Abnormal Detection Method and Abnormal Detection Program

By specifying a normal range based on the transition situations of both a primary and a secondary access target, the method addresses the challenge of low access frequency data, enhancing the accuracy of anomaly detection in access targets with insufficient data.

JP7691620B2Active Publication Date: 2025-06-12FUJITSU LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021149861
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-15
Publication Date
2025-06-12
Estimated Expiration
2041-09-15

AI Technical Summary

Technical Problem

Existing anomaly detection methods struggle with accurate detection in access targets with low access frequencies, as they lack sufficient data to set reliable normal ranges for response times.

Method used

The method involves specifying a first transition situation for an access target with insufficient response time data, identifying a second access target with a similar transition situation, and setting a normal range based on both access targets. This allows for accurate anomaly detection when a new access occurs.

Benefits of technology

This approach enables accurate anomaly detection even for access targets with low access frequencies by securing sufficient access logs for setting normal ranges, thereby improving determination accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691620000001
    Figure 0007691620000001
  • Figure 0007691620000002
    Figure 0007691620000002
  • Figure 0007691620000003
    Figure 0007691620000003
Patent Text Reader

Abstract

To provide an abnormality detection method and an abnormality detection program which can accurately perform anomaly detection.SOLUTION: An abnormality detection method specifies a first transition state for a response time of a first access object when it is determined that the number of pieces of response time information for determining a normal range used when abnormality for the response time of the first access object is detected is lower than a predetermined value, specifies a second access object in which the transition state for the response time is similar to the first transition state, sets the normal range from the first transition state and the transition state corresponding to the second access object, and detects abnormality for a response time of a new access by using the normal range when the new access for the first access object is generated.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an abnormality detection method and an abnormality detection program.

Background Art

[0002] For example, an operator (hereinafter also simply referred to as an operator) who provides services to users constructs and operates a business system for providing services. Specifically, the operator operates a business system for providing services (hereinafter also referred to as web services) via a network such as the Internet.

[0003] In the business system as described above, the operator needs to quickly detect the occurrence of events (for example, concentration of access, equipment failure, etc.) that can cause response delays from the business system in order to prevent, for example, deterioration of the quality of services provided to users. Therefore, the operator performs anomaly detection, which is a method of detecting the occurrence of a failure by analyzing the past response times from the business system and modeling the normal state. Specifically, the operator detects a response whose response time is abnormal (a response whose response time deviates from the normal range) by using, for example, the normal range of the response time automatically set from the past response times (hereinafter also simply referred to as the normal range) (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Here, in anomaly detection as described above, for example, for each access target accessed by a user, a normal range is set from statistical values of response times when accessing each access target.

[0006] However, when there is an access target with a low access frequency by a user, the operator may not be able to sufficiently secure data (for example, access logs) used for setting the normal range for that access target, and may not be able to set a normal range that enables accurate anomaly detection. That is, the operator may not be able to perform accurate anomaly detection depending on, for example, the access frequency for each access target.

[0007] Therefore, in one aspect, an object of the present invention is to provide an anomaly detection method and an anomaly detection program that enable accurate anomaly detection.

Means for Solving the Problems

[0008] In one aspect of the embodiment, when it is determined that the number of response time information used to determine the normal range for anomaly detection of the response time of the first access target is less than a predetermined value, the first transition situation of the response time of the first access target is specified, a second access target whose transition situation of the response time is similar to the first transition situation is specified, a normal range is set from the first transition situation and the transition situation corresponding to the second access target, and when a new access to the first access target occurs, the computer executes a process of performing anomaly detection on the response time of the new access by using the normal range.

Effects of the Invention

[0009] According to one aspect, it becomes possible to perform accurate anomaly detection.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Embodiments for Carrying Out the Invention

[0011] [Configuration of the Information Processing System in the First Embodiment] First, the configuration of the information processing system 10 will be described. FIG. 1 is a diagram for explaining the configuration of the information processing system 10.

[0012] As shown in FIG. 1, the information processing system 10 includes, for example, a business system 2 composed of one or more Web servers that provide web services to users, and user terminals 3a, 3b, and 3c that each user uses when accessing the business system 2. The user terminals 3a, 3b, and 3c are, for example, mobile terminals such as PCs (Personal Computers) or smartphones owned by each user. Hereinafter, the user terminals 3a, 3b, and 3c are collectively referred to simply as the user terminal 3. Also, hereinafter, the case where the information processing system 10 has three user terminals 3 will be described, but the information processing system 10 may have a number of user terminals 3 other than three.

[0013] Specifically, for example, when a user accesses the business system 2 via the user terminal 3, the business system 2 executes a process corresponding to the access target (e.g., URL (Uniform Resource Locator)) to which the access was made, and transmits the execution result (response) to the user terminal 3. Then, as shown in FIG. 1, the business system 2 accumulates, for example, an access log LG regarding the access from the user terminal 3 to the business system 2 in the storage device 2a. Hereinafter, the time from when the user terminal 3 accesses the business system 2 until a response is received is referred to as the response time.

[0014] Further, as shown in FIG. 1, the information processing system 10 has, for example, an information processing apparatus 1 that performs anomaly detection using the access log LG stored in the storage device 2a. The information processing apparatus 1 is, for example, one or more physical machines or virtual machines.

[0015] Specifically, for example, for each access target to which a user makes an access, the information processing apparatus 1 automatically sets a normal range corresponding to each access target from the statistical value of the response time included in the access log LG generated when an access is made to each access target. Then, the information processing apparatus 1 detects, for example, an access target with a response time longer than usual or an access target with a response time shorter than usual by using the set normal range as a criterion for anomaly detection.

[0016] Here, for example, when there is an access target with a low access frequency by a user, the information processing apparatus 1 cannot secure enough access log LG for setting the normal range and cannot set a normal range that enables accurate anomaly detection.

[0017] Specifically, for example, even for an access target whose response time should be included in the normal range from 2 seconds to 10 seconds, if the access log LG with a response time between 6 seconds and 10 seconds is generated at a temporarily lower frequency (for example, a lower frequency than the access log LG with a response time between 2 seconds and 6 seconds), the information processing apparatus 1 may set the range between 2 seconds and 6 seconds as the normal range. Therefore, in this case, the information processing apparatus 1 may detect an access (for example, an access with a response time of 8 seconds) that should be determined to have a response time within the normal range as an abnormal access.

[0018] Also, for example, even if an access target for which the response time between 2 seconds and 10 seconds should be within the normal range, if an access log LG with a response time between 10 seconds and 15 seconds is generated temporarily at a frequency higher than normal (for example, at the same frequency as the access log LG with a response time between 2 seconds and 10 seconds), the information processing apparatus 1 may set the range between 2 seconds and 15 seconds as the normal range. Therefore, in this case, the information processing apparatus 1 may detect an access (for example, an access with a response time of 13 seconds) that should be determined as not being within the normal range as a normal access.

[0019] That is, the information processing apparatus 1 may not be able to accurately perform anomaly detection depending on, for example, the access frequency for each access target.

[0020] Therefore, the information processing apparatus 1 in the present embodiment specifies, for example, the transition situation (hereinafter also referred to as the first transition situation) of the response time of accesses to a specific access target (hereinafter also referred to as the first access target) included in a plurality of access targets. Specifically, the information processing apparatus 1 specifies the first transition situation of the response time of the first access target, for example, when it is determined that the number of response time information used for performing anomaly detection on the response time of the first access target is less than a predetermined value. The response time information is, for example, information indicating the response time when an access is made to each access target.

[0021] Then, the information processing apparatus 1 specifies an access target (hereinafter also referred to as the second access target) among the plurality of access targets whose transition situation of the response time has a predetermined relationship with the first transition situation. Specifically, the information processing apparatus 1 specifies, for example, a second access target among the plurality of access targets whose transition situation of the response time is similar to the first transition situation.

[0022] After that, for example, the information processing apparatus 1 sets a normal range for the access response time from the response times of the accesses to the first access target and the second access target respectively. Then, for example, when a new access to the first access target occurs, the information processing apparatus 1 performs anomaly detection for the response time of the new access by using the normal range.

[0023] That is, when the transition situation of the response time of the access to the first access target and the transition situation of the response time of the access to the second access target are similar in a past predetermined period, it can be determined that the transition situations of the respective response times are likely to be similar at present. Therefore, in this case, it can be determined that the first access target and the second access target are a combination of access targets for which the normal range can be set collectively. Thus, in the information processing apparatus 1 according to the present embodiment, when the transition situation of the response time of the access to the first access target and the transition situation of the response time of the access to the second access target are similar in a past predetermined period, the first access target and the second access target are combined into one access target, and then the normal range is set.

[0024] On the other hand, for example, when the number of response times corresponding to the first access target (that is, the access frequency to the first access target) is sufficiently large, combining the normal range of the first access target and the normal range of the second access target will unnecessarily widen the normal range of the first access target, and may conversely deteriorate the accuracy of anomaly detection. Therefore, in the information processing apparatus 1 according to the present embodiment, when it is determined that the number of response time information corresponding to the first access target is less than a predetermined value, the process of combining the normal range of the first access target and the normal range of the second access target is performed.

[0025] As a result, even when there is an access target with a low access frequency by the user, the information processing apparatus 1 in the present embodiment can sufficiently secure an access log used for setting a normal range for the access target, and can set a normal range that enables accurate anomaly detection. Therefore, the information processing apparatus 1 can improve the determination accuracy of anomaly detection.

[0026] [Hardware Configuration of Information Processing System] Next, the hardware configuration of the information processing system 10 will be described. FIG. 2 is a diagram for explaining the hardware configuration of the information processing apparatus 1.

[0027] As shown in FIG. 2, the information processing apparatus 1 includes a CPU 101 as a processor, a memory 102, an I / O interface 103, and a storage medium 104. Each unit is connected to each other via a bus 105.

[0028] The storage medium 104 has, for example, a program storage area (not shown) for storing a program 110 for performing a process of detecting an access with an abnormal response time (hereinafter also referred to as an abnormality detection process). Further, the storage medium 104 has, for example, an information storage area 130 for storing information used when performing the abnormality detection process. Note that the storage medium 104 may be, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive).

[0029] The CPU 101 executes the program 110 loaded from the storage medium 104 to the memory 102 to perform the abnormality detection process.

[0030] The I / O interface 103 is, for example, an interface device such as a network interface card, and can access the storage device 2a via a network such as the Internet.

[0031] [Functions of Information Processing System] Next, the functions of the information processing system 10 will be described. FIG. 3 is a block diagram of the functions of the information processing apparatus 1.

[0032] As shown in FIG. 3, the information processing apparatus 1 realizes various functions including a situation specifying unit 111, a target specifying unit 112, a range setting unit 113, a group dividing unit 114, an abnormality detecting unit 115, and a result output unit 116 by the organic cooperation of hardware such as a CPU 101 and a memory 102 and a program 110.

[0033] Further, the information processing apparatus 1 stores, for example, feature amount information 131 and normal range information 132 in the information storage area 130.

[0034] The situation specifying unit 111 specifies, for example, a first transition situation regarding the response time for a first access target included in a plurality of access targets.

[0035] Specifically, the situation specifying unit 111 acquires, for example, the access log LG generated in a predetermined past period (hereinafter also referred to as the first period) among the access logs LG stored in the storage device 2a. Then, the situation specifying unit 111 specifies, for example, the first transition situation regarding the response time included in each of the acquired access logs LG.

[0036] More specifically, the situation specifying unit 111 specifies the first transition situation regarding the response time of the first access target when it is determined that the number of response time information corresponding to the first access target is less than a predetermined value.

[0037] The target specifying unit 112 specifies, for example, a second access target among a plurality of access targets whose transition situation of the response time has a predetermined relationship with the first transition situation.

[0038] Specifically, the target specifying unit 112 specifies, for example, a second access target among a plurality of access targets whose transition situation of the response time in the first period is similar to the first transition situation.

[0039] The range setting unit 113 sets the normal range of the response time for access to either the first access target or the second access target, for example.

[0040] Specifically, the range setting unit 113 sets the normal range of the response time for access to the first access target, for example, by using the average and standard deviation of the response times for access to the first access target and the second access target.

[0041] When the size of the normal range set by the range setting unit 113 is equal to or greater than a predetermined value, for example, the group division unit 114 divides the response time for access to either the first access target or the second access target into a plurality of groups by using the correlation information between the first access target and the second access target. Then, the range setting unit 113 re-sets the normal range for each of the plurality of groups divided by the group division unit 114.

[0042] Specifically, the group division unit 114 divides the response time for access to either the first access target or the second access target, for example, according to the size of the data size transmitted and received in association with the access to either the first access target or the second access target. Also, the group division unit 114 divides the response time for access to either the first access target or the second access target, for example, for each user who has accessed either the first access target or the second access target.

[0043] The abnormality detection unit 115 performs abnormality detection on the response time for access to either the first access target or the second access target, for example, by using the normal range set by the range setting unit 113.

[0044] Specifically, when a new access occurs to either the first access target or the second access target, for example, the abnormality detection unit 115 performs abnormality detection (anomaly detection) on the response time of the new access by using the normal range set by the range setting unit 113.

[0045] The result output unit 116 outputs, for example, the detection result by the abnormality detection unit 115 to an administrator terminal (not shown). The administrator terminal is, for example, a terminal that can be browsed by an administrator (hereinafter, also simply referred to as an administrator) who manages the business system 2.

[0046] [Outline of the First Embodiment] Next, the outline of the first embodiment will be described. FIG. 4 is a flowchart for explaining the outline of the abnormality detection process in the first embodiment.

[0047] As shown in FIG. 4, the information processing apparatus 1 waits, for example, until the processing start timing (NO in S11). The processing start timing is, for example, a timing preset by the operator.

[0048] When the processing start timing arrives (YES in S11), the information processing apparatus 1 specifies, for example, a first transition state regarding the response time of access to a first access target included in a plurality of access targets (S12).

[0049] Specifically, when it is determined that the number of response time information corresponding to the first access target is less than a predetermined value, for example, the situation specifying unit 111 specifies a first transition state regarding the response time of the first access target.

[0050] Subsequently, the information processing apparatus 1 specifies, for example, a second access target among a plurality of access targets, whose transition state of the access response time has a predetermined relationship with the first transition state (S13).

[0051] Thereafter, the information processing apparatus 1 sets a normal range regarding the response time of access to the first access target from the response times of access to the first access target and the second access target (S14).

[0052] Then, when a new access occurs to either the first access target or the second access target, for example, the information processing apparatus 1 performs anomaly detection on the response time of the new access that has occurred by using the normal range set in the process of S14 (S15).

[0053] As a result, even when there is an access target with a low access frequency by the user in the information processing apparatus 1 in the present embodiment, it becomes possible to sufficiently secure an access log used for setting the normal range for that access target, and it becomes possible to set a normal range that enables accurate anomaly detection. Therefore, the information processing apparatus 1 can improve the determination accuracy of anomaly detection. Hereinafter, a specific example of the first embodiment will be described.

[0054] [Specific Example of the First Embodiment] Figs. 5 to 7 are graphs for explaining a specific example of the first embodiment. The horizontal axis and the vertical axis in the graphs shown in Figs. 5 to 7 respectively correspond to the generation time of the access log LG and the response time to the business system 2. And in Figs. 5 to 7, there are distributed points (circular points) indicating the response time when accessing URL11a, points (star-shaped points) indicating the response time when accessing URL11b, points (triangular points) indicating the response time when accessing URL11c, and points (quadrilateral points) indicating the response time when accessing URL11d.

[0055] Hereinafter, it will be described on the assumption that each URL of the access target includes a function name (such as search, list display, and download, etc.) and an operation target (such as user name, folder name, and file name, etc.) performed in response to the access to each URL.

[0056] For example, when it is determined from the transition status of the points corresponding to each URL shown in FIG. 5 that the transition status of the point corresponding to URL11a is similar to the transition status of the point corresponding to URL11b, as shown in FIG. 6, the information processing apparatus 1 performs clustering so that the point corresponding to URL11a and the point corresponding to URL11b belong to cluster CA (S12, S13).

[0057] Further, for example, when the information processing apparatus 1 determines from the transition status of the points corresponding to each URL shown in FIG. 5 that the transition status of the point corresponding to URL11c is not similar to the transition status of the points corresponding to other URLs, as shown in FIG. 6, the information processing apparatus 1 performs clustering so that only the point corresponding to URL11c belongs to cluster CB (S12, S13).

[0058] Furthermore, for example, when the information processing apparatus 1 determines from the transition status of the points corresponding to each URL shown in FIG. 5 that the transition status of the point corresponding to URL11d is not similar to the transition status of the points corresponding to other URLs, as shown in FIG. 6, the information processing apparatus 1 performs clustering so that only the point corresponding to URL11d belongs to cluster CC (S12, S13).

[0059] Then, for example, for each of cluster CA, cluster CB, and cluster CC, the information processing apparatus 1 sets a normal range corresponding to the points included in each cluster. Specifically, as shown in FIG. 7, for example, the information processing apparatus 1 sets the normal range RA from the response times corresponding to the points included in cluster CA, sets the normal range RB from the response times corresponding to the points included in cluster CB, and further sets the normal range RC from the response times corresponding to the points included in cluster CC.

[0060] [Details of the First Embodiment] Next, the details of the first embodiment will be described. FIGS. 8 to 10 are flowchart diagrams for explaining the details of the abnormality detection process in the first embodiment. Also, FIGS. 11 to 19 are diagrams for explaining the details of the abnormality detection process in the first embodiment.

[0061] [Normal Range Setting Process] First, among the abnormality detection processes, the process of setting the normal range (hereinafter also referred to as the normal range setting process) will be described.

[0062] As shown in FIG. 8, the situation identification unit 111 waits, for example, until the range setting timing (NO in S21). The range setting timing may be, for example, a periodic timing such as once a day.

[0063] When the range setting timing is reached (YES in S21), the situation identification unit 111 identifies, for example, one of a plurality of access targets (S22).

[0064] Specifically, the situation identification unit 111 identifies, for example, an access target among a plurality of access targets accessed by the user, in which the number of response time information (that is, the access frequency) is less than a predetermined value.

[0065] The initial value of the predetermined value may be, for example, the number of samples (for example, 100 (pieces)) that can keep the tolerance within 10 (%). Also, the initial value of the predetermined value may be, for example, the number of samples (for example, 400 (pieces)) that can keep the tolerance within 5 (%). Furthermore, the administrator may appropriately change the predetermined value according to the operation status of the information processing apparatus 1, for example.

[0066] Also, in this case, the situation identification unit 111 identifies one unit period (for example, one week) included in a predetermined first period (for example, six months) (S23).

[0067] Specifically, for example, when the first period is six months from January to June, the situation identification unit 111 sequentially identifies the unit period from the first week of January, for example.

[0068] Then, the situation identification unit 111 identifies, for example, a feature amount (hereinafter also simply referred to as a feature amount) indicating the transition in the unit period specified in the process of S23 with respect to the response time for the access target specified in the process of S22 (S24). Thereafter, the situation identification unit 111 stores, for example, the identified feature amount in the information storage area 130 as the feature amount information 131.

[0069] Specifically, the situation identification unit 111 acquires, for example, logs that are generated in the unit period specified in the process of S23 and are generated in association with the access to the access target specified in the process of S22 among the access logs LG stored in the storage device 2a. Then, the situation identification unit 111 calculates, for example, a combination of a plurality of percentile values regarding the response time included in the acquired access log LG as a feature amount.

[0070] Thereby, the situation identification unit 111 can identify a feature amount indicating the transition situation of the response time for the access target specified in the process of S22. Hereinafter, specific examples of the access log LG and the feature amount information 131 will be described.

[0071] [Specific Example of Access Log] First, a specific example of the access log LG will be described. FIG. 11 is a diagram for explaining a specific example of the access log LG.

[0072] The access log LG shown in FIG. 11 has, for example, items of "timestamp" in which the generation time of each log is set, and "data size" in which the data size transmitted and received between the user terminal 3 and the business system 2 is set. Further, the access log LG shown in FIG. 11 has, for example, items of "user IP" in which the IP address of the user (user terminal 3) who accessed the business system 2 is set, "response time" in which the response time for the access to the business system 2 is set, and "URL" in which the URL of the access target accessed by the user is set.

[0073] Specifically, in the example shown in FIG. 11, for the access log LG in the first row, for example, "20210519120001" is set as the "timestamp", "3.0 (MiB)" is set as the "data size", "192.168.3.xxx" is set as the "user IP", "6 (seconds)" is set as the "response time", and " / user3 / folder3 / file3 / search" is set as the "URL".

[0074] Also, in the example shown in FIG. 11, for the access log LG in the second row, for example, "20210519120003" is set as the "timestamp", "12.4 (MiB)" is set as the "data size", "192.168.8.xxx" is set as the "user IP", "2 (seconds)" is set as the "response time", and " / user1 / folder1 / download / " is set as the "URL". Explanation of other information included in FIG. 11 is omitted.

[0075] [Specific Example of Feature Quantity Information (1)] Next, a specific example of the feature quantity information 131 will be described. FIGS. 12 and 13 are diagrams for explaining a specific example of the feature quantity information 131. Specifically, FIG. 12 shows the feature quantity information 131 generated when the URL of the access target specified in the process of S22 is "A" and the unit period specified in the process of S23 is "the first week of January".

[0076] The feature quantity information 131 shown in FIG. 12 has, as items, "URL" in which the URL of the access target specified in the process of S22 is set, and "10% of the first week of January", "50% of the first week of January", and "90% of the first week of January" in which the 10th percentile value, 50th percentile value, and 90th percentile value of the response time included in the access log LG generated in the unit period specified in the process of S23 are set, respectively.

[0077] Specifically, in the feature information 131 shown in FIG. 12, "A" is set as the "URL", "4 (seconds)" is set as "10% in the first week of January", "6 (seconds)" is set as "50% in the first week of January", and "8 (seconds)" is set as "90% in the first week of January".

[0078] Note that the situation identification unit 111 may calculate, as feature amounts, combinations of logarithms of a plurality of percentile values regarding response times included in the access log LG, for example, in the process of S24. Thereby, the situation identification unit 111 can suppress the influence of outliers on the feature amounts even when there is an access log LG (hereinafter also referred to as an outlier) whose response time is extremely slower than other access logs LG. Further, the situation identification unit 111 can suppress the influence of the difference in access frequency on the feature amounts even when there is an access target whose access frequency varies greatly depending on the time zone.

[0079] Returning to FIG. 8, the situation identification unit 111 determines, for example, whether all unit periods have been identified in the process of S23 (S25).

[0080] As a result, if it is determined that not all unit periods have been identified in the process of S23 (NO in S25), the situation identification unit 111 performs the processes after S23 again.

[0081] On the other hand, if it is determined that all unit periods have been identified in the process of S23 (YES in S25), the situation identification unit 111 determines, for example, whether all access targets have been identified in the process of S22 (S26).

[0082] As a result, if it is determined that not all access targets have been identified in the process of S22 (NO in S26), the situation identification unit 111 performs the processes after S22 again.

[0083] On the other hand, when it is determined in the process of S22 that all access targets have been identified (YES in S26), the target identification unit 112 performs clustering of the access targets by using, for example, the feature amount calculated in the process of S24 (S27).

[0084] Specifically, the target identification unit 112 refers to the feature amount information 131 accumulated in the information storage area 130 by repeating the process of S24, for example, and performs clustering of the access targets. Hereinafter, specific examples of the feature amount information 131 referred to in the process of S27 will be described.

[0085] [Specific Example of Feature Amount Information (2)] The feature amount information 131 shown in FIG. 13 further has, as items, for example, the 10th percentile value, 50th percentile value, and 90th percentile value of the response time included in the access log LG generated in the second week of January, namely, "10% of the Second Week of January", "50% of the Second Week of January", and "90% of the Second Week of January", in addition to the items that the feature amount information 131 described in FIG. 9 has. Further, the feature amount information 131 shown in FIG. 13 has, as items, for example, the 10th percentile value, 50th percentile value, and 90th percentile value of the response time included in the access log LG generated in the third week of January, namely, "10% of the Third Week of January", "50% of the Third Week of January", and "90% of the Third Week of January".

[0086] Specifically, in the information of the first row in the feature amount information 131 shown in FIG. 13, for example, "A" is set as "URL", "4 (seconds)" is set as "10% of the First Week of January", "6 (seconds)" is set as "50% of the First Week of January", "8 (seconds)" is set as "90% of the First Week of January", "4 (seconds)" is set as "10% of the Second Week of January", "6 (seconds)" is set as "50% of the Second Week of January", and "8 (seconds)" is set as "90% of the Second Week of January".

[0087] In addition, in the information on the second line of the feature amount information 131 shown in FIG. 13, for example, "B" is set as "URL", "20 (seconds)" is set as "10% in the first week of January", "21 (seconds)" is set as "50% in the first week of January", "22 (seconds)" is set as "90% in the first week of January", "19 (seconds)" is set as "10% in the second week of January", "21 (seconds)" is set as "50% in the second week of January", and "22 (seconds)" is set as "90% in the second week of January". Explanation of other information included in FIG. 13 is omitted.

[0088] Then, in the process of S27, for example, the target specifying unit 112 distributes points with combinations of percentile values of each URL as coordinates in a multi-dimensional space for each URL of the access target. Further, the target specifying unit 112 performs clustering on each point (each point corresponding to the access target URL) distributed in the multi-dimensional space by using, for example, the k-means method using the Euclidean distance.

[0089] That is, it is possible to determine that a combination of access targets with a short Euclidean distance in the multi-dimensional space is a combination of access targets with a similar transition situation regarding the response time of access. Therefore, in the process of S27, the target specifying unit 112 performs clustering on each access target by using, for example, the Euclidean distance in the multi-dimensional space.

[0090] Note that in the process of S27, the target specifying unit 112 may use any one of, for example, the Mahalanobis distance, cosine distance, Manhattan distance, Chebyshev distance, and Minkowski distance instead of the Euclidean distance. Also, in the process of S27, the target specifying unit 112 may use any one of, for example, the Ward method, group average method, single linkage method, and complete linkage method instead of the k-means method.

[0091] Returning to FIG. 9, the range setting unit 113 specifies one cluster that has been clustered in the process of S27 (S31).

[0092] Then, the range setting unit 113 sets the normal range of the response time for each access target included in the cluster specified in the process of S31 (S32).

[0093] Specifically, the range setting unit 113 acquires, for example, logs generated following a predetermined timing included in the first period (i.e., the most recent period shorter than the first period) among the access logs LG stored in the storage device 2a and associated with accesses to the access targets included in the cluster specified in the process of S31. Then, the range setting unit 113 calculates, for example, the average value μ and the standard deviation σ of the response times included in the acquired access log LG. Further, the range setting unit 113 specifies, for example, μ ± 3σ as the normal range.

[0094] Thereafter, the range setting unit 113 stores, for example, the normal range information 132 indicating the set normal range in the information storage area 130. Hereinafter, specific examples of the normal range information 132 will be described.

[0095] [Specific Example (1) of Normal Range Information] FIG. 14, FIG. 18, and FIG. 19 are diagrams for explaining specific examples of the normal range information 132.

[0096] The normal range information 132 shown in FIG. 14 etc. has items of "URL" where the URL of the access target is set, "Range Lower Limit" where the lower limit of the normal range is set, and "Range Upper Limit" where the upper limit of the normal range is set.

[0097] Specifically, in the information on the first line in the normal range information 132 shown in FIG. 14, " / user1 / folder1 / download" and " / user1 / folder1 / upload" are set as "URL", "2 (seconds)" is set as the "Range Lower Limit", and "3 (seconds)" is set as the "Range Upper Limit".

[0098] In addition, in the information on the second line of the normal range information 132 shown in FIG. 14, “ / user2 / folder2 / list” is set as the “URL”, “0 (seconds)” is set as the “lower limit of the range”, and “1 (second)” is set as the “upper limit of the range”. Explanation of other information included in FIG. 14 is omitted.

[0099] That is, the normal range information 132 shown in FIG. 14 indicates that in the process of S27, clustering was performed so that “ / user1 / folder1 / download” and “ / user1 / folder1 / upload” are included in the same cluster.

[0100] Returning to FIG. 9, the group division unit 114 determines, for example, whether the normal range set in the process of S32 satisfies a predetermined condition (S33).

[0101] Specifically, for example, when the upper limit of the response time included in the normal range is a predetermined multiple or more of the lower limit, the group division unit 114 determines that the normal range satisfies a predetermined condition.

[0102] As a result, when it is determined that the normal range set in the process of S32 does not satisfy a predetermined condition (NO in S34), the information processing apparatus 1 performs the processes after S31 again.

[0103] On the other hand, when it is determined that the normal range set in the process of S32 satisfies a predetermined condition (YES in S34), the group division unit 114 divides, for example, the response times corresponding to each of the access targets included in the cluster specified in the process of S31 into a plurality of groups based on the related information of each access target (S35).

[0104] Subsequently, the range setting unit 113 specifies, for example, one of the groups divided in the process of S35 (S36).

[0105] Then, the range setting unit 113 sets a normal range for the response times included in the group specified in the process of S36 (S37). Further, the range setting unit 113 stores, for example, normal range information 132 indicating the set normal range in the information storage area 130.

[0106] After that, the range setting unit 113 determines whether, for example, all the groups divided in the process of S35 have been specified (S38).

[0107] As a result, if it is determined that not all the groups divided in the process of S35 have been specified (NO in S38), the range setting unit 113 performs the processes after S36 again. Hereinafter, a specific example of the processes from S33 to S38 will be described.

[0108] [Specific Example of Processes from S33 to S38] FIGS. 15 to 17 are graphs for explaining a specific example of the processes from S33 to S38. The horizontal axis and the vertical axis in the graphs shown in FIGS. 15 to 17 respectively correspond to the generation time of the access log LG and the response time to the business system 2. And in FIGS. 15 to 17, points (triangular points) indicating the response times when accessing URL11c are distributed.

[0109] For example, as shown in FIG. 15, when the upper limit included in the normal range RB calculated for the cluster CB is twice or more the lower limit, the group division unit 114 divides, for example, as shown in FIG. 16, the response times corresponding to each access target included in the cluster specified in the process of S31 according to the size of the data size transmitted and received with each access to each access target. Specifically, the group division unit 114 divides, for example, as shown in FIG. 16, the points indicating the response times when accessing URL11c into points where the data size transmitted and received with each access to each access target is equal to or greater than the threshold (shaded points) and points where the data size transmitted and received with each access to each access target is less than the threshold (unshaded points).

[0110] Then, as shown in FIG. 17, for example, the range setting unit 113 calculates a correct range RB1 for a group CB1 composed of points (shaded points) where the data size transmitted and received in association with access to each access target is equal to or greater than a threshold value, and a correct range RB2 for the group CB1 composed of points (shaded points) where the data size transmitted and received in association with access to each access target is equal to or greater than a threshold value, respectively.

[0111] Thereby, the range setting unit 113 can set a correct range that further improves the determination accuracy of anomaly detection.

[0112] Note that, for example, each time a normal range is set in the process of S37, the group division unit 114 may perform a determination as to whether or not the set normal range satisfies a predetermined condition (that is, the same process as S33). Then, for example, when it is determined that the normal range set in the process of S37 satisfies a predetermined condition, the range setting unit 113 and the group division unit 114 may, for example, perform the processes from S35 to S38 again.

[0113] Returning to FIG. 9, when it is determined that all the groups divided in the process of S35 have been specified (YES in S38), the range setting unit 113 determines, for example, whether or not all the clusters have been specified in the process of S31 (S39).

[0114] As a result, when it is determined that not all the clusters have been specified in the process of S31 (NO in S39), the range setting unit 113 performs the processes after S31 again.

[0115] On the other hand, when it is determined that all the clusters have been specified in the process of S31 (YES in S39), the information processing apparatus 1 ends the normal range setting process.

[0116] [Specific Example of Normal Range Information (2)] Next, a specific example of the normal range information 132 when the process of S35 is performed based on the data size transmitted and received in association with the access to each access target will be described. FIG. 18 is a diagram for explaining a specific example of the normal range information 132 when the process of S35 is performed based on the data size transmitted and received in association with the access to each access target.

[0117] The normal range information 132 shown in FIG. 18 has, as an item, "data size" in which the data size transmitted and received between the user terminal 3 and the business system 2 is set, in addition to the items that the normal range information 132 described in FIG. 14 has.

[0118] Specifically, in the information on the first line in the normal range information 132 shown in FIG. 18, " / user1 / folder1 / download" and " / user1 / folder1 / upload" are set as "URL", and "-" indicating that no information is set as "data size" is set, "2 (seconds)" is set as "range lower limit", and "3 (seconds)" is set as "range upper limit".

[0119] Also, in the information on the second line in the normal range information 132 shown in FIG. 18, " / user2 / folder2 / list" is set as "URL", "-" is set as "data size", "0 (seconds)" is set as "range lower limit", and "1 (seconds)" is set as "range upper limit".

[0120] Also, in the information on the third line in the normal range information 132 shown in FIG. 18, " / user3 / folder3 / file3 / search" is set as "URL", "0 (MiB) to 128 (MiB)" is set as "data size", "10 (seconds)" is set as "range lower limit", and "50 (seconds)" is set as "range upper limit".

[0121] Furthermore, in the information on the fourth line of the normal range information 132 shown in FIG. 18, “ / user3 / folder3 / file3 / download” is set as the “URL”, “128 (MiB)~” is set as the “data size”, “5 (seconds)” is set as the “lower limit of the range”, and “30 (seconds)” is set as the “upper limit of the range”.

[0122] That is, the normal range information 132 shown in FIG. 18 indicates that in the process of S35, the cluster with the “URL” being “ / user3 / folder3 / file3 / search” was split.

[0123] Note that the group splitting unit 114 may split, for example, the points indicating the response time when accessing the URL11c for each user who accessed each access target in the process of S35. Hereinafter, a specific example of the normal range information 132 when the process of S35 is performed based on the users who accessed each access target will be described.

[0124] [Specific Example of Normal Range Information (3)] FIG. 19 is a diagram for explaining a specific example of the normal range information 132 when the process of S35 is performed based on the users who accessed each access target.

[0125] The normal range information 132 shown in FIG. 19 has, as an item, the “user IP” in which the IP address of the user who accessed the business system 2 is set, in addition to the items that the normal range information 132 described in FIG. 14 has.

[0126] Specifically, in the information on the first line of the normal range information 132 shown in FIG. 19, “ / user1 / folder1 / download” and “ / user1 / folder1 / upload” are set as the “URL”, “-” is set as the “user IP”, “2 (seconds)” is set as the “lower limit of the range”, and “3 (seconds)” is set as the “upper limit of the range”.

[0127] In addition, in the information on the second line in the normal range information 132 shown in FIG. 19, “ / user2 / folder2 / list” is set as the “URL”, “-” is set as the “user IP”, “0 (seconds)” is set as the “lower limit of the range”, and “1 (second)” is set as the “upper limit of the range”.

[0128] In addition, in the information on the third line in the normal range information 132 shown in FIG. 19, “ / user3 / folder3 / file3 / search” is set as the “URL”, “192.168.1.xxx” is set as the “user IP”, “10 (seconds)” is set as the “lower limit of the range”, and “30 (seconds)” is set as the “upper limit of the range”.

[0129] Furthermore, in the information on the fourth line in the normal range information 132 shown in FIG. 19, “ / user3 / folder3 / file3 / download” is set as the “URL”, “192.168.2.xxx” is set as the “user IP”, “20 (seconds)” is set as the “lower limit of the range”, and “50 (seconds)” is set as the “upper limit of the range”.

[0130] That is, the normal range information 132 shown in FIG. 19 indicates that in the process of S35, the cluster with the “URL” being “ / user3 / folder3 / file3 / search” has been split.

[0131] [Main process of anomaly detection processing] Next, the main process of the anomaly detection processing will be described. Hereinafter, a cluster that has not been split in the process of S35 may also be referred to as a group.

[0132] As shown in FIG. 10, the anomaly detection unit 115 waits, for example, until the anomaly detection timing (NO in S41). The anomaly detection timing may be, for example, a periodic timing such as at 1-minute intervals.

[0133] When the abnormal detection timing is reached (YES in S41), the abnormality detection unit 115 acquires, for example, the access log LG output within the target period (S42). The target period is, for example, the period after the previous abnormal detection timing. That is, the abnormality detection unit 115 acquires, for example, the logs in the access log LG stored in the storage device 2a for which abnormal detection has not yet been performed.

[0134] Subsequently, the abnormality detection unit 115 identifies, for example, one of the groups (clusters clustered in the process of S27) divided in the process of S35 (S43).

[0135] Next, the abnormality detection unit 115 identifies, for example, the logs in the access log LG corresponding to the access target included in the group specified in the process of S43 (the access log LG acquired in the process of S42) whose response time is not within the normal range (S44).

[0136] Then, the abnormality detection unit 115 calculates, for example, the ratio of the access log LG whose response time is not within the normal range among the access log LG corresponding to the access target included in the group specified in the process of S43 (S45).

[0137] As a result, when the ratio of the access log LG whose response time is not within the normal range is equal to or greater than a predetermined threshold (YES in S46), the abnormality detection unit 115 determines that, for example, the response time corresponding to the access target included in the group specified in the process of S43 is abnormal (S47).

[0138] On the other hand, when the ratio of the access log LG whose response time is not within the normal range is less than the predetermined threshold (NO in S46), the abnormality detection unit 115 does not perform the process of S47.

[0139] Thereafter, the abnormality detection unit 115 determines whether all the groups have been specified in the process of S43 (S48).

[0140] As a result, when it is determined in the process of S43 that not all groups have been identified (NO in S48), the abnormality detection unit 115 performs the processes after S43 again.

[0141] On the other hand, when it is determined in the process of S43 that all groups have been identified (YES in S48), the result output unit 116 outputs information indicating the access targets included in the groups determined to be abnormal in the process of S47 to an administrator terminal (not shown) (S49).

[0142] As described above, the information processing apparatus 1 in the present embodiment identifies, for example, a first transition state regarding the response time for a first access target included in a plurality of access targets. Then, the information processing apparatus 1 identifies a second access target among the plurality of access targets, the transition state of whose response time has a predetermined relationship with the first transition state.

[0143] After that, the information processing apparatus 1 sets, for example, a normal range of the response time for the first access target and the second access target. Then, the information processing apparatus 1 performs abnormality detection regarding the response time for the first access target and the second access target by using the set normal range.

[0144] That is, the response time of the access to each access target may change, for example, due to an increase or decrease in the number of records to be searched, a change in software or hardware, or the like. Also, the response time of the access to each access target may change, for example, due to the occurrence of a failure or the like. Therefore, for example, when there are a plurality of access targets that use the same resource in the same manner, it can be determined that the response times of the accesses to these access targets are likely to change in the same manner at the same timing.

[0145] Therefore, when the transition situation of the response time for the first access target and the transition situation of the response time for the second access target are similar in a past predetermined period, the information processing apparatus 1 in the present embodiment determines that it is highly likely that the transition situations for each response time are also similar at present. Therefore, in this case, the information processing apparatus 1 sets the normal range after combining the first access target and the second access target as one access target.

[0146] As a result, even when there is an access target with a low access frequency by the user, the information processing apparatus 1 in the present embodiment can sufficiently secure the access log used for setting the normal range for that access target, and can set a normal range that enables accurate anomaly detection. Therefore, the information processing apparatus 1 can improve the determination accuracy of anomaly detection.

[0147] Summarizing the above embodiments, it is as follows in the following supplementary note.

[0148] (Supplementary Note 1) When it is determined that the number of response time information for determining the normal range used when performing anomaly detection on the response time of the first access target is less than a predetermined value, the first transition situation of the response time of the first access target is specified, A second access target whose transition situation of the response time is similar to the first transition situation is specified, A normal range is set from the first transition situation and the transition situation corresponding to the second access target, When a new access to the first access target occurs, anomaly detection is performed on the response time of the new access by using the normal range. An anomaly detection method characterized in that a computer executes the process.

[0149] (Supplementary Note 2) In Supplementary Note 1, In the process of identifying the first transition situation, for each unit period included in the first period, a first feature amount indicating the transition of the response time of the access to the first access target is identified. In the process of identifying the second access target, for each unit period included in the first period, other feature amounts indicating the transition of the response time of the access to other access targets included in the plurality of access targets are calculated. When the first feature amount for each unit period and the other feature amount for each unit period are similar, the other access target and the second access target are identified. An abnormality detection method characterized by the above.

[0150] (Appendix 3) In Appendix 1, In the process of setting the normal range, by using the response time corresponding to the period after a predetermined timing included in the first period among the response times of the access to any one of the first access target and the second access target, the normal range is set. An abnormality detection method characterized by the above.

[0151] (Appendix 4) In Appendix 1, further, When the size of the set normal range satisfies a predetermined condition, the response times of the access to any one of the first access target and the second access target are each divided into a plurality of groups by using information related to each of the first access target and the second access target. For each of the divided plurality of groups, the process of setting the normal range is performed again. An abnormality detection method characterized by causing a computer to execute the process.

[0152] (Appendix 5) In Appendix 4, In the process of dividing into the plurality of groups, each of the response times for access to either the first access target or the second access target is divided according to the size of the data size transmitted and received in association with the access to each of the first access target and the second access target. An abnormality detection method characterized by the above.

[0153] (Appendix 6) In Appendix 5, In the process of dividing into the plurality of groups, each of the response times for access to either the first access target or the second access target is divided for each user who has accessed each of the first access target and the second access target. An abnormality detection method characterized by the above.

[0154] (Appendix 7) When it is determined that the number of response time information for determining the normal range used when performing abnormality detection for the response time of the first access target is less than a predetermined value, the first transition situation for the response time of the first access target is specified. Specify a second access target whose transition situation regarding the response time is similar to the first transition situation. Set a normal range from the first transition situation and the transition situation corresponding to the second access target. When a new access to the first access target occurs, use the normal range to perform abnormality detection for the response time of the new access. An abnormality detection program characterized in that a computer executes the process.

[0155] (Appendix 8) In Appendix 7, In the process of specifying the first transition situation, for each unit period included in the first period, a first feature amount indicating the transition of the response time of the access to the first access target is specified. In the process of specifying the second access target, For each unit period included in the first period, calculate other feature quantities indicating the transition of the response time of access to other access targets included in a plurality of access targets, when the first feature quantity for each unit period and the other feature quantity for each unit period are similar, specifying the other access target and the second access target, An anomaly detection program characterized by this.

Explanation of symbols

[0156] 1: Information processing device 2: Business system 2a: Storage device 3a: User terminal 3b: User terminal 3c: User terminal 10: Information processing system LG: Access log

Claims

1. When it is determined that the number of response time information for determining the normal range used when performing abnormal detection of the response time of the first access target is less than a predetermined value, the first transition state of the response time of the first access target is specified, a second access target whose transition state of the response time is similar to the first transition state is specified, a normal range is set from the first transition state and the transition state corresponding to the second access target, when a new access to the first access target occurs, abnormal detection of the response time of the new access is performed by using the normal range, An abnormal detection method characterized in that a computer executes the process.

2. In Claim 1, in the process of specifying the first transition state, for each unit period included in the first period, a first feature amount indicating the transition of the response time of the access to the first access target is specified, in the process of specifying the second access target, for each unit period included in the first period, another feature amount indicating the transition of the response time of the access to another access target included in a plurality of access targets is calculated, when the first feature amount for each unit period and the other feature amount for each unit period are similar, the other access target and the second access target are specified, An abnormal detection method characterized by that.

3. In Claim 1, in the process of setting the normal range, by using the response time corresponding to the period after a predetermined timing included in the first period among the response times of the accesses to any one of the first access target and the second access target, the normal range is set, An abnormal detection method characterized by that.

4. In Claim 1, further, when the size of the set normal range satisfies a predetermined condition, each of the response times of the accesses to any one of the first access target and the second access target is divided into a plurality of groups by using information related to each of the first access target and the second access target, for each of the divided plurality of groups, the process of setting the normal range is performed again, An abnormal detection method characterized in that a computer is caused to execute the process.

5. In Claim 4, In the process of dividing into the plurality of groups, each of the response times for access to any one of the first access target and the second access target is divided according to the size of the data size transmitted and received along with the access to each of the first access target and the second access target. An abnormality detection method characterized by the above.

6. In Claim 5, In the process of dividing into the plurality of groups, each of the response times for access to any one of the first access target and the second access target is divided for each user who has accessed each of the first access target and the second access target. An abnormality detection method characterized by the above.

7. When it is determined that the number of response time information for determining the normal range used when performing abnormality detection for the response time of the first access target is less than a predetermined value, identify the first transition situation for the response time of the first access target. Identify a second access target whose transition situation for the response time is similar to the first transition situation. Set a normal range from the first transition situation and the transition situation corresponding to the second access target. When a new access to the first access target occurs, perform abnormality detection for the response time of the new access by using the normal range. An abnormality detection program characterized in that a computer executes the process.

Citation Information

Patent Citations

  • Analysis program, analysis method, and analyzer

    JP2011258057A

  • Information processor, control method, computer program, storage medium, and model creation device

    JP2019046278A

  • Network analysis program, network analysis apparatus, and network analysis method

    JP2021022759A