of the failure. [Background technology]

[0002] When a communication failure occurs, it is generally necessary to analyze communication logs stored in devices involved in the communication in order to identify the cause of the failure and to recover from the failure. Also, it may be necessary to analyze the communication logs for reasons other than the occurrence of the communication failure.

[0003] Patent Document 1 discloses a method for analyzing communication access logs. By converting encrypted logs into plaintext logs, it is possible to analyze what data has been exchanged and to visualize the access status of categorized sites.

[0004] Patent Document 2 discloses a method for collecting and analyzing communication logs related to a failure when the failure occurs. The monitoring logs of multiple devices are collected in a single device, and when a failure occurs, the location of the failure can be identified from the monitoring logs of the multiple devices. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] JP 2020-197929 A [Patent Document 2] JP 2011-221703 A Summary of the Invention [Problem to be solved by the invention]

[0006] Typically, the communication log to be analyzed is stored in an intermediary device that mediates communication between devices. The communication log stored in the intermediary device has a log entry for each data frame received by the intermediary device and for each data frame sent by the intermediary device. For each data frame, the log entry includes a machine code representation of at least a portion of the data in that data frame.

[0007] Even if the log entries are displayed in machine code, it is difficult to analyze them unless the analyst is an experienced analyst. This makes it difficult to perform a quick analysis (for example, to quickly identify the cause of a communication failure in order to recover from the failure) when a communication failure occurs.

[0008] In addition, the viewpoint of analysis differs depending on the data type of the data in the data frame (for example, whether it is data communicated periodically, data with a response, data requiring a reply, etc.). Data representing the data type is included in the data in the data frame, and the communication log contains the machine code of the data representing the data type. For this reason, it is also difficult to identify the data type.

[0009] Neither Patent Document 1 nor Patent Document 2 discloses or suggests such a problem or a means for solving the problem. [Means for solving the problem]

[0010] A communication log analysis device acquires a communication log stored in an intermediary device. The communication log has a log entry for each data frame, and the log entry includes data indicating the time when the intermediary device received the data frame from a device or the time when the intermediary device transmitted the data frame to a device, and a machine code of at least a part of the data of the data frame (including data indicating a data type). The communication log analysis device identifies items from each log entry in the acquired communication log, including the time, whether it was sent or received, the destination device or the source device, and the data type of the data in the data frame corresponding to the log entry. The communication log analysis device identifies one or more target items, which are one or more items related to a target data type, from among the identified items, and identifies an analysis sequence, which is a communication sequence based on the identified one or more target items, and displays a diagram of the analysis sequence. Effect of the Invention

[0011] It is possible to easily analyze a communication log containing machine code data of data frames communicated between devices. [Brief description of the drawings]

[0012] [Figure 1] 1 is a diagram showing an example of a schematic configuration of an entire system according to an embodiment of the present invention; [Diagram 2] FIG. 2 is a diagram illustrating an example of the configuration of a data frame. [Diagram 3] FIG. 13 is a diagram illustrating an example of a condition input UI. [Figure 4A] FIG. 13 is a diagram illustrating an example of the configuration of all data information. [Figure 4B] FIG. 11 is a diagram illustrating an example of a configuration of extracted data information. [Diagram 5] FIG. 13 is a diagram showing an example of the configuration of special processing information. [Figure 6] 13 is a flowchart of an example of an analysis process. [Figure 7A] FIG. 13 is a diagram showing an example of a correct communication sequence. [Figure 7B]FIG. 13 is a diagram showing an example of a correct communication sequence. [Figure 8] FIG. 13 is a diagram illustrating an example of an analysis sequence diagram without special processing. [Figure 9] FIG. 13 is a diagram illustrating an example of an analysis sequence diagram with special processing; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0013] In the following description, an "interface unit" may refer to one or more interface devices. The one or more interface devices may be at least one of the following: One or more I / O (Input / Output) interface devices. The I / O (Input / Output) interface devices are interface devices to at least one of the I / O devices and a remote display computer. The I / O interface device to the display computer may be a communications interface device. The at least one I / O device may be a user interface device, e.g., either an input device such as a keyboard and a pointing device, or an output device such as a display device. One or more communication interface devices. The one or more communication interface devices may be one or more homogeneous communication interface devices (e.g., one or more NICs (Network Interface Cards)) or two or more heterogeneous communication interface devices (e.g., a NIC and an HBA (Host Bus Adapter)).

[0014] In the following description, a "memory" refers to one or more memory devices, typically a primary storage device. At least one of the memory devices in the memory may be a volatile memory device or a non-volatile memory device.

[0015] In the following description, a "persistent storage device" refers to one or more persistent storage devices. A persistent storage device is typically a non-volatile storage device (e.g., an auxiliary storage device), and specifically, for example, a hard disk drive (HDD) or a solid state drive (SSD).

[0016] Also, in the following description, "storage device" may be at least memory, including memory and persistent storage device.

[0017] In the following description, a "processor" refers to one or more processor devices. The at least one processor device is typically a microprocessor device such as a CPU (Central Processing Unit), but may be another type of processor device such as a GPU (Graphics Processing Unit). The at least one processor device may be a single-core or multi-core. The at least one processor device may be a processor core. The at least one processor device may be a processor device in a broader sense, such as a hardware circuit (e.g., an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit)) that performs part or all of the processing.

[0018] In the following description, functions may be described using the expression "yyy unit", but the functions may be realized by one or more computer programs being executed by a processor, or by one or more hardware circuits (e.g., FPGA or ASIC), or by a combination thereof. When a function is realized by a program being executed by a processor, the function may be at least a part of the processor, since the specified processing is performed using a storage device and / or an interface device, etc., as appropriate. Processing described with a function as the subject may be processing performed by a processor or a device having the processor. A program may be installed from a program source. The program source may be, for example, a program distribution computer or a computer-readable recording medium (e.g., a non-transitory recording medium). The description of each function is an example, and multiple functions may be combined into one function, or one function may be divided into multiple functions.

[0019] In addition, in the following description, when describing elements of the same type without distinguishing between them, common reference symbols will be used, and when describing elements of the same type with distinction between them, the ID (e.g., identification number) or reference symbol of the element will be used.

[0020] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.

[0021] FIG. 1 is a diagram showing an example of a schematic configuration of an entire system including a communication log analysis device (hereinafter, analysis device) according to an embodiment.

[0022] A plurality of devices 101 (101A, 101B, 101C, . . . ) communicate with each other via an intermediary device (communication intermediary device) 111. At least one of the plurality of devices 101 may be a server-client system.

[0023] The intermediary device 111 includes an interface device 51, a storage device 52, and a processor 53 connected thereto.

[0024] A plurality of devices 101, a Network Time Protocol (NTP) server 121, and an analysis device 130 are connected to an interface device 51 via, for example, a communication network. A communication log 55 is recorded in a storage device 52.

[0025] The processor 53 executes a computer program stored in the storage device 52 to realize functions such as an intermediate unit 114, a recording unit 112, and an output unit 113. The intermediate unit 114 intermediates communication between the devices 101 (receiving a data frame from the source device 101 and transmitting a data frame to the destination device 101).

[0026] The recording unit 112 records a communication log 55 of communication between the devices 101 in the storage device 52. The communication log 55 has a log entry for each data frame received by the intermediary device 111 and for each data frame transmitted by the intermediary device 111. For each data frame, the log entry includes data indicating the time when the intermediary device 111 received the data frame from the device 101 or the time when the intermediary device 111 transmitted the data frame to the device, and a machine code of the entire (or part) data of the data frame. Specifically, for example, each time the intermediary device 111 received or transmitted a data frame, the recording unit 112 specifies the time by communication with the NTP server 121 (or specifies the time by a timer inside the intermediary device 111), includes data indicating the specified time in the log entry, and includes the machine code of the data of the data frame received or transmitted by the intermediary device 111 in the log entry.

[0027] The output unit 113 transmits the communication log 55 to the analysis device 130 .

[0028] The analysis device 130 includes an interface device 71, a storage device 72, and a processor 73 connected thereto.

[0029] An intermediary device 111 and an analyst terminal 140 are connected to the interface device 71, for example, via a communication network. The analyst terminal 140 is an example of an input / output device operated by an analyst, and is, for example, a computer equipped with a display device and an input device, such as a smartphone or a personal computer.

[0030] The storage device 72 stores the communication log 55 from the intermediary device 111. The storage device 72 also stores data type rule information 156, analysis target condition information 157, special processing information 158, and sequence information 159. The data type rule information 156 is information representing rules for identifying the data type represented by data present at a position dependent on the configuration of a user area (described later). The extraction condition information 157 is information representing the analysis target condition (condition related to the communication to be analyzed). The analysis target condition is, for example, a condition specified by an analyst. The special processing information 158 is information representing the relationship between a data type and special processing. The sequence information 159 is information representing a correct communication sequence for at least one data type (for example, a data type requiring special processing).

[0031] The processor 73 executes a computer program stored in the storage device 72, thereby realizing functions such as an input unit 131, an output unit 132, and an analysis unit 133.

[0032] The input unit 131 receives (acquires) the communication log 55 from the intermediate device 111, and stores the communication log 55 in the storage device 72. The input unit 131 also accepts input of the analysis target conditions from the analyst terminal 140, and stores in the storage device 72 analysis target condition information 157 representing the analysis target conditions.

[0033] The output unit 132 displays the diagram of the analysis sequence identified by the analysis unit 133 on the analyst terminal 140 (transmits display information of the diagram of the analysis sequence to the analyst terminal 140). The analysis unit 133 analyzes the communication log 55 and identifies the analysis sequence.

[0034] The device 101 communicates with other devices via the intermediate device 111 using wired or wireless communication means. The intermediate device 111 records in the communication log 55 the time when communication between the devices was performed and the content of the communication (for example, the machine code of the data in the data frame).

[0035] For example, when the occurrence of a failure is detected by the intermediary device 111 (for example, when a failure notification is received from at least one of the source and destination devices 101), the communication log 55 accumulated in the intermediary device 111 is output from the output unit 113 and stored in the storage device 72 of the analysis device 130 via the input unit 131 of the analysis device 130. Note that the analysis device 131 does not necessarily need to be connected to the intermediary device 111, and specifically, the communication log 55 may be copied from a portable storage medium to the storage device 72 via the interface device 71.

[0036] FIG. 2 is a diagram showing an example of the structure of a data frame used in communication between devices.

[0037] 2 is a typical TCP / IP frame, and has an Etherenet header 201 (Etherenet is a registered trademark), an IP header / TCP header 202, and user data 210. The user data 210 is data that occupies a user area 203. The data length and data format of the user data 210 are arbitrary. There are no restrictions on the data length and data format of the user area 203, but data type data (data indicating a data type) 211 is present in a specified location in the user area 203.

[0038] Here, the "data type" refers to the type of data in the data frame (e.g., particularly, the user data 210). The data type means, for example, whether the user data is data that is communicated periodically, data that has a response, data that requires a reply, etc. It is desirable for the analyst to perform communication log analysis from a perspective according to the data type.

[0039] The data type data 211 exists in the user area 203 at a position that depends on the configuration of the user area 203. In other words, the position of the data type data 211 (for example, an offset from the beginning of a data frame or the beginning of a user area) is not unique. For this reason, it is difficult to identify the data type from the communication log 55 in which the user data 210 is described. For example, some user data 210 includes a user data body and a user data header, and the position of the data type data 211 differs depending on the type of user data header. Since the configuration of the user area 203 is arbitrary by the user, it is difficult to identify the data type.

[0040] Furthermore, the user data (all data in the user area 203) is written in machine language in the communication log 55. This is also a factor that makes it difficult to identify the data type.

[0041] Therefore, in this embodiment, there is prepared data type rule information 156, that is, information representing rules for identifying the data type represented by data present at a position that depends on the configuration of the user area 203. Examples of one or more rules that can be registered and data type identification according to the rules are as follows: The rule indicates the relationship between the type of device of the transmission source and the type of user data header and / or the position of data type data. When the analysis unit 133 identifies the type of device of the transmission source from the log entry, the analysis unit 133 identifies the position of the data type data 211 from the rule using the identified device type as a key, and identifies the data type from the data 211. The rule represents the relationship between the type of header (Ethernet header, IP header / TCP header, and / or user data header), the characteristics of the header (for example, the character string at the beginning of the header), and the position of the data type data 211. When the analysis unit 133 identifies the characteristics of the header from the log entry, it identifies the position of the data type data 211 from the rule using the identified characteristics as a key, and identifies the data type from the data 211. A rule expresses the relationship between a specific character string (for example, a string of letters or numbers) and the position of the data type data 211. When any specific character string is found in a log entry, the analysis unit 133 uses the specific character string as a key to identify the position of the data type data 211 from the rule, and identifies the data type from the data 211.

[0042] FIG. 3 is a diagram showing an example of a condition input UI (User Interface).

[0043] The condition input UI 300 is a UI that accepts input of analysis target conditions, and is a UI that is provided to the analyst terminal 140 by the input unit 131. The condition input UI 300 has a tool (e.g., a GUI component) that accepts input of elements of the analysis target conditions. Either tool is useful for narrowing down the log entries to be analyzed.

[0044] According to the condition input UI 300, the analyst can select the data type to be investigated using a pull-down menu 301.

[0045] Furthermore, the condition input UI 300 allows the start time and end time of the analysis target to be specified by inputting the time to be analyzed after the communication log is acquired in the text boxes 302 and 303.

[0046] Furthermore, according to the condition input UI 300, when it is desired to output an analysis sequence diagram of only data received by the intermediary device 111 or only data transmitted by the intermediary device 111, it is possible to select either transmission or reception in the pull-down menu 304.

[0047] Furthermore, when the condition input UI 300 is used to output an analysis sequence diagram of communication between specific devices, a source device can be selected from a pull-down menu 305 and a destination device can be selected from a pull-down menu 306 .

[0048] The AND of the above conditions becomes the analysis target condition, and information 157 representing this analysis target condition is stored in the storage device 72. Based on the log entries that satisfy this analysis target condition, the analysis unit 133 creates an analysis sequence diagram to be output.

[0049] In this way, the input unit 131 accepts manual input of analysis target conditions, which are conditions related to the communication to be analyzed. The analysis target conditions are composed of at least one of the following conditions: data type, time range of the communication (start time and end time, or a reference time and an offset from the reference time, etc.), whether it is transmission or reception, and the communication between which devices. By specifying the analysis target conditions, the analyst can limit the log entries to be analyzed. This makes it possible to shorten the time required for analysis processing, and to output only the information necessary for identifying the cause.

[0050] FIG. 4A is a diagram showing an example of the configuration of all data information 401. As shown in FIG.

[0051] The analysis unit 133 identifies items including the time, transmission or reception, the destination device or source device, and the data type of the data in the data frame corresponding to the log entry from each of all log entries of the communication log 55, and creates all data information 401 including information indicating the identified items. The all data information 401 has an entry for each log entry (each data frame). The entry has information such as time 411, data type 412, transmission / reception 413, communication partner 414, dataA 415, and dataB 416.

[0052] Time 411 is a time identified from a log entry, and specifically indicates the time when intermediate device 111 transmitted a data frame or received a data frame.

[0053] The data type 412 indicates the data type identified from the log entry. To identify the data type, the analysis unit 133 refers to the data type rule information 156 described above.

[0054] Sending / receiving 413 indicates sending or receiving specified from the log entry. Communication partner 414 indicates the destination device or source device specified from the log entry, specifically, the ID of the source device (e.g., the name of the device) or the ID of the destination device.

[0055] DataA 415 represents a data part (a part of a data frame) identified from a log entry, and dataB 416 represents a data part (the remainder of the data frame) identified from a log entry. That is, all or a part of a data frame identified from a log entry may be divided into a plurality of data parts, and the plurality of data parts may be included in an entry. For example, user data identified from a log entry may be divided into a plurality of data parts and stored in an entry of the total data information 401. The number of data parts may be determined arbitrarily. For example, dataA 415 may be an Ethernet header 201 and an IP header / TCP header 202, and dataB 416 may be user data 210. Alternatively, for example, dataA 415 may be a user data header, and dataB 416 may be a user data body.

[0056] FIG. 4B is a diagram showing an example of the configuration of the extracted data information 402. As shown in FIG.

[0057] The extracted data information 402 is information composed of only entries that match the analysis target condition among the entire data information 401. Therefore, the information 421 to 426 held by the entries of the extracted data information 402 is the same as the information 411 to 416 held by the entries of the entire data information 401. The analysis unit 133 identifies entries that match the analysis target condition represented by the information 157 among the entire data information 401, and generates the extracted data information 402 which is a set of the identified entries. One or more entries held by the extracted data information 402 correspond to an example of information that represents one or more items related to the target data type (the data type included in the analysis target condition).

[0058] FIG. 5 shows an example of the configuration of the special processing information 158.

[0059] The special processing information 158 indicates the relationship between a data type and the presence or absence of special processing. For example, the special processing information 158 has an entry for each data type, and the entry has information such as a data type 501, a special processing flag 502, and a special processing name 503.

[0060] A data type 501 indicates a data type. A special processing flag 502 indicates the presence or absence of a special processing ("1" means that a special processing is present, and "0" means that a special processing is not present). A special processing name 503 indicates the name of the special processing if a special processing is present. The special processing name 503 may be associated with a special processing (e.g., an algorithm).

[0061] The "special process" refers to a process carried out for generating an analysis sequence diagram to be displayed, other than identifying a communication sequence from the extracted data information 402 and generating a diagram of that communication sequence.

[0062] FIG. 6 is a flowchart of an example of the analysis process.

[0063] The communication log 55 stored in the intermediary device 111 is input by the input unit 131 of the analysis device 130, and the communication log 55 is stored in the storage device 72 (S601).

[0064] The analysis unit 133 extracts the time of communication, the data type, whether it was transmitted or received, the communication partner, and the data to be transmitted or received (all or part of the user frame) from the communication log 55, and creates all data information 401 including that information (S602). In S602, the various information is, for example, as follows: The time 411 indicates a time identified from data indicating a time in the log entry. The data type 412 represents a data type determined according to at least one rule represented by the data type rule information 156 . The send / receive 413 and communication partner 414 are information identified from the header of the data frame in the log entry. DataA 415 and dataB 416 are all or part of the data frame (eg, machine code) included in the log entry.

[0065] The input unit 131 displays a condition input UI on the analyst terminal 140, accepts input of the analysis target conditions via the condition input UI, and stores information 157 representing the input analysis target conditions in the storage device 72 (S603). Note that S603 may be performed in advance.

[0066] The analysis unit 133 creates extracted data information 402 by extracting only those entries that match the analysis target conditions from the total data information 401 (S604).

[0067] The analysis unit 133 refers to an entry in the special processing information 158 that corresponds to the data type indicated by the extracted data information 402 (or the data type included in the analysis target condition), and determines whether or not special processing is required (S605).

[0068] If special processing is not required (S605: NO), the analysis unit 133 identifies from the extracted data information 402 the time, the data type of the data frame from which device the intermediary device 111 received it, and the data type of the data frame to which device the intermediary device 111 sent it, constructs an analysis sequence that is a communication sequence that represents the identified items, and generates a diagram of the analysis sequence. The output unit 132 displays the analysis sequence diagram on the analyst terminal 140 (S606).

[0069] If special processing is required (S6005: YES), the analysis unit 133 identifies the special processing from the special processing information 158 (S607). The analysis unit 133 identifies, from the extracted data information 402, the time, the data type of the data frame from which device the intermediary device 111 received it, and the data type of the data frame to which device the intermediary device 111 transmitted it, identifies an analysis sequence that is a communication sequence that represents the identified items, and applies the special processing of S607 to the analysis sequence (S608). The analysis unit 133 generates a diagram of the analysis sequence to which the special processing has been applied. The output unit 132 displays the analysis sequence diagram on the analyst terminal 140 (S609).

[0070] Analysts have different analysis perspectives (e.g., data items they want to see) depending on the data type. The data type can be identified from a communication log containing machine code, and an analysis sequence diagram based on the perspective according to the data type is automatically generated and displayed. This makes analysis easier for analysts. Also, if special processing is associated with the target data type (the data type represented by the extracted data information 402 (or the data type included in the analysis target conditions)), the displayed analysis sequence diagram is a diagram in which the special processing has been applied to a diagram of the communication sequence obtained from the extracted data information 402. This makes analysis even easier for analysts.

[0071] 7A and 7B are diagrams showing an example of a correct communication sequence according to a data type. The correct communication sequence can be specified from sequence information 159 for each data type.

[0072] 7A is a correct communication sequence for data type 2. In relation to data type 2, data frames of data types 3 to 5 are transmitted and received.

[0073] The communication sequence illustrated in Fig. 7B is a correct communication sequence for data type 11. A data frame of data type 12 is transmitted and received in relation to data type 11. In addition, a threshold value for the time from when a data frame of data type 11 is transmitted from device 2 until a data frame of data type 12 is received by device 2, and a threshold value for the time from when a data frame of data type 11 is transmitted from device 2 until the next data frame of data type 11 is transmitted from device 2 are defined.

[0074] FIG. 8 is a diagram showing an example of an analysis sequence diagram (displayed in S606) without special processing.

[0075] The elements in the analysis sequence diagram are, for example, as follows: The time is a time specified from the time 421. Device 1 is the destination device, and device 2 is the source device. The arrows indicate the direction of data transmission. These are elements identified by the Send / Receive 423 and the Communication Partner 424. For each arrow (i.e. for each send and each receive), the data type listed in the vicinity is the data type identified from data types 422.

[0076] FIG. 9 is a diagram showing an example of an analysis sequence diagram (displayed in S609) with special processing.

[0077] Examples of special treatments include the following: A correct communication sequence for the target data type is identified from sequence information 159 indicating a correct communication sequence for each data type. Performing a sequence comparison between information representing the identified correct communication sequence and information representing the analyzed sequence (the communication sequence identified from the extracted data information 402).

[0078] The displayed analysis sequence diagram includes information based on the differences between sequences identified in the sequence comparison. According to the example shown in FIG. 9, the "information based on the differences" is as follows: The string “error” which means that there is a time in the correct communication sequence that is not in the analysis sequence. A pair of an arrow and the string “no reception” that indicates reception of device2, which is in the correct communication sequence but not in the analysis sequence. A pair of an arrow and the string “no transmission” that indicates transmission of device2, which is in the correct communication sequence but not in the analysis sequence.

[0079] In this way, the special processing identifies the difference between the correct communication sequence and the analysis sequence, and information based on the identified difference is displayed on the analysis sequence diagram, making the analysis easier and reducing the time required for the analysis.

[0080] Although several embodiments of the present invention have been described above, these are merely examples for explaining the present invention, and the scope of the present invention is not limited to these embodiments. The present invention can be implemented in various other forms. For example, any two or more of the above-described embodiments can be combined.

[0081] For example, communication log 55 may be input directly from intermediary device 111 to analysis device 130, or may be input from intermediary device 111 to analysis device 130 via a portable storage medium. In addition, communication log 55 may be input to analysis device 130 by having analysis device 130 read the communication log displayed on intermediary device 111.

[0082] In addition, the special process flag 502 and the special process name 503 of the special process information 158 may be changeable. This is expected to facilitate the handling of an increase or decrease in the number of data types or a change in the regular sequence. [Explanation of symbols]

[0083] 130 Communication log analysis device

Claims

1. An analysis unit and an output unit are provided, The analysis unit acquires a communication log stored in an intermediate device that intermediates communication between devices, the communications log has a log entry for each data frame received by the intermediary device and for each data frame transmitted by the intermediary device; For each data frame, The log entry includes data indicating a time when the intermediary device received the data frame from the device or a time when the intermediary device transmitted the data frame to the device, and a machine code of at least a portion of the data of the data frame; the machine code for the at least some data includes a machine code for data representing a data type; The analysis unit is Identifying items including a time, whether it is transmission or reception, a destination device or a source device, and a data type of data in a data frame corresponding to the log entry from each log entry in the acquired communication log; Identifying one or more subject matters among the identified plurality of subject matters, the subject matter or subjects being one or more subject matters related to the data type of interest; identifying an analysis sequence, the analysis sequence being a communication sequence based on the identified one or more subject matters; The output unit displays a diagram of the analysis sequence. Communication log analysis device.

2. An input section that accepts manual input of analysis target conditions, which are conditions related to the communication to be analyzed Further comprising: The analysis target condition is composed of at least one of a data type, a time range of the communication, whether it is transmission or reception, and a communication between which devices; Each of the identified one or more target items is an item that satisfies the analysis target condition. The communication log analysis device according to claim 1 .

3. The analysis unit determines whether information representing any one or more special processes is associated with the target data type; If the result of the determination is true, the analysis sequence diagram is a diagram obtained by subjecting the communication sequence diagram obtained from the identified one or more subject matters to the associated special processing. The communication log analysis device according to claim 1 .

4. The special treatment is Identifying a correct communication sequence for the target data type from sequence information that is information representing a correct communication sequence for each data type; performing a sequence comparison between information representative of the identified correct communication sequence and information representative of the analyzed sequence; Including, the analysis sequence diagram includes information based on differences between sequences identified in the sequence comparison; The communication log analysis device according to claim 3.

5. the machine language of the at least a portion of the data is a machine language of user data; For each data frame, the user data is the data in the user area of ​​the data frame, including data representing the data type; The communication log analysis device according to claim 1 .

6. The analysis unit is Refer to data type rule information, which is information representing rules for identifying the data type represented by data present at a position dependent on the configuration of the user area; Identifying a data type according to at least one rule represented by the data type rule information; The communication log analysis device according to claim 5.

7. The computer acquires a communication log accumulated in an intermediary device that mediates communication between the devices, the communications log has a log entry for each data frame received by the intermediary device and for each data frame transmitted by the intermediary device; For each data frame, The log entry includes data indicating a time when the intermediary device received the data frame from the device or a time when the intermediary device transmitted the data frame to the device, and a machine code of at least a portion of the data of the data frame; the machine code for the at least some data includes a machine code for data representing a data type; The computer identifies, from each log entry in the acquired communication log, items including a time, whether it is a transmission or reception, a destination device or a source device, and a data type of the data in the data frame corresponding to the log entry; the computer identifies one or more subject matters among the identified plurality of subject matters, the subject matter being one or more subject matters related to the data type of interest; the computer identifying an analysis sequence, the analysis sequence being a communication sequence based on the identified one or more subject matters; a computer displaying a diagram of the analysis sequence; How to analyze communication logs.

8. Acquire a communication log stored in an intermediary device that mediates communication between devices; the communications log has a log entry for each data frame received by the intermediary device and for each data frame transmitted by the intermediary device; For each data frame, The log entry includes data indicating a time when the intermediary device received the data frame from the device or a time when the intermediary device transmitted the data frame to the device, and a machine code of at least a portion of the data of the data frame; the machine code for the at least some data includes a machine code for data representing a data type; Identifying items including a time, whether it is transmission or reception, a destination device or a source device, and a data type of data in a data frame corresponding to the log entry from each log entry in the acquired communication log; Identifying one or more subject matters among the identified plurality of subject matters, the subject matter or subjects being one or more subject matters related to the data type of interest; identifying an analysis sequence, the analysis sequence being a communication sequence based on the identified one or more subject matters; Displaying a diagram of said analysis sequence; A computer program that causes a computer to do something.