Abnormality management device and abnormality management method
The abnormality management device uses singular value decomposition and probability modeling to detect and adjust uneven packet distribution, enhancing resource efficiency by managing signal processing imbalances.
Patent Information
- Application Number
- JP2025146154
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2026-01-05
- Estimated Expiration
- 2045-09-03
AI Technical Summary
Conventional load balancing technologies struggle to manage imbalances in signal processing efficiently, leading to decreased resource usage efficiency due to uneven distribution of packets among destination devices.
An abnormality management device that extracts characteristic directions of normal data using singular value decomposition, learns a probability model to detect abnormal signal distributions, and adjusts packet distribution based on derived probability distributions and thresholds to ensure even load balancing.
Effectively addresses the technical problem by providing a system that efficiently manages imbalance in the amount of signal processing, thereby improving the effectiveness of the system. The efficacy of the system is improved by ensuring even distribution of packets among devices, thus optimizing resource usage.
Smart Images

Figure 0007793852000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an abnormality management device and an abnormality management method. [Background technology]
[0002] A round-robin load balancer has been known as a technology for distributing loads by distributing signals to multiple devices. For example, Patent Document 1 discloses a system that instructs an edge router to change the destination server to a backup server group according to the load status of an operational server group, and then uses a load balancer to distribute signals evenly to the backup server group of the changed destination.
[0003] However, depending on the hardware resources of the destination devices, packets may not be distributed evenly to the destination devices due to processing delays or losses on the destination device side. Under such circumstances, there is a risk that the resource usage efficiency of the entire system will decrease, so a technology to detect imbalances in the signal processing volume is desired. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-142848 Summary of the Invention [Problem to be solved by the invention]
[0005] According to conventional techniques, it has been difficult to appropriately manage the imbalance in the amount of signal processing.
[0006] The present invention has been made to solve the above-mentioned problems, and has as its object to appropriately manage the imbalance in the amount of signal processing. [Means for solving the problem]
[0007] In order to solve the above-described problems, the abnormality management device according to the present invention includes a feature extraction unit configured to extract characteristic directions of normal data based on a data matrix made up of a plurality of observation vectors representing normal data indicating the number of normal signals allocated to a device for each time period; a learning unit configured to use the characteristic directions of the normal data extracted by the feature extraction unit as teacher data to learn, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that the number of signals allocated to the device for each time period corresponding to each of the characteristic directions of the normal data is normal; and The apparatus includes a derivation unit configured to derive a probability distribution for the characteristic direction of abnormal data indicating the number of abnormal signals that deviate from the range of the number of normal signals and are assigned to the device for each time period, based on the posterior probability, the probability distribution for the characteristic direction of the normal data, and the prior probability of normality; a calculation unit configured to calculate a first index value indicating the spatial coincidence formed by the probability distribution for the characteristic direction of the abnormal data derived by the derivation unit and the probability distribution for the characteristic direction of the normal data; and a setting unit configured to set the first index value calculated by the calculation unit as a determination threshold for the number of abnormal signals.
[0008] Furthermore, the abnormality management device according to the present invention may further include a collection unit configured to collect first data indicating the number of signals assigned to the managed device for each time period included in a first interval, and second data indicating the number of signals assigned to the managed device for each time period included in a second interval following the first interval, wherein the feature extraction unit extracts a characteristic direction of the first data and a characteristic direction of the second data based on a first data matrix composed of observation vectors representing the first data and a second data matrix composed of observation vectors representing the second data, respectively, and the calculation unit calculates a second index value indicating the degree of spatial coincidence formed between the extracted characteristic direction of the first data and the extracted characteristic direction of the second data, and further includes a judgment unit configured to judge that an abnormal number of signals has been assigned to the managed device in the second interval if the second index value calculated by the calculation unit exceeds the judgment threshold.
[0009] In addition, in the abnormality management device of the present invention, the number of signals allocated to the managed device collected by the collection unit includes identification information of each source device that allocated each signal, and the device may further include an identification unit configured to identify the source device that allocated more than a set number of signals to the managed device when the determination unit determines that an abnormal number of signals have been allocated, and an instruction unit configured to send an instruction to the source device identified by the identification unit to adjust the number of signals allocated to the managed device.
[0010] In addition, in the abnormality management device according to the present invention, the feature extraction unit may extract a transformation matrix of the normal data including a group of orthonormal basis vectors as the feature direction of the normal data by performing singular value decomposition on the data matrix.
[0011] In order to solve the above-described problems, an anomaly management method according to the present invention includes a feature extraction step of extracting characteristic directions of normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicating the number of normal signals assigned to a device for each time period; a learning step of using the characteristic directions of the normal data extracted in the feature extraction step as training data and learning, by maximum likelihood estimation, parameters of a probability model that outputs a posterior probability that the number of signals assigned to the device for each time period corresponding to each of the characteristic directions of the normal data is normal; a derivation step of deriving a probability distribution for the characteristic directions of abnormal data indicating the number of abnormal signals assigned to the device for each time period that deviates from the range of the number of normal signals, based on the posterior probability estimated by the probability model learned in the learning step, a probability distribution for the characteristic directions of the normal data, and a prior probability of normality; a calculation step of calculating a first index value indicating the spatial coincidence formed by the probability distribution for the characteristic directions of the abnormal data derived in the derivation step and the probability distribution for the characteristic directions of the normal data; and a setting step of setting the first index value calculated in the calculation step as a determination threshold for the number of abnormal signals.
[0012] Furthermore, the anomaly management method according to the present invention may further include a collection step of collecting first data indicating the number of signals assigned to the managed device for each time period included in a first interval, and second data indicating the number of signals assigned to the managed device for each time period included in a second interval following the first interval, wherein the feature extraction step extracts a characteristic direction of the first data and a characteristic direction of the second data based on a first data matrix composed of observation vectors representing the first data and a second data matrix composed of observation vectors representing the second data, respectively, and the calculation step calculates a second index value indicating the degree of spatial coincidence formed between the extracted characteristic direction of the first data and the extracted characteristic direction of the second data, and may further include a determination step of determining that an abnormal number of signals has been assigned to the managed device in the second interval if the second index value calculated in the calculation step exceeds the determination threshold.
[0013] In addition, in the abnormality management method of the present invention, the number of signals allocated to the managed device collected in the collection step may include identification information of each source device that allocated each signal, and may further include a determination step of identifying a source device that allocated more than a set number of signals to the managed device when it is determined in the determination step that an abnormal number of signals have been allocated, and an instruction step of sending an instruction to the source device identified in the determination step to adjust the number of signals allocated to the managed device.
[0014] In addition, in the anomaly management method according to the present invention, the feature extraction step may extract a transformation matrix of the normal data including a group of orthonormal basis vectors as the feature direction of the normal data by performing singular value decomposition on the data matrix. [Effects of the Invention]
[0015] According to the present invention, a first index value indicating the degree of spatial agreement formed between the probability distribution for the characteristic direction of the abnormal data derived by the derivation unit and the probability distribution for the characteristic direction of the normal data is set as a determination threshold for the number of abnormal signals, thereby making it possible to appropriately manage bias in the amount of signal processing. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 1 is a block diagram showing the configuration of an abnormality management system including an abnormality management device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an outline of an abnormality management system including an abnormality management device according to this embodiment. [Figure 3] FIG. 3 is a diagram for explaining an outline of the number of packets distributed by the traffic control device managed by the abnormality management device. [Figure 4] FIG. 4 is a diagram for explaining the number of packets collected by the abnormality management device according to the present embodiment. [Figure 5]FIG. 5 is a diagram for explaining the operation of the feature extraction unit included in the abnormality management device according to this embodiment. [Figure 6] FIG. 6 is a diagram for explaining the operation of the learning unit and the derivation unit included in the abnormality management device according to this embodiment. [Figure 7] FIG. 7 is a block diagram showing the hardware configuration of the abnormality management device according to this embodiment. [Figure 8] FIG. 8 shows an operation sequence of an abnormality management system including an abnormality management device according to this embodiment. [Figure 9] FIG. 9 is a flowchart showing the operation of the abnormality management device according to this embodiment. [Figure 10] FIG. 10 is a flowchart showing the operation of the abnormality management device according to this embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0017] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Preferred embodiments of the present invention will now be described in detail with reference to FIGS.
[0018] [Configuration of anomaly management system] First, referring to Figure 1, an overview of an anomaly management system according to an embodiment of the present invention will be described, which includes an anomaly management device 1, a group of traffic control devices (source devices) 2, and a group of opposing devices (devices) 3. The anomaly management system extracts the characteristic direction of normal data, derives the probability distribution of abnormal data based on the probability distribution of normal data estimated by learning a probabilistic model, and sets the maximum singular value based on the probability distribution of normal data and abnormal data as a threshold value for determining whether the number of signals distributed from the traffic control device 2 to the opposing device 3 is abnormal.
[0019] The fault management system according to this embodiment is installed in a mobile communication network or a network using fixed lines that conforms to 3G, 4G / LTE, 5G, 6G, etc. As shown in Fig. 1, the fault management device 1 is connected to a traffic control device 2 via a network NW such as a LAN, a WAN, or the Internet.
[0020] As shown in Fig. 2, the traffic control device 2 is communicatively connected to a plurality of opposite devices 3, and distributes received packets to the plurality of opposite devices 3 based on preset distribution criteria. In the following, a case where the "signal" is a "packet" will be explained. As an example, the traffic control device 2 distributes packets in an equal order to the plurality of opposite devices 3 using a round robin method. However, if a packet processing delay occurs on the opposite device 3 side, the traffic control device 2 may have to wait for packets to be sent or retransmit them, resulting in uneven distribution of packets.
[0021] L traffic control devices 2 (L is an integer equal to or greater than 2) are provided, and each traffic control device 2 is uniquely identified by a control device ID (i=1, 2, . . . , L) such as an IP address or a MAC address. The traffic control device 2 can be realized by a computer equipped with a processor, a main memory device, a communication interface, an auxiliary memory device, and an input / output (I / O), and a program that controls these hardware resources. In this embodiment, the traffic control device 2 is configured to be able to increase or decrease the amount of signals distributed to the opposing device 3 under management by changing scheduling parameters of the transmission queue, such as TPS, in response to instructions from the abnormality management device 1.
[0022] The traffic control device 2 can be realized by, for example, an Access and Mobility Management Function (AMF) provided in the core network or a load balancer. The AMF is a function node of the control plane that manages the registration of user terminals and wireless connections. The load balancer is a device provided in the user plane that distributes traffic. When the fault management system is provided in the fixed line network, the traffic control device 2 can be realized by an edge router, a load balancer, etc.
[0023] The opposite device 3 receives the packets distributed by the traffic control device 2. In this embodiment, N opposite devices 3 (N is an integer equal to or greater than 2) are provided. When the traffic control device 2 is configured with an AMF, the opposite device 3 is realized by a UDM (Unified Data Management) provided in the core network. The UDM is a functional node that manages subscriber information in the core network and manages the mobility of user terminals. Specifically, the AMF distributes packets transmitted from user terminals via base stations and transmits them to multiple UDMs. When an anomaly management system is provided in the fixed line network, the opposite device 3 is realized by a CDN (Content Delivery Network) node, a group of Web servers, or the like.
[0024] The opposite device 3 can be realized by a computer equipped with a processor, a main memory device, a communication interface, an auxiliary memory device, and an input / output (I / O), and a program that controls these hardware resources. Each opposite device 3 is identified by an opposite device ID (i=1, 2, . . . , N) such as an IP address or a MAC address. In this embodiment, at least one of the opposite devices 3 has hardware resources with a capacity different from that of the other devices. Therefore, an opposite device 3 with fewer resources than the other opposite devices 3 may experience delays in processing received packets, causing buffer congestion. In such a situation, the traffic control device 2 may take measures such as temporarily restricting transmission to that opposite device 3, resulting in uneven packet distribution overall.
[0025] The opposite device 3 is configured to count and record the number of packets distributed to the traffic control device 2. Fig. 4 is a diagram showing the number of packets distributed to each of the multiple traffic control devices 2 and received and recorded by the opposite device 3. In Fig. 4, the number of packets received and recorded by the opposite device 3 (for example, opposite device ID: 1) is recorded for each identification information of the source traffic control device 2. Fig. 4 shows, for example, the number of packets received in a certain time period (for example, 10 minutes). Also, the total number of packets received from the multiple traffic control devices 2 in that time period is recorded. The opposite device 3 records the number of packets received for each time period as time-series data.
[0026] FIG. 3 is a diagram illustrating normal data and abnormal data of the number of packets allocated to a certain opposite device 3 by each of multiple traffic control devices 2. The horizontal axis of FIG. 3 represents time, and the vertical axis represents the number of packets received by a certain opposite device 3 for each time period. FIG. 3 shows the number of packets allocated to and received by one opposite device 3 (for example, opposite device ID: 1) among the multiple opposite devices 3. The dotted line value in FIG. 3 indicates normal data a1, which is the number of normal packets allocated to the opposite device 3. The normal number of packets means the number of packets allocated by the multiple traffic control devices 2 to the opposite device 3 with opposite device ID: 1 in a set time period (for example, in 10-minute increments) according to the set allocation criteria, and which falls within the range of the allocation criteria.
[0027] On the other hand, the number of packets indicated by the solid line in Figure 3 indicates that, depending on the time period, a larger number of packets than would normally be allocated to the opposite device 3 is allocated. For example, the number of packets indicated by the solid line in section c1 indicates that a larger number of packets than would normally be allocated to the opposite device 3 with opposite device ID: 1 is allocated. In this way, the number of packets indicated by the solid line indicates abnormal data b1, in which the number of packets allocated to the opposite device 3 is abnormal.
[0028] Abnormal data is the number of packets that deviate from the range of packet numbers that are considered normal when distributed according to the set distribution criteria. For example, in the round robin method, packets are theoretically distributed evenly from each traffic control device 2 to each opposite device 3. In this case, normal data is packets that each traffic control device 2 distributes evenly or within a range that can be considered equal. Note that the number of distributed packets and the number of packets received by the opposite device 3 are the same. On the other hand, abnormal data is the number of packets that are distributed from the traffic control device 2 to the opposite device 3 when the number of packets that deviates from the range that can be considered equal, due to factors such as differences in the hardware resources of each opposite device 3, is equal.
[0029] Therefore, the abnormal data appears as a difference in the number of packets received on the opposing device 3 side due to the existence of one or more traffic control devices 2 that distribute more or fewer packets than other traffic control devices 2 among multiple traffic control devices 2. In other words, the abnormal data represents the number of packets that reflects the imbalance of the round robin.
[0030] [Function block of the abnormality management device] Next, functional blocks of the abnormality management device 1 according to this embodiment will be described with reference to the block diagram of Fig. 1. As shown in Fig. 1, the abnormality management device 1 includes a collection unit 10, a feature extraction unit 11, a learning unit 12, a derivation unit 13, a calculation unit 14, a setting unit 15, a determination unit 16, an identification unit 17, an instruction unit 18, and a storage unit 19.
[0031] The collection unit 10 collects normal data indicating the number of normal packets distributed to the opposing device 3 for each time period. The collection unit 10 collects the number of received packets (FIG. 4) per unit time (e.g., 10 minutes) that are distributed by multiple traffic control devices 2 and received and recorded by the opposing device 3 for a certain period (e.g., one month). The collection unit 10 collects data in which the number of packets is normal above a certain level as normal data and passes it to the feature extraction unit 11.
[0032] The collection unit 10 also collects the number of packets distributed to the managed opposite device 3 for each time period that the judgment unit 16 determines to be abnormal. More specifically, the collection unit 10 collects, at the managed opposite device 3, first data which is the number of packets distributed to the managed opposite device 3 for each time period included in a first interval, and second data which is the number of packets distributed to the managed opposite device 3 for each time period included in a second interval following the first interval. The first interval and the second interval each consist of N time periods. The collection unit 10 collects the number of packets distributed to the managed opposite device 3 as well as identification information of the traffic control device 2 of each source that distributed each packet.
[0033] The feature extraction unit 11 extracts the feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data, which is the number of normal packets distributed to the opposing device 3 for each time period. More specifically, the feature extraction unit 11 extracts a transformation matrix U of the normal data including a group of orthonormal basis vectors as the feature direction of the normal data by performing singular value decomposition on the data matrix composed of a plurality of observation vectors representing the normal data.
[0034] Furthermore, the feature extraction unit 11 extracts the feature direction of the first data and the feature direction of the second data based on a first data matrix composed of observation vectors representing the first data and a second data matrix composed of observation vectors representing the second data, both of which are included in the number of packets distributed to the managed opposing device 3 for each time period. The feature extraction unit 11 performs singular value decomposition on the first data matrix to extract a transformation matrix U1 of the first data including a group of orthonormal basis vectors as the feature direction of the first data. Similarly, the feature extraction unit 11 performs singular value decomposition on the second data matrix to extract a transformation matrix U2 of the second data including a group of orthonormal basis vectors as the feature direction of the second data.
[0035] 5 is a diagram for explaining the feature directions of normal data extracted by the feature extraction unit 11. In FIG. 5, if the total number of data points in each section is N, then data points t1 to t N indicates the number of packets distributed to a certain opposite device 3 observed in each time period collected by the collection unit 10, and here, time series data of the number of normally distributed packets is shown. Therefore, the number of packets observed in the nth time period is expressed as t n The feature extraction unit 11 uses a sliding window with a window width M to convert the time series data of the number of normally distributed packets into a set of M-dimensional vectors indicated by the arrows of each sliding window into a plurality of observation vectors. The time series data consisting of the observed values of the number of distributed packets with length L is expressed as L=N-M+1.
[0036] The observation vector, which is a partial time series of length M sequentially extracted by the feature extraction unit 11 by moving the sliding window from left to right in the time series data of the number of normally distributed packets, is expressed by the following equation (1).
number
[0037] Here, the data matrix X=[x (1) ,…,x (L) ] (an M×L-dimensional real-valued matrix), consider the linear combination Xν of the following equation (2).
number
[0038] From the above equation (2), ν T Under the constraint ν=1, ||Xν|| 2 This can be achieved by introducing the Lagrangian function of the following equation (3) obtained using the multiplier γ.
number
[0039] In order for the above equation (3) to be maximized, 2X differentiated with respect to the vector ν T The value of Xν-2γν is 0. Therefore, the following conditional expression (4) is obtained.
number
[0040] From the above equation (4), X T It can be seen that the eigenvalue of X is γ and the eigenvector is ν. Furthermore, the vector μ is defined by the following equation (5).
number
[0041] Using the above equations (5) and (4), the relationship shown in the following equation (6) can be found.
number
[0042] Furthermore, multiplying both sides of the above equation (4) by X and using the above equation (5) yields the following relational equation (7).
number
[0043] By applying the above equation (5) to the above equation (7), the following relational expression (8) is obtained.
number
[0044] Here, U and V are set as follows:
number
[0045] The above equation (9) can be expressed as the following equation (10).
number
[0046] U is an orthogonal matrix, and U T By multiplying and transposing both sides of the above equation (10), the relationship of the following equation (11) is obtained.
number
[0047] The above equation (11) is called the singular value decomposition of X. Let U be the left singular vector, V be the right singular vector, and Γ 1 / 2 are called singular values. That is, U is a transformation matrix that represents the feature direction, which is the main direction or pattern of normal data. V represents the axis transformation, which is the direction to which the vector is projected. Γ represents the importance of each feature direction.
[0048] The matrix U of left singular vectors is expressed by the following equation (12).
number
[0049] For example, if there are 10,000 normal data packets in the interval (N=1000), 10,000 left singular vectors U are calculated. Each component vector μ of the left singular vector U in the normal data xx The probability distribution of is obtained by the learning unit 12 using the maximum likelihood estimation method.
[0050] The learning unit 12 uses the characteristic directions of the normal data extracted by the feature extraction unit 11 as training data to learn, by maximum likelihood estimation, parameters of a probability model that outputs the posterior probability that the number of packets allocated to the opposite device 3 in each time period corresponding to each of the characteristic directions of the normal data is normal. In a situation where there is little abnormal data, the learning unit 12 learns the probability model by maximum likelihood estimation using the characteristic directions of the normal data.
[0051] Here, each element μ of the matrix of the left singular vector U xxLet x be the number of packets distributed to the opposite device 3 at a certain time period at a certain observation point (μ xx = x). In addition, the density function of normal data is expressed as ρ d (μ xx ), and the density function of the abnormal data is ρ g (μ xx ) are defined as follows: d (μ xx )=ρ d (x), ρ g (μ xx )=ρ g (x).
number
[0052] In the above equation (13), y=1 indicates the normal class and y=0 indicates the abnormal class. d (μ xx ) is the number of packets distributed when belonging to the normal class y=1 μ xx shows the tendency of appearance of ρ g (x) is the number of packets distributed when belonging to the abnormal class y=0. xx The probability distribution of both normal and abnormal data follows a normal distribution.
[0053] The density ratio γ(μ xx ) is expressed by the following equation (14).
number
[0054]
number
[0055] Here, if π=ρ(y=1), the above equation (15) can be further expressed as the following equation (16).
number
[0056] Therefore, first, the observed value μ xx The posterior probability ρ(y=1|μ xx ) is calculated. Observed value μ xx If there is a large amount of xx )≒ρ(μ xx |y=1) can be approximated. In other words, the posterior probability ρ(y=1|μ xx) can be estimated. For the sake of explanation, we will use the observed value μ xx is denoted as x. At an observation point x n Assuming that the normal distribution is assumed, it is defined as shown in the following equation (17).
number
[0057] Furthermore, the output of the probabilistic model f(x n ) can be expressed as a linear combination as shown in the following equation (18).
number
[0058]
number
[0059]
number
[0060] Furthermore, the number of packets to be distributed f(x n ) and the actual number of successfully distributed packets t n The average error from the (teacher signal) is the variance σ of the normal distribution shown in the following equation (21). 2 The value becomes
number
[0061] In this way, when a linear combination probability model estimates the posterior probability that the number of distributed packets is normal for an input x, each observed value t is calculated based on the estimated value f(x n ) is assumed to follow a normal distribution with mean x n ,t n ) by maximum likelihood estimation, we can obtain the parameters w and error variance σ of the probability model. 2 Estimate.
[0062] 6 is a diagram for explaining the configuration of the learning unit 12 and the derivation unit 13. As shown in FIG. xx Therefore, the learning unit 12 calculates each component μ of the matrix U of left singular vectors obtained by performing singular value decomposition on the data matrix of normal data. xx Probability distribution ρ for d (μ xx ) is calculated. If there is a matrix U of 10,000 left singular vectors, each component μ xx Ten thousand normal probability distributions are calculated. The learning unit 12 calculates the components μ xx As described above, there are as many matrices U of left singular vectors as there are normal data. Therefore, the learning unit 12 performs maximum likelihood estimation the number of times corresponding to the number of matrices U of left singular vectors.
[0063] Here, again μ xxBy expressing x as the normal data posterior probability ρ(y=1|x), we can approximately estimate ρ(y=1|x)≒q w The relationship is (y=1|x). The estimated posterior probability that the number of input packets x is normal is q w Based on (y=1|x), the cross entropy is defined as the loss function L as shown in the following equation (22).
number
[0064] The convergence value (minimum value) of the loss function L in the above equation (22) is expressed by the following equation (23).
number
[0065] The derivation unit 13 transforms the above equation (23) into the following equation (24), and calculates the density function ρ g Derive (x).
number
[0066] x to μ xx When substituted, the above equation (24) becomes the following equation (25).
number
[0067] In the above equation (25), the probability distribution of normal data, i.e., the density function of normal data, ρ d (μ xx ) is calculated from the normal data collected by the collection unit 10. The prior probability of normal data, π, is much larger than the prior probability of abnormal data, (1-π), and can be set to, for example, 0.99. Furthermore, the observed value μ xx For (=x), the log likelihood lnq when y=1 w (y=1|μ xx) is calculated by maximum likelihood estimation based on a large amount of normal data (teacher signal), as shown in the above equations (18) to (21). In this way, even if there is a small amount of abnormal data, the probability distribution of abnormal data can be calculated from the normal data.
[0068] The derivation unit 13 calculates the estimated value q of the posterior probability of normal data estimated by the probability model learned by the learning unit 12. w (y=1|μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) and the prior probability π of normality, the density function ρ for the feature direction of the abnormal data indicating the number of abnormally sorted packets that deviates from the range of the number of normally sorted packets is calculated. g (μ xx ) is derived. As mentioned above, the posterior probability estimate of normal data, q w (y=1|μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) is normally distributed, the density function ρ g (μ xx ) is also normally distributed.
[0069] The derivation unit 13 calculates the estimated value q of the posterior probability of normal data. w (y=1|μ xx ) (for example, 10,000) and the same number of abnormal data density functions ρ g (μ xx ) of the density function ρ g (μ xx ) is the sum of the anomalous data density function ρ g (μ xx ) as the final solution. The derivation unit 13 also calculates the density function ρ d (μ xx ) is the density function ρ d (μ xx ) is the final solution.
[0070] Here, the density function ρ for the feature direction of normal data is d (μ xx ) and the density function ρ for the feature direction of the abnormal data g (μ xx ) are expressed by the following matrix (26).
number
[0071] The calculation unit 14 calculates the density function ρ g (μ xx ) (probability distribution) and the density function ρ for the feature direction of normal data d (μ xx ) (probability distribution) for the characteristic direction of the abnormal data. g (μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) as the first index value. Specifically, the calculation unit 14 calculates the maximum singular value of the matrix formed based on the matrix 2-norm ∥ρ d (μ xx ) T ρ g (μ xx )||2 is calculated as the first index value.
[0072]
number
[0073] The sum of the vector components of each column in the above equation (27) is S1, ,S M Then, the matrix 2-norm is calculated by the following equation (28).
number
[0074] The calculation unit 14 also calculates a second index value indicating the degree of spatial coincidence formed between the feature directions of the first data and the feature directions of the second data, each of which indicates the number of packets distributed to the managed opposite device 3 in each time period, extracted by the feature extraction unit 11. More specifically, the calculation unit 14 calculates, as the second index value, the matrix 2 norm of the transposed matrix U1 of the left singular vectors of the first data and the matrix U2 of the left singular vectors of the second data.
[0075] The setting unit 15 sets the first index value calculated by the calculation unit 14 as a determination threshold for the number of abnormal packets distributed to the opposite device 3. The setting unit 15 sets a threshold for each opposite device 3.
[0076] If the second index value calculated by the calculation unit 14 exceeds the threshold value, the determination unit 16 determines that an abnormal number of packets have been distributed to the opposite device 3 to be managed in the second section.
[0077] When the determining unit 16 determines that an abnormal number of packets has been distributed, the identifying unit 17 identifies the source traffic control device 2 that distributed a set number of packets or more to the managed opposing device 3. The identifying unit 17 identifies, among the multiple traffic control devices 2, a traffic control device 2 that distributed more or fewer packets than the other traffic control devices 2 during the time period of the second section. The number of traffic control devices 2 to be identified is not limited to one, and may be multiple.
[0078] The instruction unit 18 transmits an instruction to the traffic control device 2 identified by the identification unit 17 to adjust the number of packets to be distributed to the opposite device 3 to be managed. For example, the instruction unit 18 transmits an instruction to a traffic control device 2 that distributes a larger number of packets than other traffic control devices 2 to reduce the number of packets to be distributed to the opposite device 3 to be managed, so that the multiple traffic control devices 2 each distribute an equal number of packets to the opposite device 3 to be managed.
[0079] The storage unit 18 stores the threshold value set by the setting unit 15. The storage unit 18 stores the threshold value for each associated device 3.
[0080] [Hardware configuration of the fault management device] Next, an example of a hardware configuration for realizing the abnormality management device 1 having the above-described functions will be described with reference to FIG.
[0081] 7, the fault management device 1 can be realized by, for example, a computer including a processor 102, a main memory device 103, a communication interface 104, an auxiliary memory device 105, and an input / output (I / O) 106 connected via a bus 101, and a program for controlling these hardware resources. Furthermore, the fault management device 1 includes a display device 107.
[0082] The processor 102 is a circuit or device that performs arithmetic processing, and is realized by, for example, a general-purpose central processing unit (CPU), a graphics processing unit (GPU), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc. Alternatively, the processor 102 may be configured by combining some or all of these.
[0083] The main memory device 103 is configured, for example, by a volatile random access memory (RAM), and pre-stores programs for the processor 102 to perform various controls and calculations. The processor 102 and the main memory device 103 realize the functions of the abnormality management device 1, such as the collection unit 10, feature extraction unit 11, learning unit 12, derivation unit 13, calculation unit 14, setting unit 15, judgment unit 16, identification unit 17, and instruction unit 18 shown in FIG.
[0084] The communication interface 104 is an interface circuit for connecting the abnormality management device 1 to various external electronic devices via a network.
[0085] The auxiliary storage device 105 is composed of a readable / writable storage medium and a drive for reading and writing various information such as programs and data from and to the storage medium. The auxiliary storage device 105 can use non-volatile storage such as a hard disk or flash memory as the storage medium.
[0086] The auxiliary storage device 105 has a program storage area for storing an abnormality management program. The auxiliary storage device 105 also has a program storage area for storing a feature extraction program for extracting characteristic directions of normal data by the subspace method executed by the abnormality management device 1. The auxiliary storage device 105 also has a program storage area for storing a learning program for a probability model executed by the abnormality management device 1. The auxiliary storage device 105 realizes the storage unit 19 described in FIG. 1. Furthermore, for example, the auxiliary storage device 105 may have a backup area for backing up the above-mentioned data, programs, etc.
[0087] The input / output I / O 106 is an input / output device that inputs signals from external devices and outputs signals to external devices.
[0088] The display device 107 is configured by an organic EL display, a liquid crystal display, etc. The display device 107 can display on a screen time-series data of the number of packets distributed to the counterpart device 3 to be managed.
[0089] [Operation of the abnormality management device] Next, the operation of the abnormality management device 1 having the above-described configuration will be described with reference to the sequence of FIG. 8 and the flowcharts of FIGS.
[0090] As shown in FIG. 8, first, the opposing device 3 records the number of packets allocated by the traffic control device 2 (step S1). In step S1, the opposing device 3 records the number of packets allocated to the opposing device 3 from each of the multiple traffic control devices 2 in 10-minute increments over a one-month period, for example (FIG. 4). Next, the collection unit 10 collects time-series data on the number of packets allocated to the opposing device 3 for each time period that contains a certain amount of normal data (step S2). The collection unit 10 collects, via the network NW, the number of allocated packets in which, for example, 99% or so are normal data, from the opposing device 3. In step S2, the collection unit 10 collects, for example, the number of packets allocated to the opposing device 3 with opposing device ID: 1 in 10-minute increments over a one-month period.
[0091] Next, the feature extraction unit 11 extracts feature directions of the normal data based on a data matrix composed of multiple observation vectors representing normal data (step S3). The feature extraction unit 11 extracts multiple observation vectors of a partial time series by shifting the data on the number of packets allocated to the normal data for each time period using a sliding window with a window width M as shown in FIG. 5. The feature extraction unit 11 performs singular value decomposition on the data matrix X that summarizes the observation vectors expressed by the above formula (1), and extracts the transformation matrix U expressed by the above formulas (11) and (12). In step S3, for example, if there are 10,000 normal data items for the number of packets allocated to the interval (N=1000), 10,000 transformation matrices U are calculated.
[0092] Next, the learning unit 12 uses the characteristic directions of the normal data extracted by the feature extraction unit 11 in step S2 as training data to learn parameters of a probability model that outputs the posterior probability that the number of packets allocated to the opposite device 3 in each time period corresponding to each of the characteristic directions of the normal data is normal by maximum likelihood estimation (step S4). Thereafter, the derivation unit 13 derives a probability distribution for the characteristic directions of the abnormal data, which indicates the number of abnormal packets allocated to the opposite device 3 in each time period that deviates from the range of the number of normally allocated packets, based on the posterior probability of the normal data estimated by the probability model learned by the learning unit 12 in step S4, the probability distribution for the characteristic directions of the normal data, and the prior probability of normality (step S5).
[0093] 9 is a flowchart illustrating steps S4 and S5 in more detail. As shown in step S30 of FIG. 9, the learning unit 12 uses the transformation matrix U of the normal data obtained in step S3 as training data, and calculates the components μ xx For each packet, the number of packets to be distributed is μ xx The posterior probability estimate q is normal w (y=1|μ xx ) parameters w,σ of the probabilistic model that outputs 2 is learned by maximum likelihood estimation (step S30). If there are 10,000 transformation matrices U of normal data, 10,000 estimated values q w (y=1|μ xx ) is obtained. In step S30, the learning unit 12 performs learning by maximum likelihood estimation in accordance with the above equations (18) to (21).
[0094] Furthermore, the learning unit 12 calculates the components μ of the transformation matrix U of the normal data. xx The number of normal packets μ distributed to the opposite device 3 in each time period xx Based on the normal data density function ρ d (μ xx ) (normal distribution) is estimated (step S31). In step S31, as shown in FIG. 6, maximum likelihood estimation is performed for each column vector of the transformation matrix U, and each component μ xx The density function ρ of normal data for d (μxx In step S31, maximum likelihood estimation is performed for each of the multiple transformation matrices U.
[0095] Next, the derivation unit 13 adds the log likelihood lnq of the posterior probability calculated in step S30 to the above equation (25). w (y=1|μ xx ), the density function ρ of the normal data obtained in step S31 d (μ xx ), and the prior probability of normal data π (e.g., 0.99) to obtain the density function ρ of the abnormal data. g (μ xx ) is derived (step S33). The density function ρ g (μ xx ) is calculated by the log likelihood lnq w (y=1|μ xx ) is the same number as the number of
[0096] Thereafter, the process proceeds to step S6 in Fig. 8. Subsequently, in step S5, the calculation unit 14 calculates the density function ρ g (μ xx ) (probability distribution) and the density function ρ for the feature direction of normal data d (μ xx ) (probability distribution) for the characteristic direction of the abnormal data is calculated (step S5). g (μ xx ) and the density function ρ for the feature direction of normal data d (μ xx ) is the maximum singular value of the matrix constructed based on the matrix 2-norm ||ρ d (μ xx ) T ρ g (μ xx )||2 is calculated as the first index value.
[0097] Next, the setting unit 15 sets the matrix 2 norm calculated in step S6 as a threshold for determining the number of abnormally distributed packets (step S7). Thereafter, the managed opposing device 3 records the number of packets distributed by each of the multiple traffic control devices 2 for each time period (step S8). The managed opposing device 3 is the device with the opposing device ID: 1, which is the same as the opposing device 3 for which the threshold was set in step S6. In step S8, the number of distributed packets over a month in 10-minute increments is recorded, for example (FIG. 4).
[0098] Next, the collection unit 10 collects time series data of the number of packets distributed to the managed counterpart device 3 in each time period (step S9). As shown in FIG. 10, the collection unit 10 collects time series data of the number of packets distributed to the managed counterpart device 3 in the time period t1 to t N The collection unit 10 collects first data indicating the number of packets distributed to the managed counterpart device 3 during each time period included in the first section from t N+1 From t N+N The second data indicating the number of packets distributed to the opposite device 3 to be managed in each time period included in the second section from
[0099] Next, the feature extraction unit 11 performs singular value decomposition on the first data matrix to extract a transformation matrix U1 of the first data, which includes a group of orthonormal basis vectors, as the feature direction of the first data. Similarly, the feature extraction unit 11 performs singular value decomposition on the second data matrix to extract a transformation matrix U2 of the second data, which includes a group of orthonormal basis vectors, as the feature direction of the second data (step S10). Here, as shown in "step S10" in FIG. 10, the sliding windows for the first and second intervals are shifted to the right for each set time period (e.g., each time period), and singular value decomposition is performed on each of the first and second data matrices. Furthermore, FIG. 10 shows that the transformation matrices U1 and U2 are extracted as matrices of left singular vectors. In this way, the feature extraction unit 11 performs singular value decomposition to extract the transformation matrices U1 and U2 each time the sliding window is shifted.
[0100] Next, the calculation unit 14 calculates a second index value indicating the degree of spatial coincidence formed between the feature direction of the first data observed in the first interval extracted in step S10 and the feature direction of the second data observed in the second interval (step S11). The calculation unit 14 calculates the maximum singular value, i.e., the matrix 2-norm ||U1 T U2∥2 is calculated as the second index value (“Step S11” in FIG. 10).
[0101] Next, in step S11, if the second index value calculated by the calculation unit 14 exceeds the threshold value set in step S7, the determination unit 16 determines that the number of abnormal packets has been allocated to the second section in the managed opposing device 3 (step S12). If it is not determined in step S12 that the number of abnormal packets has been allocated, as shown in FIG. 10, the first section and the second section are sequentially shifted to the right, and the processing from step S8 to step S12 is repeated each time. When the processing from step S8 to step S12 is repeated while shifting the first section and the second section to the right along the time axis, the processing can be repeated by sequentially shifting the sections by any set time interval. In addition to repeating the processing by shifting by one time period as described above, for example, the section that was the second section in the first determination processing can be the first section in the next determination processing, and steps S8 to S12 can be executed.
[0102] Next, when it is determined in step S12 that an abnormal number of packets has been allocated to the counterpart device 3 under management, the identifying unit 17 identifies, among the multiple traffic control devices 2, a traffic control device 2 that is allocating more packets than the other traffic control devices 2 in the second section (step S13). In step S13, one or more traffic control devices 2 can be identified.
[0103] Next, the instruction unit 18 transmits an instruction to the traffic control device 2 identified in step S13 to adjust the number of packets to be distributed (step S14). Specifically, the instruction unit 18 instructs the traffic control device 2 that is distributing more packets to the opposite device 3 to be managed than the other traffic control devices 2 to distribute an equal number of packets to the other traffic control devices 2. Thereafter, the traffic control device 2 that received the instruction changes the number of packets to be distributed to the opposite device 3 to be managed, i.e., the scheduling parameters of the transmission queue such as TPS, in accordance with the instruction (step S15). Thereafter, the processing from step S1 to step S15 is executed for each opposite device 3 other than the opposite device ID: 1 (opposing device IDs: 2 to N).
[0104] As described above, the abnormality management device 1 according to this embodiment performs singular value decomposition on the data matrix of normal data using the subspace method, and uses the matrix U of the obtained left singular vectors as training data to learn parameters of a probabilistic model that outputs the posterior probability that the number of packets allocated to the opposite device 3 is normal by maximum likelihood estimation, thereby estimating the posterior probability that the number of packets allocated is normal. Furthermore, the density function of the abnormal data is derived based on the estimated value of the posterior probability, the density function of the normal data, and the prior probability of the normal data. Furthermore, the maximum singular value of the matrix of the derived density function of the abnormal data and the density function of the normal data is set as a determination threshold for the number of abnormal packets allocated to the opposite device 3. This makes it possible to appropriately manage imbalances in the amount of signal processing.
[0105] Furthermore, according to the abnormality management device 1 of this embodiment, the time window for the number of distribution packets, which is the observed value, is shifted sequentially, and an abnormality is judged using the judgment threshold for the number of abnormal distribution packets obtained by learning based on normal data, so it is possible to detect the occurrence of an abnormal number of distribution packets in real time.
[0106] The above describes embodiments of the abnormality management device and abnormality management method of the present invention, but the present invention is not limited to the described embodiments, and various modifications that a person skilled in the art can conceive are possible within the scope of the invention described in the claims. [Explanation of symbols]
[0107] 1...abnormality management device, 2...traffic control device, 3...opposing device, 10...collection unit, 11...feature extraction unit, 12...learning unit, 13...derivation unit, 14...calculation unit, 15...setting unit, 16...judgment unit, 17...identification unit, 18...instruction unit, 19...memory unit, 101...bus, 102...processor, 103...main memory device, 104...communication interface, 105...auxiliary memory device, 106...input / output I / O, 107...display device, NW...network.
Claims
1. a feature extraction unit configured to extract a feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicating the number of normal signals assigned to the device for each time period; a learning unit configured to learn, by maximum likelihood estimation, parameters of a probabilistic model that outputs a posterior probability that the number of signals assigned to the device for each time period corresponding to each of the feature directions of the normal data is normal, using the feature directions of the normal data extracted by the feature extraction unit as training data; a derivation unit configured to derive a probability distribution for characteristic directions of abnormal data indicating the number of abnormal signals allocated to the device for each time period that deviates from the range of the number of normal signals, based on the posterior probability estimated by the probability model learned by the learning unit, a probability distribution for characteristic directions of the normal data, and a prior probability of normality; a calculation unit configured to calculate, as a first index value, a maximum singular value configured based on the probability distribution for the feature direction of the abnormal data derived by the derivation unit and the probability distribution for the feature direction of the normal data; a setting unit configured to set the first index value calculated by the calculation unit as a determination threshold value for the number of abnormal signals; An abnormality management device comprising:
2. 2. The abnormality management device according to claim 1, further comprising a collection unit configured to collect first data indicating the number of signals allocated to the managed device for each time period included in a first section, and second data indicating the number of signals allocated to the managed device for each time period included in a second section following the first section, the feature extraction unit extracts a feature direction of the first data and a feature direction of the second data based on a first data matrix constituted by observation vectors representing the first data and a second data matrix constituted by observation vectors representing the second data, the calculation unit calculates, as a second index value, a maximum singular value configured based on the extracted feature direction of the first data and the extracted feature direction of the second data; Further, a determination unit configured to determine that an abnormal signal count has been assigned to the device to be managed in the second section when the second index value calculated by the calculation unit exceeds the determination threshold value. An abnormality management device characterized by:
3. 3. The abnormality management device according to claim 2, the collection unit collects the number of signals distributed to the devices to be managed as well as identification information of each source device that distributed each signal; an identification unit configured to identify a source device that has assigned a set number of signals or more to the managed device when the determination unit determines that an abnormal number of signals has been assigned; an instruction unit configured to transmit an instruction to the source device identified by the identification unit to adjust the number of signals to be distributed to the managed device; An abnormality management device comprising:
4. 2. The abnormality management device according to claim 1, The feature extraction unit extracts a transformation matrix of the normal data including a group of orthonormal basis vectors as a feature direction of the normal data by performing singular value decomposition on the data matrix. An abnormality management device characterized by:
5. A computer-implemented anomaly management method, comprising: a feature extraction step of extracting a feature direction of the normal data based on a data matrix composed of a plurality of observation vectors representing normal data indicating the number of normal signals assigned to the device for each time period; a learning step of learning, by maximum likelihood estimation, parameters of a probabilistic model that outputs a posterior probability that the number of signals assigned to the device is normal for each time period corresponding to each of the characteristic directions of the normal data, using the characteristic directions of the normal data extracted by the feature extraction step as training data; a derivation step of deriving a probability distribution for characteristic directions of abnormal data indicating the number of abnormal signals allocated to the device for each time period that deviates from the range of the number of normal signals, based on the posterior probability estimated by the probability model learned in the learning step, a probability distribution for characteristic directions of the normal data, and a prior probability of normality; a calculation step of calculating, as a first index value, a maximum singular value configured based on the probability distribution for the feature direction of the abnormal data derived in the derivation step and the probability distribution for the feature direction of the normal data; a setting step of setting the first index value calculated in the calculation step as a determination threshold value for the number of abnormal signals; An abnormality management method comprising:
6. 6. The abnormality management method according to claim 5, further comprising a collecting step of collecting first data indicating the number of signals allocated to the managed device for each time period included in a first section, and second data indicating the number of signals allocated to the managed device for each time period included in a second section following the first section, the feature extraction step extracts a feature direction of the first data and a feature direction of the second data based on a first data matrix constituted by observation vectors representing the first data and a second data matrix constituted by observation vectors representing the second data, the calculating step calculates, as a second index value, a maximum singular value configured based on the extracted feature direction of the first data and the extracted feature direction of the second data; Further, the method includes a determination step of determining that an abnormal signal count has been assigned to the device to be managed in the second section when the second index value calculated in the calculation step exceeds the determination threshold value. An abnormality management method characterized by:
7. 7. The abnormality management method according to claim 6, the collecting step collects the number of signals distributed to the managed devices as well as identification information of each source device that distributed each signal; and a specifying step of specifying a source device that has assigned a set number of signals or more to the managed device when it is determined in the determining step that an abnormal number of signals has been assigned. an instruction step of transmitting an instruction to the source device identified in the identification step to adjust the number of signals to be distributed to the managed device; An abnormality management method comprising:
8. 6. The abnormality management method according to claim 5, The feature extraction step extracts a transformation matrix of the normal data including a group of orthonormal basis vectors as a feature direction of the normal data by performing singular value decomposition on the data matrix. An abnormality management method characterized by:
Citation Information
Patent Citations
Communication service system and congestion avoidance method
JP2018142848A
Manufacturing method of optical element, optical element, optical system, and imaging apparatus
JP2019070695A
Abnormal management device, abnormal management method, and abnormal management system
JP7706675B1
JPP7706675B