IoT Log Prioritization for Accurate Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for reducing log data sent by IoT devices to analysis devices in control systems are inefficient, leading to increased communication bandwidth strain and costs without maintaining accuracy in anomaly detection.
Innovation Solution
An information processing method that determines the priority of log items based on anomaly determination rules, allowing IoT devices to send only necessary data to the analysis device, optimizing log data volume while maintaining analysis accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IoT devices send all log data to external analysis devices, then anomaly detection accuracy is maintained, but communication bandwidth strain and analysis costs increase
Solution Approach 1:
The patent applies preliminary action by having the external analysis device generate and distribute anomaly determination rules to IoT devices in advance. These rules enable IoT devices to pre-filter their log data locally, determining which logs match the anomaly criteria before transmission. This preliminary filtering action reduces the volume of log data that needs to be communicated while ensuring that all potentially anomalous logs are captured for accurate anomaly detection.
2Measurement precision
If log sending rules are manually updated by administrators, then log analysis accuracy is maintained, but administrator workload increases
Solution Approach 1:
The patent implements self-service by enabling IoT devices to automatically receive, store, and apply anomaly determination rules distributed by the external analysis device. The system eliminates the need for manual administrator intervention in updating log filtering rules, as the rules are automatically pushed from the analysis device to IoT devices. This maintains log analysis accuracy through up-to-date rules while significantly reducing administrator workload.
Solution Approach 2:
The system uses feedback mechanisms where the external analysis device monitors anomaly detection performance and automatically adjusts anomaly determination rules based on detected patterns and false positive rates. These updated rules are then redistributed to IoT devices, creating a closed-loop system that continuously improves log analysis accuracy without requiring manual administrator input.
3Quantity of substance
If log data volume is reduced, then communication bandwidth strain decreases, but anomaly detection accuracy may deteriorate
Solution Approach 1:
The patent applies local quality by enabling each IoT device to independently evaluate its own log data against anomaly determination rules and selectively transmit only matching logs. This localized filtering ensures that each device sends a customized subset of logs relevant to its specific operations and anomaly patterns, rather than applying a uniform reduction approach. The result is reduced overall data volume while maintaining detection accuracy for device-specific anomalies.
Data Source
AI summary
An information processing method according to one aspect of the present disclosure is an information processing method executed by a computer, including: obtaining one or more anomaly determination rules to be used in an anomaly determination for a log of a device, each of the one or more anomaly determination rules including a predetermined condition using one or more items among a plurality of items included in the log of the device; determining a priority of each of the plurality of items based on the one or more anomaly determination rules obtained, the priority being a degree for determining an item, among the plurality of items, to be included in a first log to be sent to an analysis device that performs the anomaly determination; and outputting priorities, each being the priority determined.


