Anomaly Analysis Using Feature Context Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The high cost of analyzing data output by devices is exacerbated by false positive detection results from operational errors, environmental changes, and cyber-attacks, which are difficult to distinguish from actual anomalies in network-connected devices.
Innovation Solution
An information processing apparatus that includes a storage unit for storing feature contexts related to device data and an analyzing unit that analyzes anomalies using both the received data and stored feature contexts to reduce false detection and associated analysis costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection is performed on all device data, then cyber-attack detection capability is improved, but false positive results increase due to operational errors and environmental changes
Solution Approach 1:
The patent segments anomaly detection into two levels: device-level detection using lightweight rules in the vehicle, and cloud-level detection using comprehensive feature contexts. This segmentation allows basic anomaly filtering at the device while more accurate cloud-based analysis handles complex cases, reducing false positives from environmental changes and operational errors.
Solution Approach 2:
The system performs preliminary anomaly detection at the device level using simple rules before transmitting data to the cloud. This preliminary action filters out obvious anomalies and prepares data for more sophisticated cloud-based analysis, improving overall detection accuracy while reducing cloud processing load.
2Measurement precision
If comprehensive anomaly analysis is performed on all detected anomalies, then detection accuracy is improved, but analysis cost increases due to false positives
Solution Approach 1:
The patent applies different quality levels of analysis to different anomalies. Cloud-based comprehensive analysis with full feature contexts is applied selectively to suspicious cases identified by device-level detection, while routine anomalies receive simpler processing. This local quality approach optimizes analysis cost by applying high-resource processing only where necessary.
3Measurement precision
If feature contexts are stored for all device data, then anomaly analysis accuracy is improved, but storage requirements increase
Solution Approach 1:
The system extracts and stores only the most relevant feature contexts in the cloud (device information, communication patterns, error logs) rather than storing all raw device data. This extraction approach maintains anomaly analysis accuracy by preserving key contextual information while significantly reducing storage requirements compared to storing complete device datasets.
Data Source
AI summary
A storage processing unit configured to store, in a storage unit, first data output by a device or any one of multiple devices in association with a first feature context related to the first data, and an analyzing unit configured to obtain a second feature context related to second data in a case where the second data is received from the device or any one of the multiple devices, and analyze an anomaly of the received second data based on the received second data and the obtained second feature context and based on the first data and the first feature context stored in the storage unit, are provided.


