Message abnormality automatic detection device, method and program
First Claim
1. A detection device comprising:
- learning means for extracting a sequence pattern of at least two consecutive messages from a first group of messages generated by a system, and for counting a number of the sequence pattern of messages in the first group;
memory means for storing the sequence pattern and the number of the sequence pattern of messages in the first group; and
collation means for referencing the sequence pattern and the number of the sequence pattern of the messages in the first group stored in the memory means, for counting a number of the sequence pattern of messages in a second group of messages generated by the system, and for determining abnormality when the number of the sequence pattern of the messages in the second group is not within a range set using the number of the sequence pattern of messages in the first group,the collation means is to determine the abnormality when a proportion of the counted number of the sequence pattern of messages in the second group to the number of the sequence pattern of messages in the first group is equal to or larger than a certain number.
1 Assignment
0 Petitions
Accused Products
Abstract
In order to provide a message abnormality automatic detection device, method and program for accurately detecting messages indicating abnormalities requiring response from a large amount of messages, the message abnormality automatic detection device 1 comprises a message collection unit 2 for collecting messages, a learning unit 3 for extracting patterns from the collected messages, a normal pattern memory unit 4 for storing normal patterns, a collation unit 5 for collating the collected messages with normal patterns and detecting message abnormalities, a warning unit 6 for outputting abnormalities to display 9 and the like, and a definition unit 7 for storing the definition data related to normal patterns.
26 Citations
11 Claims
-
1. A detection device comprising:
-
learning means for extracting a sequence pattern of at least two consecutive messages from a first group of messages generated by a system, and for counting a number of the sequence pattern of messages in the first group; memory means for storing the sequence pattern and the number of the sequence pattern of messages in the first group; and collation means for referencing the sequence pattern and the number of the sequence pattern of the messages in the first group stored in the memory means, for counting a number of the sequence pattern of messages in a second group of messages generated by the system, and for determining abnormality when the number of the sequence pattern of the messages in the second group is not within a range set using the number of the sequence pattern of messages in the first group, the collation means is to determine the abnormality when a proportion of the counted number of the sequence pattern of messages in the second group to the number of the sequence pattern of messages in the first group is equal to or larger than a certain number. - View Dependent Claims (2, 3, 4, 5)
-
-
6. A detection device comprising:
-
learning means for extracting a sequence pattern of at least two consecutive messages from a first group of messages obtained from a device within a first period of time, and for counting a number of the sequence pattern of messages in the first group; memory means for storing the sequence pattern and the number of the sequence pattern of messages in the first group; and collation means for referencing the sequence pattern and the number of the sequence pattern of the messages in the first group stored in the memory means, for counting a number of the sequence pattern of messages in a second group of messages obtained within a second period of time that is after the first period of time, and for determining abnormality when the number of the sequence pattern of the messages in the second group is not within a range set using the number of the sequence pattern of messages in the first group, wherein the collation means is to determine the abnormality when a proportion of the counted number of the sequence pattern of messages in the second group to the number of the sequence pattern of messages in the first group is equal to or smaller than the certain number. - View Dependent Claims (7)
-
-
8. A detection device comprising:
-
learning means for extracting a sequence pattern of at least two consecutive messages from a first group of messages generated by a system, and for counting a number of the sequence pattern of messages in the first group; memory means for storing the sequence pattern and the number of the sequence pattern of messages in the first group; and collation means for selecting a sequence pattern of the extracted sequence patterns, which includes a message indicating a content same as a first message obtained after the first group of messages, and for determining abnormality when the selected sequence pattern does not include a message indicating a content same as a second message obtained subsequent to the first message as a message obtained subsequent to the message indicating the content same as the first message; wherein the selection of the sequence pattern of the selected sequence patterns, which does not include the message indicating the content same as the second message as a message obtained subsequent to the first message, is released, and a sequence pattern of the extracted sequence patterns, which includes a message indicating a content same as the second message as a message obtained first is further selected. - View Dependent Claims (9)
-
-
10. A detection method causing a computer to execute:
-
extracting a sequence pattern of at least two consecutive messages from a first group of messages generated by a system, and counting a number of the sequence pattern of messages in the first group; storing the sequence pattern and the number of the sequence pattern of messages in the first group; referencing the sequence pattern and the number of the sequence pattern of the messages in the first group stored in the memory means, counting a number of the sequence pattern of messages in a second group of messages generated by the system, and determining abnormality when the number of the sequence pattern of the messages in the second group is not within a range set using the number of the sequence pattern of messages in the first group; and determining the abnormality when a proportion of the counted number of the sequence pattern of messages in the second group to the number of the sequence pattern of messages in the first group is equal to or larger than a certain number.
-
-
11. A detection device comprising:
-
a memory, and a processor which executes; extracting a sequence pattern of at least two consecutive messages from a first group of messages generated by a system, and counting a number of the sequence pattern of messages in the first group; storing the sequence pattern and the number of the sequence pattern of messages in the first group on the memory; referencing the sequence pattern and the number of the sequence pattern of the messages in the first group stored in the memory, counting a number of the sequence pattern of messages in a second group of messages generated by the system, and determining abnormality when the number of the sequence pattern of the messages in the second group is not within a range set using the number of the sequence pattern of messages in the first group; and determining the abnormality when a proportion of the counted number of the sequence pattern of messages in the second group to the number of the sequence pattern of messages in the first group is equal to or larger than a certain number.
-
Specification