Abnormality management device and abnormality management method

The abnormality management device uses singular value decomposition and probability modeling to set thresholds for detecting abnormal traffic in IoT networks, addressing the data requirement challenge and enabling efficient traffic management.

JP7752279B1Active Publication Date: 2025-10-09INTERNET INITIATIVE JAPAN INC
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025125384
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-10-09
Estimated Expiration
2045-07-28

AI Technical Summary

Technical Problem

Conventional methods for detecting abnormal traffic in IoT devices require large amounts of past abnormal traffic data, making it difficult to estimate or detect such traffic when sufficient data is not available.

Method used

An abnormality management device that extracts characteristic directions of normal data using singular value decomposition, learns a probability model through maximum likelihood estimation, and sets a threshold based on the spatial coincidence between normal and abnormal data distributions to detect anomalous communication without relying on extensive historical data.

Benefits of technology

Enables effective detection of abnormal traffic without the need for large datasets, allowing for timely intervention in communication networks by identifying and managing anomalous communication patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007752279000001_ABST
    Figure 0007752279000001_ABST
Patent Text Reader

Abstract

To manage abnormal traffic without collecting a large amount of data on past abnormal traffic. [Solution] The abnormality management device 1 includes a learning unit 12 that uses the characteristic directions of normal data as training data to learn, by maximum likelihood estimation, parameters of a probability model that outputs the posterior probability that the communication volume at each time corresponding to each of the characteristic directions of the normal data is normal; a derivation unit 13 that derives a probability distribution for the characteristic directions of abnormal data that shows abnormal communication volume that deviates from the range of normal communication volume based on the estimated posterior probability, the probability distribution for the characteristic directions of the normal data, and the prior probability of normality; and a calculation unit 14 that calculates a first index value that indicates the degree of spatial agreement formed by the derived probability distribution for the characteristic directions of the abnormal data and the probability distribution for the characteristic directions of the normal data.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an abnormality management device and an abnormality management method. [Background technology]

[0002] In recent years, IoT devices such as home appliances and smart meters have become widespread in addition to smartphones and tablets. As the number of IoT devices increases, controlling the traffic of IoT device communications has become an issue.

[0003] Conventionally, there are known techniques for estimating abnormal traffic such as burst traffic and predicting the amount of traffic flowing through a communication network. For example, Patent Document 1 discloses a system that predicts the maximum value of traffic volume for a predetermined link using a statistical estimation method such as maximum likelihood estimation based on correlation data of multiple past traffic data for different links.

[0004] However, when estimating abnormal traffic such as burst traffic using statistical estimation such as maximum likelihood estimation as disclosed in Patent Document 1, a large amount of data on past abnormal traffic is required. Also, when estimating abnormal traffic using machine learning based on a supervised learning model, a large amount of learning data related to abnormal traffic must be prepared. Therefore, if it is not possible to collect a large amount of data on past abnormal traffic, it may be difficult to estimate or detect abnormal traffic. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-216585 Summary of the Invention [Problem to be solved by the invention]

[0006] As described above, with conventional techniques, it may be difficult to detect abnormal traffic unless a large amount of past abnormal traffic data is collected.

[0007] The present invention has been made to solve the above-mentioned problems, and has as its object to manage abnormal traffic without collecting a large amount of data on past abnormal traffic. [Means for solving the problem]

[0008] In order to solve the above-described problems, an abnormality management device according to the present invention includes: a feature extraction unit configured to extract characteristic directions of normal data, based on a data matrix composed of a plurality of observation vectors representing normal data indicating normal communication volumes included in time-series data of communication volumes; a learning unit configured to learn, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that communication volumes at each time corresponding to each of the characteristic directions of the normal data are normal, using the characteristic directions of the normal data extracted by the feature extraction unit as training data; a derivation unit configured to derive a probability distribution for characteristic directions of abnormal data indicating abnormal communication volumes that deviate from the range of normal communication volumes, based on the posterior probability estimated by the probability model learned by the learning unit, a probability distribution for the characteristic directions of the normal data, and a prior probability of normality; a calculation unit configured to calculate a first index value that indicates a spatial coincidence formed between the probability distribution for the characteristic directions of the abnormal data derived by the derivation unit and the probability distribution for the characteristic directions of the normal data; and a setting unit configured to set the first index value calculated by the calculation unit as a determination threshold for the abnormal communication volumes.

[0009] Furthermore, the anomaly management device according to the present invention may further include a collection unit configured to collect first time series data of the communication volume observed in a first interval and second time series data of the communication volume observed in a second interval following the first interval as time series data of the communication volume to be managed, wherein the feature extraction unit extracts characteristic directions of the first time series data and characteristic directions of the second time series data based on a first data matrix composed of observation vectors representing the first time series data and a second data matrix composed of observation vectors representing the second time series data, respectively, and the calculation unit calculates a second index value indicating a spatial coincidence formed between the extracted characteristic directions of the first time series data and the extracted characteristic directions of the second time series data, and further includes a determination unit configured to determine that anomalous communication has occurred in the second interval if the second index value calculated by the calculation unit exceeds the determination threshold.

[0010] In addition, in the abnormality management device of the present invention, the time series data of communication volume may be time series data of communication volume for each communication terminal, and may further include a communication management unit configured to instruct the communication terminal that performs communication related to the time series data of communication volume of the managed object to cut off communication when the judgment unit determines that abnormal communication has occurred.

[0011] In addition, in the abnormality management device of the present invention, the time series data of communication volume is time series data of communication volume of the entire communication network, and the device may further include a communication management unit configured to notify that a communication abnormality has occurred in the communication network when the determination unit determines that abnormal communication has occurred.

[0012] In addition, in the abnormality management device according to the present invention, the feature extraction unit may extract a transformation matrix of the normal data including a group of orthonormal basis vectors as the feature direction of the normal data by performing singular value decomposition on the data matrix.

[0013] In order to solve the above-described problems, an anomaly management method according to the present invention includes a feature extraction step of extracting a characteristic direction of normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicating normal communication volumes included in time-series data of communication volumes; a learning step of using the characteristic directions of the normal data extracted in the feature extraction step as training data and learning, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that communication volumes at each time corresponding to each of the characteristic directions of the normal data are normal; a derivation step of deriving a probability distribution for the characteristic direction of abnormal data indicating abnormal communication volumes that deviate from the range of normal communication volumes based on the posterior probability estimated by the probability model learned in the learning step, a probability distribution for the characteristic direction of the normal data, and a prior probability of normality; a calculation step of calculating a first index value that indicates a spatial coincidence formed by the probability distribution for the characteristic direction of the abnormal data derived in the derivation step and the probability distribution for the characteristic direction of the normal data; and a setting step of setting the first index value calculated in the calculation step as a determination threshold for the abnormal communication volumes.

[0014] Furthermore, the anomaly management method according to the present invention may further include a collection step of collecting first time series data of the communication volume observed in a first interval and second time series data of the communication volume observed in a second interval following the first interval as time series data of the communication volume to be managed, wherein the feature extraction step extracts characteristic directions of the first time series data and characteristic directions of the second time series data based on a first data matrix constituted by observation vectors representing the first time series data and a second data matrix constituted by observation vectors representing the second time series data, respectively, and the calculation step calculates a second index value indicating a spatial coincidence formed between the extracted characteristic directions of the first time series data and the extracted characteristic directions of the second time series data, and may further include a determination step of determining that anomalous communication has occurred in the second interval if the second index value calculated in the calculation step exceeds the determination threshold.

[0015] In addition, in the abnormality management method of the present invention, the time series data of communication volume may be time series data of communication volume for each communication terminal, and may further include a communication management step of instructing the communication terminal that performs communication related to the time series data of communication volume of the managed object to cut off communication when it is determined in the determination step that abnormal communication has occurred.

[0016] In addition, in the abnormality management method of the present invention, the time series data of communication volume may be time series data of communication volume of the entire communication network, and the method may further include a communication management step of issuing a notification indicating that a communication abnormality has occurred in the communication network when it is determined in the determination step that abnormal communication has occurred.

[0017] In addition, in the anomaly management method according to the present invention, the feature extraction step may extract a transformation matrix of the normal data including a group of orthonormal basis vectors as the feature direction of the normal data by performing singular value decomposition on the data matrix. [Effects of the Invention]

[0018] According to the present invention, a first index value indicating the spatial coincidence between the probability distribution for the characteristic direction of the anomalous data derived by the derivation unit and the probability distribution for the characteristic direction of the normal data is set as a threshold value for determining anomalous traffic volume. Therefore, anomalous traffic can be managed without collecting a large amount of data on past anomalous traffic. [Brief explanation of the drawings]

[0019] [Figure 1] FIG. 1 is a block diagram showing the configuration of an abnormality management system including an abnormality management device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram for explaining an outline of traffic abnormality data managed by the abnormality management device according to this embodiment. [Figure 3] FIG. 3 is a diagram for explaining the operation of the feature extraction unit included in the abnormality management device according to this embodiment. [Figure 4] FIG. 4 is a diagram for explaining the operation of the learning unit and the derivation unit included in the abnormality management device according to this embodiment. [Figure 5] FIG. 5 is a block diagram showing the hardware configuration of the abnormality management device according to this embodiment. [Figure 6] FIG. 6 is a flowchart showing the operation of the abnormality management device according to this embodiment. [Figure 7] FIG. 7 is a flowchart showing the operation of the abnormality management device according to this embodiment. [Figure 8] FIG. 8 is a flowchart showing the operation of the abnormality management device according to this embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0020] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Preferred embodiments of the present invention will now be described in detail with reference to FIGS.

[0021] [Configuration of anomaly management system] First, an overview of an anomaly management system including an anomaly management device 1 according to an embodiment of the present invention will be described with reference to Fig. 1. The anomaly management system extracts the characteristic direction of normal data, derives the probability distribution of abnormal data based on the probability distribution of normal data estimated by learning a probabilistic model, and sets the maximum singular value based on the probability distribution of normal data and abnormal data as a determination threshold for abnormal communication.

[0022] The fault management system according to this embodiment includes a fault management device 1, a communication terminal 2, a base station 3, and a core network 4. As an example, the fault management system is provided in a 5G mobile communication network, but may also be a network using a fixed line. As shown in FIG. 1, the fault management device 1 is connected to the core network 4 via a network NW such as a LAN, a WAN, or the Internet.

[0023] The communication terminal 2 is realized as a mobile communication terminal such as a smartphone, a tablet computer, a laptop computer, a wearable device, an industrial robot, etc. The communication terminal 2 is equipped with a SIM (Subscriber Identity Module), and the contract profile of the SIM includes identifier information such as an International Mobile Subscriber Identity (IMSI). The communication terminal 2 is uniquely identified by the IMSI.

[0024] The communication terminal 2 is also configured as an IoT device to which a terminal IP address that uniquely identifies the terminal is assigned. In this embodiment, there are n communication terminals 2 (n is a positive integer of 2 or more). The communication terminals 2 connect to an external data network (not shown) from a core network 4 via the base station 3 in which each communication terminal 2 is located.

[0025] Among the multiple communication terminals 2, there are some that communicate at a volume exceeding the set bandwidth, which can cause or threaten traffic congestion. Other communication terminals 2 may also include terminals that engage in sudden or continuous high-volume communications that deviate from normal usage trends, irregular communications, or communications at unconventional times or protocols. Such communications with abnormal volumes that deviate from normal volumes include intentional communications by users of the communication terminals 2, as well as unintentional communications such as DDoS attacks. In this specification, such communications volumes exceeding the set bandwidth are defined as abnormal volumes that deviate from the normal range of communications volumes.

[0026] Fig. 2 is a diagram for explaining abnormal data on communication volume. In Fig. 2, the horizontal axis represents time and the vertical axis represents communication volume, and time series data of abnormal communication volume from a certain communication terminal 2 is shown. In the time period of section a, traffic suddenly increases, and an abnormality in communication volume occurs.

[0027] The base station 3 is composed of a wireless base station compatible with the 5G system, and relays communications between the communication terminal 2 located within the communication area and the core network 4. The base station 3 is connected to the core network 4 via a network such as a backhaul link.

[0028] The core network 4 provides centralized control, routing, management, and security for communications relayed by the base station 3. The core network 4 includes a UPF (User Plane Function) 40 in the U-plane. The core network 4 also includes nodes in the C-plane, such as an AMF (Access and Mobility Management Function) and a UDM (Unified Data Management), which are not shown. Functional nodes in the U-plane and C-plane other than the UPF 40 that the core network 4 includes are not shown in the figure.

[0029] The UPF 40 is a user plane function that processes packets between the base station 3 and a data network such as the Internet. The UPF 40 includes a communication interface 40a for communicating with the abnormality management device 1. The UPF 40 records the communication volume of the communication terminal 2 that performs traffic processing.

[0030] [Function block of the abnormality management device] Next, the functional blocks of the fault management device 1 according to this embodiment will be described with reference to the block diagram of Fig. 1. As shown in Fig. 1, the fault management device 1 includes a collection unit 10, a feature extraction unit 11, a learning unit 12, a derivation unit 13, a calculation unit 14, a setting unit 15, a determination unit 16, a communication management unit 17, and a storage unit 18.

[0031] The collection unit 10 acquires time-series data of communication volume collected by the core network 4 that controls communication between multiple communication terminals 2. The collection unit 10 acquires a history of communication volume for each communication terminal 2 for which traffic processing is performed on the UPF 40. The time-series data of communication volume indicates communication volume for each IMSI. The time-series data of communication volume also indicates communication volume at each time (time period).

[0032] The collection unit 10 collects time series data containing normal communication volumes above a certain level, and passes the data to the feature extraction unit 11. The collection unit 10 also collects time series data of communication volumes of the managed object that are to be subjected to abnormality determination by the determination unit 16. More specifically, the collection unit 10 collects first time series data of the communication volumes observed in a first interval and second time series data of the communication volumes observed in a second interval following the first interval, as time series data of the communication volumes of the managed object.

[0033] The feature extraction unit 11 extracts the feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicative of normal communication volume included in the time-series data of communication volume. More specifically, the feature extraction unit 11 extracts a transformation matrix U of the normal data including a group of orthonormal basis vectors as the feature direction of the normal data by performing singular value decomposition on the data matrix composed of a plurality of observation vectors representing normal data.

[0034] Furthermore, the feature extraction unit 11 extracts feature directions of the first time series data and the second time series data based on a first data matrix composed of observation vectors representing the first time series data and a second data matrix composed of observation vectors representing the second time series data, both of which are included in the time series data of the communication volume to be managed. The feature extraction unit 11 performs singular value decomposition on the first data matrix to extract a transformation matrix U1 of the first time series data including a group of orthonormal basis vectors as the feature direction of the first time series data. Similarly, the feature extraction unit 11 performs singular value decomposition on the second data matrix to extract a transformation matrix U2 of the second time series data including a group of orthonormal basis vectors as the feature direction of the second time series data.

[0035] FIG. 3 is a diagram for explaining the feature directions of normal data extracted by the feature extraction unit 11. If the total number of data points in each interval is N, Data points t1 to t are indicated by white circles Nindicates the traffic volume observed at each time (time period) collected by the collection unit 10, and here, time series data of normal traffic volume is shown. Therefore, the traffic volume observed in the n-th time period is expressed as t n The feature extraction unit 11 uses a sliding window with a window width M to convert the time series data of normal communication volume into a set of M-dimensional vectors indicated by the arrows of each sliding window into a plurality of observation vectors. The time series data consisting of observed values ​​of communication volume with length L is expressed as L=N-M+1.

[0036] The observation vector, which is a partial time series of length M sequentially extracted by the feature extraction unit 11 by moving the sliding window from left to right in the time series data of normal communication volume, is expressed by the following equation (1).

number

[0037] Here, the data matrix X=[x (1) ,…,x (L) ] (an M×L-dimensional real-valued matrix), consider the linear combination Xν of the following equation (2).

number

[0038] From the above equation (2), ν T Under the constraint ν=1, ||Xν|| 2 This can be achieved by introducing the Lagrangian function of the following equation (3) obtained using the multiplier γ.

number

[0039] In order for the above equation (3) to be maximized, 2X differentiated with respect to the vector ν T The value of Xν-2γν is 0. Therefore, the following conditional expression (4) is obtained.

number

[0040] From the above equation (4), X T It can be seen that the eigenvalue of X is γ and the eigenvector is ν. Furthermore, the vector μ is defined by the following equation (5).

number

[0041] Using the above equations (5) and (4), the relationship shown in the following equation (6) can be found.

number

[0042] Furthermore, multiplying both sides of the above equation (4) by X and using the above equation (5) yields the following relational equation (7).

number

[0043] By applying the above equation (5) to the above equation (7), the following relational expression (8) is obtained.

number

[0044] Here, U and V are set as follows:

number

[0045] The above equation (9) can be expressed as the following equation (10).

number

[0046] U is an orthogonal matrix, and U T By multiplying and transposing both sides of the above equation (10), the relationship of the following equation (11) is obtained.

number

[0047] The above equation (11) is called the singular value decomposition of X. Let U be the left singular vector, V be the right singular vector, and Γ 1 / 2 are called singular values. That is, U is a transformation matrix that represents the feature direction, which is the main direction or pattern of normal data. V represents the axis transformation, which is the direction to which the vector is projected. Γ represents the importance of each feature direction.

[0048] The matrix U of left singular vectors is expressed by the following equation (12).

number

[0049] for example, In the interval (N=1000) If there are 10,000 pieces of normal data with a communication volume, 10,000 left singular vectors U are obtained. Each component vector μ of the left singular vector U in the normal data xx The probability distribution of is obtained by the learning unit 12 using the maximum likelihood estimation method.

[0050] The learning unit 12 uses the feature directions of the normal data extracted by the feature extraction unit 11 as training data to learn, by maximum likelihood estimation, parameters of a probability model that outputs the posterior probability that the communication volume at each time corresponding to each feature direction of the normal data is normal. In a situation where there is little abnormal data, the learning unit 12 learns the probability model by maximum likelihood estimation using the feature directions of the normal data.

[0051] Here, each element μ of the matrix of the left singular vector U xx Let x be the communication volume at a certain observation point in a certain time period (e.g., time slot number) (μ xx = x). In addition, the density function of normal data is expressed as ρ d (μ xx ), and the density function of the abnormal data is ρ g (μxx ) are defined as follows: d (μ xx )=ρ d (x), ρ g (μ xx )=ρ g (x).

number

[0052] In the above equation (13), y=1 indicates the normal class and y=0 indicates the abnormal class. d (μ xx ) is the communication volume μ when it belongs to the normal class y=1. xx shows the tendency of appearance of ρ g (x) is the communication volume μ when it belongs to the abnormal class y=0. xx The probability distribution of both normal and abnormal data follows a normal distribution.

[0053] The density ratio γ(μ xx ) is expressed by the following equation (14).

number

[0054]

number

[0055] Here, if π=ρ(y=1), the above equation (15) can be further expressed as the following equation (16).

number

[0056] Therefore, first, the observed value μ xx The posterior probability ρ(y=1|μ xx ) is calculated. Observed value μ xx If there is a large amount of xx )≒ρ(μ xx |y=1) can be approximated. In other words, the posterior probability ρ(y=1|μ xx ) can be estimated. For the sake of explanation, we will use the observed value μ xx is denoted as x. At an observation point x n Assuming that the normal distribution is assumed, it is defined as shown in the following equation (17).

number

[0057] Furthermore, the output of the probabilistic model f(x n ) can be expressed as a linear combination as shown in the following equation (18).

number

[0058]

number

[0059]

number

[0060] Furthermore, the communication volume f(x n ) and the actual normal traffic volume t nThe average error from the (teacher signal) is the variance σ of the normal distribution shown in the following equation (21). 2 The value becomes

number

[0061] In this way, when a linear combination of probability models estimates the posterior probability that communication volume is normal for an input x, each observation t is calculated based on the estimated value f(x n ) is assumed to follow a normal distribution with mean x n ,t n ) by maximum likelihood estimation, we can obtain the parameters w and error variance σ of the probability model. 2 Estimate.

[0062] 4 is a diagram for explaining the configuration of the learning unit 12 and the derivation unit 13. As shown in FIG. xx Therefore, the learning unit 12 calculates each component μ of the matrix U of left singular vectors obtained by performing singular value decomposition on the data matrix of normal data. xx Probability distribution ρ for d (μ xx ) is calculated. If there is a matrix U of 10,000 left singular vectors, each component μ xx Ten thousand normal probability distributions are calculated. The learning unit 12 calculates the components μ xx As described above, there are as many matrices U of left singular vectors as there are normal data. Therefore, the learning unit 12 performs maximum likelihood estimation the number of times corresponding to the number of matrices U of left singular vectors.

[0063] Here, again μ xx By expressing x as the normal data posterior probability ρ(y=1|x), we can approximately estimate ρ(y=1|x)≒q w The relationship is (y=1|x). The posterior probability that the input communication volume x is normal is estimated as q w Based on (y=1|x), the cross entropy is defined as the loss function L as shown in the following equation (22).

number

[0064] The convergence value (minimum value) of the loss function L in the above equation (22) is expressed by the following equation (23).

number

[0065] The derivation unit 13 transforms the above equation (23) into the following equation (24), and calculates the density function ρ g Derive (x).

number

[0066] x to μ xx When substituted, the above equation (24) becomes the following equation (25).

number

[0067] In the above equation (25), the probability distribution of normal data, i.e., the density function of normal data, ρ d (μ xx ) is calculated from the normal data collected by the collection unit 10. The prior probability π of normal data is much larger than the prior probability (1-π) of abnormal data, so it can be set to, for example, 0.99. Furthermore, the observed value μ xx For (=x), the log likelihood lnq when y=1 w (y=1|μ xx ) is calculated by maximum likelihood estimation based on a large amount of normal data (teacher signal), as shown in the above equations (18) to (21). In this way, even if there is a small amount of abnormal data, the probability distribution of abnormal data can be calculated from the normal data.

[0068] The derivation unit 13 calculates the estimated value q of the posterior probability of normal data estimated by the probability model learned by the learning unit 12. w (y=1|μ xx) and the density function ρ for the feature direction of normal data d (μ xx ) and the prior probability π of normality, the density function ρ for the feature direction of the abnormal data that indicates abnormal traffic volume outside the range of normal traffic volume is calculated. g (μ xx ) is derived. As mentioned above, the posterior probability estimate of normal data, q w (y=1|μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) is normally distributed, the density function ρ g (μ xx ) is also normally distributed.

[0069] The derivation unit 13 calculates the estimated value q of the posterior probability of normal data. w (y=1|μ xx ) (for example, 10,000) and the same number of abnormal data density functions ρ g (μ xx ) of the density function ρ g (μ xx ) is the sum of the anomalous data density function ρ g (μ xx ) is the final solution. The derivation unit 13 also calculates the density function ρ of normal data that is normally distributed. d (μ xx ) is the density function ρ d (μ xx ) is the final solution.

[0070] Here, the density function ρ for the feature direction of normal data is d (μ xx ) and the density function ρ for the feature direction of the abnormal data g (μ xx ) are expressed by the following matrix (26).

number

[0071] The calculation unit 14 calculates the density function ρ g (μ xx ) (probability distribution) and the density function ρ for the feature direction of normal data d (μ xx ) (probability distribution) for the characteristic direction of the abnormal data. g (μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) as the first index value. Specifically, the calculation unit 14 calculates the maximum singular value of the matrix formed based on the matrix 2-norm ∥ρ d (μ xx ) T ρ g (μ xx )||2 is calculated as the first index value.

[0072]

number

[0073] The sum of the vector components of each column in the above equation (27) is S1, ,S M Then, the matrix 2-norm is calculated by the following equation (28).

number

[0074] The calculation unit 14 also calculates a second index value indicating the spatial degree of coincidence formed between the feature direction of the first time series data and the feature direction of the second time series data included in the time series data of the communication volume of the management target extracted by the feature extraction unit 11. More specifically, the calculation unit 14 calculates, as the second index value, the matrix 2 norm of the transposed matrix U1 of the left singular vectors of the first time series data and the matrix U2 of the left singular vectors of the second time series data.

[0075] The setting unit 15 sets the first index value calculated by the calculation unit 14 as a threshold for determining an abnormal traffic volume.

[0076] If the second index value calculated by the calculation unit 14 exceeds the threshold value, the determination unit 16 determines that abnormal communication has occurred in the second section.

[0077] When the determination unit 16 determines that the communication is abnormal, the communication management unit 17 instructs the communication terminal 2 that performs communication related to the time-series data of the communication volume to be determined to cut off the communication. For example, the communication management unit 18 specifies the IMSI and transmits an instruction to cut off the communication to the core network 4. Specifically, the communication management unit 17 can be configured to transmit a control request to the policy control function (PCF) or the session management function (SMF) to stop the communication of the IMSI, and invalidate the communication session of the communication terminal 2.

[0078] The storage unit 18 stores the threshold value set by the setting unit 15.

[0079] [Hardware configuration of the fault management device] Next, an example of a hardware configuration for realizing the abnormality management device 1 having the above-described functions will be described with reference to FIG.

[0080] 5, the fault management device 1 can be realized by, for example, a computer including a processor 102, a main memory device 103, a communication interface 104, an auxiliary memory device 105, and an input / output (I / O) 106 connected via a bus 101, and a program for controlling these hardware resources. Furthermore, the fault management device 1 includes a display device 107.

[0081] The processor 102 is realized by a CPU, a GPU, an FPGA, an ASIC, or the like.

[0082] The main memory device 103 pre-stores programs for the processor 102 to perform various controls and calculations. The processor 102 and the main memory device 103 implement the functions of the abnormality management device 1, such as the collection unit 10, feature extraction unit 11, learning unit 12, derivation unit 13, calculation unit 14, setting unit 15, judgment unit 16, and communication management unit 17 shown in FIG.

[0083] The communication interface 104 is an interface circuit for connecting the abnormality management device 1 to various external electronic devices via a network.

[0084] The auxiliary storage device 105 is composed of a readable / writable storage medium and a drive for reading and writing various information such as programs and data from and to the storage medium. The auxiliary storage device 105 can use a semiconductor memory such as a hard disk or flash memory as the storage medium.

[0085] The auxiliary storage device 105 has a program storage area for storing an abnormality management program. The auxiliary storage device 105 also has a program storage area for storing a feature extraction program for extracting characteristic directions of normal data using the subspace method executed by the abnormality management device 1. The auxiliary storage device 105 also has a program storage area for storing a learning program for a probability model executed by the abnormality management device 1. The auxiliary storage device 105 realizes the storage unit 18 described in FIG. 1. Furthermore, the auxiliary storage device 105 may have, for example, a backup area for backing up the above-mentioned data, programs, etc.

[0086] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.

[0087] The display device 107 is configured by an organic EL display, a liquid crystal display, etc. The display device 107 can display time series data of the communication volume of the observation data on a screen.

[0088] [Operation of the abnormality management device] Next, the operation of the abnormality management device 1 having the above-described configuration will be described with reference to the flowcharts of FIGS.

[0089] 6, first, the collection unit 10 collects time-series data of communication volume that includes a certain amount or more of normal data (step S1). The collection unit 10 collects time-series data of communication volume in which, for example, 99% of the data constituting the time-series data of communication volume is normal data. The collection unit 10 collects time-series data of communication volume of each communication terminal 2 from the UPF 40.

[0090] Next, the feature extraction unit 11 extracts the feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data (step S2). The feature extraction unit 11 extracts a plurality of observation vectors of a partial time series by shifting a sliding window with a window width M for each time period as shown in FIG. 3 for the time series data of the communication volume of the normal data. The feature extraction unit 11 performs singular value decomposition on the data matrix X that brings together the observation vectors expressed by the above formula (1), and extracts the transformation matrix U expressed by the above formulas (11) and (12). In step S2, for example, Section (N = 1000), 10,000 transformation matrices U are calculated.

[0091] Next, the learning unit 12 uses the feature directions of the normal data extracted by the feature extraction unit 11 in step S2 as training data to learn parameters of a probability model that outputs the posterior probability that the communication volume at each time corresponding to each feature direction of the normal data is normal by maximum likelihood estimation (step S3). Thereafter, the derivation unit 13 derives a probability distribution for the feature directions of the abnormal data, which indicates an abnormal communication volume outside the range of normal communication volume, based on the posterior probability of the normal data estimated by the probability model learned by the learning unit 12 in step S3, the probability distribution for the feature directions of the normal data, and the prior probability of normality (step S4).

[0092] 7 is a flowchart illustrating steps S3 and S4 in more detail. As shown in step S30 of FIG. 7, the learning unit 12 uses the transformation matrix U of the normal data obtained in step S2 as training data, and calculates the components μ xx For each, the communication volume μ xx The posterior probability estimate q is normal w (y=1|μ xx ) parameters w,σ 2 is learned by maximum likelihood estimation (step S30). If there are 10,000 transformation matrices U of normal data, 10,000 estimated values ​​q w (y=1|μ xx ) is obtained. In step S30, the learning unit 12 performs learning by maximum likelihood estimation in accordance with the above equations (18) to (21).

[0093] Furthermore, the learning unit 12 calculates the components μ of the transformation matrix U of the normal data. xx Normal communication volume μ xx Based on the normal data density function ρ d (μ xx ) (normal distribution) is estimated (step S31). In step S31, as shown in FIG. 4, maximum likelihood estimation is performed for each column vector of the transformation matrix U, and each component μ xx The density function ρ of normal data for d (μ xx In step S31, maximum likelihood estimation is performed for each of the multiple transformation matrices U.

[0094] Next, the derivation unit 13 adds the log likelihood lnq of the posterior probability calculated in step S30 to the above equation (25). w (y=1|μ xx ), the density function ρ of the normal data obtained in step S31 d (μ xx ), and the prior probability of normal data π (e.g., 0.99) to obtain the density function ρ of the abnormal data. g (μ xx ) is derived (step S33). The density function ρ g (μ xx ) is calculated by the log likelihood lnqw (y=1|μ xx ) is the same number as the number of

[0095] Thereafter, the process proceeds to step S5 in Fig. 6. Subsequently, in step S4, the calculation unit 14 calculates the density function ρ g (μ xx ) (probability distribution) and the density function ρ for the feature direction of normal data d (μ xx ) (probability distribution) for the characteristic direction of the abnormal data is calculated (step S5). g (μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) is the maximum singular value of the matrix constructed based on the matrix 2-norm ||ρ d (μ xx ) T ρ g (μ xx )||2 is calculated as the first index value.

[0096] Next, the setting unit 15 sets the matrix 2 norm calculated in step S5 as a threshold for determining abnormal communication volume (step S6). After that, the collection unit 10 collects time series data of communication volume of the management target (step S7). Specifically, as shown in FIG. 8, the collection unit 10 collects time series data of communication volume of the management target from time period t1 to t N The collecting unit 10 collects first time series data of the traffic volume in the first section up to the time period t N+1 From t N+N The collecting unit 10 collects second time series data of the communication volume in the second section up to and including the first time series data and the second time series data by sliding a sliding window having a window width M from left to right.

[0097] Next, the feature extraction unit 11 performs singular value decomposition on the first data matrix to extract a transformation matrix U1 of the first time series data, which includes a group of orthonormal basis vectors, as the feature direction of the first time series data. Similarly, the feature extraction unit 11 performs singular value decomposition on the second data matrix to extract a transformation matrix U2 of the second time series data, which includes a group of orthonormal basis vectors, as the feature direction of the second time series data (step S8). Here, as shown in "step S8" in FIG. 8, the sliding windows for the first and second intervals are shifted to the right by one time period, and singular value decomposition is performed on each of the first and second data matrices. Furthermore, FIG. 8 shows that the transformation matrices U1 and U2 are extracted as matrices of left singular vectors. In this way, the feature extraction unit 11 performs singular value decomposition to extract the transformation matrices U1 and U2 each time the sliding window is shifted.

[0098] Next, the calculation unit 14 calculates a second index value indicating the spatial degree of coincidence formed between the feature direction of the first time series data observed in the first interval extracted in step S8 and the feature direction of the second time series data observed in the second interval (step S9). The calculation unit 14 calculates the maximum singular value, i.e., the matrix 2-norm ||U1 T U2∥2 is calculated as the second index value (“Step S9” in FIG. 8).

[0099] Next, in step S9, if the second index value calculated by the calculation unit 14 exceeds the threshold value set in step S6, the determination unit 16 determines that abnormal communication has occurred in the second section (step S10). As shown in Fig. 8, the first section and the second section are sequentially shifted to the right, and the processes from step S7 to step S10 are repeated each time.

[0100] Next, the communication management unit 17 identifies the IMSI of the communication terminal 2 that performed the communication related to the time series data of the communication volume that was determined to be abnormal communication, and instructs the core network 4 to cut off the communication by specifying the identified IMSI (step S11).

[0101] As described above, the abnormality management device 1 according to this embodiment performs singular value decomposition on the data matrix of normal data using the subspace method, and uses the matrix U of the obtained left singular vectors as training data to learn the parameters of a probabilistic model that outputs the posterior probability that the communication volume is normal by maximum likelihood estimation, thereby estimating the posterior probability that the communication volume is normal. Furthermore, the density function of the abnormal data is derived based on the estimated value of the posterior probability, the density function of the normal data, and the prior probability of the normal data. Furthermore, the maximum singular value of the matrix of the derived density function of the abnormal data and the density function of the normal data is set as the threshold for determining abnormal communication volume. Therefore, abnormal traffic can be managed without collecting a large amount of past abnormal traffic data.

[0102] Furthermore, the abnormality management device 1 according to this embodiment collects time-series data on the communication volume for each communication terminal 2 and determines the abnormal data, thereby identifying the communication terminal 2 performing abnormal communication and then cutting off the communication. This allows for more effective traffic management of the communication network.

[0103] [Variations] Next, a modified example of this embodiment will be described. In the above-described embodiment, the collection unit 10 collects time-series data on the communication volume for each communication terminal 2, and identifies a communication terminal 2 that is performing anomalous communication. In contrast, in this modified example, the collection unit 10 collects communication volume for the entire communication network, and detects anomalous communication that occurs in the entire communication network. The following description will focus on configurations that differ from the above-described embodiment.

[0104] In the abnormality management device 1 according to the modified example, the collection unit 10 collects time-series data on the communication volume of the entire communication network. Furthermore, when the determination unit 16 determines that communication is abnormal, the communication management unit 17 issues a notification indicating that a communication abnormality has occurred in the communication network. For example, the communication management unit 17 can issue a notification to an external management and monitoring system. Furthermore, the learning unit 12 learns the parameters of a probabilistic model based on the time-series data on the communication volume of the entire communication network.

[0105] In this way, according to the abnormality management device 1 of the modified example, even if there is little abnormal data, it is possible to build a database of abnormal data based on normal data and detect abnormal communications throughout the entire communication network.

[0106] In the embodiment described above, the anomaly management system is described as a system conforming to the 5G standard, but the communication standard may be 3G, 4G / LTE, 6G, etc. Furthermore, the anomaly management system is not limited to a mobile communication network, and may be a network using a fixed line as described above. In this case, the system may be configured to collect communication volume logs via a wireless router or wireless access point.

[0107] The above describes embodiments of the abnormality management device and abnormality management method of the present invention, but the present invention is not limited to the described embodiments, and various modifications that a person skilled in the art can conceive are possible within the scope of the invention described in the claims. [Explanation of symbols]

[0108] 1...abnormality management device, 2...communication terminal, 3...base station, 4...core network, 10...collection unit, 11...feature extraction unit, 12...learning unit, 13...derivation unit, 14...calculation unit, 15...setting unit, 16...judgment unit, 17...communication management unit, 18...memory unit, 101...bus, 102...processor, 103...main memory device, 104...communication interface, 105...auxiliary memory device, 106...input / output I / O, 107...display device, NW...network.

Claims

1. a feature extraction unit configured to extract a feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicating normal communication volume included in the time-series data of communication volume; a learning unit configured to learn, by maximum likelihood estimation, parameters of a probabilistic model that outputs a posterior probability that the communication volume at each time corresponding to each of the feature directions of the normal data is normal, using the feature directions of the normal data extracted by the feature extraction unit as training data; and a derivation unit configured to derive a probability distribution for a characteristic direction of abnormal data indicating an abnormal communication volume that deviates from the range of normal communication volume, based on the posterior probability estimated by the probability model learned by the learning unit, a probability distribution for a characteristic direction of the normal data, and a prior probability of normality; a calculation unit configured to calculate a first index value indicating a spatial degree of coincidence formed between the probability distribution for the characteristic direction of the abnormal data derived by the derivation unit and the probability distribution for the characteristic direction of the normal data; a setting unit configured to set the first index value calculated by the calculation unit as a determination threshold value for the abnormal communication volume; An abnormality management device comprising:

2. 2. The abnormality management device according to claim 1, a collection unit configured to collect first time series data of the communication volume observed in a first interval and second time series data of the communication volume observed in a second interval following the first interval as time series data of the communication volume to be managed, the feature extraction unit extracts feature directions of the first time series data and feature directions of the second time series data based on a first data matrix constituted by observation vectors representing the first time series data and a second data matrix constituted by observation vectors representing the second time series data, the calculation unit calculates a second index value indicating a degree of spatial coincidence formed between the extracted characteristic direction of the first time series data and the extracted characteristic direction of the second time series data; The communication system further includes a determination unit configured to determine that an abnormal communication has occurred in the second section when the second index value calculated by the calculation unit exceeds the determination threshold value. An abnormality management device characterized by:

3. 3. The abnormality management device according to claim 2, the time series data of communication volume is time series data of communication volume for each communication terminal, a communication management unit configured to instruct, when the determination unit determines that abnormal communication has occurred, to cut off communication with a communication terminal that performs communication related to the time-series data of the communication volume of the management target. An abnormality management device comprising:

4. 3. The abnormality management device according to claim 2, the time series data of the communication volume is time series data of the communication volume of the entire communication network, a communication management unit configured to, when the determination unit determines that abnormal communication has occurred, issue a notification indicating that a communication abnormality has occurred in the communication network. An abnormality management device comprising:

5. 2. The abnormality management device according to claim 1, The feature extraction unit extracts a transformation matrix of the normal data including a group of orthonormal basis vectors as a feature direction of the normal data by performing singular value decomposition on the data matrix. An abnormality management device characterized by:

6. A computer-implemented anomaly management method, comprising: a feature extraction step of extracting a feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicating normal communication volume included in the time-series data of communication volume; a learning step of learning, by maximum likelihood estimation, parameters of a probabilistic model that outputs a posterior probability that the communication volume at each time corresponding to each of the feature directions of the normal data is normal, using the feature directions of the normal data extracted in the feature extraction step as training data; a derivation step of deriving a probability distribution for a characteristic direction of abnormal data indicating an abnormal communication volume that deviates from the range of normal communication volume, based on the posterior probability estimated by the probability model learned in the learning step, a probability distribution for a characteristic direction of the normal data, and a prior probability of normality; a calculation step of calculating a first index value indicating a spatial degree of coincidence formed between the probability distribution for the characteristic direction of the abnormal data derived in the derivation step and the probability distribution for the characteristic direction of the normal data; a setting step of setting the first index value calculated in the calculation step as a determination threshold value for the abnormal communication volume; An abnormality management method comprising:

7. 7. The abnormality management method according to claim 6, further comprising a collection step of collecting first time series data of the communication volume observed in a first interval and second time series data of the communication volume observed in a second interval following the first interval as time series data of the communication volume to be managed, the feature extraction step extracts feature directions of the first time series data and feature directions of the second time series data based on a first data matrix constituted by observation vectors representing the first time series data and a second data matrix constituted by observation vectors representing the second time series data, the calculating step calculates a second index value indicating a degree of spatial coincidence formed between the extracted characteristic direction of the first time series data and the extracted characteristic direction of the second time series data; Further, the method includes a determination step of determining that an abnormal communication has occurred in the second section when the second index value calculated in the calculation step exceeds the determination threshold value. An abnormality management method characterized by:

8. The abnormality management method according to claim 7, the time series data of communication volume is time series data of communication volume for each communication terminal, and a communication management step of issuing an instruction to cut off communication with a communication terminal that performs communication related to the time-series data of the communication volume of the management target when it is determined in the determination step that abnormal communication has occurred. An abnormality management method comprising:

9. The abnormality management method according to claim 7, the time series data of the communication volume is time series data of the communication volume of the entire communication network, and a communication management step of notifying the user that a communication abnormality has occurred in the communication network when the determination step determines that an abnormal communication has occurred. An abnormality management method comprising:

10. 7. The abnormality management method according to claim 6, The feature extraction step extracts a transformation matrix of the normal data including a group of orthonormal basis vectors as a feature direction of the normal data by performing singular value decomposition on the data matrix. An abnormality management method characterized by:

Citation Information

Patent Citations

  • Learning device, learning method, and program

    JP2019070965A

  • Anomaly detection device and anomaly detection method

    JP7565471B1

  • Abnormal management device, abnormal management method, and abnormal management system

    JP7706675B1

  • Abnormal management device and abnormal management method

    JP7710633B1

  • Traffic volume upper limit value prediction device, method and program

    JP2015216585A