Trail log analysis system, medium storing trail log analysis program, and trail log analysis method
First Claim
1. A trail log analysis system comprising:
- a processor that;
defines as comparison targets a subject, an object, and an action in a trail log of an information system, count an event occurrence number for each time zone corresponding to an event occurrence time recorded on a trail log to be analyzed which was last collected for each combination of the comparison targets, and generates a first information development table;
generates a second information development table by accumulating the event occurrence number of the first information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed when the event occurrence number of the first information development table corresponds to a normal event, wherein the processor does not accumulate the event occurrence number of the first information development table in the second information development table when the event occurrence number of the first information development table corresponds to an abnormal event; and
compares the first information development table with the second information development table, and outputs a comparison result,wherein the processor detects an event corresponding to a combination A as a newly performed operation and outputs the comparison result when the combination A of the comparison targets included in the first information development table does not exist in combinations of the comparison targets of the second information development table.
1 Assignment
0 Petitions
Accused Products
Abstract
A trail log analysis system detects a fraudulent operation from a trail log of an information system, and confirms the correctness of a system action. An information development device generates an information development table from a trail log to be analyzed. The information development table defines a subject (who), an object (what), and an action (what is to be done) as comparison targets, and counts and record an event occurrence number corresponding to an event occurrence time recorded in a trail log for each combination of comparison targets. An accumulation device generates an accumulative information development table by accumulating the information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed. A comparison device compares the information development table with the accumulative information development table, and outputs a comparison result.
-
Citations
18 Claims
-
1. A trail log analysis system comprising:
-
a processor that; defines as comparison targets a subject, an object, and an action in a trail log of an information system, count an event occurrence number for each time zone corresponding to an event occurrence time recorded on a trail log to be analyzed which was last collected for each combination of the comparison targets, and generates a first information development table; generates a second information development table by accumulating the event occurrence number of the first information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed when the event occurrence number of the first information development table corresponds to a normal event, wherein the processor does not accumulate the event occurrence number of the first information development table in the second information development table when the event occurrence number of the first information development table corresponds to an abnormal event; and compares the first information development table with the second information development table, and outputs a comparison result, wherein the processor detects an event corresponding to a combination A as a newly performed operation and outputs the comparison result when the combination A of the comparison targets included in the first information development table does not exist in combinations of the comparison targets of the second information development table. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A non-transitory computer readable storage medium storing a trail log analysis program used to direct an information processing device to perform:
-
an information developing to define as comparison targets a subject, an object, and an action in a trail log of an information system, to count an event occurrence number for each time zone corresponding to an event occurrence time recorded on a trail log to be analyzed which has last collected for each combination of the comparison targets, and to generate a first information development table; an accumulating to generate a second information development table by accumulating the event occurrence number of the first information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed when the event occurrence number of the first information development table corresponds to a normal event, wherein the accumulating does not accumulate the event occurrence number of the first information development table in the second information development table when the event occurrence number of the first information development table corresponds to an abnormal event; and a comparing to compare the first information development table with the second information development table, and to output a comparison result, wherein the comparing detects an event corresponding to a combination A as a newly performed operation and outputs the comparison result when the combination A of the comparison targets included in the first information development table does not exist in combinations of the comparison targets of the second information development table. - View Dependent Claims (14, 15, 16, 17)
-
-
18. A trail log analysis method conducted by an information processing device, the method comprising:
-
defining as comparison targets a subject, an object, and an action in a trail log of an information system, counting an event occurrence number for each time zone corresponding to an event occurrence time recorded on a trail log to be analyzed which has last collected for each combination of the comparison targets, and generating a first information development table; generating a second information development table by accumulating the even occurrence number of the first information development table corresponding to a trail log recorded previously and up to a time point immediately before the last collected trail log to be analyzed when the event occurrence number of the first information development table corresponds to a normal event, wherein the generating does not accumulate the event occurrence number of the first information development table in the second information development table when the event occurrence number of the first information development table corresponds to an abnormal event; and comparing the first information development table with the second information development table, and outputting a comparison result, wherein the comparing detects an event corresponding to a combination A as a newly performed operation and the outputting outputs the comparison result when the combination A of the comparison targets included in the first information development table does not exist in combinations of the comparison targets of the second information development table.
-
Specification