WO2020004315A1 - 異常検知装置、および、異常検知方法 - Google Patents
異常検知装置、および、異常検知方法 Download PDFInfo
- Publication number
- WO2020004315A1 WO2020004315A1 PCT/JP2019/024928 JP2019024928W WO2020004315A1 WO 2020004315 A1 WO2020004315 A1 WO 2020004315A1 JP 2019024928 W JP2019024928 W JP 2019024928W WO 2020004315 A1 WO2020004315 A1 WO 2020004315A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- communication
- communication log
- information
- abnormality
- learning
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N20/00—Machine learning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/06—Generation of reports
- H04L43/065—Generation of reports related to network devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
Definitions
- the present invention relates to an abnormality detection device and an abnormality detection method.
- Patent Document 1 As a method to detect abnormalities due to virus infection etc. in devices such as PCs, a signature detection method that matches device behavior patterns with known abnormal patterns to detect abnormalities, and matches device behavior patterns with normal state behavior patterns Conventionally, an anomaly detection method for detecting an abnormality has been proposed and used (see Patent Document 1).
- an abnormality can be detected when the abnormal pattern matches the abnormal pattern.
- an abnormality in which the abnormal pattern is not predetermined due to an unknown virus or the like cannot be detected.
- a normal state is learned by using a machine learning technique as in Patent Literature 1, and all behavior patterns that do not match the learned model are detected as abnormal. Therefore, an abnormality due to an unknown virus or the like can be detected.
- the anomaly detection method when the normal state is changed due to a change in device settings or the like, a behavior pattern that does not match the past model is detected as abnormal.
- Patent Document 1 the behavior of the normal state of the device used for the anomaly detection method is determined based on past observation values. In order to follow the change, it is necessary to re-learn the behavior in the normal state.
- an object of the present invention is to solve the above-described problem and perform relearning of the behavior of the device in a normal state at an appropriate timing.
- the present invention provides a learning unit that generates a detection model for detecting an abnormality of the communication device by using a communication log during a normal operation of the communication device as learning data;
- An abnormality detection unit that detects an abnormality of the communication device by using a model and a communication log of the communication device; and a predetermined communication log that is later than a first communication log that is a communication log used to generate the detection model.
- a data acquisition unit for acquiring a second communication log that is a communication log generated during a period, and adding a communication log of the second communication log in which an abnormality is detected by the detection model to the first communication log
- An additional information specifying unit for specifying as information
- a deletion information specifying unit for specifying deletion information obtained by removing additional information of the first communication log from difference information between the first communication log and the second communication log.
- the re-learning of the behavior of the device in the normal state can be performed at an appropriate timing.
- FIG. 1 is a diagram illustrating a configuration example of a system.
- FIG. 2 is a diagram for explaining additional information and deletion information in the present embodiment.
- FIG. 3 is a diagram for explaining difference information, additional information, and deletion information between the pre-update learning data set and the latest learning data set.
- FIG. 4 is a flowchart illustrating an example of a processing procedure of the abnormality detection device in FIG.
- FIG. 5 is a diagram illustrating an example of a computer that executes an abnormality detection program.
- the system includes, for example, a communication device 10, a gateway device 20, and an abnormality detection device 30, as shown in FIG.
- the communication device 10 and the gateway device 20 are connected by a LAN (Local Area Network) or the like.
- the gateway device 20 and the abnormality detection device 30 are connected by a network such as the Internet.
- the communication device 10 is a communication device that is to be detected as an abnormality in the present system.
- the communication device 10 is, for example, a PC or the like.
- the gateway device 20 is a device that connects the communication device 10 to an external device via a network such as the Internet or connects to another communication device 10 in the same LAN.
- the gateway device 20 acquires information indicating the behavior of the communication device 10, such as information on a network flow transmitted and received by each communication device 10, a communication feature amount of the network flow, an operation log of each communication device 10, and the like.
- the network flow information includes, for example, a source IP (Internet Protocol) address, a source MAC (Media Access Control) address, a destination IP address, a destination MAC address, and a communication port of the network flow.
- the number is the number of received packets, the number of transmitted packets, the communication payload, and the like.
- the communication feature amount is, for example, a source IP address, a source MAC address, a destination IP address, a destination MAC address of the network flow, an average value of the total number of received packets, a variance value of the total number of transmitted packets, and the like.
- the operation log includes an ID of a process executed in the communication device 10, an execution start time of the process, and the like.
- the anomaly detection device 30 detects anomalies such as unauthorized access to each communication device 10 and virus infection by learning information indicating the behavior of each communication device 10 in a normal state acquired from the gateway device 20.
- the anomaly detection device 30 learns, for example, the network flow information of each communication device 10 in a normal state, the communication feature amount of the network flow, the operation log of each communication device, and the like (collectively referred to as “communication log”). To generate a detection model of the anomaly detection type. Then, the abnormality detection device 30 performs anomaly detection type abnormality detection using the generated detection model and the network flow information, the communication feature amount, the operation log, and the like of the communication device 10 to be detected.
- the abnormality detection device 30 re-learns the communication log of the normal state of each communication device 10 in order to follow a change in the normal state due to a setting change or the like of each communication device 10 and performs detection using the result of the re-learning. Update the model.
- the abnormality detection device 30 acquires the communication log (learning data set B) of each of the communication devices 10 that has occurred after the communication log (learning data set A) used to generate the current detection model A.
- the abnormality detection device 30 performs relearning using the learning data set B.
- the abnormality detection device 30 can re-learn the behavior of the communication device 10 in a normal state at an appropriate timing even in an environment where a calculation cost cannot be applied.
- the abnormality detection device 30 includes a learning unit 31, an abnormality detection unit 32, and a relearning execution determination unit 33.
- the learning unit 31 generates a detection model for detecting an abnormality in the communication device 10 using the communication log in a normal state of the communication device 10 as learning data. For example, when the learning unit 31 acquires a communication log in a normal state of each communication device 10 from the gateway device 20, the learning unit 31 generates a detection model for detecting an abnormality of each communication device 10 using the communication log as learning data.
- the learning unit 31 causes the abnormality detection unit 32 to start abnormality detection (analysis for abnormality detection) using the detection model. Then, the learning unit 31 re-learns the identification information of the communication device 10 used for the learning, the communication log (the learning data set A), and the detection model (the detection model A) generated by learning the communication log. It is stored in the execution determination unit 33.
- the abnormality detection unit 32 performs anomaly detection type abnormality detection on the communication device 10 using the detection model generated by the learning unit 31 and the communication log of the communication device 10. For example, when acquiring the communication log of the communication device 10 to be detected from the gateway device 20, the abnormality detection unit 32 performs abnormality detection of the communication device 10 using the detection model generated by the learning unit 31.
- the re-learning execution determination unit 33 determines whether the learning unit 31 should re-learn the communication log.
- the re-learning execution determination unit 33 includes a data acquisition unit 330, an additional information identification unit 331, a difference information identification unit 332, a deletion information identification unit 333, and a determination unit 334.
- the data acquisition unit 330 transmits the communication log (for the predetermined period from the time point) to the predetermined communication device 10 from the gateway device 20 for each predetermined period or when an instruction is input from the administrator of the abnormality detection device 30. 2 communication log).
- the additional information specifying unit 331 adds, to the second communication log acquired by the data acquisition unit 330, a communication log in which an abnormality is detected by the detection model (detection model A) currently used by the abnormality detection unit 32. Identify as information.
- the difference information specifying unit 332 compares the communication log (learning data set A) used for generating the detection model A with the second communication log (learning data set B) acquired by the data acquiring unit 330, It is determined whether there is difference information.
- the difference information specifying unit 332 when the learning data sets A and B to be compared are the network flow information or the communication feature amount of the communication device 10, the difference information specifying unit 332 generates the 5-tuple information (the transmission source / Destination IP address, source / destination MAC address, communication port number). Further, for example, when the learning data sets A and B are operation logs of the communication device 10, the difference information specifying unit 332 compares the IP address, the MAC address, and the communication port of the destination communication device of the communication device 10. .
- the deletion information specifying unit 333 specifies deletion information excluding the additional information from difference information between the first communication log (learning data set A) and the second communication log (learning data set B).
- each network flow information may include information other than the 5-tuple (for example, the number of received packets, the number of transmitted packets, the payload, etc.) in addition to the 5-tuple information.
- the additional information specifying unit 331 confirms the presence or absence of abnormality detection in the learning data set B by using the pre-update detection model (detection model A), thereby adding an additional flow (additional information) to the learning data set B. ), It is possible to identify the additional flow (additional information) ((1)).
- the fact that an abnormality is detected in the learning data set B using the detection model A means that the learning data set B has a communication log (a communication log of an additional flow) with a communication destination that is not in the learning data set A. Is included. Therefore, if there is a communication log of the learning data set B in which an abnormality has been detected by the detection model A, the difference information specifying unit 332 specifies the communication log as additional information.
- the difference information specifying unit 332 checks the difference (difference information) between the two data sets by using the 5-tuple information of the learning data set A and the learning data set B. 333 removes an additional flow (additional information) from the difference information. Accordingly, the deletion information specifying unit 333 can specify not only the presence or absence of the deletion flow (deletion information) but also the deletion flow (deletion information) ((2)).
- the deletion information specifying unit 333 specifies the communication log as the deletion information.
- the determination unit 334 When there is difference information between the first communication log (learning data set A) and the second communication log (learning data set B), the determination unit 334 sends the second communication log (learning) to the learning unit 31. An instruction is issued to generate (re-learn) the abnormality detection model using the data set B) as learning data.
- the determination unit 334 determines whether additional information included in the difference information is present.
- the learning unit 31 is instructed to perform re-learning using the second communication log (learning data set B) as learning data.
- the determination unit 334 determines (1) if the number of additional information exceeds a predetermined threshold, (2) if the number of deletion information exceeds a predetermined threshold, or (3) the sum of the additional information and the deletion information. Is larger than a predetermined threshold value, the learning unit 31 is instructed to carry out re-learning.
- the thresholds used in (1) to (3) may be determined by the user of the abnormality detection device 30, or may be determined by the abnormality detection device 30 based on past statistical values or the like.
- the determination unit 334 selects one of (1) to (3). Alternatively, if the evaluation criterion described by a combination of these is satisfied, the learning unit 31 may be instructed to perform relearning. Note that the user of the abnormality detection device 30 can appropriately set which evaluation criterion is used by the determination unit 334.
- the abnormality detection unit 32 performs abnormality detection using the detection model B (analysis for abnormality detection). To start. Then, the learning unit 31 re-learns the identification information of the communication device 10 used for the re-learning, the communication log (the learning data set B), and the detection model (the detection model B) generated by learning the communication log. It is overwritten and stored in the execution determination unit 33.
- the relationship between the pre-update learning data set (learning data set A) and the latest learning data set (learning data set B) may be patterns 1 to 4 shown in FIG. That is, the case where all the latest learning data sets are included in the pre-update learning data set as in pattern 1 and the case where a part of the pre-update learning data set is included in part of the latest learning data set as in pattern 2 It is considered that the entirety of the pre-update learning data set is included in the latest learning data set as in pattern 3 and the case where the pre-update learning data set and the latest learning data set are completely different as in pattern 4. .
- the hatched portions of patterns 1 to 4 in FIG. 3 indicate difference information between the pre-update learning data set and the latest learning data set in each pattern.
- pattern 1 there is no additional information in the difference information, but there is deletion information.
- patterns 2 and 4 there are both additional information and deletion information in the difference information.
- difference information includes additional information but does not include deletion information. Therefore, in the case of pattern 1, the learning unit 31 can generate a detection model in which the abnormality is not overlooked by learning the latest learning data set.
- the learning unit 31 learns the latest learning data set, and thereby can generate a detection model with few oversights of abnormalities and few false detections.
- the learning unit 31 can generate a detection model with less erroneous detection by learning the latest learning data set.
- the determination unit 334 determines whether or not to perform re-learning using an evaluation criterion using additional information or deletion information (or a combination thereof). , The learning unit 31 can be instructed to perform relearning at an appropriate timing.
- the determining unit 334 (2) instructs the learning unit 31 to perform re-learning when the number of pieces of deletion information exceeds a predetermined value, thereby realizing re-learning with the latest learning data set in the patterns 1, 2, and 4. it can. As a result, the learning unit 31 can generate a detection model in which the abnormality is not overlooked.
- the determining unit 334 instructs the learning unit 31 to perform re-learning when the total number of the additional information and the deleted information exceeds a predetermined value, thereby realizing the re-learning using the latest learning data set in the patterns 2 and 4. it can. As a result, the learning unit 31 can generate a detection model in which erroneous detection and oversight of abnormality are less.
- the learning unit 31 learns a normal operation (learning data set A) of the communication device 10 and generates a detection model A (S1). Then, the learning unit 31 stores the learning data set A and the detection model A in the re-learning execution determination unit 33 (S2). Further, the learning unit 31 causes the abnormality detection unit 32 to start an analysis operation of abnormality detection using the detection model (S3).
- the data acquisition unit 330 acquires a communication log (learning data set B) after the learning data set A (S11).
- the additional information specifying unit 331 checks presence / absence of additional information based on the detection model A and the learning data set B (S12). That is, the additional information specifying unit 331 checks whether or not the learning data set B includes a communication log in which an abnormality has been detected by the detection model A, and if so, specifies the communication log as additional information.
- the deletion information specifying unit 333 checks the presence or absence of the deletion information based on the learning data set A, the learning data set B, and the additional information (S13).
- the difference information specifying unit 332 checks whether there is a difference between the learning data set A and the learning data set B, and if there is a difference, specifies the communication log of the difference as difference information. Then, the deletion information specifying unit 333 checks whether or not the difference information includes a communication log other than the additional information specified in S12, and if so, specifies the communication log as the deletion information.
- the determination unit 334 determines that there is additional information or deletion information (that is, there is difference information) (Yes in S14), and that the number of additional information or the number of deletion information is a predetermined evaluation criterion (for example, If (1) to (3)) are satisfied (Yes in S15), the learning unit 31 is instructed to re-learn the normal operation and generate the detection model B (S16). That is, the determination unit 334 instructs the learning unit 31 to learn the learning data set B and generate the detection model B. Thereby, the learning unit 31 generates the detection model B. Thereafter, the learning unit 31 overwrites the learning data set A of the relearning execution determination unit 33 with the learning data set B, and overwrites the detection model A with the detection model B (S17). Further, the learning unit 31 causes the abnormality detection unit 32 to start an analysis operation of abnormality detection using the detection model (detection model B) overwritten in S17 (S18). Then, the process returns to S11.
- the process returns to S11. Also, when the determining unit 334 determines that the number of additional information or the number of deleted information does not satisfy a predetermined evaluation criterion (for example, (1) to (3) described above) (No in S15), the process returns to S11. .
- the abnormality detection device 30 determines whether or not to perform re-learning based on the evaluation criterion using the number of additional information or the number of deleted information in the learning data set. That is, the abnormality detection device 30 determines whether or not to perform relearning based on the number of added flows or the number of deleted flows after the current detection model is generated. As a result, the abnormality detection device 30 can perform relearning at an appropriate timing.
- the abnormality detection device 30 determines whether or not to perform re-learning based on an evaluation criterion using the number of additional information or the number of deleted information in the learning data set, but is not limited thereto. For example, the abnormality detection device 30 may determine that re-learning is performed when there is difference information regardless of the presence or absence of additional information or deletion information in the learning data set.
- the abnormality detection device 30 can be implemented by installing a program for realizing the function of the abnormality detection device 30 described in the above-described embodiment in a desired information processing device (computer).
- a desired information processing device computer
- the information processing device can function as the abnormality detection device 30.
- the information processing device referred to here includes a desktop or notebook personal computer.
- the information processing apparatus includes a mobile communication terminal such as a smartphone, a mobile phone, or a PHS (Personal Handyphone System), and a PDA (Personal Digital Assistant) in its category.
- the abnormality detection device 30 may be mounted on a cloud server.
- the computer 1000 has, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These units are connected by a bus 1080.
- the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012.
- the ROM 1011 stores, for example, a boot program such as a BIOS (Basic Input Output System).
- BIOS Basic Input Output System
- the hard disk drive interface 1030 is connected to the hard disk drive 1090.
- the disk drive interface 1040 is connected to the disk drive 1100.
- a removable storage medium such as a magnetic disk or an optical disk is inserted.
- a mouse 1110 and a keyboard 1120 are connected to the serial port interface 1050.
- a display 1130 is connected to the video adapter 1060, for example.
- the hard disk drive 1090 stores, for example, the OS 1091, the application program 1092, the program module 1093, and the program data 1094.
- the various data and information described in the above embodiment are stored in, for example, the hard disk drive 1090 or the memory 1010.
- the CPU 1020 reads the program module 1093 and the program data 1094 stored in the hard disk drive 1090 into the RAM 1012 as necessary, and executes the above-described procedures.
- the program module 1093 and the program data 1094 relating to the management program are not limited to being stored in the hard disk drive 1090.
- the program module 1093 and the program data 1094 are stored in a removable storage medium, It may be read.
- the program module 1093 and the program data 1094 relating to the above program are stored in another computer connected via a network such as a LAN (Local Area Network) or a WAN (Wide Area Network), and are stored in the network interface 1070. And may be read by the CPU 1020.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Artificial Intelligence (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Data Mining & Analysis (AREA)
- Evolutionary Computation (AREA)
- Medical Informatics (AREA)
- Mathematical Physics (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Maintenance And Management Of Digital Transmission (AREA)
- Debugging And Monitoring (AREA)
Abstract
Description
まず、図1を用いて、本実施形態の異常検知装置を含むシステムの構成例を説明する。システムは、例えば、図1に示すように、通信機器10と、ゲートウェイ装置20と、異常検知装置30とを備える。通信機器10とゲートウェイ装置20とはLAN(Local Area Network)等により接続される。また、ゲートウェイ装置20と異常検知装置30とはインターネット等のネットワークにより接続される。
引き続き図1を用いて異常検知装置30を詳細に説明する。異常検知装置30は、学習部31と、異常検知部32と、再学習実施判定部33とを備える。
次に、図4を用いて異常検知装置30の処理手順を説明する。異常検知装置30の処理は、最初の検知モデルを生成する初期学習フェーズと、再学習により検知モデルを更新する運用フェーズとに分けられる。まず初期学習フェーズから説明する。
まず、学習部31は、通信機器10の正常動作(学習データセットA)を学習し、検知モデルAを生成する(S1)。そして、学習部31は、再学習実施判定部33に、学習データセットAと検知モデルAを保存する(S2)。また、学習部31は、異常検知部32に対し、当該検知モデルを用いた異常検知の分析動作を開始させる(S3)。
次に、運用フェーズを説明する。S3の後、データ取得部330は、学習データセットA以降の通信ログ(学習データセットB)を取得する(S11)。その後、追加情報特定部331は、検知モデルAと学習データセットBとにより追加情報の有無を確認する(S12)。つまり、追加情報特定部331は、学習データセットBに、検知モデルAで異常を検知した通信ログがあるか否かを確認し、あれば当該通信ログを追加情報として特定する。その後、削除情報特定部333は、学習データセットAと学習データセットBと追加情報とにより削除情報の有無を確認する(S13)。つまり、まず、差分情報特定部332が、学習データセットAと学習データセットBとの差分の有無を確認し、差分があれば、その差分の通信ログを差分情報として特定する。そして、削除情報特定部333は、当該差分情報に、S12で特定された追加情報以外の通信ログがあるか否かを確認し、あれば当該通信ログを削除情報として特定する。
また、上記の実施形態で述べた異常検知装置30の機能を実現するプログラムを所望の情報処理装置(コンピュータ)にインストールすることによって実装できる。例えば、パッケージソフトウェアやオンラインソフトウェアとして提供される上記のプログラムを情報処理装置に実行させることにより、情報処理装置を異常検知装置30として機能させることができる。ここで言う情報処理装置には、デスクトップ型またはノート型のパーソナルコンピュータが含まれる。また、その他にも、情報処理装置にはスマートフォン、携帯電話機やPHS(Personal Handyphone System)等の移動体通信端末、さらには、PDA(Personal Digital Assistant)等がその範疇に含まれる。また、異常検知装置30を、クラウドサーバに実装してもよい。
20 ゲートウェイ装置
30 異常検知装置
31 学習部
32 異常検知部
33 再学習実施判定部
330 データ取得部
331 追加情報特定部
332 差分情報特定部
333 削除情報特定部
334 判定部
Claims (4)
- 通信機器の正常動作時の通信ログを学習データとして用いて、前記通信機器の異常を検知する検知モデルを生成する学習部と、
前記生成された検知モデルと、前記通信機器の通信ログとを用いて、前記通信機器の異常を検知する異常検知部と、
前記検知モデルの生成に用いられた通信ログである第1の通信ログよりも後の所定期間に発生した通信ログである第2の通信ログを取得するデータ取得部と、
前記第2の通信ログのうち、当該検知モデルにより異常が検知された通信ログを前記第1の通信ログの追加情報として特定する追加情報特定部と、
前記第1の通信ログと前記第2の通信ログとの差分情報から、前記第1の通信ログの追加情報を除いた削除情報を特定する削除情報特定部と、
前記第1の通信ログの追加情報または削除情報が存在する場合において、前記追加情報の数または前記削除情報の数が所定の評価基準を満たすとき、前記学習部に、前記第2の通信ログを学習データとして用いて検知モデルを生成するよう命令する判定部と、
を備えることを特徴とする異常検知装置。 - 前記判定部は、
前記追加情報または前記削除情報が存在する場合において、前記追加情報の数が所定の閾値を超えるとき、または、前記削除情報の数が所定の閾値を超えるとき、または、前記追加情報と前記削除情報との合計数が所定の閾値を超えるとき、前記学習部に、前記第2の通信ログを学習データとして用いて検知モデルを生成するよう命令する
ことを特徴とする請求項1に記載の異常検知装置。 - 前記通信機器の通信ログは、
当該通信機器が送受信するネットワークフローの情報、前記ネットワークフローの通信特徴量、および、当該通信機器の動作ログの少なくともいずれかを含む
ことを特徴とする請求項1に記載の異常検知装置。 - 通信機器の異常を検知する異常検知装置により実行される異常検知方法であって、
通信機器の正常動作時の通信ログを学習データとして用いて、前記通信機器の異常を検知する検知モデルを生成するステップと、
前記生成された検知モデルと、前記通信機器の通信ログとを用いて、前記通信機器の異常を検知するステップと、
前記検知モデルの生成に用いられた通信ログである第1の通信ログよりも後の所定期間に発生した通信ログである第2の通信ログを取得するステップと、
前記第2の通信ログのうち、当該検知モデルにより異常が検知された通信ログを前記第1の通信ログの追加情報として特定するステップと、
前記第1の通信ログと前記第2の通信ログとの差分情報から、前記第1の通信ログの追加情報を除いた削除情報を特定するステップと、
前記第1の通信ログの追加情報または削除情報が存在する場合において、前記追加情報の数または前記削除情報の数が所定の評価基準を満たすとき、前記検知モデルを生成する学習部に、前記第2の通信ログを学習データとして用いて検知モデルを生成するよう命令するステップと、
を含んだことを特徴とする異常検知方法。
Priority Applications (5)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| AU2019293409A AU2019293409B2 (en) | 2018-06-27 | 2019-06-24 | Abnormality sensing device and abnormality sensing method |
| EP19827096.9A EP3796196B1 (en) | 2018-06-27 | 2019-06-24 | Abnormality sensing device and abnormality sensing method |
| CN201980042316.8A CN112437920B (zh) | 2018-06-27 | 2019-06-24 | 异常检测装置和异常检测方法 |
| US17/255,897 US12206689B2 (en) | 2018-06-27 | 2019-06-24 | Abnormality sensing device and abnormality sensing method |
| US18/222,340 US12244623B2 (en) | 2018-06-27 | 2023-07-14 | Abnormality sensing device and abnormality sensing method |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2018-121953 | 2018-06-27 | ||
| JP2018121953A JP6984551B2 (ja) | 2018-06-27 | 2018-06-27 | 異常検知装置、および、異常検知方法 |
Related Child Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US17/255,897 A-371-Of-International US12206689B2 (en) | 2018-06-27 | 2019-06-24 | Abnormality sensing device and abnormality sensing method |
| US18/222,340 Continuation US12244623B2 (en) | 2018-06-27 | 2023-07-14 | Abnormality sensing device and abnormality sensing method |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020004315A1 true WO2020004315A1 (ja) | 2020-01-02 |
Family
ID=68985696
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2019/024928 Ceased WO2020004315A1 (ja) | 2018-06-27 | 2019-06-24 | 異常検知装置、および、異常検知方法 |
Country Status (6)
| Country | Link |
|---|---|
| US (2) | US12206689B2 (ja) |
| EP (1) | EP3796196B1 (ja) |
| JP (1) | JP6984551B2 (ja) |
| CN (1) | CN112437920B (ja) |
| AU (1) | AU2019293409B2 (ja) |
| WO (1) | WO2020004315A1 (ja) |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112632030A (zh) * | 2020-12-04 | 2021-04-09 | 贝壳技术有限公司 | 数据异常定位方法及装置 |
| WO2022255247A1 (ja) * | 2021-05-31 | 2022-12-08 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 監視装置、監視システム及び監視方法 |
| CN116601922A (zh) * | 2020-12-24 | 2023-08-15 | 松下电器(美国)知识产权公司 | 阈值计算装置、异常检测装置、阈值计算方法及异常检测方法 |
| WO2023188052A1 (ja) * | 2022-03-30 | 2023-10-05 | 三菱電機株式会社 | 学習データ選択装置、学習データ選択方法及び異常検知装置 |
| EP4307612A1 (en) * | 2022-07-04 | 2024-01-17 | Fujitsu Limited | Detection program, detection apparatus, and detection method |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP6984551B2 (ja) | 2018-06-27 | 2021-12-22 | 日本電信電話株式会社 | 異常検知装置、および、異常検知方法 |
| US11928208B2 (en) * | 2018-10-02 | 2024-03-12 | Nippon Telegraph And Telephone Corporation | Calculation device, calculation method, and calculation program |
| CA3060144A1 (en) * | 2018-10-26 | 2020-04-26 | Royal Bank Of Canada | System and method for max-margin adversarial training |
| JP7510760B2 (ja) * | 2020-01-15 | 2024-07-04 | キヤノンメディカルシステムズ株式会社 | 医用情報処理装置及び医用情報処理システム |
| JP7452849B2 (ja) * | 2020-05-25 | 2024-03-19 | 日本電気通信システム株式会社 | 異常操作検出装置、異常操作検出方法、およびプログラム |
| CN117043770A (zh) * | 2021-03-19 | 2023-11-10 | 日本电信电话株式会社 | 通信业务传感器、分析方法以及分析程序 |
| JP7593491B2 (ja) * | 2021-05-28 | 2024-12-03 | 日本電信電話株式会社 | 検知装置、検知方法および検知プログラム |
| JP7812607B2 (ja) * | 2023-02-21 | 2026-02-10 | Kddi株式会社 | ネットワークのデータ変化検知装置、方法及びプログラム |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2004312064A (ja) | 2003-02-21 | 2004-11-04 | Intelligent Cosmos Research Institute | ネットワーク異常検出装置、ネットワーク異常検出方法およびネットワーク異常検出プログラム |
| JP2015162032A (ja) * | 2014-02-27 | 2015-09-07 | 株式会社日立製作所 | 移動体の診断装置 |
| US20180007084A1 (en) * | 2016-06-29 | 2018-01-04 | Cisco Technology, Inc. | Automatic retraining of machine learning models to detect ddos attacks |
| US20180032903A1 (en) * | 2016-07-28 | 2018-02-01 | International Business Machines Corporation | Optimized re-training for analytic models |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030101260A1 (en) * | 2001-11-29 | 2003-05-29 | International Business Machines Corporation | Method, computer program element and system for processing alarms triggered by a monitoring system |
| US7225343B1 (en) * | 2002-01-25 | 2007-05-29 | The Trustees Of Columbia University In The City Of New York | System and methods for adaptive model generation for detecting intrusions in computer systems |
| JP5531064B2 (ja) * | 2012-08-10 | 2014-06-25 | エヌ・ティ・ティ・コミュニケーションズ株式会社 | 通信装置、通信システム、通信方法、および、通信プログラム |
| KR102063681B1 (ko) * | 2013-03-11 | 2020-01-08 | 삼성전자주식회사 | 컨텐츠 중심 네트워크에서 컨텐츠 폐기 리스트를 이용하여 유효하지 않은 컨텐츠를 삭제하는 관리 노드, 요청 노드 및 일반 노드의 통신 방법 |
| US9202052B1 (en) * | 2013-06-21 | 2015-12-01 | Emc Corporation | Dynamic graph anomaly detection framework and scalable system architecture |
| US9189623B1 (en) * | 2013-07-31 | 2015-11-17 | Emc Corporation | Historical behavior baseline modeling and anomaly detection in machine generated end to end event log |
| US10397261B2 (en) * | 2014-10-14 | 2019-08-27 | Nippon Telegraph And Telephone Corporation | Identifying device, identifying method and identifying program |
| US9699205B2 (en) * | 2015-08-31 | 2017-07-04 | Splunk Inc. | Network security system |
| US10768628B2 (en) * | 2017-12-12 | 2020-09-08 | Uatc, Llc | Systems and methods for object detection at various ranges using multiple range imagery |
| WO2019210484A1 (en) * | 2018-05-03 | 2019-11-07 | Siemens Aktiengesellschaft | Analysis device, method and system for operational technology system and storage medium |
| JP6984551B2 (ja) | 2018-06-27 | 2021-12-22 | 日本電信電話株式会社 | 異常検知装置、および、異常検知方法 |
-
2018
- 2018-06-27 JP JP2018121953A patent/JP6984551B2/ja active Active
-
2019
- 2019-06-24 WO PCT/JP2019/024928 patent/WO2020004315A1/ja not_active Ceased
- 2019-06-24 EP EP19827096.9A patent/EP3796196B1/en active Active
- 2019-06-24 CN CN201980042316.8A patent/CN112437920B/zh active Active
- 2019-06-24 US US17/255,897 patent/US12206689B2/en active Active
- 2019-06-24 AU AU2019293409A patent/AU2019293409B2/en active Active
-
2023
- 2023-07-14 US US18/222,340 patent/US12244623B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2004312064A (ja) | 2003-02-21 | 2004-11-04 | Intelligent Cosmos Research Institute | ネットワーク異常検出装置、ネットワーク異常検出方法およびネットワーク異常検出プログラム |
| JP2015162032A (ja) * | 2014-02-27 | 2015-09-07 | 株式会社日立製作所 | 移動体の診断装置 |
| US20180007084A1 (en) * | 2016-06-29 | 2018-01-04 | Cisco Technology, Inc. | Automatic retraining of machine learning models to detect ddos attacks |
| US20180032903A1 (en) * | 2016-07-28 | 2018-02-01 | International Business Machines Corporation | Optimized re-training for analytic models |
Cited By (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112632030B (zh) * | 2020-12-04 | 2023-04-14 | 贝壳技术有限公司 | 数据异常定位方法及装置 |
| CN112632030A (zh) * | 2020-12-04 | 2021-04-09 | 贝壳技术有限公司 | 数据异常定位方法及装置 |
| EP4270877A4 (en) * | 2020-12-24 | 2024-06-26 | Panasonic Intellectual Property Corporation of America | THRESHOLD VALUE CALCULATION DEVICE, ANOMALY DETECTION DEVICE, THRESHOLD VALUE CALCULATION METHOD AND ANOMALY DETECTION METHOD |
| CN116601922A (zh) * | 2020-12-24 | 2023-08-15 | 松下电器(美国)知识产权公司 | 阈值计算装置、异常检测装置、阈值计算方法及异常检测方法 |
| JP7189397B1 (ja) * | 2021-05-31 | 2022-12-13 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 監視装置、監視システム及び監視方法 |
| JP7253663B2 (ja) | 2021-05-31 | 2023-04-06 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 監視装置、監視システム及び監視方法 |
| JP2023002832A (ja) * | 2021-05-31 | 2023-01-10 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 監視装置、監視システム及び監視方法 |
| WO2022254519A1 (ja) * | 2021-05-31 | 2022-12-08 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 監視装置、監視システムおよび監視方法 |
| WO2022255247A1 (ja) * | 2021-05-31 | 2022-12-08 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 監視装置、監視システム及び監視方法 |
| WO2023188052A1 (ja) * | 2022-03-30 | 2023-10-05 | 三菱電機株式会社 | 学習データ選択装置、学習データ選択方法及び異常検知装置 |
| JPWO2023188052A1 (ja) * | 2022-03-30 | 2023-10-05 | ||
| JP7504318B2 (ja) | 2022-03-30 | 2024-06-21 | 三菱電機株式会社 | 学習データ選択装置、学習データ選択方法及び異常検知装置 |
| EP4307612A1 (en) * | 2022-07-04 | 2024-01-17 | Fujitsu Limited | Detection program, detection apparatus, and detection method |
Also Published As
| Publication number | Publication date |
|---|---|
| EP3796196A1 (en) | 2021-03-24 |
| US12206689B2 (en) | 2025-01-21 |
| JP2020004009A (ja) | 2020-01-09 |
| CN112437920A (zh) | 2021-03-02 |
| EP3796196B1 (en) | 2023-11-08 |
| EP3796196A4 (en) | 2022-03-02 |
| CN112437920B (zh) | 2024-10-01 |
| US12244623B2 (en) | 2025-03-04 |
| JP6984551B2 (ja) | 2021-12-22 |
| US20230362182A1 (en) | 2023-11-09 |
| AU2019293409A1 (en) | 2021-01-21 |
| US20210273964A1 (en) | 2021-09-02 |
| AU2019293409B2 (en) | 2022-05-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12244623B2 (en) | Abnormality sensing device and abnormality sensing method | |
| CN110121876B (zh) | 用于通过使用行为分析检测恶意设备的系统和方法 | |
| JP5972401B2 (ja) | 攻撃分析システム及び連携装置及び攻撃分析連携方法及びプログラム | |
| CN111737081B (zh) | 云服务器监控方法、装置、设备及存储介质 | |
| WO2016208159A1 (ja) | 情報処理装置、情報処理システム、情報処理方法、及び、記憶媒体 | |
| CH716656B1 (it) | Metodo di generazione e archivazione di metadati specifici dell'informatica forense. | |
| CN112352402B (zh) | 生成装置、生成方法和记录介质 | |
| CN111510339A (zh) | 一种工业互联网数据监测方法和装置 | |
| US10296746B2 (en) | Information processing device, filtering system, and filtering method | |
| JPWO2019043804A1 (ja) | ログ分析装置、ログ分析方法及びプログラム | |
| JP6864610B2 (ja) | 特定システム、特定方法及び特定プログラム | |
| JP6676790B2 (ja) | リクエスト制御装置、リクエスト制御方法、および、リクエスト制御プログラム | |
| JP6683655B2 (ja) | 検知装置および検知方法 | |
| JP7184197B2 (ja) | 異常検出装置、異常検出方法および異常検出プログラム | |
| EP2942728A1 (en) | Systems and methods of analyzing a software component | |
| US10754719B2 (en) | Diagnosis device, diagnosis method, and non-volatile recording medium | |
| JP6734228B2 (ja) | 異常検出装置、および、異常検出方法 | |
| JP6760884B2 (ja) | 生成システム、生成方法及び生成プログラム | |
| US20190018959A1 (en) | Diagnosis device, diagnosis method, and non-transitory recording medium | |
| JP4777366B2 (ja) | ワーム対策プログラム、ワーム対策装置、ワーム対策方法 | |
| CN111566643A (zh) | 攻击检测装置、攻击检测方法和攻击检测程序 | |
| WO2026009572A1 (ja) | 情報処理方法、情報処理装置、および、プログラム | |
| CN120675802A (zh) | 自动化恶意样本检测方法、装置、电子设备及存储介质 | |
| CN120639666A (zh) | 一种网络流量的监测方法、装置、设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19827096 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2019827096 Country of ref document: EP Effective date: 20201217 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2019293409 Country of ref document: AU Date of ref document: 20190624 Kind code of ref document: A |