Anomaly Analysis Using Feature Context Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The high cost of analyzing data output by devices is exacerbated by false positive detection results from operational errors, environmental changes, and cyber-attacks, which are difficult to distinguish from actual anomalies in network-connected devices.

Innovation Solution

An information processing apparatus that includes a storage unit for storing feature contexts related to device data and an analyzing unit that analyzes anomalies using both the received data and stored feature contexts to reduce false detection and associated analysis costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anomaly detection is performed on all device data, then cyber-attack detection capability is improved, but false positive results increase due to operational errors and environmental changes

Engineering Contradiction:
Improvecyber-attack detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments anomaly detection into two levels: device-level detection using lightweight rules in the vehicle, and cloud-level detection using comprehensive feature contexts. This segmentation allows basic anomaly filtering at the device while more accurate cloud-based analysis handles complex cases, reducing false positives from environmental changes and operational errors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary anomaly detection at the device level using simple rules before transmitting data to the cloud. This preliminary action filters out obvious anomalies and prepares data for more sophisticated cloud-based analysis, improving overall detection accuracy while reducing cloud processing load.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive anomaly analysis is performed on all detected anomalies, then detection accuracy is improved, but analysis cost increases due to false positives

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidanalysis cost
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent applies different quality levels of analysis to different anomalies. Cloud-based comprehensive analysis with full feature contexts is applied selectively to suspicious cases identified by device-level detection, while routine anomalies receive simpler processing. This local quality approach optimizes analysis cost by applying high-resource processing only where necessary.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If feature contexts are stored for all device data, then anomaly analysis accuracy is improved, but storage requirements increase

Engineering Contradiction:
Improveanomaly analysis accuracyVSAvoidstorage capacity
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts and stores only the most relevant feature contexts in the cloud (device information, communication patterns, error logs) rather than storing all raw device data. This extraction approach maintains anomaly analysis accuracy by preserving key contextual information while significantly reducing storage requirements compared to storing complete device datasets.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11863574B2Information processing apparatus, anomaly analysis method and program
Publication Date: 2024.01.02 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11863574B2 patent drawing
  • US11863574B2 patent drawing
  • US11863574B2 patent drawing

AI summary

A storage processing unit configured to store, in a storage unit, first data output by a device or any one of multiple devices in association with a first feature context related to the first data, and an analyzing unit configured to obtain a second feature context related to second data in a case where the second data is received from the device or any one of the multiple devices, and analyze an anomaly of the received second data based on the received second data and the obtained second feature context and based on the first data and the first feature context stored in the storage unit, are provided.