Monitoring assistance method, monitoring assistance system, and program

The monitoring support method and system optimize ticket assignment by estimating processing times based on analyst proficiency, addressing uneven workload and speeding up ticket processing in Security Operation Centers.

WO2025220484A1PCT designated stage Publication Date: 2025-10-23PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/013289
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-19
Filing Date
2025-03-31
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

Existing ticket assignment methods in Security Operation Centers (SOC) lead to uneven workload distribution among analysts, resulting in longer processing times due to reliance on analysts' skills without considering their proficiency with specific ticket types.

Method used

A monitoring support method and system that estimates the processing time required for each analyst based on their proficiency with ticket types and assigns tickets to the analyst who can complete processing the fastest, taking into account both current and past performance.

Benefits of technology

This approach reduces uneven workload distribution and speeds up ticket processing by assigning tickets to analysts who can complete them quickly, thereby improving overall efficiency and reducing processing time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025013289_23102025_PF_FP_ABST
    Figure JP2025013289_23102025_PF_FP_ABST
Patent Text Reader

Abstract

This monitoring assistance method includes allocating a ticket indicating an alert relating to a system being monitored to any of two or more analysts, wherein, on the basis of the skill level of the analysts for each ticket type, when an object ticket that is a ticket to be allocated is allocated to the analysts, the processing time required for the analysts to complete processing for the object ticket is estimated by each of the two or more analysts, and an analyst to whom the object ticket is to be allocated is determined on the basis of the processing time of each of the two or more analysts.
Need to check novelty before this filing date? Find Prior Art

Description

Monitoring support method, monitoring support system and program

[0001] The present disclosure relates to a monitoring support method, a monitoring support system, and a program.

[0002] Patent document 1 discloses that when matching is performed based on two pieces of condition information that indicate the required conditions of a service requester and the conditions provided by a service provider and each of which contains qualitative data, the qualitative data is converted into quantitative data that includes skills, etc., and the degree of compatibility of the two pieces of condition information that have been converted and now contain only quantitative data is calculated.

[0003] Japanese Patent Application Laid-Open No. 2005-216100

[0004] Meanwhile, a huge number of tickets related to alerts from monitored systems are submitted to a Security Operation Center (SOC). These tickets are assigned to analysts who handle the tickets, but it is desirable that this assignment be done appropriately.

[0005] However, if tickets are assigned based solely on the skills of analysts as in Patent Document 1, the workload on analysts may become uneven, which could result in a longer total ticket processing time.

[0006] Therefore, the present disclosure provides a monitoring support method, a monitoring support system, and a program that can reduce the uneven load on analysts and speed up ticket processing.

[0007] A monitoring support method according to one aspect of the present disclosure is a monitoring support method for assigning a ticket indicating an alert related to a system to be monitored to one of two or more analysts, wherein the two or more analysts each estimate the processing time required for the analyst to complete processing of a target ticket, which is the ticket to be assigned, based on the analyst's level of proficiency with each ticket type, and the analyst to whom the target ticket is to be assigned is determined based on the processing time of each of the two or more analysts.

[0008] A monitoring support system according to one aspect of the present disclosure is a monitoring support system that assigns a ticket indicating an alert related to a system to be monitored to one of two or more analysts, and includes an estimation unit that estimates, for each of the two or more analysts, the processing time required for the analyst to complete processing of a target ticket, which is the ticket to be assigned, if the target ticket is assigned to the analyst based on the analyst's proficiency with each ticket type, and a determination unit that determines the analyst to whom the target ticket is to be assigned based on the processing time of each of the two or more analysts.

[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described monitoring assistance method.

[0010] According to one aspect of the present disclosure, it is possible to realize a monitoring support method and the like that can suppress uneven load on analysts and speed up ticket processing.

[0011] FIG. 1 is a block diagram showing the functional configuration of a monitoring support system according to an embodiment. FIG. 2 is a diagram showing an example of ticket queue information according to an embodiment. FIG. 3 is a diagram showing an example of a ticket list waiting for allocation according to an embodiment. FIG. 4 is a diagram showing an example of an analyst characteristic table according to an embodiment. FIG. 5 is a diagram showing an example of a processed ticket processing time table according to an embodiment. FIG. 6 is a flowchart showing the operation of allocating tickets in the monitoring support system according to an embodiment. FIG. 7 is a diagram for explaining calculation of an estimated processing time according to an embodiment. FIG. 8 is a flowchart showing the operation of updating the analyst characteristic table in the monitoring support system according to an embodiment. FIG. 9 is a diagram for explaining updating of the analyst characteristic table in the monitoring support system according to an embodiment.

[0012] (Background to the Invention of the Present Disclosure) Before describing the embodiments of the present disclosure, the background to the invention of the present disclosure will be described.

[0013] As described in the "Problem to be Solved by the Invention" section, a huge number of tickets related to the systems to be monitored are submitted to the SOC. These tickets are assigned to analysts who will handle the tickets, and it is desirable that the assignment be done appropriately.

[0014] Tickets are assigned either by an assigner such as a senior analyst according to an assignment policy, or without the senior analyst's involvement. When assigned by a senior analyst, the assignment relies on the senior analyst's experience and the senior analyst manually corrects any bias in the assignment, resulting in a heavy workload. When assigned by a senior analyst, tickets may be assigned to analysts in order without a policy, or to whoever is available on an ad hoc basis. In this case, tickets may not be assigned to analysts that are appropriate for them. For example, this could result in an uneven workload or a failure to assign tickets according to the analyst's skills (e.g., delays in ticket processing).

[0015] Therefore, the inventors of the present application conducted extensive research into monitoring support methods and the like that can reduce the uneven load on analysts and speed up ticket processing when allocating tickets, and have devised the monitoring support methods and the like described below.

[0016] A monitoring support method according to a first aspect of the present disclosure is a monitoring support method for assigning a ticket indicating an alert related to a system to be monitored to one of two or more analysts, wherein the two or more analysts each estimate the processing time required for the analyst to complete processing of a target ticket, which is the ticket to be assigned, based on the analyst's level of proficiency with each ticket type, and the analyst to whom the target ticket is to be assigned is determined based on the processing time of each of the two or more analysts.

[0017] This uses processing time in addition to proficiency, which prevents the concentration of target tickets on analysts with high proficiency and makes it possible to assign target tickets to analysts who can complete processing quickly, thereby reducing the uneven load on analysts and realizing faster ticket processing.

[0018] Furthermore, for example, the monitoring support method according to the second aspect may be the monitoring support method according to the first aspect, in which the processing time is estimated using one or more unprocessed tickets that have been assigned to the analyst but have not been processed by the analyst, and the target ticket.

[0019] This allows the processing time to be estimated taking into account unprocessed tickets already assigned to the analyst. For example, the target ticket is prevented from being assigned to an analyst who spends a lot of time processing unprocessed tickets.

[0020] Furthermore, for example, a monitoring support method according to a third aspect may be the monitoring support method according to the second aspect, wherein, for each of the two or more analysts, a first processing time required for that analyst to process the one or more unprocessed tickets of that analyst and a second processing time required for that analyst to process the target ticket are estimated based on the analyst's proficiency for each ticket type, and the processing times are estimated based on the first processing time and the second processing time.

[0021] This allows the processing time to be estimated according to the skill of the analyst, which means that the processing time can be accurately estimated.

[0022] Furthermore, for example, the monitoring support method according to the fourth aspect may be the monitoring support method according to the third aspect, in which the total time of the first processing time and the second processing time is estimated as the processing time, and the analyst who has the shortest processing time among the two or more analysts may be determined to be the analyst to whom the target ticket is assigned.

[0023] This allows tickets to be assigned to the analyst who can complete the process in the shortest time possible, thereby speeding up ticket processing.

[0024] Furthermore, for example, a monitoring support method according to a fifth aspect may be the monitoring support method according to the third or fourth aspect, wherein a priority indicating the degree to which the ticket is to be processed with priority is assigned to the ticket, and unprocessed tickets having a priority equal to or higher than the priority of the target ticket are extracted from the one or more unprocessed tickets of the analyst, and the first processing time may indicate the time required for the analyst to process the extracted unprocessed tickets.

[0025] This makes it possible to estimate the time until the processing of the target ticket starts, assuming that the tickets are processed in order of priority.

[0026] Furthermore, for example, the monitoring support method according to the sixth aspect is a monitoring support method according to any one of the first to fifth aspects, and the proficiency level of the analyst may be calculated for each ticket type based on the actual time required by the analyst to process tickets of that ticket type.

[0027] This allows the proficiency level to be calculated based on the actual time spent processing the ticket, making it possible to calculate the proficiency level more accurately.

[0028] Furthermore, for example, the monitoring support method according to the seventh aspect may be a monitoring support method according to any one of the second to sixth aspects, and may acquire the actual time required by the analyst to process one of the one or more unprocessed tickets, and may update the proficiency level of the analyst corresponding to the ticket type of the processed unprocessed ticket based on the acquired actual time.

[0029] This allows the analyst's proficiency to be updated based on the newly acquired actual time, providing the analyst's proficiency at that point in time. Using this proficiency allows for more accurate processing time estimation.

[0030] Furthermore, for example, a monitoring support method according to an eighth aspect is a monitoring support method according to any one of the first to seventh aspects, and the ticket type may include at least one of an alert indicating an authentication error, an alert indicating a communication abnormality, a scan alert, and an invalid DNS (Domain Name System) alert.

[0031] This allows tickets containing at least one of an authentication error alert, a communication anomaly alert, a scan alert, and an invalid DNS alert to be assigned to an analyst while minimizing load imbalances and speeding up ticket processing.

[0032] Furthermore, a monitoring support system according to a ninth aspect of the present disclosure is a monitoring support system that assigns a ticket indicating an alert related to a system to be monitored to one of two or more analysts, and includes an estimation unit that estimates, for each of the two or more analysts, the processing time required for the analyst to complete processing of a target ticket, which is the ticket to be assigned, if the target ticket is assigned to the analyst, based on the analyst's proficiency with each ticket type, and a determination unit that determines the analyst to whom the target ticket is to be assigned, based on the processing time of each of the two or more analysts.

[0033] This provides the same effects as the above-described monitoring support method.

[0034] A program according to a tenth aspect of the present disclosure is a program for causing a computer to execute the monitoring assistance method according to any one of the first to eighth aspects.

[0035] This provides the same effects as the above-described monitoring support method.

[0036] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet.

[0037] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0038] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.

[0039] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.

[0040] Furthermore, in this specification, numerical values ​​and numerical ranges are not expressions that express only the strict meaning, but are expressions that mean that they also include a substantially equivalent range, for example, a difference of about several percent (or about 10%).

[0041] (Embodiment) A monitoring support system according to this embodiment will be described below with reference to Figs.

[0042] 1. Configuration of the Monitoring Support System First, the configuration of the monitoring support system according to this embodiment will be described with reference to Figures 1 to 5. Figure 1 is a block diagram showing the functional configuration of a monitoring support system 100 according to this embodiment.

[0043] As shown in FIG. 1, the monitoring support system 100 is a system that executes a monitoring support method that assigns a ticket indicating an alert related to a system to be monitored to one of two or more analysts (in the example of FIG. 1, analysts A, B, and C), and has a functional configuration including a communication unit 10, a ticket assignment unit 20, a first memory unit 30, a proficiency level determination unit 40, and a second memory unit 50.

[0044] The monitoring support system 100 also includes, as its hardware configuration, a non-volatile memory in which a program is stored, a volatile memory that is a temporary storage area for executing the program, an input / output port, a communication interface, a processor that executes the program, etc. The communication unit 10, the ticket assignment unit 20, and the proficiency level determination unit 40 are realized by a processor that executes the program stored in the memory, etc. The monitoring support system 100 may be realized by a mobile terminal such as a stationary personal computer (PC), a portable PC, a smartphone, or a tablet, a dedicated computer, etc., or may be realized by a server (e.g., a cloud server), or may be realized by a combination thereof.

[0045] The communication unit 10 is a communication interface that enables the monitoring support system 100 to communicate with the information terminals (not shown) of the analysts A to C and the system to be monitored (target system). The communication unit 10 receives, for example, a ticket indicating an alert detected in the target system via communication from the target system. The communication unit 10 is configured to include, for example, a communication circuit (communication module).

[0046] The target system is not particularly limited, but may be, for example, a system for monitoring the inside of a facility. The facility may be a residential facility or a non-residential facility. Examples of residential facilities are detached houses and apartment buildings. Each of the multiple dwelling units in an apartment building may be considered a "facility," or the entire apartment building may be considered a "facility." Examples of non-residential facilities include stores, office buildings, schools, welfare facilities, commercial complexes, hospitals, factories, etc.

[0047] The ticket allocation unit 20 executes a process of assigning a target ticket, which is a ticket to be assigned, to one of two or more analysts. As will be described in detail later, the ticket allocation unit 20 estimates, for each of analysts A to C, the processing time that the analyst will require to complete processing the target ticket if the target ticket is assigned to that analyst, based on the analyst's proficiency for each ticket type, and determines the analyst to whom the target ticket is assigned based on the estimation result. For example, the ticket allocation unit 20 estimates the processing time based on the ticket type of the target ticket, the analyst characteristic table 51 (see FIG. 4, described later) generated by the proficiency determination unit 40, and the processed ticket processing time table 52 (see FIG. 5, described later), and determines which of the two or more analysts to assign the target ticket to based on the estimated processing time.

[0048] The first storage unit 30 is a storage device that stores various information used in processing by the ticket allocation unit 20. In this embodiment, the first storage unit 30 stores ticket queue information 31 and a list of tickets waiting to be allocated 32. The ticket queue information 31 and the list of tickets waiting to be allocated 32 are generated, for example, by the ticket allocation unit 20. The first storage unit 30 is realized, for example, by a semiconductor memory or the like, but is not limited to this.

[0049] 2 is a diagram showing an example of ticket queue information 31 according to the present embodiment. In the ticket queue shown in FIG. 2, the order of execution, ticket number, ticket type, and priority are listed.

[0050] As shown in FIG. 2, the ticket queue information 31 is a list showing, by analyst, tickets that have been assigned to the analyst but have not yet been processed by that analyst, and includes items such as analyst and ticket queue.

[0051] An analyst is a person (analyst) who processes tickets collected by the monitoring support system 100. Although Fig. 2 shows an example in which there are three analysts, analysts A to C, the number of analysts is not particularly limited as long as it is two or more.

[0052] The ticket queue indicates tickets that have been assigned to the analyst but that the analyst has not been able to process, and includes the order of execution, ticket number, ticket type, and priority.

[0053] The execution order indicates the order in which tickets among unprocessed tickets will be processed. For example, when each of analysts A to C finishes processing the ticket they are currently working on, they will next process the ticket in execution order [1] that corresponds to them. In this embodiment, the execution order is determined so that the higher the priority, the earlier the order (for example, in order of priority). The information terminal of the analyst may present information about the tickets to be processed to that analyst according to the execution order.

[0054] The ticket number is identification information for identifying the ticket.

[0055] The ticket type is a classification of alerts, and includes, for example, at least one of an authentication error alert, a communication abnormality alert, a scan alert, and an invalid DNS alert.

[0056] An authentication error alert is an alert indicating that authentication has failed within the target system, a communication anomaly alert is an alert indicating that a communication anomaly has been detected within the target system, a scan alert is an alert indicating that an anomaly has been detected during a scan (e.g., during a virus scan), and a fraudulent DNS alert is an alert indicating that fraudulent communication that misuses DNS has been detected. Thus, the ticket according to this embodiment includes information indicating that a security alert has been detected.

[0057] The priority indicates the degree to which an analyst is to prioritize processing of the ticket, and the higher the priority, the faster the analyst is expected to complete processing of the ticket. The priority is determined, for example, based on at least one of the urgency, importance, and difficulty of the alert and the importance of the monitored target. The priority is determined, for example, by the target system that sent the ticket, but may also be determined by the monitoring support system 100. A priority is set for each ticket.

[0058] 3 is a diagram showing an example of the list of tickets waiting for allocation 32 according to this embodiment. In the list of tickets waiting for allocation 32 shown in FIG. 3, tickets are listed in the order of [ticket number], ticket type, and priority.

[0059] The waiting ticket list 32 is a list showing tickets that have come up from the target system and have not yet been assigned to an analyst (tickets waiting for assignment).

[0060] The waiting-for-allocation ticket list 32 includes ticket numbers, ticket types, and priorities. The ticket numbers, ticket types, and priorities in the waiting-for-allocation ticket list 32 are the same as those shown in Fig. 2. In the waiting-for-allocation ticket list 32, tickets are arranged in descending order of priority. Fig. 3 shows an example in which there are six tickets waiting for allocation.

[0061] Referring back to FIG. 1, the proficiency level determining unit 40 generates an analyst characteristics table 51 and a processed ticket processing time table 52 which are used when the ticket allocation unit 20 determines an analyst to allocate a target ticket to.

[0062] The second storage unit 50 is a storage device that stores various information generated by the proficiency level determination unit 40. In this embodiment, the second storage unit 50 stores an analyst characteristic table 51 and a processed ticket processing time table 52. The second storage unit 50 is realized by, for example, a semiconductor memory or the like, but is not limited to this.

[0063] FIG. 4 is a diagram showing an example of the analyst characteristic table 51 according to this embodiment.

[0064] As shown in FIG. 4, the analyst characteristic table 51 is a table showing the proficiency level for each analyst and each ticket type, and includes the analyst and the analyst proficiency level.

[0065] The analyst proficiency indicates the analyst's proficiency with each ticket type and indicates the analyst's level of ability to process tickets. In the example of FIG. 4, the analyst proficiency indicates the estimated processing time required for the analyst to process a ticket. Calculation of processing time will be described later with reference to FIG. 5. For example, when analyst A processes a ticket indicating a communication anomaly alert, the estimated processing time is 40 minutes; when analyst B processes a ticket indicating a communication anomaly alert, the estimated processing time is 50 minutes; and when analyst C processes a ticket indicating a communication anomaly alert, the estimated processing time is 20 minutes. Each analyst has strengths and weaknesses for each ticket type. In the example of FIG. 5, analyst C can process communication anomaly alerts the fastest.

[0066] 5 is a diagram showing an example of a processed ticket processing time table 52 according to this embodiment. For convenience, only the processing time table of analyst A is shown in FIG. 5, but similar processing time tables are generated for other analysts as well.

[0067] As shown in FIG. 5, the processed ticket processing time table 52 includes an analyst and a processing time table, and the processing time table includes ticket types and processing times for each ticket.

[0068] The processing time for each ticket indicates the actual time required when the analyst (here, Analyst A) has processed the ticket in the past. For example, in the case of a ticket showing an authentication error alert, Analyst A has processed it six times in the past, with actual processing times of 27 minutes, 23 minutes, 15 minutes, 19 minutes, 18 minutes, and 18 minutes.

[0069] The proficiency determination unit 40 obtains the actual processing time for a ticket (actual time) and adds the actual time to the processing time table to generate and update the processed ticket processing time table 52. For example, the proficiency determination unit 40 may update the processed ticket processing time table 52 every time an analyst processes a ticket, or may update the processed ticket processing time table 52 at predetermined intervals.

[0070] Furthermore, the proficiency determination unit 40 generates the analyst characteristic table 51 based on the processed ticket processing time table 52. Using an authentication error alert as an example, the proficiency determination unit 40 calculates the statistical value of the processing times for the six authentication error alerts shown in FIG. 5 as the analyst proficiency (estimated processing time) shown in FIG. 4. The statistical value is an average value, but is not limited to this, and may be, for example, a median, a mode, a maximum value, a minimum value, or the like. FIG. 4 shows an example in which the average value of the processing times for the six authentication error alerts is calculated as the analyst proficiency. In this way, the proficiency determination unit 40 calculates the analyst proficiency for each analyst and each ticket type using past performance times.

[0071] In this way, the monitoring support system 100 is configured to automatically assign tickets received from the target system to analysts in accordance with the analysts' proficiency and ticket queues, eliminating the need for senior analysts to perform the assignment work.

[0072] 2. Operation of the Monitoring Support System Next, the operation of the monitoring support system 100 configured as described above will be described with reference to Fig. 6 to Fig. 9. Fig. 6 is a flowchart showing the operation of allocating tickets (monitoring support method) in the monitoring support system 100 according to this embodiment.

[0073] 6, the ticket allocation unit 20 extracts the ticket with the highest priority from the list of tickets awaiting allocation 32 (S10). Hereinafter, the extracted ticket (target ticket) will also be referred to as ticket T. For example, the ticket allocation unit 20 extracts the ticket with "

[0014] communication abnormality alert: 9.3" (target ticket) from the list of tickets awaiting allocation 32 shown in FIG. 3 as ticket T. In this way, ticket T is extracted based on the priority of each ticket included in the list of tickets awaiting allocation 32.

[0074] Next, the ticket allocation unit 20 determines whether all analysts have finished checking the estimated processing time, which indicates the time it will take to complete processing of ticket T if ticket T is assigned to that analyst (S20). The ticket allocation unit 20 determines whether the estimated processing time for ticket T if assigned to each of analysts A to C has been calculated.

[0075] Next, if the ticket allocation unit 20 determines that confirmation of all analysts has not been completed (NO in S20), it selects the next analyst (S30). For example, let us say that the ticket allocation unit 20 selected analyst A in the first round. In addition, steps S40 to S70 shown below will mainly describe the processing for analyst A as an example.

[0076] Next, the ticket allocation unit 20 checks the ticket queue for analyst A (S40). The ticket allocation unit 20 reads out the ticket queue for analyst A from the ticket queue information 31 shown in FIG.

[0077] Next, the ticket allocation unit 20 extracts the processing time of each ticket from the analyst A's analyst characteristic table 51 for tickets with a priority of ticket T or higher among the tickets read out for analyst A, and calculates the total (Lx) (S50). For each ticket with a priority of ticket T or higher, the ticket allocation unit 20 reads out the proficiency level corresponding to the ticket type of the ticket as the processing time.

[0078] 7 is a diagram for explaining the calculation of the estimated processing time according to this embodiment. The estimated processing order shows the processing order of tickets sorted by priority after ticket T (here, “

[0014] communication abnormality alert: 9.3” and shown in bold and underlined in FIG. 7) is added to the ticket queue shown in FIG. 2.

[0079] As shown in FIG. 7 , assuming that ticket T is assigned to analyst A, the ticket allocation unit 20 determines the processing order for analyst A based on the priority. For analyst A, there is one unprocessed ticket with a priority higher than ticket T, which is a ticket with a priority of 10.3. Therefore, in the example of FIG. 7 , the ticket allocation unit 20 adds ticket T between "[1]

[1001] Authentication error alert: 10.3" and "[2]

[1007] Communication abnormality alert: 8.7" based on the priority of each ticket, i.e., second in the processing order. When ticket T is added, the ticket allocation unit 20 extracts tickets with a priority higher than ticket T from the ticket queue.

[0080] Then, the ticket allocation unit 20 estimates the processing time required for analyst A to process the extracted ticket based on the extracted ticket and analyst A's proficiency included in the analyst characteristic table 51 shown in FIG. 4. The ticket allocation unit 20 estimates the processing time to be 20 minutes because the extracted ticket type is an authentication error alert and analyst A's proficiency with authentication error alerts is 20 minutes. Here, 20 minutes is the total (Lx), but if there are multiple tickets with a priority higher than ticket T, the total (Lx) is calculated by adding up the respective proficiencies (ticket processing times). The total (Lx) is an example of a first processing time.

[0081] Referring again to FIG. 6, the ticket allocation unit 20 calculates the processing time (Mx) of ticket T from the analyst characteristic table 51 of analyst A (S60).

[0082] Because the ticket type of ticket T is a communication anomaly alert, the ticket allocation unit 20 reads out 40 minutes, which is analyst A's proficiency level with communication anomaly alerts included in the analyst characteristic table 51 shown in Fig. 4, as the processing time (Mx) of ticket T. The processing time (Mx) is an example of the second processing time.

[0083] In this way, since the processing time based on the past performance time is stored as the proficiency in the analyst characteristics table 51, the processing time in steps S50 and S60 can be easily estimated.

[0084] Next, the ticket allocation unit 20 enters (Lx + Mx) in the estimated processing time table (S70). The ticket allocation unit 20 adds up the 20 minutes (Lx) calculated in step S50 and the 40 minutes (Mx) calculated in step S60 to estimate an estimated processing time of 60 minutes (see the estimated processing time table shown in FIG. 7). Under the assumption that analysts process assigned tickets in order of priority, an estimated processing time of 60 minutes means that if ticket T is assigned to analyst A, the processing of ticket T will be completed in 60 minutes. In this way, the ticket allocation unit 20 functions as an estimation unit that estimates an estimated processing time.

[0085] Next, the ticket allocation unit 20 returns to step S20 and executes steps S30 to S70 for analysts B and C. For example, the estimated processing time for analyst B is estimated in the second round, and the estimated processing time for analyst C is estimated in the third round.

[0086] As shown in FIG. 7, the estimated processing times for assigning ticket T are 60 minutes for analyst A, 50 minutes for analyst B, and 120 minutes for analyst C.

[0087] In this way, the ticket allocation unit 20 estimates for each of analysts A to C the processing time (estimated processing time shown in FIG. 7 ) that analyst A will need to complete processing of the target ticket if ticket T is assigned to analyst A, based on analyst A's proficiency for each ticket type. The processing time is estimated using the target ticket and one or more unprocessed tickets that have been assigned to analyst A but that the analyst has not yet been able to process.

[0088] Next, when the ticket allocation unit 20 determines that confirmation of each analyst has been completed (YES in S20), it determines the analyst to whom ticket T will be allocated based on the processing time (estimated processing time) of each of analysts A to C. For example, the ticket allocation unit 20 extracts the analyst with the shortest processing time from the estimated processing time table (S80).

[0089] 7, the ticket allocation unit 20 determines that the analyst to whom ticket T should be assigned is analyst B, who has the shortest estimated processing time in the estimated processing time table. In other words, the ticket allocation unit 20 determines that ticket T should be assigned to the analyst who will complete processing of ticket T earliest. In this way, the ticket allocation unit 20 functions as a determination unit that determines the analyst to whom ticket T should be assigned.

[0090] This allows ticket T to be processed 70 minutes faster than when ticket T is assigned to analyst C who can process ticket T of that type alone the fastest (i.e., when assigned using the conventional method that uses only skills). Step S80 is a process for determining the analyst to whom the target ticket is assigned.

[0091] Next, the ticket allocation unit 20 allocates ticket T to analyst B and lists it in the ticket queue for analyst B (S90). The ticket allocation unit 20 adds ticket T to the ticket queue for analyst B. The ticket queue to which ticket T has been added will be arranged in the same order as the queue shown in the estimated processing order for analyst B in FIG. 7.

[0092] Next, the ticket allocation unit 20 deletes ticket T from the list of tickets waiting to be assigned 32 (S100). The ticket allocation unit 20 deletes "

[0014] Communication abnormality alert: 9.3" from the list of tickets waiting to be assigned 32 shown in Fig. 3. As a result, the ticket with the highest priority in the list of tickets waiting to be assigned 32 becomes "

[0012] Authentication error alert: 8.8".

[0093] Then, the ticket allocation unit 20 sets the ticket with "

[0012] authentication error alert: 8.8" as the next ticket T, and executes the processes from step S10 onwards.

[0094] This allows the target ticket (ticket T) to be assigned to the analyst who can complete processing of the target ticket the fastest, thereby realizing faster ticket processing (faster completion of processing). Since the ticket according to this embodiment is a security alert, it is necessary to quickly determine whether or not there is a problem in the target system. The monitoring support system 100 according to this embodiment makes it possible to speed up ticket processing, and therefore it is possible to determine whether or not there is a problem in the target system more quickly than before.

[0095] Furthermore, since the target ticket (ticket T) is assigned to the analyst who can complete processing of the target ticket the fastest, it is possible to prevent tickets from concentrating on a specific analyst, for example, on an analyst who takes a short time to process the target ticket alone. Therefore, the monitoring support system 100 can prevent uneven distribution of workloads on analysts.

[0096] Next, updating of the analyst characteristic table 51 will be described with reference to Fig. 8 and Fig. 9. Fig. 8 is a flowchart showing the operation (monitoring support method) for updating the analyst characteristic table 51 in the monitoring support system 100 according to this embodiment. Note that Fig. 8 shows the operation for updating the analyst characteristic table 51 when ticket T is assigned to analyst A.

[0097] 8 , the proficiency assessment unit 40 acquires information that analyst A has completed processing ticket T of ticket type Ts (here, a communication anomaly alert) in M ​​minutes (S210). The proficiency assessment unit 40 may acquire the actual processing time (M minutes) by, for example, having a timer and measuring the time from when the analyst starts processing ticket T to when the processing is completed, or may acquire the actual processing time (M minutes) through input by analyst A. M minutes is an example of actual time, and step S210 is a step for acquiring the actual time required by the analyst to process one unprocessed ticket (here, ticket T) out of one or more unprocessed tickets.

[0098] Next, the proficiency level determination unit 40 adds the ticket name (T) and the processing time (M minutes) to the ticket type Ts in the processed ticket processing time table 52 for analyst A (S220). The proficiency level determination unit 40 adds the processing time (M minutes) acquired in step S210 to the processing time for each ticket of the ticket type communication abnormality alert in the processed ticket processing time table 52 shown in FIG.

[0099] 9 is a diagram for explaining the update of the analyst characteristics table 51 in the monitoring support system 100 according to this embodiment. Fig. 9(a) shows the processed ticket processing time table 52 to which the processing time (M minutes) has been added, and Fig. 9(b) shows the analyst characteristics table 51 to which analyst A's analyst proficiency level for communication anomaly alerts has been updated. It is assumed that the processing time acquired in step S210 is 36 minutes.

[0100] As shown in (a) of Figure 9, the proficiency level determination unit 40 adds the fact that the processing time for ticket T is 36 minutes to the communication anomaly alert column. In (a) of Figure 9, the added processing time for ticket T is shown in bold and underlined. Note that in the communication anomaly alert, ticket number

[0004] is the oldest acquired processing time (actual measured value), and ticket number

[0014] is the most recently acquired processing time (actual measured value). The processing times (actual measured values) are arranged in the order in which they were acquired.

[0101] 8 again, next, the proficiency assessment unit 40 calculates the average processing time (Tm) for ticket type Ts (here, communication anomaly alerts) in the processed ticket processing time table 52 (S230). The proficiency assessment unit 40 calculates the average processing time as the average value of the four processing times (actual measured values) for communication anomaly alerts, including the 36 minutes updated in step S220. In this case, the average processing time calculated is 39 minutes, which is the average of 50 minutes, 35 minutes, 35 minutes, and 36 minutes.

[0102] Next, the proficiency determination unit 40 changes the average processing time for ticket type Ts in analyst A's analyst characteristic table 51 to Tm (S240). The proficiency determination unit 40 updates the average processing time for ticket types with communication anomaly alerts in analyst A's analyst characteristic table 51 from 40 minutes to 39 minutes. In this way, the proficiency of the analyst corresponding to the ticket type of the unprocessed ticket that has been processed is updated based on the actual time acquired in step S210.

[0103] This allows the proficiency determination unit 40 to update the average processing time, i.e., the analyst's proficiency in ticket processing. The proficiency determination unit 40 can effectively reflect the analyst's skills, which are updated daily, in the proficiency.

[0104] In addition, when there are multiple processing times for each ticket, the proficiency level determination unit 40 may calculate the average processing time based on, for example, the processing time (actual measured value) for the most recent predetermined number of tickets or within a predetermined period of time.

[0105] (Other Embodiments) While the monitoring support method and the like according to one or more aspects have been described above based on the embodiments, the present disclosure is not limited to these embodiments. As long as they do not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiments and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.

[0106] For example, in the above embodiment, an example was described in which tickets are allocated in order from the highest priority ticket in the list of tickets waiting for allocation 32, but this is not limited to this. For example, tickets may be allocated in order of the oldest ticket obtained via the communication unit 10, or in order of the ticket type that has had the most recent alert occurrences.

[0107] Furthermore, although the ticket queue information 31 in the above embodiment does not include tickets currently being processed by analysts, it may include, for example, tickets currently being processed by analysts.

[0108] Furthermore, in the above embodiment, an example has been described in which the ticket allocation unit 20 allocates the target ticket to the analyst with the shortest estimated processing time among analysts A to C, but this is not limiting. For example, if the first and second estimated processing times are close to each other (for example, within a threshold value), the ticket allocation unit 20 may allocate the target ticket to the analyst with the second shortest estimated processing time.

[0109] In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0110] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and other orders may be used. Some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.

[0111] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0112] Furthermore, the monitoring support system 100 according to the above embodiment may be realized as a single device (monitoring support device) or may be realized by multiple devices. When the monitoring support system 100 is realized by multiple devices, the components of the monitoring support system 100 may be distributed in any manner among the multiple devices. When the monitoring support system 100 is realized by multiple devices, the communication method between the multiple devices is not particularly limited, and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.

[0113] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, which is an integrated circuit. These components may be individually integrated into a single chip, or some or all of them may be integrated into a single chip. Here, the term "LSI" is used, but depending on the level of integration, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI. Furthermore, the integrated circuit implementation method is not limited to LSI, and may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After LSI fabrication, a field programmable gate array (FPGA) that can be programmed or a reconfigurable processor that can reconfigure the connections or settings of circuit cells within the LSI may also be used. Furthermore, if an integrated circuit technology that replaces LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.

[0114] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip. Specifically, it is a computer system that includes a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), etc. Computer programs are stored in the ROM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0115] Furthermore, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the monitoring assistance method shown in either FIG. 6 or FIG. 8 .

[0116] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.

[0117] The present disclosure is useful for a monitoring support system that monitors a target system, etc.

[0118] REFERENCE SIGNS LIST 10 Communication unit 20 Ticket allocation unit (estimation unit, determination unit) 30 First storage unit 31 Ticket queue information 32 List of tickets waiting for allocation 40 Proficiency determination unit 50 Second storage unit 51 Analyst characteristics table 52 Processed ticket processing time table 100 Monitoring support system A, B, C Analysts

Claims

1. A monitoring support method for assigning a ticket indicating an alert related to a monitored system to one of two or more analysts, wherein the two or more analysts each estimate the processing time required for the analyst to complete processing of a target ticket if the target ticket is assigned to the analyst based on the analyst's proficiency with each ticket type, and the analyst to whom the target ticket is assigned is determined based on the processing time of each of the two or more analysts.

2. The monitoring support method according to claim 1, wherein the processing time is estimated using the target ticket and one or more unprocessed tickets that have been assigned to the analyst but have not been processed by the analyst.

3. The monitoring support method according to claim 2, wherein for each of the two or more analysts, a first processing time required for that analyst to process the one or more unprocessed tickets and a second processing time required for that analyst to process the target ticket are estimated based on the analyst's proficiency for each ticket type, and the processing times are estimated based on the first processing time and the second processing time.

4. The monitoring support method according to claim 3, further comprising: estimating the total time of the first processing time and the second processing time as the processing time; and determining, among the two or more analysts, the analyst with the shortest processing time as the analyst to whom the target ticket is to be assigned.

5. The monitoring support method according to claim 3 or 4, wherein a priority indicating the degree to which the ticket is to be given priority for processing is assigned to the ticket; unprocessed tickets having a priority equal to or higher than the priority of the target ticket are extracted from the one or more unprocessed tickets of the analyst; and the first processing time indicates the time required for the analyst to process the extracted unprocessed tickets.

6. The monitoring support method according to any one of claims 1 to 4, wherein the proficiency level of the analyst is calculated for each ticket type based on the actual time required by the analyst to process tickets of the ticket type.

7. The monitoring support method according to any one of claims 2 to 4, further comprising: acquiring an actual time required by the analyst to process one of the one or more unprocessed tickets; and updating the proficiency of the analyst corresponding to the ticket type of the processed unprocessed ticket based on the acquired actual time.

8. The monitoring support method according to any one of claims 1 to 4, wherein the ticket type includes at least one of an alert indicating an authentication error, an alert indicating a communication abnormality, a scan alert, and an invalid DNS (Domain Name System) alert.

9. A monitoring support system that assigns tickets indicating alerts related to a monitored system to one of two or more analysts, comprising: an estimation unit that estimates, for each of the two or more analysts, the processing time that will be required for the analyst to complete processing of a target ticket if the target ticket, which is the ticket to be assigned, is assigned to that analyst based on the analyst's proficiency for each ticket type; and a determination unit that determines the analyst to whom the target ticket will be assigned based on the processing time of each of the two or more analysts.

10. A program for causing a computer to execute the monitoring support method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method for controlling data processor

    JP1997265459A

  • Remote control system

    JP2022094393A

  • Automatic assignment of incidents in an information technology (IT) and security operations application

    US11916929B1