Analysis device, analysis method, and analysis program
By splitting and analyzing carrier network traffic into streams, the device accurately detects anomalies, addressing the challenges of superposition in conventional methods and enhancing network stability.
Patent Information
- Application Number
- JP2023557601
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-08
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-11-08
AI Technical Summary
Conventional methods struggle to accurately analyze traffic in large-capacity carrier networks due to the superposition of multiple flows, making it difficult to capture changes in feature quantities and achieve precise classification, especially in detecting anomalies end-to-end in service and access sides.
The analysis device splits communication traffic into multiple streams, using autoregressive analysis and comparisons between similar streams to calculate degrees of abnormality, enabling accurate traffic analysis by normalizing feature amounts and determining anomaly causes.
This approach allows for high-accuracy traffic analysis in carrier networks, enabling quick detection of anomalies across the service and access sides, ensuring stable operation of social infrastructure.
Smart Images

Figure 0007700871000010 
Figure 0007700871000011 
Figure 0007700871000012
Abstract
Description
Technical Field
[0001] The present invention relates to an analyzer, an analysis method, and an analysis program.
Background Art
[0002] In carrier networks that support social infrastructure such as video distribution, Web conference connections in the new normal, and Cloud interconnects for promoting DX, rapid detection and countermeasures for communication network anomalies are required.
[0003] Services using carrier networks are composed of complex and diverse components such as mobile base stations, relay core networks, and OTT clouds. In carrier networks that provide relay networks, it is required not only to quickly detect anomalies and failures in one's own network, but also to quickly detect anomalies in the service end-to-end including anomalies on the access side and OTT side, and to realize stable use of social infrastructure.
[0004] Conventionally, as a technique for detecting and predicting communication network anomalies from traffic, for example, a stream mining technique for discovering various features from time series data such as communication traffic has been established (see, for example, Non-Patent Document 1).
[0005] In addition, a method has been proposed in which traffic is classified based on certain rules and analyzed for future prediction and the like for those classified (see, for example, Non-Patent Document 2).
Prior Art Documents
Non-Patent Documents
[0006]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0007] However, the conventional technology has a problem that it is difficult to accurately perform traffic analysis of the carrier network.
[0008] For example, since the large-capacity traffic flowing through the carrier network is a superposition of multiple flows, it is difficult to capture changes in feature quantities by the stream mining described in Non-Patent Document 1.
[0009] Also, for example, the classification method described in Non-Patent Document 2 performs predictive classification based on trends rather than definite classification, so there are cases where accurate classification cannot be achieved.
Means for Solving the Problems
[0010] In order to solve the above-described problems and achieve the object, the analysis device includes a splitting unit that splits communication traffic in a network into a plurality of streams, and based on the result of autoregressive analysis of a first stream among the plurality of streams and the comparison result between the first stream and a second stream similar to the first stream, a calculation unit that calculates the degree of abnormality of the first stream, and is characterized by having the above.
Effects of the Invention
[0011] According to the present invention, traffic analysis of a carrier network can be accurately performed.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Modes for Carrying Out the Invention
[0013] Hereinafter, embodiments of the analyzer, analysis method, and analysis program according to the present application will be described in detail with reference to the drawings. Note that the present invention is not limited to the embodiments described below.
[0014] First, the carrier network to be analyzed in the embodiment will be described with reference to FIG. 1. FIG. 1 is a diagram showing a configuration example of the carrier network.
[0015] As shown in FIG. 1, the carrier network includes a service section, a core network section, and an access section.
[0016] In the service section, there is OTT (Over The Top). In the access section, there are base stations and users accommodated in the base stations.
[0017] In the following description, the service section as viewed from the core network (Core Network) may be referred to as the service side. Also, the access section as viewed from the core network may be referred to as the service side.
[0018] One object of the present embodiment is to accurately analyze traffic in a large-scale carrier network as shown in FIG. 1, and as a result, quickly detect anomalies end-to-end in the service, including anomalies on the access side and the service side (OTT side), and realize stable use of social infrastructure.
[0019] Here, in the stream mining as described in Non-Patent Document 1, time-series data generated moment by moment is defined as a stream, and finding the characteristics of the stream itself (trend detection, acquisition of statistical information), predicting the future (prediction), comparing between streams and sequences (similarity search, clustering), etc. are performed.
[0020] On the other hand, when the large-capacity traffic flowing through the carrier network is regarded as a stream, a plurality of flows are superimposed on the stream. Therefore, it is difficult to capture changes in the feature amounts of the large-capacity traffic flowing through the carrier network by conventional stream mining.
[0021] For example, in a carrier network, even if a specific service fluctuates due to a service anomaly, the overall traffic hardly changes due to the aggregation effect.
[0022] Furthermore, the classification method described in Non-Patent Document 2 classifies traffic patterns based solely on traffic behavior and may not necessarily achieve accurate classification.
[0023] For example, even if the traffic of a carrier network is classified into traffic patterns with specific fluctuations by the technology of Non-Patent Document 2, there may be multiple different services superimposed on the classified traffic patterns, making it difficult to capture fluctuations limited to a specific service using the classification results.
[0024] [Configuration of the First Embodiment] FIG. 2 is a diagram showing a configuration example of an analysis system according to the first embodiment. As shown in FIG. 2, the analysis system 1 includes an analysis device 10 and a monitoring device 20.
[0025] The analysis device 10 and the monitoring device 20 can communicate data with each other. The analysis device 10 and the monitoring device 20 are, for example, servers.
[0026] The monitoring device 20 is connected to a communication network N. For example, the communication network N is the core network shown in FIG. 1.
[0027] For example, the monitoring device 20 is connected to a node 30 included in the communication network N. The node 30 is, for example, a server and network equipment.
[0028] The monitoring device 20 acquires information regarding the communication network N from the node 30 and transmits the acquired information to the analysis device 10.
[0029] For example, the monitoring device 20 acquires network configuration information (connection information of nodes and links), traffic information (flow information, packet capture), and path information through which traffic flows in the communication network N.
[0030] Based on the information provided by the monitoring device 20, the analysis device 10 performs traffic analysis on the communication network N. The analysis device 10 can output the analysis results to the user or another device (GUI device, terminal device) via the user interface.
[0031] The configuration of the analysis device 10 will be described with reference to FIG. 3. FIG. 3 is a diagram showing a configuration example of the analysis device according to the first embodiment.
[0032] As shown in FIG. 3, the analysis device 10 includes a communication unit 11, an input unit 12, an output unit 13, a storage unit 14, and a control unit 15.
[0033] The communication unit 11 performs data communication with other devices via the network. For example, the communication unit 11 is a NIC (Network Interface Card). For example, the communication unit 11 performs data communication with the monitoring device 20.
[0034] The input unit 12 receives input of data from the user. The input unit 12 is, for example, an input device such as a mouse or a keyboard.
[0035] The output unit 13 outputs data by displaying on a screen or the like. The output unit 13 is, for example, a display device such as a display.
[0036] The storage unit 14 is a storage device such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), or an optical disk. Note that the storage unit 14 may be a semiconductor memory capable of rewriting data, such as a RAM (Random Access Memory), a flash memory, or an NVSRAM (Non Volatile Static Random Access Memory).
[0037] The storage unit 14 stores the OS (Operating System) and various programs executed by the analyzer 10.
[0038] The storage unit 14 stores an analysis result DB 141, a route DB 142, a topology DB 143, and a traffic DB 144.
[0039] The analysis result DB 141 stores the results of traffic analysis. The traffic analysis is performed by each part of the control unit 15 described later.
[0040] In addition, the results of the traffic analysis stored in the analysis result DB 141 are output via the communication unit 11 or the output unit 13.
[0041] The route DB 142 stores route information through which communication traffic flows in the communication network N.
[0042] The topology DB 143 stores connection information of nodes and links in the communication network N.
[0043] The traffic DB 144 stores traffic information (for example, flow information).
[0044] The information in the route DB 142, the topology DB 143, and the traffic DB 144 may be stored via the monitoring device 20, or may be input by an operator.
[0045] The control unit 15 controls the entire analyzer 10. The control unit 15 is, for example, an electronic circuit such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a GPU (Graphics Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).
[0046] In addition, the control unit 15 has an internal memory for storing programs and control data that define various processing procedures, and executes each process using the internal memory.
[0047] Also, the control unit 15 functions as various processing units when various programs operate.
[0048] For example, the control unit 15 includes a division unit 151, a calculation unit 152, and a determination unit 153.
[0049] Using FIG. 4, the details of each part of the control unit 15 will be described together with the flow of the analysis process by the analyzer 10. FIG. 4 is a diagram for explaining the flow of the analysis process.
[0050] The division unit 151 divides the communication traffic in the communication network N into a plurality of streams.
[0051] Here, it is assumed that the communication traffic has been acquired by the monitoring device 20 and is stored in the traffic DB 144.
[0052] For example, the division unit 151 divides the communication traffic into flows by 5-tuple. The divided flows are called streams.
[0053] The 5-tuple consists of five items: source IP address, source port number, destination IP address, destination port number, and protocol type. For example, the division unit 151 divides the packets constituting the communication traffic into streams for each source IP address. At this time, each stream includes packets having a common source IP address.
[0054] In the carrier network, packets may be encapsulated by a tunneling protocol. Therefore, the division unit 151 divides the communication traffic by the method described in References 1 to 3. Thereby, even when the packets are encapsulated, the communication traffic can be divided by 5-tuple. Reference 1: Japanese Patent Application Laid-Open No. 2019-097069 Reference 2: Japanese Patent Application Laid-Open No. 2021-090161 Reference 3: International Publication No. 2021 / 149245
[0055] For example, Reference 1 describes a method of discriminating a protocol stack pattern of a packet and converting a format according to the discriminated protocol stack pattern.
[0056] In the example of FIG. 4, the splitting unit 151 splits the communication traffic into three streams including Stream X. Here, Stream X is an example of the first stream.
[0057] Here, Stream X is set as the stream to be analyzed. However, the analysis device 10 can perform the same analysis as Stream X on the streams obtained by splitting.
[0058] The calculation unit 152 calculates score1 based on the result of the autoregressive analysis of Stream X among the plurality of streams, and score2 based on the comparison result between Stream X and Stream Z similar to Stream X.
[0059] Note that the autoregressive analysis can be a comparison with Stream Y which is a past stream of Stream X.
[0060] Stream Z is an example of the second stream. Also, score1 is an example of the first degree of abnormality. Also, score2 is an example of the second degree of abnormality.
[0061] First, the sequence (stream) X to be analyzed raw is represented by the vector of formula (1).
[0062]
Equation
[0063] The calculation unit 152 normalizes X raw to obtain the stream X of Equation (2). The normalization method is as shown in Equation (3).
[0064]
Number
[0065]
Number
[0066] Also, Equation (4) is obtained by normalizing the past stream Y (Y T ) of the stream X. The calculation unit 152 calculates the average value (average vector) of the stream Y as shown in Equation (5). The calculation method of the average value is as shown in Equation (6). Y T is a time-series vector. T represents time.
[0067]
Number
[0068]
Number
[0069]
Number
[0070] Each element of the stream Y may be created for each sliding window. At this time, T is the start time of the sliding window.
[0071] Also, Equation (7) is a stream Z (Z S) is the normalized one. As shown in equation (8), the calculation unit 152 calculates the average value (average vector) of the stream Z. The calculation method of the average value is as shown in equation (9). S represents services related to communication traffic, base stations, etc.
[0072]
Number
[0073]
Number
[0074]
Number
[0075] Note that x1 before normalization raw etc. are, for example, the communication data size and the number of packets of the stream X. Also, x1, y1 T , z1 S etc. can be said to be the values obtained by normalizing the communication data size and the number of packets, etc., which are feature quantities.
[0076] The calculation unit 152 removes noise by calculating the average value for the stream Y and the stream Z.
[0077] The relationship among the stream X, the stream Y, and the stream Z is represented as shown in FIG. 5. FIG. 5 is a diagram for explaining each stream.
[0078] The stream Y is located in the past in time series with respect to the stream X. On the other hand, the stream Z occurs at the same time as the stream X.
[0079] The calculation unit 152 performs calculations according to the code in FIG. 6. FIG. 6 is a diagram showing an example of the code of the program for executing the analysis.
[0080] Note that the calculation unit 152 executes the steps from the first line to the thirteenth line of FIG. 6. The step of the fourteenth line is executed by the determination unit 153. Note that the string after # is a comment.
[0081] First, as shown in the second line, the calculation unit 152 calculates the average value of the stream Y (the past trend of the measurement target). Also, as shown in the third line, the calculation unit 152 calculates the average value of the stream Z (the similar stream at the current time). The current time means the time when the stream X occurred. Each average value is calculated by the formulas from (4) to (9) described above.
[0082] Here, when the distance (d1) between the average value of the stream X and the average value of the stream Y is greater than or equal to the threshold value (Th1) (the fourth line is true), the calculation unit 152 sets a bit in X - Y_Error (substitute true). In this case, further, the calculation unit 152 calculates score1 as shown in the sixth line.
[0083] On the other hand, when the distance (d1) between the average value of the stream X and the average value of the stream Y is not greater than or equal to the threshold value (Th1) (the fourth line is false), the calculation unit 152 calculates score1 as shown in the eighth line.
[0084] In this way, the calculation unit 152 calculates score1 based on the difference between the feature amount of the stream X for a predetermined period and the average value of the feature amount (stream Y) of the period before the predetermined period of the stream X.
[0085] Then, when the distance (d2) between the average value of the stream X and the average value of the stream Z is greater than or equal to the threshold value (Th2) (the ninth line is true), the calculation unit 152 sets a bit in X - Z_Error (substitute true). In this case, further, the calculation unit 152 calculates score2 as shown in the eleventh line.
[0086] On the other hand, when the distance (d2) between the average value of the stream X and the average value of the stream Z is not greater than or equal to the threshold value (Th2) (the ninth line is false), the calculation unit 152 calculates score2 as shown in the thirteenth line.
[0087] In this way, the calculation unit 152 calculates score2 based on the difference between the feature amount of stream X and the average value of the feature amounts of a plurality of streams Z.
[0088] Note that U is a constant representing the upper limit and is larger than Th1 and Th2. On the other hand, L is a constant representing the lower limit and is smaller than Th1 and Th2.
[0089] Also, DISTANCE in the 4th and 9th lines is a function that outputs the difference degree between vectors. In the function DISTANCE, the calculation unit 152 can calculate the difference degree by the Euclidean distance between vectors, the correlation value, the cosine similarity, DTW (Dynamic Time Warping), comparison of frequency components (conversion by Fourier transform is required), etc. Note that the larger the distances d1 and d2 are, the larger the difference degree is and the smaller the similarity degree is.
[0090] For example, if stream X is the communication traffic of a certain user using a certain service for one day, then stream Y may be the communication traffic of the user using the same service in the past one week.
[0091] Also, for example, if stream X is the communication traffic of a certain user using a certain service, then stream Z may be the communication traffic of another user using the same service or the communication traffic of the user using another service.
[0092] At this time, the calculation unit 152 calculates score2 based on the comparison result between stream X and stream Z, where stream Z is a stream in which only one of the corresponding user and service is different from stream X.
[0093] Regarding how far back stream Y goes and how many users or services stream Z includes, they can be arbitrarily set as parameters. Increasing these parameters increases the comparison targets and improves the analysis accuracy of the analysis device 10, but the calculation load increases.
[0094] Based on score1 and score2, the determination unit 153 determines whether the cause of the abnormality is in stream X, a stream different from stream X, or the communication network N.
[0095] For example, as shown in the 14th line of FIG. 6, the determination unit 153 determines the alert type based on X-Y_Error, X-Z_Error, score1, and score2.
[0096] The method for determining the alert type by the determination unit 153 will be described separately for the case where stream X is a stream from the service side and the case where it is a stream from the access side.
[0097] FIG. 7 is a diagram for explaining a stream from the service side. As shown in FIG. 7, the stream from the service side is, for example, communication traffic transmitted from OTT.
[0098] FIG. 8 is a diagram for explaining the method for determining the type of alert regarding the stream from the service side.
[0099] As shown in FIG. 8, when X-Y_Error is true and X-Z_Error is not true, the determination unit 153 identifies that the communication network N (Network) is suspected. Note that being suspected means, for example, that there is a high possibility of a failure occurring.
[0100] This is because although stream X is different from the past trend, it has the same trend as similar streams at the same time, so it is suspected that the communication network N itself is abnormal at the current time.
[0101] Also, when X-Y_Error is not true and X-Z_Error is true, the determination unit 153 identifies that a stream other than stream X is suspected. This means that there is a high possibility that a failure has occurred in a user other than the user corresponding to stream X or a service other than the service corresponding to stream X.
[0102] This is because stream X is the same as the past trend but has a different trend from similar streams at the same time, so it is suspected that the similar streams are abnormal.
[0103] Also, when X-Y_Error is true and X-Z_Error is true, the determination unit 153 identifies that stream X is suspected. This means that there is a high possibility that a failure has occurred in the user corresponding to stream X or the service corresponding to stream X.
[0104] This is because stream X is different from the past trend and also has a different trend from similar streams at the same time, so it is suspected that stream X is abnormal.
[0105] FIG. 9 is a diagram for explaining a stream from the access side. As shown in FIG. 9, the stream from the access side is communication traffic transmitted from a user accommodated in a base station.
[0106] FIG. 10 is a diagram for explaining a method for determining the type of alert regarding a stream from the access side.
[0107] As shown in FIG. 10, when X-Y_Error is true and X-Z_Error is not true, the determination unit 153 identifies that the communication network N (Network) is suspected.
[0108] Also, when X-Y_Error is false and X-Z_Error is true, the determination unit 153 identifies that a stream other than stream X is suspected. This means that there is a high possibility that a failure has occurred in a user different from the user corresponding to stream X or in a base station different from the base station accommodating the user corresponding to stream X.
[0109] Also, when X-Y_Error is true and X-Z_Error is true, the determination unit 153 identifies that stream X is suspected. This means that there is a high possibility that a failure has occurred in the user corresponding to stream X or in the base station accommodating the user.
[0110] Also, the determination unit 153 outputs the identified suspected target together with the certainty. The determination unit 153 can calculate the certainty from score1 and score2.
[0111] For example, when only X-Y_Error is true, the determination unit 153 uses score1 as the certainty. Also, for example, when only X-Z_Error is true, the determination unit 153 uses score2 as the certainty. Also, for example, when both X-Y_Error and X-Z_Error are true, the determination unit 153 uses the average of score1 and score2 as the certainty.
[0112] For example, Suspected(80%) means that it is the suspected target and the certainty is 80% (0.8).
[0113] (Learning of Threshold Value) The analysis device 10 can adjust the threshold value by learning. For example, the calculation unit 152 records the degree of deviation (upper deviation, lower deviation) between d1 in the 4th row and d2 in the 9th row of FIG. 6 and each threshold value.
[0114] And, for example, if it is later found that a failure occurred at the time of 30% lower burst in FIG. 11, the analysis device 10 updates the threshold value (for example, Th1) so that the sample can be determined as abnormal (for example, the fourth line is true). FIG. 11 is a diagram for explaining a method of learning a threshold value.
[0115] (Focused monitoring of specific users) FIG. 12 is a diagram for explaining focused monitoring of specific users. When the analysis device 10 analyzes the target user as stream X and no abnormality is found, it determines X - Y_Error for streams X1, X2,..., XN of users who use the same network equipment as the target user.
[0116] Users who use the same network equipment as the target user are, for example, users who exist on the same link and SR path as the target user.
[0117] At that time, if a change is observed such that the communication traffic of the user in whom X - Y_Error has occurred increases significantly, the analysis device 10 deems that the user may affect the target user and outputs an alert.
[0118] [Processing of the first embodiment] FIG. 13 is a flowchart showing the processing flow of the analysis device according to the first embodiment. As shown in FIG. 13, first, the analysis device 10 creates streams Z and Y for stream X (step S101).
[0119] When the difference degree between stream X and stream Y (d1 in the fourth line of FIG. 6) is equal to or greater than the threshold value (step S102, Yes), the analysis device 10 sets a bit for X - Y_Error and calculates an error score (score1 in the sixth line of FIG. 6) (step S103).
[0120] On the other hand, when the difference degree between stream X and stream Y is not equal to or greater than the threshold value (step S102, No), the analysis device 10 calculates a normal score (score1 in the eighth line of FIG. 6) (step S105).
[0121] When the difference between stream X and stream Z (d2 in the 9th row of FIG. 6) is equal to or greater than the threshold value (step S104, Yes), the analysis device 10 sets a bit in X-Z_Error and calculates an error score (score2 in the 9th row of FIG. 6) (step S106).
[0122] On the other hand, when the difference between stream X and stream Z is less than the threshold value (step S104, No), the analysis device 10 calculates a normal score (score2 in the 13th row of FIG. 6) (step S107).
[0123] Then, the analysis device 10 determines an alert type based on X-Y_Error, X-Z_Error, score1, and score2 (step S108).
[0124] [Effect of the First Embodiment] As described above, the splitting unit 151 splits the communication traffic in the communication network into a plurality of streams. The calculation unit 152 calculates a first degree of abnormality based on the result of the autoregressive analysis of the first stream among the plurality of streams, and a second degree of abnormality based on the comparison result between the first stream and a second stream similar to the first stream.
[0125] In this way, the analysis device 10 can perform analysis after splitting the communication traffic. As a result, according to the embodiment, traffic analysis of the carrier network can be performed with high accuracy.
[0126] Furthermore, by accurately analyzing the communication traffic of the carrier network, it is possible to quickly detect anomalies end-to-end in the service including anomalies on the access side and OTT side, and realize stable use of social infrastructure.
[0127] The calculation unit 152 calculates the first degree of abnormality based on the difference between the feature amount of a predetermined period of the first stream and the average value of the feature amounts of a period past the predetermined period of the first stream.
[0128] This makes it possible to perform comparative analysis with past trends while reducing errors.
[0129] The calculation unit 152 calculates the second degree of abnormality based on the difference between the feature amount of the first stream and the average value of the feature amounts of the plurality of second streams.
[0130] This makes it possible to perform comparative analysis with the streams that are occurring across the board at the same time while reducing errors.
[0131] The calculation unit 152 calculates the second degree of abnormality based on the comparison result between the first stream and the second stream, which is a stream in which only the corresponding user and service are different from the first stream.
[0132] This makes it possible to perform comparative analysis with similar streams shared by the user or service.
[0133] The determination unit 153 determines whether the cause of the abnormality is in the first stream, a stream different from the first stream, or the communication network based on the first degree of abnormality and the second degree of abnormality.
[0134] This makes it possible to provide the user with specific information regarding response to the failure.
[0135] [System configuration, etc.] In addition, each component of each of the illustrated devices is functionally conceptual and does not necessarily have to be physically configured as illustrated. That is, the specific forms of distribution and integration of each device are not limited to those illustrated, and all or part of them can be functionally or physically distributed or integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU (Central Processing Unit) and a program analyzed and executed by the CPU, or can be realized as hardware by wired logic. Note that the program may be executed not only by the CPU but also by other processors such as a GPU.
[0136] Also, among the various processes described in this embodiment, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method. In addition, regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified.
[0137] [Program] As one embodiment, the analysis device 10 can be implemented by installing an analysis program that executes the above analysis process as package software or online software on a desired computer. For example, by causing the information processing device to execute the above analysis program, the information processing device can function as the analysis device 10. The information processing device mentioned here includes desktop or notebook personal computers. In addition, other information processing devices include mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone System), and further include slate terminals such as PDAs (Personal Digital Assistant) within its scope.
[0138] Alternatively, the analysis device 10 can also be implemented as an analysis server device that uses the terminal device used by the user as a client and provides services related to the above analysis processing to the client. For example, the analysis server device is implemented as a server device that takes communication traffic as input and outputs analysis results. In this case, the analysis server device may be implemented as a web server, or may be implemented as a cloud that provides services related to the above analysis processing through outsourcing.
[0139] FIG. 14 is a diagram showing an example of a computer that executes an analysis program. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0140] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.
[0141] The hard disk drive 1090 stores, for example, an OS 1091, application programs 1092, program modules 1093, and program data 1094. That is, the programs defining each process of the analyzer 10 are implemented as program modules 1093 in which computer-executable code is described. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, program modules 1093 for executing processes similar to the functional configurations in the analyzer 10 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0142] Also, the setting data used in the processes of the above-described embodiments is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed, and executes the processes of the above-described embodiments.
[0143] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (such as a LAN (Local Area Network) or a WAN (Wide Area Network)). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from the other computer via the network interface 1070.
Description of Reference Numerals
[0144] N Communication network 10 Analyzer 11 Communication Unit 12 Input Unit 13 Output Unit 14 Memory Unit 15 Control Unit 20 Monitoring Device 30 Node 141 Analysis Result DB 142 Route DB 143 Topology DB 144 Traffic DB 151 Division Unit 152 Calculation Unit 153 Decision Unit
Claims
1. A splitting unit that splits communication traffic in a communication network into a plurality of streams; A calculation unit that calculates a first degree of abnormality based on the result of autoregressive analysis of a first stream among the plurality of streams, and a second degree of abnormality based on a comparison result between the first stream and a second stream similar to the first stream; A determination unit that determines whether the cause of the abnormality is in the first stream, a stream different from the first stream, or the communication network based on the first degree of abnormality and the second degree of abnormality; An analysis apparatus, characterized by comprising the above.
2. The analysis apparatus according to claim 1, wherein the calculation unit calculates the first degree of abnormality based on a difference between a feature amount of a predetermined period of the first stream and an average value of feature amounts of a period prior to the predetermined period of the first stream.
3. The analysis apparatus according to claim 1 or 2, wherein the calculation unit calculates the second degree of abnormality based on a difference between a feature amount of the first stream and an average value of feature amounts of a plurality of the second streams.
4. The analysis apparatus according to any one of claims 1 to 3, wherein the calculation unit calculates the second degree of abnormality based on a comparison result between the first stream and the second stream, which is a stream different from the first stream in that only a corresponding user and service are different from the first stream.
5. An analysis method executed by an analysis apparatus, comprising: A splitting step of splitting communication traffic in a communication network into a plurality of streams; A calculation step of calculating a first degree of abnormality based on the result of autoregressive analysis of a first stream among the plurality of streams, and a second degree of abnormality based on a comparison result between the first stream and a second stream similar to the first stream; A determination step of determining whether the cause of the abnormality is in the first stream, a stream different from the first stream, or the communication network based on the first degree of abnormality and the second degree of abnormality; An analysis method, characterized by including the above.
6. An analysis program for causing a computer to function as the analysis apparatus according to any one of claims 1 to 4.
Citation Information
Patent Citations
Flowlet Resolution For Application Performance Monitoring And Management
US20180287907A1
Low-complexity detection of potential network anomalies using intermediate-stage processing
US20190068623A1
Anomaly detection apparatus, anomaly detection system, and anomaly detection method
WO2017163352A1