TRAIL LOG ANALYSIS SYSTEM, MEDIUM STORING TRAIL LOG ANALYSIS PROGRAM, AND TRAIL LOG ANALYSIS METHOD
First Claim
1. A trail log analysis system, comprising:
- a processor to realize functions comprising;
an information development unit configured to define as comparison targets a subject, an object, and an action in a trail log of an information system, count an event occurrence number for each time zone corresponding to a event occurrence time recorded on a trail log to be analyzed which has last collected for each combination of the comparison targets, and generate an information development table;
an accumulation unit configured to generate an accumulative information development table by accumulating the information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed; and
a comparison unit configured to compare the information development table with the accumulative information development table, and output a comparison result.
1 Assignment
0 Petitions
Accused Products
Abstract
A trail log analysis system detects a fraudulent operation from a trail log of an information system, and confirms the correctness of a system action. An information development device generates an information development table from a trail log to be analyzed. The information development table defines a subject (who), an object (what), and an action (what is to be done) as comparison targets, and counts and record an event occurrence number corresponding to an event occurrence time recorded in a trail log for each combination of comparison targets. An accumulation device generates an accumulative information development table by accumulating the information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed. A comparison device compares the information development table with the accumulative information development table, and outputs a comparison result.
-
Citations
19 Claims
-
1. A trail log analysis system, comprising:
a processor to realize functions comprising; an information development unit configured to define as comparison targets a subject, an object, and an action in a trail log of an information system, count an event occurrence number for each time zone corresponding to a event occurrence time recorded on a trail log to be analyzed which has last collected for each combination of the comparison targets, and generate an information development table; an accumulation unit configured to generate an accumulative information development table by accumulating the information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed; and a comparison unit configured to compare the information development table with the accumulative information development table, and output a comparison result. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
14. A non-transitory computer readable storage medium storing a trail log analysis program used to direct an information processing device to perform:
-
an information developing to define as comparison targets a subject, an object, and an action in a trail log of an information system, to count an event occurrence number for each time zone corresponding to a event occurrence time recorded on a trail log to be analyzed which has last collected for each combination of the comparison targets, and to generate an information development table; an accumulating to generate an accumulative information development table by accumulating the information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed; and a comparing to compare the information development table with the accumulative information development table, and to output a comparison result. - View Dependent Claims (15, 16, 17, 18)
-
-
19. A trail log analysis method conducted by an information processing device, the method comprising:
-
defining as comparison targets a subject, an object, and an action in a trail log of an information system, counting an event occurrence number for each time zone corresponding to a event occurrence time recorded on a trail log to be analyzed which has last collected for each combination of the comparison targets, and generating an information development table; generating an accumulative information development table by accumulating the information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed; and comparing the information development table with the accumulative information development table, and outputting a comparison result.
-
Specification