INFORMATION PROCESSING SYSTEM, INFORMATION PROCESSING METHOD AND STORAGE MEDIUM
1 Assignment
0 Petitions
Accused Products
Abstract
To support work of an operator of a monitoring system to set a monitoring rule depending on an environment to be monitored. An information processing system includes an environment expression extracting unit which extracts environment expressions from incident information expressing a certain incident, which includes the environment expressions expressing environments to be monitored and action expressions expressing actions performed in the environments; an action expression extracting unit which extracts the action expressions from the incident information; and an information collecting unit which generates information in which the extracted action expressions are associated with the environment expressions expressing the environments when the actions expressed by the action expressions have been performed among the extracted environment expressions, conducts a search with respect to the generated information, with the action expressions as a key, and calculates, on the basis of the search, frequency at which the environment expressions have been extracted.
9 Citations
28 Claims
-
1-10. -10. (canceled)
-
11. An information processing system comprising circuitry configured to:
-
extract environment expressions from incident information, which describes an incident in which what abnormal action was performed in what environment, and which includes the environment expressions expressing the environments to be monitored and action expressions expressing actions performed in the environments; extract the action expressions from the incident information; generate information in which the extracted action expressions are associated with the environment expressions expressing the environments when the actions expressed by the action expressions have been performed among the extracted environment expressions, conducts a search with respect to the generated information, with the action expressions as a key, and calculates, on the basis of the search, frequency at which the environment expressions have been extracted; store the action expressions and the associated environment; refer to the stored expressions, and, when the frequency at which the environment expressions associated with a specific action expression among the stored action expressions have been extracted is higher than a predetermined threshold value, associates the specific action expression with the environment expressions having high frequency of extraction and outputs the associated expressions; and generate a monitoring rule for monitoring occurrence of an abnormal circumstance, on the basis of the outputted environment expressions and action expression, the monitoring rule having a conditional clause in which the environments expressed by the environment expressions are satisfied and the action expressed by the action expression is detected. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
-
27. An information processing method executed by a computer, comprising processes of:
-
extracting environment expressions from incident information, which describes an incident in which what abnormal action was performed in what environment, and which includes the environment expressions expressing the environments to be monitored and action expressions expressing actions performed in the environments; extracting the action expressions from the incident information; generating information in which the extracted action expressions are associated with the environment expressions expressing the environments when the actions expressed by the action expressions have been performed among the extracted environment expressions, conducts a search with respect to the generated information, with the action expressions as a key, and calculates, on the basis of the search, frequency at which the environment expressions have been extracted; storing the action expressions and the associated environment expressions; referring to the stored expressions, and, when the frequency at which the environment expressions associated with a specific action expression among the stored action expressions have been extracted is higher than a predetermined threshold value, associates the specific action expression with the environment expressions having high frequency of extraction and outputs the associated expressions; and generating a monitoring rule for monitoring occurrence of an abnormal circumstance, on the basis of the outputted environment expressions and action expression, the monitoring rule having a conditional clause in which the environments expressed by the environment expressions are satisfied and the action expressed by the action expression is detected.
-
-
28. A non-transitory computer-readable storage medium storing a program which causes a computer to execute processing for:
-
extracting environment expressions from incident information, which describes an incident in which what abnormal action was performed in what environment, and which includes the environment expressions expressing the environments to be monitored and action expressions expressing actions performed in the environments; extracting the action expressions from the incident information; generating information in which the extracted action expressions are associated with the environment expressions expressing the environments when the actions expressed by the action expressions have been performed among the extracted environment expressions, conducts a search with respect to the generated information, with the action expressions as a key, and calculates, on the basis of the search, frequency at which the environment expressions have been extracted; storing the action expressions and the associated environment expressions; referring to the stored expressions, and, when the frequency at which the environment expressions associated with a specific action expression among the stored action expressions have been extracted is higher than a predetermined threshold value, associates the specific action expression with the environment expressions having high frequency of extraction and outputs the associated expressions; and generating a monitoring rule for monitoring occurrence of an abnormal circumstance, on the basis of the outputted environment expressions and action expression, the monitoring rule having a conditional clause in which the environments expressed by the environment expressions are satisfied and the action expressed by the action expression is detected.
-
Specification