Classification device, classification method, and classification program

The classification device addresses the challenge of classifying work operations by considering their similarity, using operation logs to calculate co-occurrence frequency and similarity, and classifying operations into classes, thereby achieving accurate and precise categorization.

JP7687530B2Active Publication Date: 2025-06-03NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024526221
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-10
Publication Date
2025-06-03
Estimated Expiration
2042-06-10

AI Technical Summary

Technical Problem

Conventional technologies face challenges in classifying work operations considering the similarity between operations, leading to inaccurate classification when URL and window styles change.

Method used

A classification device that collects operation logs from information processing devices, calculates co-occurrence frequency and similarity between operations using inner product of attribute values with preset weights, and classifies operations into classes based on this information.

Benefits of technology

Enables accurate classification of work operations considering their similarity, resulting in more precise categorization that reflects the actual business processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007687530000007
    Figure 0007687530000007
  • Figure 0007687530000008
    Figure 0007687530000008
  • Figure 0007687530000009
    Figure 0007687530000009
Patent Text Reader

Abstract

A classification device (10) according to an embodiment collects operation logs of a terminal device (20). The classification device (10) creates, on the basis of the operation logs, information that indicates the frequency at which operations on the terminal device (20) co-occur, and information that indicates similarity, which is the similarity between operations, that is the inner product of weights and attribute values to which the weights are set in advance and are obtained from the operation logs. A classification device (10) classifies, into classes, the operations on the terminal device (20) by using information indicating the co-occurrence frequency and information indicating the similarity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a classification device, a classification method, and a classification program.

Background Art

[0002] In order to effectively improve business in enterprises and the like, it is important to accurately grasp the target business. Persons in charge of business perform a plurality of businesses every day using information terminals such as a PC and a tablet, and the business performed via the information terminal is composed of a plurality of operations. The operations performed on the PC refer to, for example, a series of information input operations (input to a text box, click of a button, etc.) necessary to perform the business.

[0003] In actual business, the operation procedures vary due to various factors such as the person in charge and the content of the order. Although the operation procedures are basically defined by a manual, there may be a deviation from the manual because the work content has changed since the manual was created or the person in charge has performed the work in an original way.

[0004] As a prerequisite for considering business improvement measures, business analysts need to grasp what kind of work is being carried out, how much time is spent, and what procedures (operations) are used. For example, in order to introduce RPA (Robotic Process Automation) and enhance the improvement effect, it is possible to efficiently achieve business improvement by grasping the types and amounts of work performed in the business and introducing RPA from the work types with a large amount of work.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Non-Patent Documents

[0006]

Non-Patent Document 1

[0007] However, in the conventional technology, it may be difficult to classify work considering the similarity between operations.

[0008] For example, Non-Patent Document 4 describes a method of classifying operation logs by operation type, then focusing on the co-occurrence of operations to divide the operation logs into segments, and classifying the divided segments into work units using agglomerative clustering.

[0009] Here, consider a system in which the URL and window style change depending on the case. At this time, for example, an operation such as "press the decision button" is preferably classified as the same work even if the URL and window style change.

[0010] On the other hand, in the method of Non-Patent Document 4, since the similarity between operations is not considered, when the URL and window style change, the operation of "press the decision button" may be classified as different work.

Means for Solving the Problems

[0011] In order to solve the above-described problems and achieve the object, the classification device of the present invention includes a collection unit that collects an operation log of an information processing device, and based on the operation log, information representing the co-occurrence frequency between operations on the information processing device, and the similarity between operations, which is information representing the similarity that is the inner product of an attribute value with a preset weight obtained from the operation log and the weight, and a classification unit that classifies operations on the information processing device into classes using the information representing the co-occurrence frequency and the information representing the similarity.

Effects of the Invention

[0012] According to the present invention, it is possible to classify work in consideration of the similarity between operations.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

[0014] Hereinafter, embodiments of the classification apparatus, classification method, and classification program according to the present application will be described in detail with reference to the drawings. Further, the present invention is not limited to the embodiments described below.

[0015] [Configuration of Classification Apparatus] FIG. 1 is a block diagram showing an example of the configuration of a classification device. As shown in FIG. 1, the classification device 10 is connected to a terminal device 20 via a network.

[0016] The terminal device 20 is an information processing device used by a user. The user is, for example, a person in charge of business. The person in charge of business uses various software such as a business system and general-purpose applications on the terminal device 20, for example.

[0017] Note that the terminal device 20 may be any type of information processing device including client devices such as smartphones, desktop PCs, notebook PCs, and tablet PCs.

[0018] Also, in the example of FIG. 1, the classification device 10 and the terminal device 20 are shown as separate devices, but the terminal device 20 may have some or all of the functions of the classification device 10.

[0019] The terminal device 20 acquires an operation log of the user. For example, the terminal device 20 acquires an operation log including the operation date and time, the operation location, the operation position, etc. at the timing when an operation event occurs. The terminal device 20 transmits the acquired operation log to the classification device 10.

[0020] The classification device 10 includes a communication unit 11, a storage unit 12, and a control unit 13.

[0021] The communication unit 11 is realized by a NIC (Network Interface Card) or the like and controls communication with external devices via a telecommunication line such as a LAN (Local Area Network) and the Internet. For example, the communication unit 11 receives an operation log from the terminal device 20.

[0022] The storage unit 12 stores data and programs necessary for various processes by the control unit 13, and has an operation log storage unit 121 and a similarity storage unit 122. For example, the storage unit 12 is a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk.

[0023] The operation log storage unit 121 stores the operation logs acquired from the terminal device 20.

[0024] FIG. 2 is a diagram showing an example of an operation log. As shown in FIG. 2, the operation log stored in the operation log storage unit 121 includes the operation date and time, user information which is information for identifying the user who performed the operation, application information which is information for identifying the application to be operated, window information which is information regarding the window to be operated, the operation location (objects such as buttons, text boxes, cells, etc.), a captured image of the screen when the operation is performed, and the operation position (coordinates within the screen).

[0025] The classification device 10 receives the operation log from the terminal device 20 and stores the received operation log in the operation log storage unit 121. Note that the timing at which the classification device 10 receives the operation log may be any timing. For example, the classification device 10 may receive the operation log at regular time intervals, or may receive the operation log each time a new operation log is generated.

[0026] The similarity storage unit 122 stores the similarity between the centroid vectors described later. The centroid vectors and the similarity will be described later.

[0027] The control unit 13 has an internal memory for storing programs and required data that define various processing procedures and the like, and executes various processes based on these.

[0028] For example, the control unit 13 includes a collection unit 131, a specification unit 132, a creation unit 133, and a classification unit 134.

[0029] The control unit 13 is an electronic circuit such as a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0030] The collection unit 131 collects the operation logs of the terminal device 20. The terminal device 20 is an example of an information processing device.

[0031] The specifying unit 132 specifies the operation corresponding to the operation log. For example, the specifying unit 132 reads out the operation log table shown in FIG. 2 from the operation log storage unit 121 and adds a column for the operation content.

[0032] The specifying unit 132 adds information obtained by combining window information and the operation location to the column for the operation content, and stores it in the operation log storage unit 121.

[0033] For example, the specifying unit 132 adds information such as "Web page 1 + button e" and "Web page 1 + text box b" to the column for the operation content.

[0034] Furthermore, for operations with the same operation content, the specifying unit 132 specifies that they are the same operation. The specifying unit 132 can specify the type of operation.

[0035] To explain with a specific example, when there are a plurality of operations with the operation content of "Web page 1 + button a", the specifying unit 12 specifies that these operations are the same operation.

[0036] The creation unit 133 creates information representing the co-occurrence frequency between operations on the terminal device 20 and information representing the similarity between operations, based on the operation logs.

[0037] For example, the creation unit 133 creates a co-occurrence matrix having the same number of rows and columns as the number of operations on the terminal device 20 and having the co-occurrence frequency between operations as elements, and a similarity matrix having the same number of rows and columns as the number of operations and having the similarity between operations as elements.

[0038] FIG. 5 is a diagram showing an example of a co-occurrence matrix. The creation unit 133 reads operations from the operation log storage unit 121 in chronological order (in the order of earlier operation date and time), counts the n (where n is an integer of 1 or more) operations before and after each operation, and creates a co-occurrence matrix for each operation. Each row of the operation log storage unit 121 corresponds to an operation.

[0039] At this time, when the operations before and after occur within the same window (the web page and file are common), the creation unit 133 may count them with weights. For example, the creation unit 133 counts an operation on a different web page as 1, and counts an operation on the same web page as 0.5.

[0040] FIG. 6 is a diagram showing an example of a similarity matrix. Here, each of a, b, c, d, and e is an operation identified as being the same by the specific unit 132.

[0041] Therefore, for example, there may be a plurality of operation logs corresponding to each operation (for example, operation a) in the operation log storage unit 121.

[0042] As shown in FIG. 6, the similarity matrix is represented as a square matrix in which each operation corresponds to rows and columns.

[0043] Each component of the similarity matrix is the similarity between operations. The similarity is a continuous value from 0 to 1. In the embodiment, by considering such a similarity, compared with the case where the relationship between operations is represented by a binary value (1 (identical) or 0 (non-identical)), the operations can be classified more appropriately considering the similarity.

[0044] Note that the greater the similarity, the more similar the operations are. If the similarity between two operations is 1, the two operations are regarded as identical.

[0045] The similarity of operations may be given in advance by an administrator or the like. Further, the similarity may be calculated by the creation unit 133 based on the similarity of each item in the operation log storage unit 121.

[0046] In the embodiment, the creation unit 133 creates information representing the similarity between operations, which is the inner product of the attribute value with a preset weight obtained from the operation log and the weight, based on the operation log. Hereinafter, two types of similarity calculation methods using the attribute value and the weight will be described.

[0047] (First similarity calculation method) The creation unit 133 can create information representing the similarity between operations, which is the inner product of the attribute value output from the OS of the terminal device 20 and the weight.

[0048] FIG. 3 is a diagram showing an example of attributes and weights output by the OS. As shown in FIG. 3, general attributes output from the OS include window title, file path, window handle, application name, application path, mouse event, and keyboard event. The attribute values of these attributes are included in the operation log.

[0049] Also, a weight is set for each attribute. The attribute value between operation i and operation j is σ xij as shown. However, x is an index for identifying the attribute. In the example of FIG. 3, x = 1, 2, 3, 4, 5, 6, 7. However, the total weight is 1 or less, and each weight is 0 or more.

[0050] The weight is a parameter for considering the contribution degree of each attribute to the similarity. The greater the contribution degree to the similarity, the greater the weight.

[0051] For example, the attribute value σ of the window title between operation i and operation j 1ijIt takes 0 if the window is different between operation i and operation j, and takes 1 if the window is the same between operation i and operation j. The attribute value takes a value in the range from 0 to 1, and the larger the attribute value, the more similar the operations are to each other.

[0052] The creation unit 133 calculates the inner product of the attribute value and the weight as the similarity s ij between operation i and operation j. In the example of FIG. 3, the creation unit 133 calculates s ij = w 1 * σ 1ij + w 2 * σ 2ij +…+ w 7 * σ 7ij as follows.

[0053] (Second similarity calculation method) The creation unit 133 can create information representing the similarity, which is the inner product of the attribute value related to the application in which the operation is performed and the weight, as the similarity between operations.

[0054] FIG. 4 is a diagram showing an example of attributes and weights related to an application. In the example of FIG. 4, for each attribute, the applications that can be obtained are defined. However, it is assumed that the total weight is 1 or less and each weight is 0 or more.

[0055] For attributes that can be obtained from all applications, the applications that can be obtained are set to be common.

[0056] For example, the attributes that can be obtained from browser-based applications are application type, window title, file path, operation type, application path, URL, operation target, and input value.

[0057] In the example of FIG. 4, when the applications of the operation targets of operation i and operation j are both browser-based, the creation unit 133 calculates the similarity as s ij = w 1 * σ 1ij + w 2 * σ 2ij+…+w 8 *σ 8ij Calculate as follows.

[0058] In the example of FIG. 4, when the applications to be operated for operation i and operation j are both Excel, the creation unit 133 calculates the similarity as s ij =w 1 *σ 1ij +w 2 *σ 2ij +…+w 5 *σ 5ij +w 8 *σ 8ij +w 9 *σ 9ij +w 10 *σ 10ij Calculate as follows.

[0059] Furthermore, the creation unit 133 creates a co-occurrence similarity matrix from the co-occurrence matrix and the similarity matrix.

[0060] Here, the co-occurrence matrix C is represented as in equation (1). For example, c ij is the co-occurrence frequency of operation i and operation j. Note that the creation unit 133 can create the co-occurrence matrix by the method described in Non-Patent Document 4.

[0061]

Equation

[0062] Also, the similarity matrix S is represented as in equation (2). For example, s ij is the similarity between operation i and operation j.

[0063]

Equation

[0064] In this case, n is the number of operations. Then, the creation unit 133 calculates the components of the co-occurrence similarity matrix according to equation (3). However, i, j, and k are indices for specifying the components of the matrix.

[0065]

Number

[0066] FIG. 7 is a diagram for explaining a method of creating a similarity co-occurrence matrix. The creation unit 133 applies the method of equation (3) to the co-occurrence matrix of FIG. 5 and the similarity matrix of FIG. 6, and calculates the components of the row corresponding to operation a as shown in FIG. 7.

[0067] In the example of FIG. 7, the operation vector of operation a is [0.4, 1.6, 2, 0.7].

[0068] In this way, the creation unit 133 creates an operation vector for each operation using the similarity co-occurrence matrix.

[0069] Since the length of the operation vector is equal to the number of operation types, the higher the number of operation types, the higher the calculation cost. Therefore, the creation unit 133 may use a dimensionality reduction method such as SVD (Single Value Decomposition) to perform dimensionality reduction on each operation vector. For example, the creation unit 133 compresses a 1000-dimensional operation vector to 50 dimensions by SVD.

[0070] The classification unit 134 classifies the operations on the terminal device 20 into classes using the information representing the co-occurrence frequency and the information representing the similarity. For example, the classification unit 134 classifies the operations on the terminal device 20 into classes using the co-occurrence matrix and the similarity matrix.

[0071] Also, the classification unit 134 classifies the operations on the terminal device 20 into classes using the similarity co-occurrence matrix obtained by adding the product of the co-occurrence matrix and the similarity matrix to the co-occurrence matrix.

[0072] Specifically, the classification unit 134 obtains each row of the similarity co-occurrence matrix as an operation vector, determines a split point in the sequence of operations based on the operation log, and classifies the set of operations split at the split point into classes based on the change in the similarity between the centroids of the operation vectors of a plurality of operations before and after the split point in the sequence.

[0073] First, the classification unit 134 arranges the operations in chronological order. The sequence obtained here is called an operation sequence. Also, each operation in the operation sequence is identified by a number (for example, operation 1, operation i, operation n).

[0074] Then, the classification unit 134 sets the operation i, which is the i-th operation in the operation sequence, as the operation to be judged for splitting (split point), and acquires m operation sequences up to operation i (operation (i - m), operation (i - m + 1), …, operation i) and m operation sequences after operation i (operation (i + 1), operation (i + 2), …, operation (i + m + 1)).

[0075] The m operation sequences up to operation i are set as operation sequence A. Also, the m operation sequences after operation i are set as operation sequence B.

[0076] The classification unit 134 acquires the operation vectors of each operation included in operation sequence A and calculates the centroid vector of the acquired operation vectors.

[0077] FIG. 8 is a diagram showing an example of an operation sequence. In the example of FIG. 8, it is assumed that a split point is defined between the operation sequence bdefg (operation sequence A) and the operation sequence opqrs (operation sequence B).

[0078] At this time, the classification unit 134 calculates the centroid (centroid vector A) of operation sequence A as shown in Equation (4).

[0079]

Equation

[0080] Also, the classification unit 134 calculates the centroid (centroid vector B) of operation sequence B as shown in Equation (5).

[0081]

Equation

[0082] However, m is the number of operation vectors, and in the examples of equations (4) and (5), m = 5. Note that the classification unit 134 may calculate the sum vector instead of the centroid vector.

[0083] Furthermore, the classification unit 134 calculates the similarity between the calculated centroid vectors as shown in equation (6), and stores the calculated similarity in the similarity storage unit 122. Here, |V| is the dimension number of the centroid vector.

[0084]

Number

[0085] Similarly, the classification unit 134 calculates the similarity between the centroid vectors for each division point of the operation sequence. Note that the similarity may be the cosine similarity shown in equation (6), or may be the Euclidean distance or the like.

[0086] FIG. 9 is a diagram for explaining the change in the similarity between centroids. The line in FIG. 9 represents the change in the similarity between the centroid vectors for each division point.

[0087] The classification unit 134 divides the operation sequence at a division point where the difference in similarity is equal to or greater than the threshold value. The arrows in FIG. 9 represent monotonic decrease and monotonic increase. The classification unit 134 divides the operation sequence at the division point corresponding to the minimum point if (similarity at the start position of monotonic decrease - similarity at the minimum point) + (similarity at the end position of monotonic increase - similarity at the minimum point) is equal to or greater than the threshold value.

[0088] In the example of FIG. 9, the classification unit 134 obtains the operation sequences abcdefg, opqrstuvwxyz, and hijklmn by division. Thus, the operation sequences obtained by division are called an operation set.

[0089] The classification unit 134 classifies the operation set into classes. First, the classification unit 134 performs classification in descending order of the types of operations included.

[0090] FIG. 10 and FIG. 11 are diagrams showing an example of classification results. In the example of FIG. 10, as shown in FIG. 11, the operation set can be divided according to the number of types of operations included.

[0091] First, the classification unit 134 classifies the operation set abcdefgabcdefefg, which has the largest number of types of operations included, into class 1.

[0092] Then, for the operation set opqrssutxwxyz, which has the second largest number of types of operations included, since the number of operations in common with the classified operation set abcdefgabcdefefg is 0 and is below the threshold value (for example, 5), the classification unit 134 classifies the operation set opqrssutxwxyz into class 2, which is a new class.

[0093] Also, for the operation set abcdefg, since the number of operations in common with the classified operation set abcdefgabcdefefg is 5 and is above the threshold value, the classification unit 134 classifies the operation set abcdefg into class 1.

[0094] [Processing Procedure of Classification Device] The flow of each process by the classification device 10 will be described using a flowchart.

[0095] FIG. 12 is a flowchart showing the flow of the process of collecting operation logs. As shown in FIG. 12, the classification device 10 acquires operation logs from the PC terminal (terminal device 20) while the user of the PC terminal does not stop the process or shut down the PC terminal (step S101, No) (step S102).

[0096] Also, when the user of the PC terminal stops the process or shuts down the PC terminal (step S101, Yes), the classification device 10 ends the process of collecting operation logs.

[0097] FIG. 13 is a flowchart showing the flow of a process for creating a similarity matrix. As shown in FIG. 13, until the classification device 10 substitutes similarity degrees for all components of the similarity matrix (step S201, No), it substitutes the operation - to - operation similarity degree for each component of the similarity matrix (step S202).

[0098] Here, the classification device 10 can calculate the similarity degree by the above - mentioned first similarity calculation method or second similarity calculation method.

[0099] When the classification device 10 has finished substituting similarity degrees for all components of the similarity matrix (step S201, Yes), it ends the process of creating the similarity matrix.

[0100] FIG. 14 is a flowchart showing the flow of a process for creating a co - occurrence matrix. As shown in FIG. 14, until it targets all operations (step S301, No), the classification device 10 targets operations in chronological order, counts the n operations before and after, and reflects them in the co - occurrence matrix (step S302).

[0101] When the reflection of the co - occurrence matrix has been completed for all operations (step S301, Yes), the classification device 10 ends the process of creating the co - occurrence matrix.

[0102] FIG. 15 is a flowchart showing the flow of a process for creating a similarity co - occurrence matrix. As shown in FIG. 15, until it targets all components of the co - occurrence matrix (step S401, No), the classification device 10 creates a similarity co - occurrence matrix from the similarity matrix and the co - occurrence matrix (step S402).

[0103] When the classification device 10 has finished targeting all components of the co - occurrence matrix (step S401, Yes), it generates an operation vector for each operation from the similarity co - occurrence matrix (step S403).

[0104] FIG. 16 is a flowchart showing the flow of a process for calculating the similarity of the center-of-gravity vectors. As shown in FIG. 16, until all operations are targeted (step S501, No), the classification device 10 targets operations in chronological order and generates the center-of-gravity vectors of the first m operations including the target operation (step S502).

[0105] Subsequently, the classification device 10 generates the center-of-gravity vectors of m operations starting from the operation next to the target operation (step S503). Then, the classification device 10 calculates the similarity between the two center-of-gravity vectors and stores it in the similarity storage unit 122 (step S504).

[0106] When the classification device 10 has targeted all operations (step S501, Yes), the process of calculating the similarity of the center-of-gravity vectors ends.

[0107] FIG. 17 is a flowchart showing the flow of a process for dividing an operation sequence. As shown in FIG. 17, until all operations are targeted (step S601, No), the classification device 10 detects the start of a decrease in the similarity between the center-of-gravity vectors arranged in chronological order (step S602).

[0108] Here, the classification device 10 detects the next start of a decrease (= the end of an increase) and the local minimum point therebetween starting from the start of the decrease in similarity (step S603).

[0109] The classification device 10 calculates the depth (d) = the difference between the local minimum point and the start of the decrease in similarity + the difference between the local minimum point and the end of the increase (step S604).

[0110] If the calculated depth is greater than or equal to the threshold value (step S605, Yes), the classification device 10 divides between the target operation and the next operation (step S606). If the calculated depth is less than the threshold value (step S605, No), the classification device 10 returns to step S601.

[0111] When the classification device 10 has targeted all operations (step S601, Yes), the process of dividing the operation sequence ends.

[0112] FIG. 18 is a flowchart showing the flow of a process for classifying operations into classes. As shown in FIG. 18, until the classification device 10 targets all operation sequences (step S701, No), it determines the target operation sequence (step S702).

[0113] Here, if there is no classified operation sequence (step S703, No), the classification device 10 classifies the target operation sequence into a new class (step S707).

[0114] If there is a classified operation sequence (step S703, Yes), the classification device 10 calculates the number of common operation types between the target operation sequence and the operation sequences within each class (step S704).

[0115] Then, when there is a class where the number of common operation types is equal to or greater than the threshold and the number of common operation types is the largest (step S705, Yes), the classification device 10 classifies the target operation sequence into the class that satisfies the conditions (step S706).

[0116] When there is no class where the number of common operation types is equal to or greater than the threshold and the number of common operation types is the largest (step S705, No), the classification device 10 classifies the target operation sequence into a new class with the conditions (step S707).

[0117] When the classification device 10 has finished targeting all operation sequences (step S701, Yes), it ends the process of dividing the operation sequences.

[0118] [Effects of the Embodiment] As described above, the classification device 10 of the embodiment includes a collection unit 131, a creation unit 133, and a classification unit 134. The collection unit 131 collects the operation logs of the terminal device 20. The creation unit 133 creates information representing the co-occurrence frequency between operations on the terminal device 20 based on the operation logs, and information representing the similarity between operations, which is the similarity represented by the inner product of the attribute value with a preset weight and the weight obtained from the operation logs. The classification unit 134 classifies the operations on the terminal device 20 into classes using the information representing the co-occurrence frequency and the information representing the similarity.

[0119] In this way, the classification device 10 can classify work considering the similarity between operations. As a result, the work can be classified in a form closer to the actual state of the business.

[0120] [Regarding the System Configuration of the Embodiment] Each component of the classification device 10 shown in FIG. 1 is functionally conceptual and does not necessarily have to be physically configured as shown in the figure. That is, the specific form of the dispersion and integration of the functions of the classification device 10 is not limited to that shown in the figure, and all or part of it can be functionally or physically dispersed or integrated in any unit according to various loads, usage situations, etc.

[0121] Also, all or any part of each process performed in the classification device 10 may be realized by a program analyzed and executed by a CPU and the CPU. Also, each process performed in the classification device 10 may be realized as hardware by wired logic.

[0122] Also, among the processes described in the embodiment, all or part of the processes described as being automatically performed can be manually performed. Or, all or part of the processes described as being manually performed can be automatically performed by a known method. In addition, the above-described and illustrated process procedures, control procedures, specific names, and information including various data and parameters can be appropriately changed unless otherwise specified.

[0123] [Program] FIG. 19 is a diagram showing an example of a computer that executes a classification program. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0124] The memory 1010 includes a ROM 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0125] The hard disk drive 1090 stores, for example, an OS (Operating System) 1091, an application program 1092, a program module 1093, and program data 1094. That is, the program that defines each process of the classification device 10 is implemented as a program module 1093 in which code executable by the computer 1000 is described. The program module 1093 is stored in the hard disk drive 1090, for example. For example, a program module 1093 for executing the same processes as the functional configuration in the classification device 10 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).

[0126] In addition, the setting data used in the processing of the above-described embodiment is stored, for example, in the memory 1010 or the hard disk drive 1090 as program data 1094. Then, the CPU 1020 reads out and executes the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed.

[0127] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (such as a LAN (Local Area Network), WAN (Wide Area Network), etc.). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.

[0128] As described above, the embodiments to which the invention made by the present inventor is applied have been described, but the present invention is not limited by the description and drawings that form a part of the disclosure of the present invention according to this embodiment. That is, all other embodiments, examples, operation techniques, etc. made by those skilled in the art based on this embodiment are included in the scope of the present invention.

Explanation of Reference Numerals

[0129] 10 Classification device 11 Communication unit 12 Storage unit 13 Control unit 20 Terminal device 121 Operation log storage unit 122 Similarity storage unit 131 Collection unit 132 Identification unit 133 Creation unit 134 Classification unit

Claims

1. A collecting unit that collects operation logs of an information processing device, Based on the operation logs, an information representing the co-occurrence frequency between operations on the information processing device, and an information representing the similarity between the operations, which is an inner product of an attribute value with a preset weight obtained from the operation logs and the weight, and a creating unit that creates information representing the similarity, A classification unit that classifies operations on the information processing device into classes using the information representing the co-occurrence frequency and the information representing the similarity, A classification device characterized by comprising the above.

2. The classification device according to claim 1, wherein the creating unit creates information representing the similarity between the operations, which is an inner product of the attribute value output from the OS of the information processing device and the weight.

3. The classification device according to claim 1, wherein the creating unit creates information representing the similarity between the operations, which is an inner product of the attribute value related to the application on which the operation is performed and the weight.

4. A classification method executed by a classification device, A collecting step of collecting operation logs of an information processing device, Based on the operation logs, a creating step of creating information representing the co-occurrence frequency between operations on the information processing device, and information representing the similarity between the operations, which is an inner product of an attribute value with a preset weight obtained from the operation logs and the weight, and information representing the similarity, A classification step of classifying operations on the information processing device into classes using the information representing the co-occurrence frequency and the information representing the similarity, A classification method characterized by including the above.

5. A collecting step of collecting operation logs of an information processing device, Based on the operation logs, a creating step of creating information representing the co-occurrence frequency between operations on the information processing device, and information representing the similarity between the operations, which is an inner product of an attribute value with a preset weight obtained from the operation logs and the weight, and information representing the similarity, A classification step of classifying operations on the information processing device into classes using the information representing the co-occurrence frequency and the information representing the similarity, A classification program characterized by causing a computer to execute the above.

Citation Information

Patent Citations

  • Search word clustering device, method, program and recording medium

    JP2009031931A

  • Information processing apparatus and information processing program

    JP2015106340A

  • Business flow specification regeneration method

    JP2017045080A

  • Information processing terminal, information processing method, and information processing program

    JP2020095574A

  • Information processing apparatus, information processing method, and computer-readable medium

    US20150154718A1