Anomaly detection support device, anomaly detection support method, and anomaly detection support program
The anomaly detection support device streamlines the management of anomaly responses by displaying response statuses and allowing multiple users to register comments, reducing repetitive responses and improving corrective action efficiency.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2026-03-04
AI Technical Summary
Existing anomaly detection systems do not facilitate easy checking of the response status to detected anomalies in business data, leading to potential delays in corrective actions and difficulties in managing and registering corrective actions effectively.
Anomaly detection support device and method that includes a control unit to display anomaly detection results, manage judgment result data, and allow for the registration and display of response statuses, comments, and similarity judgments to streamline the management of anomaly responses.
Enables easy checking of response statuses, allows multiple users to register comments, manages comment history, and reduces repetitive responses by identifying similar anomalies, thereby enhancing the efficiency of corrective actions.
Smart Images

Figure 0007824211000001 
Figure 0007824211000002 
Figure 0007824211000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an anomaly detection support device, an anomaly detection support method, and an anomaly detection support program. [Background technology]
[0002] For example, there is an increasing trend in systems that detect anomalies in business data. Depending on the nature of the detected anomaly, it may have a serious impact on business operations, so a mechanism that enables prompt and accurate corrective action is required. Conventional anomaly detection systems include, for example, Patent Document 1. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2021-165998 Summary of the Invention [Problem to be solved by the invention]
[0004] However, Patent Document 1 does not mention anything about how, when an anomaly is detected in business data, a person in charge can easily check the status of the response to the anomaly.
[0005] The present invention has been made in consideration of the above, and aims to provide an anomaly detection support device, an anomaly detection support method, and an anomaly detection support program that allow a person in charge to easily check the response status to an anomaly when an anomaly is detected in business data. [Means for solving the problem]
[0006] In order to solve the above-mentioned problems and achieve the object, the present invention provides an anomaly detection support device that includes a control unit and displays anomaly detection results for business data, wherein the control unit is configured to be able to access judgment result data that includes an execution ID, line number, anomaly judgment result, detection target, detection date and time, definition name, and summary message for managing the results of anomaly detection, and judgment result comment data that includes a comment ID, execution ID, execution line number, comment content, response status indicating the response situation, update user, and update date and time, and controls the display of an alert screen, and on the alert screen, refers to the judgment result data to display a list of anomaly detection results in a list display area, and at that time, refers to the judgment result comment data to display the response status of each anomaly detection result.
[0007] According to another aspect of the present invention, the response status may include: response required, confirmed, response in progress, pending, response completed, or no response required.
[0008] According to another aspect of the present invention, the control unit may further include a comment processing means for registering comments entered by a person in charge regarding the target abnormality detection result on the alert screen in the judgment result comment data.
[0009] According to another aspect of the present invention, the comment may be configured so that it can be input multiple times by multiple people.
[0010] According to another aspect of the present invention, the comment processing means may refer to the judgment result comment data and display a history of comments on the target anomaly detection result.
[0011] Furthermore, according to one aspect of the present invention, the control unit is configured to be able to access a default value update condition detail master in which a default value update condition ID, a condition detail number, and a similarity judgment condition are registered in association with each other, and a default value update condition master in which a default value update condition ID, a default value update condition name, an execution ID, an execution line number, and a status specifying no action are registered in association with each other, and the judgment result data may include a similarity judgment result, and may be provided with a similarity judgment means that performs a similarity judgment with an existing anomaly detection result for the target anomaly detection result in accordance with the similarity judgment conditions registered in the default value update condition detail master, and if a judgment is made that the result is similar, updates the similarity judgment result of the judgment result data to "True" and updates the response status of the judgment result comment data to no action is required in accordance with the status of the default value update condition master.
[0012] In addition, in order to solve the above-mentioned problems and achieve the object, the present invention provides an anomaly detection support method executed by an information processing device having a control unit, wherein the control unit is configured to be able to access judgment result data for managing anomaly detection results, including an execution ID, a line number, anomaly judgment result, a detection target, a detection date and time, a definition name, and a summary message, and judgment result comment data for managing comments registered in response to anomaly detection, including a comment ID, an execution ID, an execution line number, comment content, a response status indicating the response situation, an update user, and an update date and time, and the method includes a display control step of controlling the display of an alert screen executed by the control unit, and displaying a list of anomaly detection results in a list display area on the alert screen by referring to the judgment result data, and at that time, displaying the response status of each anomaly detection result by referring to the judgment result comment data.
[0013] In addition, in order to solve the above-mentioned problems and achieve the object, the present invention provides an anomaly detection support program to be executed by an information processing device having a control unit, wherein the control unit is configured to manage the results of anomaly detection and to be able to access judgment result data including an execution ID, line number, anomaly judgment result, detection target, detection date and time, definition name, and summary message, and to manage comments registered in response to anomaly detection and to be able to access judgment result comment data including a comment ID, execution ID, execution line number, comment content, response status indicating the response situation, update user, and update date and time, and the control unit controls the display of an alert screen, and on the alert screen, refers to the judgment result data to display a list of anomaly detection results in a list display area, and at that time refers to the judgment result comment data to display the response status of each anomaly detection result, characterized in that the anomaly detection support program causes the control unit to execute a display control process. [Effects of the Invention]
[0014] According to the present invention, when an abnormality is detected in business data, the person in charge can easily check the status of the response to the abnormality. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a diagram for explaining the first problem of the present invention. [Figure 2] FIG. 2 is a diagram for explaining the second problem of the present invention. [Figure 3] FIG. 3 is a diagram for explaining the third problem of the present invention. [Figure 4] FIG. 4 is a diagram for explaining the fourth problem of the present invention. [Figure 5] FIG. 5 is a diagram for explaining the fifth problem of the present invention. [Figure 6] FIG. 6 is a block diagram showing an example of the configuration of an anomaly detection support device according to this embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of the configuration of the default value update condition master. [Figure 8] FIG. 8 is a diagram illustrating an example of the configuration of the default value update condition detail master. [Figure 9] FIG. 9 is a diagram illustrating an example of the configuration of the abnormality determination definition master. [Figure 10] FIG. 10 is a diagram showing an example of the configuration of the determination result data string information master. [Figure 11] FIG. 11 is a diagram illustrating an example of the configuration of the default value update history table. [Figure 12] FIG. 12 is a diagram illustrating an example of the configuration of the determination result data. [Figure 13] FIG. 13 is a diagram showing an example of the structure of the determination result comment data. [Figure 14] FIG. 14 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 15] FIG. 15 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 16A] FIG. 16A is a diagram for explaining a specific example of processing by the control unit of the anomaly detection support device according to this embodiment. [Figure 16B] FIG. 16B is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 17] FIG. 17 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 18A] FIG. 18A is a diagram for explaining a specific example of processing by the control unit of the anomaly detection support device according to this embodiment. [Figure 18B] FIG. 18B is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 19A] FIG. 19A is a diagram for explaining a specific example of processing by the control unit of the anomaly detection support device according to this embodiment. [Figure 19B] FIG. 19B is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 20]FIG. 20 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 21] FIG. 21 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 22] FIG. 22 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 23] FIG. 23 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 24] FIG. 24 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 25] FIG. 25 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 26] FIG. 26 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 27] FIG. 27 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 28] FIG. 28 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 29] FIG. 29 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. [Figure 30] FIG. 30 is a diagram for explaining a specific example of the processing of the control unit of the anomaly detection support device according to this embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An embodiment of the present invention will be described in detail with reference to the accompanying drawings. However, the present invention is not limited to this embodiment.
[0017] [1. Overview] The outline of the present invention will be explained in the order of background, issues and measures.
[0018] (1-1. Background) Recently, there has been an increase in systems that detect anomalies in business data. Depending on the nature of the anomaly detected, it could have a significant impact on business operations, so a system that allows for quick and accurate corrective action is required. Therefore, anomaly detection support devices must be equipped with not only anomaly detection logic, but also a flow for correcting detected anomalies. The following three points are important requirements for a flow for correcting detected anomalies.
[0019] · The person in charge of corrective action can easily check the status of the response to the abnormality. -Register the details of corrective actions · Ability to manage and check the details of past corrective actions
[0020] (1-2. Issues / measures) Problems 1 to 5 of the present invention and the measures taken to address them will be described with reference to Figures 1 to 5. Figures 1 to 5 are diagrams for explaining Problems 1 to 5 of the present invention, the measures taken to address them, and an overview of their functions.
[0021] (1) Task 1 There is an issue that it takes time to check the latest response status for detected anomalies. Specifically, when correcting and managing detected anomalies, it is necessary to understand the latest response status for the anomaly. However, if checking the latest status takes time and effort, subsequent corrective actions will also be delayed. For example, checking the status of an abnormality during corrective action requires communication with the relevant parties, which makes checking the status time-consuming. For this reason, a system is needed to quickly and easily check the latest response status of detected abnormalities.
[0022] As a countermeasure to this, the present invention is equipped with a function that sets a "response status" indicating the response situation for each anomaly detection result, changes the response status depending on the response situation, and furthermore, displays the response status for each anomaly detection result on a list screen of abnormalities that have occurred.
[0023] This allows the person in charge of corrective action to quickly check the status of the response to the abnormality.
[0024] (2) Task 2 There is a challenge in that it is necessary to register and manage the details of the corrections of abnormalities in detail. Specifically, when checking the specific details of the corrective action taken for a detected abnormality, statuses such as "in progress" or "resolved" alone are insufficient. In addition, it is difficult for anyone other than the person in charge of correction to accurately grasp the current status of the abnormality response, and when there are multiple people in charge of correction, there is a risk of misunderstandings between them. For example, for an abnormality with a status of "in progress," it is unclear what kind of response has been taken and to what extent. For this reason, a system is needed that allows the details of the corrective action to be registered in the form of comments.
[0025] To address this issue, the present invention is equipped with a function for registering a comment for each anomaly detection result.
[0026] This allows details to be entered for each anomaly detection result, making it possible to manage corrective actions at a finer granularity.
[0027] (3) Task 3 Assuming that multiple people will be working together to correct a single anomaly, there is a need for each person to be able to register comments multiple times. Specifically, when multiple people are working together to correct a detected anomaly, and each person registers details of their own response and interactions with other people in comments, it is necessary for all people to be able to register comments multiple times.
[0028] For example, if User1 is responsible for implementing corrective actions and User2 is responsible for confirming the corrective actions, the following comments can be used:
[0029] User1 provided details of the corrective action in the comments. User2 wrote in the comments that he / she confirmed User1's corrective action. -The exchange between User1 and User2 is also included in the comments.
[0030] For this reason, a system is needed that allows multiple corrective personnel to register comments multiple times for a single anomaly.
[0031] To address this issue, the present invention is equipped with a function that allows multiple people to register comments multiple times for each anomaly detection result.
[0032] This allows multiple people to handle the task of correcting the abnormality.
[0033] (4) Task 4 There is an issue of needing to be able to check the history of comments registered in the past. Specifically, when checking past corrective actions for a certain anomaly, it is necessary to check not only the most recent comment but also the history of comments registered in the past. If the comment history cannot be checked, it becomes difficult to manage past corrective actions. For example, if there is an anomaly that has been left uncorrected, it is necessary to check the history of past comments to determine the reason for leaving it uncorrected. For this reason, a mechanism is needed to check the history of comments registered in the past.
[0034] To address this issue, the present invention is equipped with a function that enables management of comment history.
[0035] This makes it possible to manage past corrective actions and control unauthorized data manipulation.
[0036] (5) Task 5 If similar anomalies are repeatedly detected, there is a risk that this will hinder corrective action. Specifically, when anomaly detection is performed periodically, If an error that has already occurred has not been dealt with, there is a possibility that a similar error will be detected again, making it difficult to distinguish between an error that has already occurred and a new error. This increases the risk of having to deal with the same error multiple times, or of the volume of error notifications being so large that more important errors will be overlooked.
[0037] For example, if there is an anomaly ART001 that takes several days to correct, and anomaly detection is performed automatically daily, and similar anomalies occur repeatedly (anomalies ART002, ART003, ART004, etc.) until the corrective action for ART001 is completed, it will be difficult to determine whether or not a response is required for ART002, ART003, ART004, etc. For this reason, a mechanism is needed to distinguish whether the anomaly that has occurred is similar in content to an existing anomaly or not.
[0038] As a countermeasure to this, the present invention is equipped with a function that updates the response status of an anomaly detection result to the response status set in the master if it is determined to be similar to an existing anomaly detection result.
[0039] This reduces the risk of having to respond to the same anomaly multiple times, reduces the number of anomaly notifications, and reduces the risk of overlooking more important anomalies.
[0040] The anomaly detection support device of the present invention is applicable to all business types and industries.
[0041] [2. Configuration] An example of the configuration of the anomaly detection support device 100 according to this embodiment will be described with reference to Fig. 6. Fig. 6 is a block diagram showing an example of the configuration of the anomaly detection support device 100.
[0042] The anomaly detection support device 100 is a commercially available desktop personal computer. Note that the anomaly detection support device 100 is not limited to a stationary information processing device such as a desktop personal computer, but may also be a portable information processing device such as a commercially available notebook personal computer, a PDA (Personal Digital Assistant), a smartphone, or a tablet personal computer.
[0043] The anomaly detection support device 100 includes a control unit 102, a communication interface unit 104, a storage unit 106, and an input / output interface unit 108. The units included in the anomaly detection support device 100 are connected to each other so as to be able to communicate with each other via any communication path.
[0044] The communication interface unit 104 communicatively connects the anomaly detection support device 100 to a network 300 via a communication device such as a router and a wired or wireless communication line such as a dedicated line. The communication interface unit 104 has a function of communicating data with other devices via the communication line. Here, the network 300 has a function of communicatively connecting the anomaly detection support device 100 with the server 200, the business system 400, and the terminal device 500, for example, the Internet or a LAN (Local Area Network).
[0045] The business system 400 is configured to be able to communicate data with the anomaly detection support device 100 via the network 300. The business system 400 generates various types of business data such as cost data, manufacturing data, order data, purchase data, sales data, and journal data. The anomaly detection unit 102a of the anomaly detection support device 100 performs automatic anomaly detection on this business data.
[0046] The terminal devices 500... are terminal devices used by, for example, User1, User2, User3, etc. The terminal devices 500... are configured to be able to communicate data with the anomaly detection support device 100 via the network 300. For example, User1, User2, User3, etc. use the terminal devices 500... to access the anomaly detection support device 100 and check the response status of the anomaly detection result or enter comments on an alert screen provided by the anomaly detection support device 100.
[0047] An input device 112 and an output device 114 are connected to the input / output interface unit 108. The output device 114 may be a monitor (including a home television), a speaker, or a printer. The input device 112 may be a keyboard, a mouse, a microphone, or a monitor that cooperates with a mouse to achieve a pointing device function. Note that, hereinafter, the output device 114 may be referred to as the monitor 114, and the input device 112 may be referred to as the keyboard 112 or the mouse 112. Displaying information on the monitor 114 and the user operating the input device 112 may be referred to as a "user operation via a UI."
[0048] Various databases, tables, files, etc. are stored in the storage unit 106. Computer programs that work in conjunction with an OS (Operating System) to issue commands to a CPU (Central Processing Unit) to perform various processes are recorded in the storage unit 106. The storage unit 106 can be, for example, a memory device such as a RAM (Random Access Memory) or a ROM (Read Only Memory), a fixed disk device such as a hard disk, a flexible disk, an optical disk, etc.
[0049] The storage unit 106 stores a default value update condition master 106a, a default value update condition detail master 106b, an abnormality determination definition master 106c, a determination result data string information master 106d, a default value update history table 106e, determination result data, determination result comment data, etc. FIG. 7 is a diagram showing an example of the configuration of the default value update condition master 106a. FIG. 8 is a diagram showing an example of the configuration of the default value update condition detail master 106b. FIG. 9 is a diagram showing an example of the configuration of the abnormality determination definition master 106c. FIG. 10 is a diagram showing an example of the configuration of the determination result data string information master 106d. FIG. 11 is a diagram showing an example of the configuration of the default value update history table 106e. FIG. 12 is a diagram showing an example of the configuration of the determination result data. FIG. 13 is a diagram showing an example of the configuration of the determination result comment data.
[0050] The default value update condition master 106a is a master for managing the response status and comment to be updated for an abnormality detection result that is determined to be similar to an existing abnormality detection result. 7, the default value update condition master 106a can be configured as a table or the like that associates and registers the default value update condition ID, default value update condition name, execution ID, execution line number, status type, status, whether to copy a comment or add a default comment, and the default comment content. In the example shown in the figure, the first line contains the default value update condition ID "UC001," the default value update condition name "Default value update condition A," the execution ID "EX002," the execution line number "1," the status type "Fixed value," the status "No action required," whether to copy a comment "False," whether to add a default comment "True," and the default comment content "Updated automatically."
[0051] The default value update condition detail master 106b is a master for managing conditions for determining whether a newly detected anomaly is similar to an existing anomaly detection result. As shown in FIG. 8, the default value update condition detail master 106b can be configured as a table or the like in which default value update condition IDs, condition detail numbers, similarity determination conditions (result table information IDs, comparison operators, determination value types, and determination values), etc., are associated and registered. In the example shown in the figure, the first row contains the default value update condition ID "UC001," the condition detail number "1," the result table information ID "fiscal year," the comparison operator "=", and the determination value type "the same value as the original anomaly." The second row contains the default value update condition ID "UC001," the condition detail number "2," the result table information ID "product name," the comparison operator "=", and the determination value type "the same value as the original anomaly."
[0052] The abnormality determination definition master 106c is a master for managing the definitions of abnormality determination in business data. As shown in FIG. 9, the abnormality determination definition master 106c can be configured as a table or the like in which abnormality determination definition IDs, abnormality determination definition names, etc. are associated and registered. In the example shown in the same figure, the first line has the abnormality determination definition ID "JD001" and the abnormality determination definition name "inventory turnover alert." The abnormality determination definition master 106c is not relevant to this application except for the abnormality determination definition ID, so a detailed description will be omitted.
[0053] The judgment result data string information master 106d is a master for managing information (header name, type, etc.) of the table string of judgment result data. As shown in Fig. 10, the judgment result data string information master 106d can be configured as a table or the like in which abnormality judgment definition ID, column number, column, column name, type, and type name are associated and registered. In the example shown in the same figure, the first row has abnormality judgment definition ID "JD001", column number "1", column "AlertDefinitionID", column name "abnormality judgment definition ID", type "string", and type name "character".
[0054] The default value update history table 106e is a table for managing the conditions used to determine whether a default value should actually be updated when updating a default value. As shown in FIG. 11, the default value update history table 106e may include a default value update history ID, an execution ID, an execution line number, and a default value update condition ID. In the example shown in the figure, the first row contains the default value update history ID "UH001," the execution ID "EX002," the execution line number "1," and the default value update condition ID "UC001."
[0055] The judgment result data is a table for managing the results of abnormality judgment on business data. The judgment result data may include anomaly judgment definition ID, execution ID, line number, judgment result, anomaly rank, fiscal year, fiscal year and month, product name, inventory turnover rate, whether the judgment result is similar, detection date and time, definition name, summary message, detection target, detection method, threshold, judgment method, and lower limit. The "anomaly rank" is a ranking of the degree of anomaly based on the calculated value of the anomaly judgment method used when automatic anomaly judgment was executed. In the example shown in the same figure, the first line contains the anomaly judgment definition ID "JD001," execution ID "EX001," line number "1," judgment result "True," anomaly rank "3," fiscal year "2022," fiscal month "2022 / 11," product name "Product name A," inventory turnover rate "0.36," whether it is a similar judgment result "False," detection date and time "2022 / 11 / 1 01:02:03," definition name "Inventory turnover alert," summary message "Product A detected," detection target "2022 / 11 Product A 0.36," detection method "Interquartile range," threshold "1.5 times normal range," judgment method "Values smaller than the lower limit are judged to be abnormal," and lower limit value "0.83."
[0056] The judgment result comment data is data for managing comments registered for abnormalities. The judgment result comment data may include a comment ID, an execution ID, an execution line number, comment content, response status, an update user, and an update date and time, as shown in FIG. 13. In the example shown in the same figure, the first line contains the comment ID "CM001", the execution ID "EX001", the execution line number "1", the response status "Response required", the update user "Automatic execution", and the update date and time "2022 / 11 / 1 01:02:03".
[0057] The control unit 102 is a CPU or the like that performs overall control of the anomaly detection support device 100. The control unit 102 has an internal memory for storing control programs such as an OS, programs that define various processing procedures, required data, etc., and executes various information processing operations based on these stored programs.
[0058] The control unit 102 is configured to be able to access the default value update condition master 106a, the default value update condition detail master 106b, the abnormality determination definition master 106c, the determination result data string information master 106d, the default value update history table 106e, the determination result data, the determination result comment data, and the like, which are stored in the storage unit 106. Note that the default value update condition master 106a, the default value update condition detail master 106b, the abnormality determination definition master 106c, the determination result data string information master 106d, the default value update history table 106e, the determination result data, and the determination result comment data may be provided in another location (for example, the server 200) as long as the control unit 102 is able to access them.
[0059] The control unit 102 conceptually includes an abnormality detection unit 102a, a similarity determination unit 102b, a comment processing unit 102c, and a screen display control unit 102d.
[0060] The control unit 102 has a function of adding comments and response status to the anomaly detection result and a function of determining similarity.
[0061] The abnormality detection unit 102a performs automatic abnormality detection on various business data generated by the business system 400 in accordance with the abnormality determination definition master 106c and the like, and registers the abnormality detection results in the storage unit 106 as determination result data.
[0062] The screen display control unit 102d controls the display of various screens and inputs thereto. For example, the screen display control unit 102d controls the display of an alert screen and inputs thereto, and on the alert screen, references the judgment result data to display a list of anomaly detection results in a list display area, and at that time, references the judgment result comment data to display the response status of each anomaly detection result. The response status may include response required, confirmed, response in progress, on hold, response completed, or no response required.
[0063] The comment processor 102c registers comments entered by a person in charge of the target anomaly detection result on the alert screen in the judgment result comment data. The comment may be configured so that multiple people can enter comments multiple times. The comment processor 102c may refer to the judgment result comment data and display a history of comments on the target anomaly detection result.
[0064] The similarity determination unit 102b performs a similarity determination between the target anomaly detection result and an existing anomaly detection result in accordance with the similarity determination conditions set in the default value update condition detail master 106b, and if it determines that the result is similar, it updates the similarity determination result of the determination result data to "True" and updates the response status of the determination result comment data to "no response required" in accordance with the status of the default value update condition master 106a.
[0065] [3. Specific Examples] Specific examples of processing by the control unit 102 of the anomaly detection support device 100 in this embodiment will be described with reference to Fig. 14 to Fig. 30. Fig. 14 to Fig. 30 are diagrams for explaining specific examples of processing by the control unit 102 of the anomaly detection support device 100 in this embodiment.
[0066] (3-1. Comment function) The comment function on the alert screen will be described with reference to Fig. 14 to Fig. 20. The comment function on the alert screen will be outlined with reference to Fig. 14. Fig. 14 is a diagram for explaining the outline of the comment function on the alert screen.
[0067] The alert screen consists of two screens: the alert list screen (initial screen) and the alert details screen. The "alert list screen" is a screen where detected abnormalities can be checked in list format, and the response status for each abnormality detection result can be checked on the list screen. The "alert details screen" is a screen where you can check the details of detected abnormalities.
[0068] You can register comments about abnormalities and check the history of past comments. The following three operations are explained.
[0069] 1. When one person in charge writes details of the corrective action for the abnormality in the comments (User001 is in charge) 1.1 Operations on the alert list screen Set a "Response Status" that indicates the status of the response to the abnormality 1.2 Operations on the alert details screen Register a comment for each anomaly detection result
[0070] 2. When registering a comment for an anomaly for which another person has already registered a comment (User002 is in charge) 2.1 Operations on the alert details screen Multiple people can register comments for each anomaly detection result.
[0071] 3. When an administrator checks an error that has been resolved (User003) 3.1 Operations on the alert details screen You can manage and check the history of past comments.
[0072] Fig. 15 is a diagram for explaining the case where one person in charge writes details of the corrective action for an abnormality in a comment (User001 is in charge). In Fig. 15, (A) shows an example of the display of the alert list screen, and also shows which columns of the judgment result data and judgment comment data are referenced to extract the data.
[0073] As shown in (A), the alert list screen includes an extraction condition specification area, an anomaly detection result list display area, and a comment button.
[0074] The extraction condition specification area has an input field for the response status and a display button. When the response status is specified and the display button is pressed, the judgment result data and judgment result comment data corresponding to the specified response status are extracted and displayed in the judgment result list display area. Specifically, the execution ID for which the response status is the specified response status is obtained from the judgment result comment data, and the judgment result data is extracted using the obtained execution ID and execution line number as keys. In the judgment result list display area, one process (per execution ID and execution line number) in the anomaly judgment execution is displayed as one detail. If no extraction conditions are specified, all judgment results are displayed. The example shown in Figure 15 shows the case where no extraction conditions are specified.
[0075] In the anomaly detection result list display area, each detail displays the definition name of the judgment result data, the detection date and time, a summary message, the response status indicating the status of the response to the anomaly, the number of comments in the judgment result comment data, the user who updated the most recent comment, and the update date and time. The number of comments is calculated by tallying the number of comment contents for each execution ID and execution line number of the judgment result comment data. Records with no comments entered are not included in the tally. For example, in the example shown in the same figure, the first detail displays the definition name "Inventory Turnover Alert," the detection date and time "2022 / 11 / 1 01:02:03," the summary message "Product A detected," the response status "Response required," and the number of comments "0." In addition, the second detail displays the definition name "Inventory rotation alert," detection date and time "2022 / 11 / 2 01:02:03," summary message "Product A detected," response status "In progress," number of comments "2," update user "User002," and update date and time "2022 / 11 / 2 12:22:32."
[0076] In this way, it is possible to set a status according to the response status of the anomaly, such as "action required" or "response in progress," and the response status for each anomaly detection result can be checked on the alert list screen. A background color can be set for each response status; for example, "action required" can be displayed in red, "confirmed" in green, "response in progress" in blue, "on hold" in yellow, "response completed" in navy blue, and "no action required" in gray. A fixed background color can be specified in advance. In this way, in this embodiment, it is possible to easily check the response status for each anomaly detection result.
[0077] Next, operations on the alert details screen will be explained with reference to Figures 16A and 16B. Figures 16A and 16B are diagrams for explaining operations on the alert details screen, with (A) showing an example of the alert list screen display, (B) showing an example of the alert details screen display, and (C) showing an example of the display when a comment is entered in the response / comment area of the alert details screen, and further showing which columns of the judgment result data and judgment comment data are referenced to extract data.
[0078] As shown in (A), when you click on the target anomaly detection result in the anomaly detection result list display area on the alert list screen, the alert details screen will be displayed as shown in (B). The alert details screen displays details of the anomaly detection result and an area for responses and comments.
[0079] The details of the anomaly detection results are displayed by extracting data such as the fiscal year and month of the judgment result data, product name, inventory turnover rate, detection target, detection method, threshold value, reflection method, and lower limit value using the execution ID and execution line number corresponding to the clicked anomaly detection result as keys.
[0080] The response / comment area uses the execution ID and execution line number as keys to reference the judgment result comment data and displays the latest response status, comment update history, and comment input field. The latest response status displays the last updater, update date, response status, and comment status. In this example, the "Response Status" of the latest response status is "Response Required."
[0081] The comment update history displays the latest comment and history if there is a comment in the judgment result comment data. The comment input field allows you to select the response status and has an add button for registering a comment. In the comment input field, select the response status, enter a comment, and press the add button to register new judgment result comment data according to the input content.
[0082] As shown in (C), if User1 selects the response status "In progress" in the comment input field, enters the comment "Sales amount of sales slip A001 changed from 10,000 yen to 1,000 yen," and presses the Add button, the following will be newly registered in the judgment result comment data: comment ID "CM004," execution ID "EX001," execution line number "1," comment content "Sales amount of sales slip A001 changed from 10,000 yen to 1,000 yen," response status "In progress," update user "User001," and update date and time "2022 / 11 / 9 20:21:00."
[0083] In this way, for each anomaly detection result, detailed responses can be registered in the form of comments, allowing the details of the person in charge to be recorded in detail. This makes it possible to manage corrective actions at a fine level of granularity.
[0084] Referring to FIG. 17, a case where pressing the comment button switches between displaying and hiding the "correspondence and comment area." FIG. 17 is a diagram for explaining a case where pressing the comment button switches between displaying and hiding the "correspondence and comment area," with (A) showing the state before pressing the comment button and (B) showing the state after pressing the comment button. Pressing the comment button switches between displaying and hiding the "correspondence and comment area." Pressing the comment button in (A) hides the "correspondence and comment area," as shown in (B). Pressing the comment button in (B) displays the "correspondence and comment area," as shown in (A).
[0085] With reference to Figures 18A and 18B, the case where a comment is registered (by User002) for an anomaly for which another person in charge has already registered a comment will be described. Figures 18A and 18B are diagrams for explaining the case where a comment is registered (by User002) for an anomaly for which another person in charge has already registered a comment, with (A) showing the state after User001 has registered a comment (the state after User001 has registered a comment in Figure 16(C)), and (B) showing the state after User002 has further registered a comment, and also showing the judgment result data to be referenced and the judgment comment data to be referenced and registered. Here, the operations to be performed after selecting an anomaly detection result from the alert list screen will be described.
[0086] As shown in (A), the details of the anomaly detection result show the response status as "In progress" and the number of comments as "1." The response / comment area also shows the latest response status, with the most recent updater as "User001," the update date as "2022 / 11 / 9 20:21:00," the response status as "In progress," and the comment as "Sales amount changed from 10,000 yen to 1,000 yen on sales slip A001." The comment update history also shows "User001 2022 / 11 / 9 20:21:00 In progress Changed sales amount on sales slip A001 from 10,000 yen to 1,000 yen."
[0087] Here, as shown in (B), if User002 selects the response status "In progress" in the comment input field, enters the comment "Confirm User001's corrective response," and presses the Add button, for example, the following will be newly registered in the judgment result comment data: comment ID "CM005," execution ID "EX001," execution line number "1," response status "In progress," update user "User002," comment content "Confirm User001's corrective response," and update date and time "2022 / 11 / 10 20:54:00."
[0088] In this way, multiple personnel can register comments for each anomaly detection result. Specifically, multiple personnel can register comments multiple times for each anomaly detection result, allowing each personnel to register details of their own response. In addition, it is possible to register interactions between personnel in comments, making it possible to leave detailed evidence of corrective responses that become more complex when multiple personnel are involved. This allows multiple personnel to handle the work of correcting anomalies.
[0089] With reference to Figures 19A and 19B, we will explain the case where an administrator (User003 is in charge) checks an abnormality for which a response has been completed. Figures 19A and 19B are figures for explaining the case where an administrator (User003 is in charge) checks an abnormality for which a response has been completed, where (A) is a figure showing the state in which User002 has registered a comment (the state after User002 has registered a comment in Figure 18(B)), and (B) is a figure showing the state in which User003 has further registered a comment, and also shows the judgment result data to be referenced and the judgment comment data to be referenced and registered. Here, we will describe the operations to be performed after selecting an abnormality detection result from the alert list screen.
[0090] As shown in (A), the details of the anomaly detection result show the response status "In progress" and the number of comments "2." The response / comment area also shows the latest response status: the most recent updater "User002," the update date "2022 / 11 / 10 20:54:00," the response status "In progress," and the comment "Currently checking User001's corrective action." The comment update history also shows the comment "User002, 2022 / 11 / 10 20:54:00, In progress, Currently checking User001's corrective action," and the comment "User001 2022 / 11 / 9 20:21:00 In progress, Changed the sales amount of sales slip A001 from 10,000 yen to 1,000 yen," displayed in order of most recent.
[0091] Here, as shown in (B), if User003 selects the response status "Response completed" in the comment input field, enters the comment "This abnormality response is closed," and presses the Add button, for example, the following will be newly registered in the judgment result comment data: comment ID "CM006," execution ID "EX001," execution line number "1," response status "Response completed," update user "User003," comment content "This abnormality response is closed," and update date and time "2022 / 11 / 11 20:35:00."
[0092] In this way, it is possible to manage and check the history of past comments. Specifically, it is possible to manage the history of previously registered comments for each anomaly detection result, and it is also possible to check the history of previously registered comments. The comment history displays the name of the person who made the update and the date and time of the update, so it is possible to check "who" and "when" the comment was registered. This makes it possible to manage past corrective actions and control unauthorized data manipulation.
[0093] (3-2. Similarity determination function) The similarity determination function will be explained with reference to Figures 20 to 30. Here, we will explain the mechanism for determining similarity between a detected anomaly detection result and past anomaly detection results. The function for updating the response status and comments previously set in the master for an anomaly detection result that is determined to be similar to an existing anomaly detection result is called "default value update."
[0094] Here we will explain an example of a hypothetical business. For example, anomaly detection for inventory turnover is performed at the end of the month. The end of the month is often the time for accounting closing, and it is common to check for any accounting anomalies at the same time as closing the books. Furthermore, if an anomaly in inventory turnover is detected for the same product during the same fiscal year, there will be multiple anomalies in inventory turnover for the same key item, which could cause confusion for the person in charge. Therefore, if an anomaly with the same key is detected again, the anomaly is considered to be "taking corrective action" and the anomaly detection result is set to "no action required."
[0095] Below, we will explain an example of the conditions for similarity determination, using the case where (1) the fiscal year matches and (2) the product name matches. If a similarity determination is made, the comment content "Updated automatically," the response status "No action required," and the update user "Automatic execution" are automatically registered in the determination result comment data. In addition, the response status "No action required" is displayed in the details of the anomaly detection results on the alert list screen.
[0096] A setting example of the default value update condition master 106a and the default value update condition detail master 106b will be described with reference to Fig. 20. In order to carry out the above-mentioned assumed business, data is set in the default value update condition master 106a and the default value update condition detail master 106b.
[0097] In this case, the anomaly detection result for "Execution ID=EX002, Execution Line Number=1" is confirmed, and a master record is provided in case a similar anomaly is detected in the future.
[0098] FIG. 20(A) is a diagram showing an example of data settings for the default value update condition master 106a. The default value update condition master 106a has fields for default value update condition ID, default value update condition name, execution ID, execution line number, status type, status, whether to copy comment, whether to add default comment, and default comment content. The execution ID and execution line number are used to specify the anomaly detection result (determination result data) of the judgment source. The "response status" is used to specify the response status of an anomaly detection result determined to be similar. The "status type" is expected to specify either "fixed value" or "same value as judgment source." The behavior when "same value as judgment source" is set will be described later. The "whether to copy comment," "whether to add default comment," and "default comment content" are used to control the comment of an anomaly detection result determined to be similar. The "whether to copy comment" option will be described later.
[0099] In the example shown in the figure, the settings are: default value update condition ID "UC001", default value update condition name "default value update condition A", execution ID "EX002", execution line number "1", status type "fixed value", status "no action required", whether to copy comment "False", whether to add default comment "True", and default comment content "Updated automatically".
[0100] FIG. 20B is a diagram showing an example of data setting in the default value update condition detail master 106b. The default value update condition detail master 106b has the following fields: default value update condition ID, condition detail number, result table information ID, comparison operator, judgment value type, and judgment value. The conditions for similarity judgment are specified using the "result table information ID," "comparison operator," "judgment value type," and "judgment value." It is also possible to specify a fixed value for the "judgment value type," in which case the fixed value is entered into the "judgment value."
[0101] In the example shown in the same figure, the first line has the default value update condition ID "UC001", condition detail number "1", result table information ID "fiscal year", comparison operator "=", and judgment value type "same value as the original abnormality". The second line has the default value update condition ID "UC001", condition detail number "2", result table information ID "product name", comparison operator "=", and judgment value type "same value as the original abnormality".
[0102] For the default value update condition master 106a, one default value update condition can be applied to multiple anomaly detection results, and Fig. 20(C) shows an example in which one default value update condition is applied to multiple anomaly detection results. In the example shown in the figure, the default value update condition ID "UC001" and the default value update condition name "Default value update condition A" are applied to the execution ID "EX002", the execution line number "1", the execution ID "EX001", the execution line number "1", and the execution ID "EX001", the execution line number "1".
[0103] The records of the default value update condition master 106a and the default value update condition detail master 106b are provided according to the need for similarity determination after the detected abnormality determination result is confirmed. Furthermore, the above-mentioned records of the default value update condition master 106a and the default value update condition detail master 106b are an example set for abnormality detection regarding inventory turnover. The actual contents of the records will vary depending on the items set for each abnormality determination definition (settings in the determination result data string information master 106d) and the conditions used for similarity determination. In the following explanation, it is assumed that the execution of anomaly detection has already been completed.
[0104] A case where similarity determination is performed will be described with reference to Fig. 21. Fig. 21 is a diagram for explaining a case where similarity determination is performed. (A) shows an example of determination result data, and (B) shows determination result comment data. Similarity determination is performed between anomaly detection results with the same "abnormality determination definition ID," but is not performed when the "abnormality determination definition ID" is different because the types of abnormality determination definitions are different.
[0105] For example, in (A) and (B), the first line of the judgment result data and the first and second lines of the judgment result comment data indicate the anomaly detection results detected in the past, and the second line of the judgment result data indicates the anomaly detection result created as a result of the current anomaly detection. The "anomaly judgment definition ID 'JD001'" in the second line of the judgment result data is the same as in the first line, so a similarity judgment is made with the first line. In this case, the fiscal year and product name match, so the similarity judgment result is "True."
[0106] On the other hand, as shown in (C), if the anomaly determination definition IDs are different, similarity determination is not performed. Note that if the anomaly determination definition IDs are different, similarity determination is not performed even if the accounting year and product name match.
[0107] The mechanism of similarity determination will be described with reference to Figures 22 to 24. Figures 22 to 24 are diagrams for explaining the mechanism of similarity determination. Similarity determination is performed in the following order.
[0108] 1. Similarity determination is performed according to the conditions registered in the default value update condition detail master 106b. 2. Register a comment according to the settings registered in the default value update condition master 106a 3. Update the response status for anomaly detection results that are judged to be similar
[0109] These processes will be described in detail below. (1. Similarity determination is performed according to the conditions registered in the default value update condition detail master 106b) If it is determined that the abnormality detection result is similar, information on the similarity determination history is newly registered in the default value update history table 106e.
[0110] In FIG. 22, in the default value update condition detail master 106b, the similarity determination condition is = the same value as the anomaly in the source of the judgment, and product name = the same value as the anomaly in the source of the judgment. The execution ID "EX002" and line number "1" in the first line of the judgment result data indicate the fiscal year "2022" and the product name "Product A". The execution ID "EX003" and line number "1" of the current anomaly detection result indicate the fiscal year "2022" and the product name "Product A", which meets the similarity judgment condition, so the similarity judgment result is updated to "True" and newly registered in the default value update history table 106e. In the example shown in the same figure, default value update history ID "UH001", execution ID "EX003", execution line number "1", and default value update condition ID "UC001" are newly registered.
[0111] (2. Register a comment according to the settings registered in the default value update condition master 106a) 23, in the default value update condition master 106a, whether to add a default comment is set to "True" and the default comment content is set to "Updated automatically." If a similarity judgment is made, in accordance with this setting, the comment content "Updated automatically," the response status "Response required (initial value when an abnormality is detected)," and the update user "Automatic execution" are registered in the judgment result comment data.
[0112] In this way, it is possible to automatically distinguish whether the anomaly that has occurred is similar to an existing anomaly or not.
[0113] (3. Update the response status for anomaly detection results that are judged to be similar) The "Response Status" of the record determined to be a similar abnormality detection is updated to the status set in the default value update condition detail master 106b.
[0114] 24, the status "no action required" is set in the default value update condition detail master 106b. In accordance with this setting, the action status of the judgment comment data is updated from "action required" to "action not required."
[0115] In this way, it is possible to automatically distinguish whether the anomaly that has occurred is similar to an existing anomaly, and if the anomaly detection result is determined to be similar to an existing anomaly detection result, the response status is updated to "no response required." This means that the response status can be updated automatically, without the need for a person in charge to manually update it. This reduces the risk of having to respond to the same anomaly multiple times, reduces the number of anomaly notifications, and reduces the risk of overlooking anomalies of higher importance.
[0116] Next, how anomaly detection results that have been determined to be similar are displayed on the alert list screen and alert details screen will be described with reference to Figures 25 to 27. For anomaly detection results that have been determined to be similar, a function has been added to each screen.
[0117] In FIG. 25, if the similarity determination result of the determination result data is "True," the anomaly detection result list display area on the alert list screen displays the response status according to the status of the default value update condition master 106a in FIG. 24, along with a similarity information icon. The similarity information icon is displayed only if it is determined to be similar to an existing anomaly detection result. For example, when the mouse is hovered over the similarity information icon, a message indicating that the content is similar to an existing anomaly is displayed, such as "The response status has been updated due to the similarity determination. Please check the similarity determination result for details." This makes it possible to confirm from the alert list screen that an existing anomaly detection result is similar in content.
[0118] Clicking on an anomaly detection result will display an alert details screen such as that shown in Figure 26. The response / comment area displays the "Confirm similarity judgment result" button and the date and time of the similarity judgment. The "Confirm similarity judgment result" button is only displayed for anomaly detection results where the similarity judgment determined that "no action is required." Pressing the "Confirm similarity judgment result" button will transition to the similarity judgment result details screen. The similarity judgment date and time will display the date and time the judgment result data was updated.
[0119] The similarity determination result details screen will be described with reference to Fig. 27. Fig. 27 is a diagram showing an example of the display of the similarity determination result details screen. When the "Confirm similarity determination result" button is pressed in Fig. 26, the similarity determination result details screen as shown in Fig. 27 is displayed. The similarity determination result details screen displays (1) anomaly detection results that have been determined to be similar to existing anomaly detection results, (2) the anomaly detection results of the original judgment, (3) the conditions used in the similarity determination, and (4) the settings and values used in updating the default values.
[0120] Referring to FIG. 28, the function of copying the corresponding status and comment when a similar anomaly detection result is determined will be described.
[0121] The similarity judgment function also allows for a setting to "copy the latest response status and comment from the anomaly that was judged to be similar to the anomaly that was judged to be similar." This is intended for use in an operation where an anomaly detection result that is judged to already have a similar anomaly is not deemed "no action required," but is left as an anomaly detection result that requires action. This can be controlled by the settings of the default value update condition master 106a.
[0122] 28, by setting the status type to "Update to the same value as the judgment source" in the default value update condition master 106a, the latest response status that is the same as the judgment source can be registered in the response status of the judgment result comment data. Also, by setting "True" to whether to copy the comment in the default value update condition master 106a, the comment of the judgment source can be registered in the comment content of the judgment result comment data.
[0123] 29 and 30, a case where multiple default value update conditions are set for one anomaly detection result will be described. The similarity determination function makes it possible to link multiple default value update condition masters 106a to one anomaly detection result. There are cases where the default value update processing content is branched depending on the content of the anomaly detection result.
[0124] For example, in the case of an inventory turnover alert, we will explain the case where the condition for updating the default value is branched depending on the "degree of deviation from the threshold of inventory turnover." For example, if the "degree of deviation from the threshold of inventory turnover" exceeds a certain value, the response status of the anomaly detection result determined to be similar is set to "action required" (treated as a new anomaly). Also, in addition to the conditions of "fiscal year" and "product name," a condition of "anomaly rank" is added.
[0125] 29, the default value update condition master 106a allows multiple default value update condition IDs to be linked to the same anomaly detection result. In the example shown in the figure, default value update condition IDs "UC001" and "UC002" are set for execution ID "EX002" and execution line number "1." For "UC001," the status "No action required" is set, and for "UC0002," the status "Action required" is set.
[0126] In the default value update condition detail master 106b, three similarity judgment conditions are set for each of "UC001" and "UC002," and the detailed condition number "3" for "UC002" has the result table information ID "anomaly rank," the comparison operator "≧," the judgment value type "fixed value," and the judgment value "3." Because the abnormality rank of the judgment result data is "3" (the product name and fiscal year are the same as those of the judgment source), the response status of the judgment result comment data is updated to "action required."
[0127] The anomaly rank is calculated based on how far the detected abnormal value deviates from the threshold. The higher the rank number, the greater the deviation from the threshold. Figure 30 shows an example of calculating the anomaly ranks of products A, B, and C based on the deviation of the inventory turnover rate from the threshold.
[0128] As described above, according to this embodiment, the display of the alert screen is controlled, and on the alert screen, a list of anomaly detection results is displayed in the list display area by referring to the judgment result data, and at that time, a screen display control unit 102d is provided which displays the response status for each anomaly detection result by referring to the judgment result comment data, so that when an anomaly is detected in business data, the person in charge can easily check the response status for the anomaly.
[0129] [4. Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This embodiment can contribute to improving business efficiency and promoting appropriate management decisions by companies, thereby contributing to the achievement of SDGs Goals 8 and 9.
[0130] Furthermore, this embodiment can contribute to reducing waste and promoting paperless and electronic systems, thereby contributing to the achievement of SDGs Goals 12, 13, and 15.
[0131] Furthermore, this embodiment can contribute to strengthening control and governance, which can contribute to the achievement of Goal 16 of the SDGs.
[0132] 5. Other Embodiments The present invention may be implemented in various different embodiments other than those described above within the scope of the technical concept set forth in the claims.
[0133] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using known methods.
[0134] Furthermore, the processing procedures, control procedures, specific names, information including parameters such as registered data and search conditions for each process, screen examples, and database configurations shown in this specification and drawings can be changed as desired unless otherwise specified.
[0135] Furthermore, with regard to the anomaly detection support device 100, the components shown in the figures are functional concepts, and do not necessarily have to be physically configured as shown in the figures.
[0136] For example, all or any part of the processing functions of the anomaly detection support device 100, particularly the processing functions performed by the control unit, may be implemented by a CPU and a program interpreted and executed by the CPU, or may be implemented as hardware using wired logic. The program is recorded on a non-transitory computer-readable recording medium containing programmed instructions for causing the information processing device to execute the processes described in this embodiment, and is mechanically read by the anomaly detection support device 100 as needed. That is, a computer program for providing instructions to the CPU in cooperation with the OS and performing various processes is recorded in a storage unit such as a ROM or HDD (Hard Disk Drive). The computer program is executed by being loaded into RAM, and cooperates with the CPU to form the control unit.
[0137] In addition, this computer program may be stored in an application program server connected to the anomaly detection support device 100 via any network, and all or part of it may be downloaded as needed.
[0138] Furthermore, the program for executing the processes described in this embodiment may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product. Here, the term "recording medium" includes any "portable physical medium" such as a memory card, a Universal Serial Bus (USB) memory, a Secure Digital (SD) card, a flexible disk, a magneto-optical disk, a ROM, an Erasable Programmable Read Only Memory (EPROM), an Electrically Erasable and Programmable Read Only Memory (EEPROM (registered trademark)), a Compact Disk Read Only Memory (CD-ROM), a Magneto-Optical disk (MO), a Digital Versatile Disk (DVD), and a Blu-ray (registered trademark) disc.
[0139] Furthermore, a "program" is a data processing method written in any language or description method, regardless of the format, such as source code or binary code. Note that a "program" is not necessarily limited to a single program, but also includes programs that are distributed as multiple modules or libraries, or programs that achieve their functions by working together with other programs, such as an OS. Note that the specific configurations and reading procedures for reading a recording medium in each device shown in the embodiments, as well as the installation procedures after reading, can use well-known configurations and procedures.
[0140] The various databases stored in the memory unit are storage means such as memory devices such as RAM and ROM, fixed disk devices such as hard disks, flexible disks, and optical disks, and store various programs, tables, databases, and web page files used for various processes and providing websites.
[0141] The anomaly detection support device 100 may be configured as an information processing device such as a known personal computer or workstation, or may be configured as the information processing device to which any peripheral device is connected. The anomaly detection support device 100 may also be realized by installing software (including programs, data, etc.) that causes the device to perform the processing described in this embodiment.
[0142] Furthermore, the specific form of distribution and integration of the devices is not limited to that shown in the drawings, and all or part of them can be configured by functionally or physically distributing and integrating them in any unit according to various additions or functional loads. In other words, the above-described embodiments can be implemented in any combination, or embodiments can be implemented selectively. [Explanation of symbols]
[0143] 100 Anomaly detection support device 102 Control section 102a Abnormality detection unit 102b Similarity determination section 102c Comment processing section 102d Screen display control unit 104 Communication interface unit 106 Storage section 106a Default value update condition master 106b Default value update condition detail master 106c Abnormality Judgment Definition Master 106d Judgment result data string information master 106e Default value update history table 108 Input / Output Interface Section 112 Input Device 114 Output Device 200 servers 300 Network 400 Business Systems 500 Terminal Equipment
Claims
1. An anomaly detection support device that includes a control unit and displays an anomaly detection result for business data, The control unit This is for managing the results of anomaly detection, and includes the execution ID, line number, anomaly detection result, detection target, detection date and time, definition name, and summary message. This is for managing comments registered in response to anomaly detection, and includes judgment result comment data including a comment ID, an execution ID, an execution line number, comment content, a response status indicating the response status, an update user, and an update date and time. It is configured to be accessible to a display control means for controlling the display of an alert screen, and displaying a list of abnormality detection results in a list display area on the alert screen by referring to the judgment result data, and at that time, displaying a response status for each abnormality detection result by referring to the judgment result comment data; The control unit A default value update condition detail master in which a default value update condition ID, a condition detail No., and a similarity determination condition are associated and registered; A default value update condition master in which a default value update condition ID, a default value update condition name, an execution ID, an execution line number, and a status specifying no action are associated and registered; It is configured to be accessible to the determination result data includes a similarity determination result, An anomaly detection support device characterized by comprising a similarity determination means that performs a similarity determination between the target anomaly detection result and an existing anomaly detection result in accordance with the similarity determination conditions registered in the default value update condition detail master, and if it is determined to be similar, updates the similarity determination result of the determination result data to "True", and updates the correspondence status of the determination result comment data to "no correspondence required" in accordance with the status of the default value update condition master.
2. The anomaly detection support device according to claim 1 , wherein the response status includes: response required, confirmed, response in progress, pending, response completed, or no response required.
3. The control unit further The anomaly detection support device according to claim 1, further comprising a comment processing means for registering comments entered by a person in charge regarding the target anomaly detection result on the alert screen in the judgment result comment data.
4. 4. The anomaly detection support device according to claim 3, wherein the comment is configured so that multiple people can input the comment multiple times.
5. 5. The anomaly detection support device according to claim 3, wherein the comment processing means refers to the judgment result comment data and displays a history of comments on the target anomaly detection result.
6. An anomaly detection support method executed by an information processing device including a control unit, The control unit This is for managing the results of anomaly detection, and includes the execution ID, line number, anomaly detection result, detection target, detection date and time, definition name, and summary message. This is for managing comments registered in response to anomaly detection, and includes judgment result comment data including a comment ID, an execution ID, an execution line number, comment content, a response status indicating the response status, an update user, and an update date and time. It is configured to be accessible to Executed in the control unit: a display control step of controlling the display of an alert screen, and displaying a list of abnormality detection results in a list display area on the alert screen by referring to the judgment result data, and at that time, displaying a response status for each abnormality detection result by referring to the judgment result comment data; The control unit A default value update condition detail master in which a default value update condition ID, a condition detail No., and a similarity determination condition are associated and registered; A default value update condition master in which a default value update condition ID, a default value update condition name, an execution ID, an execution line number, and a status specifying no action are associated and registered; It is configured to be accessible to the determination result data includes a similarity determination result, An anomaly detection support method characterized by including a similarity determination step of performing a similarity determination between the target anomaly detection result and an existing anomaly detection result in accordance with the similarity determination conditions registered in the default value update condition detail master, and if a determination is made that the result is similar, updating the similarity determination result of the determination result data to "True" and updating the response status of the determination result comment data to "no response required" in accordance with the status of the default value update condition master.
7. An abnormality detection support program to be executed by an information processing device having a control unit, The control unit This is for managing the results of anomaly detection, and includes the execution ID, line number, anomaly detection result, detection target, detection date and time, definition name, and summary message. This is for managing comments registered in response to anomaly detection, and includes judgment result comment data including a comment ID, an execution ID, an execution line number, comment content, a response status indicating the response status, an update user, and an update date and time. It is configured to be accessible to In the control unit, an anomaly detection support program for executing a display control step of controlling the display of an alert screen, displaying a list of anomaly detection results in a list display area on the alert screen by referring to the judgment result data, and displaying a response status for each anomaly detection result by referring to the judgment result comment data, The control unit A default value update condition detail master in which a default value update condition ID, a condition detail No., and a similarity determination condition are associated and registered; A default value update condition master in which a default value update condition ID, a default value update condition name, an execution ID, an execution line number, and a status specifying no action are associated and registered; It is configured to be accessible to the determination result data includes a similarity determination result, An anomaly detection support program for executing a similarity determination process that performs a similarity determination between the target anomaly detection result and an existing anomaly detection result in accordance with the similarity determination conditions registered in the default value update condition detail master, and if determined to be similar, updates the similarity determination result of the determination result data to "True," and updates the response status of the determination result comment data to "no response required" in accordance with the status of the default value update condition master.
Citation Information
Patent Citations
Facility management apparatus, facility management system, program and facility management method
JP2018185774A
Information processing device, information processing method and information processing program
JP2019028891A
Monitoring device, monitoring method and program
JP2020013300A
Abnormality monitoring assisting device, program and method thereof
JP2021165998A