Estimation device, estimation method, and estimation program

The estimation device uses spectrogram conversion and non-negative tensor factorization to simplify the estimation of communication purpose, overcoming DPI inefficiencies and eliminating the need for user interaction or expert inference.

JP7789526B2Active Publication Date: 2025-12-22NTT DOCOMO BUSINESS INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021181863
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-08
Publication Date
2025-12-22
Estimated Expiration
2041-11-08

AI Technical Summary

Technical Problem

DPI devices are expensive and inefficient for processing large amounts of network traffic, and without direct packet analysis, estimating communication purpose becomes cumbersome and requires user interaction or expert inference.

Method used

An estimation device that converts traffic into a spectrogram via frequency decomposition and uses non-negative tensor factorization to decompose time components, allowing for easy estimation of communication use based on pre-defined templates.

Benefits of technology

Enables efficient and automated estimation of communication purpose without the need for DPI devices, reducing computational complexity and user intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007789526000001
    Figure 0007789526000001
  • Figure 0007789526000002
    Figure 0007789526000002
  • Figure 0007789526000003
    Figure 0007789526000003
Patent Text Reader

Abstract

To enable simply estimating an application of communication of a line of a processing object.SOLUTION: An estimation device 10 comprises: a second frequency decomposition unit 1423 that converts a traffic of a line of a processing object to a spectrogram by means of frequency decomposition; a second non-negative value tensor factorization unit 1424 that fixes one factor at a template of a time component factor depending on a pre-acquired predetermined application and decomposes a time component into time tensors by means of non-negative value tensor factorization of the spectrogram converted by the second frequency decomposition unit 1423; and an application estimation unit 1425 that estimates an application for each time for the line of the processing object on the basis of a decomposition result obtained by means of the second non-negative value tensor factorization unit 1424.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an estimation device, an estimation method, and an estimation program. [Background technology]

[0002] For telecommunications carriers and corporate information system administrators, analyzing the purpose and usage of communications flowing over a network is important for network maintenance and operation. Traditionally, methods using DPI (Deep Packet Inspection) devices that directly analyze the payload inside packets have been widely used to analyze the purpose and usage of communications flowing over a network. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-141236 Summary of the Invention [Problem to be solved by the invention]

[0004] This DPI device is expensive and, due to its ability to analyze the inside of packets, is not suited to processing large amounts of traffic, making it a bottleneck in network configuration.

[0005] In addition, in the past, the purpose of communication was estimated by introducing collection and analysis devices such as DPI devices, but if packets cannot be analyzed directly, the method using the DPI device cannot estimate the purpose.

[0006] Therefore, in the absence of a DPI device, the purpose of communication was determined by performing cumbersome processes such as asking the user (or network administrator) about the purpose, or having an expert infer the purpose from traffic waveforms, etc.

[0007] The present invention has been made in view of the above, and aims to provide an estimation device, an estimation method, and an estimation program that can easily estimate the communication use of a line to be processed. [Means for solving the problem]

[0008] In order to solve the above-mentioned problems and achieve the object, the estimation device according to the present invention is characterized by having a first decomposition unit that converts traffic of a line to be processed into a spectrogram by frequency decomposition, a second decomposition unit that fixes one factor to a template of time component factors corresponding to a predetermined use that has been acquired in advance, and decomposes the time component of the spectrogram converted by the first decomposition unit into a time tensor by non-negative tensor factorization, and an estimation unit that estimates the use of the line to be processed by time based on the decomposition results by the second decomposition unit. [Effects of the Invention]

[0009] According to the present invention, the communication purpose of the line to be processed can be easily estimated. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a block diagram illustrating an example of a configuration of an estimation device according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the data configuration of template data. [Figure 3] FIG. 3 is a diagram illustrating the flow of processing by the pre-processing unit. [Figure 4] FIG. 4 is a diagram illustrating the flow of processing by the estimation unit. [Figure 5] FIG. 5 is a flowchart showing the procedure of the pre-processing according to the embodiment. [Figure 6] FIG. 6 is a flowchart illustrating a processing procedure of the estimation process according to the embodiment. [Figure 7] FIG. 7 is a diagram showing another example of the data structure of the template data. [Figure 8]FIG. 8 is a diagram illustrating a computer that executes a program. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, embodiments of an estimation device, an estimation method, and an estimation program according to the present application will be described in detail with reference to the accompanying drawings. Note that the estimation device, the estimation method, and the estimation program according to the present application are not limited to these embodiments.

[0012] In the following embodiments, the estimation device and the flow of the estimation process in the embodiments will be described in order, and finally, the effects of the embodiments will be described.

[0013] [Embodiment Mode] First, an embodiment will be described. In this embodiment, the purpose of communication is estimated at each time based on the waveform of communication volume, rather than estimating the purpose from packet or flow (5-tuple) information. In this embodiment, traffic is decomposed into several factors by non-negative tensor factorization, and the purpose is estimated from the characteristics of the factors after decomposition.

[0014] In this case, in this embodiment, one factor is fixed to a template of time component factors corresponding to a predetermined application that has been acquired in advance, and the time components of the traffic spectrogram are decomposed into time tensors by non-negative tensor factorization.

[0015] In this manner, in the embodiment, while the template for the intended use is fixed, nonnegative tensor factorization is performed to separate the waveform into factors for the intended use and factors for other uses. Then, in the embodiment, based on the results of this separation, it is determined for each time period which of the factors for the intended use or the factors for other uses is dominant, thereby estimating the use at that time.

[0016] [Configuration of the estimation device] The configuration of an estimation device according to an embodiment will be described below: Fig. 1 is a block diagram showing an example of the configuration of an estimation device according to an embodiment.

[0017] As shown in FIG. 1, an estimation device 10 according to the embodiment includes a communication unit 11, an input / output unit 12, a storage unit 13, and a control unit .

[0018] The communication unit 11 is a communication interface that transmits and receives various information to and from other devices (for example, network devices such as transfer devices) connected via a network.

[0019] The input / output unit 12 accepts information input by operation of the user of the estimation device 10, and displays and outputs the information to present it to the user. The input / output unit 12 is, for example, an input / output device such as a display, a speaker, a keyboard, a mouse, a microphone, or a touch panel.

[0020] The storage unit 13 is a storage device such as a hard disk drive (HDD), a solid state drive (SSD), or an optical disk. Note that the storage unit 13 may be a rewritable semiconductor memory such as a random access memory (RAM), a flash memory, or a non-volatile static random access memory (NVSRAM). The storage unit 13 stores traffic data 131 including traffic collected for template registration or usage estimation, and template data 132.

[0021] Template data 132 includes templates of time component factors according to various uses. Fig. 2 is a diagram showing an example of the data configuration of template data 132. Template data 132 has a template item for storing templates and an item for uses corresponding to the templates.

[0022] For example, template T1 corresponds to human processing, specifically business processing applications, specifically general human business use, and is a component that includes the characteristic of being active during the day. Furthermore, template T2 corresponds to data processing applications by machines other than humans, specifically batch processing by machines and communications at fixed times (such as updates), and is a component that includes the characteristic of being active regardless of whether it is daytime or nighttime.

[0023] The control unit 14 controls the entire estimation device 10. The control unit 14 is, for example, an electronic circuit such as a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array). The control unit 14 also has an internal memory for storing programs that define various processing procedures and control data, and executes each process using the internal memory. The control unit 14 also functions as various processing units by running various programs. The control unit 14 has a pre-processing unit 141 and an estimation unit 142.

[0024] The pre-processing unit 141 performs a process of registering in advance a template of a time component factor according to a predetermined application. The pre-processing unit 141 has a first collecting unit 1411, a first frequency decomposition unit 1412 (third decomposition unit), a first non-negative tensor factorization unit 1413 (fourth decomposition unit), a registration information receiving unit 1414 (receiving unit), and a template registration unit 1415 (registration unit). Figure 3 is a diagram illustrating the processing flow of the pre-processing unit 141.

[0025] The first collection unit 1411 collects traffic from a plurality of lines for template registration. For example, the first collection unit 1411 collects traffic from a plurality of lines over a certain period of time ((1) in FIG. 3). Here, it is desirable that the plurality of lines are lines used for various purposes.

[0026] The first frequency decomposition unit 1412 converts the traffic of multiple lines collected by the first collection unit 1411 into a spectrogram by frequency decomposition. The first frequency decomposition unit 1412 normalizes the collected traffic and then converts it into a spectrogram by frequency decomposition ((2) in FIG. 3). Here, the final data format is expressed as a tensor of line axis x frequency axis x time axis. Note that the time axis may be divided into multiple axes such as date, hour, month, and year. This is because traffic activity generally changes not according to date but according to time.

[0027] The first nonnegative tensor factorization unit 1413 decomposes the time components of the spectrogram transformed by the first frequency decomposition unit 1412 into time tensors using nonnegative tensor factorization. Nonnegative tensor factorization is a method for extracting patterns from nonnegative tensor data. A tensor represents a multidimensional array. In nonnegative tensor factorization, the traffic spectrogram is factorized at the granularity of line, frequency, and time by expressing the data structure as a tensor of second order or higher.

[0028] The first nonnegative tensor factorization unit 1413 decomposes each component into multiple factors as a line tensor, a frequency tensor, and a time tensor by nonnegative tensor factorization ((3) in FIG. 3). The first nonnegative tensor factorization unit 1413 outputs the line tensor, the frequency tensor, and the time tensor as the factorization results from the input / output unit 12.

[0029] The registration information receiving unit 1414 receives input of identification information that identifies a factor of a time component corresponding to a predetermined application from the decomposed time tensor. For example, an expert analyzes the time tensor output from the estimating device 10 and identifies factor W1 among the factors as a factor having an activity pattern that is thought to be a business application by a human ((4) in FIG. 3). Then, the expert inputs identification information that identifies factor W1 as a template of a factor of a time component corresponding to a process (business process) by a human to the estimating device 10 via the input / output unit 12.

[0030] The template registration unit 1415 registers a time component factor corresponding to a predetermined application as a template of a time component factor according to the predetermined application, based on the specific information received as input by the registration information receiving unit 1414. Specifically, the template registration unit 1415 registers factor W1 (see FIG. 3) in the template data 132 as template T1 of a time component factor corresponding to human processing (business processing) ((4) in FIG. 3). Furthermore, when it is desired to separate applications involving machine batch processing, the expert may identify in advance a factor having an activity pattern that is thought to be machine batch processing, and may register this factor in the estimating device 10 as template T2 corresponding to machine batch processing.

[0031] The estimation unit 142 separates the line to be processed into factors for the predetermined use and factors for other uses using a template for the predetermined use, and estimates whether the use for each time period is the predetermined use or other uses. The estimation unit 142 has a second collection unit 1421, a use selection unit 1422, a second frequency decomposition unit 1423 (first decomposition unit), a second non-negative tensor factorization unit 1424 (second decomposition unit), and a use estimation unit 1425 (estimation unit). Figure 4 is a diagram illustrating the processing flow of the estimation unit 142.

[0032] The second collection unit 1421 collects traffic of a line to be processed. The second collection unit 1421 collects traffic for a certain period of time for one line ((1) in FIG. 4).

[0033] The usage selection unit 1422 receives a selection of usage to be separated for the line to be processed. The usage selection unit 1422 selects a factor template corresponding to the received usage from the template data 132, and incorporates and fixes it as an initial value for non-negative tensor factorization.

[0034] For example, if a user of the estimation device 10 wants to check whether a line to be processed is being used for business processing by a human, the user inputs "business processing by a human" as the purpose. This causes the purpose selection unit 1422 to select a factor template T1 corresponding to business processing by a human from the template data 132, and incorporate and fix it as the initial value of the nonnegative tensor factorization. Furthermore, if the user inputs "data processing by a non-human" as the purpose to check the components of machine-based batch processing, the purpose selection unit 1422 selects a template T2, and incorporates and fixes it as the initial value of the nonnegative tensor factorization.

[0035] The second frequency decomposition unit 1423 converts the traffic of the line to be processed, collected by the second collection unit 1421, into a spectrogram by frequency decomposition. Similar to the first frequency decomposition unit 1412, the second frequency decomposition unit 1423 normalizes the collected traffic and then converts it into a spectrogram by frequency decomposition ((2) in FIG. 4). The data converted by the second frequency decomposition unit 1423 is represented as a tensor of frequency x time.

[0036] The second non-negative tensor factorization unit 1424 fixes one factor to a template of a time component factor corresponding to a predetermined application that has been acquired in advance, and decomposes the time component of the spectrogram transformed by the second frequency decomposition unit into a time tensor by non-negative tensor factorization.

[0037] When the second nonnegative tensor factorization unit 1424 decomposes the spectrogram into multiple factors by nonnegative tensor factorization, it fixes the template selected by the application selection unit 1422 (e.g., template T1 intended for human business processing) as an initial value and performs the decomposition ((3) in FIG. 4). As a result, factor W11 of template T1 saved as a human business processing is separated as a factor intended for human business processing ((4) in FIG. 4). Furthermore, factor W12 other than factor W11 is separated as a factor intended for non-human business processing, i.e., machine data processing ((5) in FIG. 4).

[0038] The usage estimation unit 1425 estimates the usage of the target line for each time period based on the decomposition result by the second nonnegative tensor factorization unit 1424, and outputs the estimation result. Specifically, the usage estimation unit 1425 reconstructs traffic for each factor decomposed by the second nonnegative tensor factorization unit 1424 for the target line ((6) in FIG. 4).

[0039] The usage estimation unit 1425 estimates the factor that is dominant at each time as the usage at that time ((7) in FIG. 4). For example, the usage estimation unit 1425 estimates that the line to be processed was used for business processing by a human at a time when factor W11 of template T1 saved as business processing by a human is dominant. Furthermore, the usage estimation unit 1425 estimates that the line to be processed was used for data processing by a non-human at a time when factor W12 is dominant. For example, the usage estimation unit 1425 estimates that the line to be processed was used for business purposes from 8:00 to 18:00 on a certain date and time, and for data processing purposes at other times.

[0040] The usage estimation unit 1425 estimates the usage of communication for each time period ((8) in FIG. 4). Then, the usage estimation unit 1425 associates the estimated usage for each time period with the reconstructed traffic and outputs it.

[0041] For example, the usage estimation unit 1425 outputs, as an estimation result, a graph G1 in which the reconstructed traffic waveform is color-coded according to the time for business processing by humans and the time for data processing by machines ((9) in FIG. 4) via the input / output unit 12. By recognizing this graph G1, the user can recognize at which time the line being processed was used for business processing by humans or data processing by machines.

[0042] [Pre-processing procedure] Next, a description will be given of the procedure of pre-processing by the pre-processing unit 141. Fig. 5 is a flowchart showing the procedure of pre-processing in the embodiment.

[0043] 5, in the pre-processing unit 141, the first collecting unit 1411 collects traffic of a plurality of lines (step S1). The first frequency decomposing unit 1412 converts the traffic of the plurality of lines collected by the first collecting unit 1411 into a spectrogram by frequency decomposition (step S2).

[0044] The first nonnegative tensor factorization unit 1413 decomposes the time components of the spectrogram transformed by the first frequency decomposition unit 1412 into time tensors by nonnegative tensor factorization (step S3). The first nonnegative tensor factorization unit 1413 outputs the factorization result from the input / output unit 12 (step S4).

[0045] The registration information receiving unit 1414 receives input of specific information that identifies a factor of a time component corresponding to a predetermined application from the decomposed time tensor (step S5). The template registration unit 1415 registers the factor of a time component corresponding to a predetermined application as a template of a factor of a time component according to the predetermined application based on the specific information received by the registration information receiving unit 1414 (step S6).

[0046] [Estimation processing procedure] Next, a description will be given of the procedure of the pre-processing by the estimation unit 142. Fig. 6 is a flowchart showing the procedure of the estimation process according to the embodiment.

[0047] 6, the estimation unit 142 collects traffic of a line to be processed (step S11). The usage selection unit 1422 receives a selection of usages to be separated for the line to be processed (step S12), selects a factor template corresponding to the received usage, and incorporates and fixes it as an initial value for nonnegative tensor factorization (step S13).

[0048] The second frequency decomposition unit 1423 converts the traffic of the line to be processed, collected by the second collection unit 1421, into a spectrogram by frequency decomposition (step S14).

[0049] The second non-negative tensor factorization unit 1424 fixes one factor to the factor template selected by the application selection unit 1422, and decomposes the time component of the spectrogram transformed by the second frequency decomposition unit into a time tensor by non-negative tensor factorization (step S15).

[0050] The usage estimation unit 1425 estimates the usage of the line to be processed for each time period based on the decomposition result by the second nonnegative tensor factorization unit 1424 (step S16), and outputs the estimation result (step S17).

[0051] [Effects of the embodiment] In the embodiment, the traffic of the line to be processed is converted into a spectrogram by frequency decomposition, one factor is fixed to a template of a time component factor corresponding to a predetermined use that has been acquired in advance, the converted spectrogram is decomposed into time tensors by non-negative tensor factorization, and the use of the line to be processed by time is estimated based on the decomposition results.

[0052] That is, in the embodiment, factors of time components corresponding to a predetermined use are acquired in advance as a template, and one factor is fixed to this template, and by simply performing non-negative tensor factorization on the traffic spectrogram, it is possible to automatically estimate whether the use is the predetermined use or something else. Therefore, according to the embodiment, in order to acquire the communication use of the line, it is not necessary to perform complicated processes such as asking users about the use or having experts estimate the use from traffic waveforms, etc.

[0053] Furthermore, in the embodiment, it is sufficient to register a template for a time component factor corresponding to a predetermined use once for each use, so that the use of a line for each time period can be easily estimated.

[0054] Furthermore, in the embodiment, the purpose of communication at each time is estimated based on the waveform of communication volume, rather than estimating the purpose from packet or flow (5-tuple) information. Therefore, in the embodiment, the purpose of communication at each time can be estimated with a simple configuration without requiring a network device such as a DPI device.

[0055] Furthermore, in the embodiment, the factors corresponding to a predetermined use can be separated simply by acquiring the factors of the time components corresponding to the predetermined use as templates in advance and performing non-negative tensor factorization. Therefore, the use of communication at each time can be estimated easily and quickly without performing computationally intensive processing using a supervised learning model.

[0056] In the embodiment, the templates T1 and T2 are registered according to the purpose of processing by humans and the purpose of processing by non-humans, but multiple templates active in different time periods for the same purpose may be registered. The second non-negative tensor factorization unit 1424 can use multiple templates active in different time periods for a predetermined purpose as fixed templates.

[0057] 7 is a diagram showing another example of the data configuration of template data 132. As shown in FIG. 7, pre-processing unit 141, for example, classifies human processing into patterns of business processing use that are active during the daytime from 8:00 to 18:00 and patterns of business processing use that are active on days other than Saturday and Sunday, and registers templates T1-1 and T1-2. When estimating unit 142 receives a selection of a business processing use by a human, it may combine and fix template T1-1 and template T1-2, and perform non-negative tensor factorization.

[0058] 7, the pre-processing unit 141 classifies non-human processing into a data processing use pattern such as batch processing that is active between midnight and 6:00, and an application updater processing use pattern that is active between 8:00 and 12:00 on a specific day of the week (for example, Wednesday), and registers templates T2-1 and T2-2. When the estimation unit 142 receives a selection of a non-human data processing use, the estimation unit 142 may combine and fix template T2-1 and template T2-2, and perform non-negative tensor factorization.

[0059] In addition, in the embodiment, the templates may be automatically identified by the estimating device 10. In this case, the estimating device 10 stores in advance identification rules that indicate, for example, activity patterns that are considered for business use by humans and activity patterns that are considered for batch processing by machines.

[0060] The estimation device 10 then refers to the specific rule to identify a factor having an activity pattern that can be considered as a business application by a human from among the factors decomposed by the nonnegative tensor factorization, and registers the factor as a template of a factor corresponding to a business processing application by a human. Alternatively, the estimation device 10 refers to the specific rule to identify a factor having an activity pattern that can be considered as a batch processing application by a machine from among the factors decomposed by the nonnegative tensor factorization, and registers a child factor as a template of a factor corresponding to a batch processing application by a machine.

[0061] [System configuration, etc.] Furthermore, the components of each device shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown in the figure, and all or part of each device can be functionally or physically distributed and integrated in any unit depending on various loads and usage conditions. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU or GPU and a program analyzed and executed by the CPU or GPU, or can be realized as hardware using wired logic.

[0062] Furthermore, among the processes described in this embodiment, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.

[0063] [program] It is also possible to create a program in which the processing performed by the estimation device 10 described in the above embodiment is written in a language executable by a computer. For example, it is also possible to create a program in which the processing performed by the estimation device 10 in the above embodiment is written in a language executable by a computer. In this case, the same effects as those of the above embodiment can be obtained by having a computer execute the program. Furthermore, such a program may be recorded on a computer-readable recording medium, and the program recorded on the recording medium may be read and executed by a computer to realize processing similar to that of the above embodiment.

[0064] 8 is a diagram showing a computer that executes a program. As shown in the example of FIG. 8, a computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070, and these components are connected by a bus 1080.

[0065] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012, as exemplified in FIG. 8. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090, as exemplified in FIG. 8. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0066] 8, the hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the above programs are stored on the hard disk drive 1090, for example, as program modules in which instructions to be executed by the computer 1000 are written.

[0067] The various data described in the above embodiment are stored as program data, for example, in the memory 1010 or the hard disk drive 1090. The CPU 1020 then reads the program module 1093 and the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed, and executes various processing procedures.

[0068] Note that the program module 1093 and program data 1094 related to the program are not limited to being stored in the hard disk drive 1090, and may be stored in, for example, a removable storage medium and read by the CPU 1020 via a disk drive or the like. Alternatively, the program module 1093 and program data 1094 related to the program may be stored in another computer connected via a network (such as a LAN (Local Area Network) or WAN (Wide Area Network)) and read by the CPU 1020 via the network interface 1070.

[0069] The above-described embodiments and their modifications are included in the technology disclosed in this application, as well as in the scope of the invention described in the claims and their equivalents. [Explanation of symbols]

[0070] 10 Estimation device 11 Communications Department 12 Input / output section 13 Storage section 14 Control Unit 131 Traffic Data 132 Template Data 141 Pre-processing section 142 Estimation Department 1411 First Collection Department 1412 First frequency decomposition unit 1413 First non-negative tensor factorization unit 1414 Registration Information Reception Department 1415 Template Registration Department 1421 Second Collection Department 1422 Use Selection Section 1423 Second Frequency Decomposition Unit 1424 Second Nonnegative Tensor Factorization Unit 1425 Usage Estimation Department

Claims

1. a first decomposition unit that converts traffic of a line to be processed into a spectrogram by frequency decomposition; a second decomposition unit that fixes one factor to a template of a time component factor according to a predetermined application acquired in advance, and decomposes the time component into a time tensor by non-negative tensor factorization of the spectrogram transformed by the first decomposition unit; an estimation unit that estimates a usage for each time period of the line to be processed based on the decomposition result by the second decomposition unit; An estimation device comprising:

2. a third decomposition unit that converts traffic of a plurality of lines into a spectrogram by frequency decomposition; a fourth decomposition unit that decomposes the spectrogram transformed by the third decomposition unit into time tensors by non-negative tensor factorization; a receiving unit that receives input of specific information that identifies a factor of a time component corresponding to the predetermined application from the decomposed time tensor; a registration unit that registers a factor of a time component corresponding to the predetermined use as a template of a factor of a time component according to the predetermined use based on the specific information received by the reception unit; 2. The estimation device according to claim 1, further comprising:

3. 3. The estimation device according to claim 1, wherein the estimation unit reconstructs traffic for each factor decomposed by the second decomposition unit for the line to be processed, and outputs the reconstructed traffic in association with the estimated use for each time period.

4. 4. The estimation device according to claim 1, wherein the predetermined use is a business use by a human or a data processing use by a machine.

5. As the template, a plurality of templates active in different time periods for the same purpose are registered, 5. The estimation device according to claim 1, wherein the second decomposition unit uses, as fixed templates, a plurality of templates active during different time periods for the predetermined use.

6. An estimation method executed by an estimation device, a first decomposition step of converting traffic of a line to be processed into a spectrogram by frequency decomposition; a second decomposition step of fixing one factor to a template of a time component factor corresponding to a predetermined application obtained in advance, and decomposing the time component into a time tensor by non-negative tensor factorization of the spectrogram transformed in the first decomposition step; an estimation step of estimating the usage of the line to be processed for each time period based on the decomposition result in the second decomposition step; An estimation method comprising:

7. a first decomposition step of converting traffic of a line to be processed into a spectrogram by frequency decomposition; a second decomposition step of fixing one factor to a template of a time component factor according to a predetermined application obtained in advance, and decomposing the time component into a time tensor by non-negative tensor factorization of the spectrogram transformed in the first decomposition step; an estimation step of estimating a usage for each time period of the line to be processed based on the decomposition result in the second decomposition step; An estimation program for causing a computer to execute the above.

Citation Information

Patent Citations

  • System and Method for Determining Application-Dependent Paths in a Data Center

    JP2013526237A

  • Channel utilization state acquisition device, channel utilization state acquisition method, and program

    JP2015050622A

  • Signal analyzer, method, and program

    JP2018136368A

  • Identification device and identification program

    JP2020141236A