WO2022149265A1 - 抽出装置、抽出方法、および、抽出プログラム - Google Patents

抽出装置、抽出方法、および、抽出プログラム Download PDF

Info

Publication number
WO2022149265A1
WO2022149265A1 PCT/JP2021/000509 JP2021000509W WO2022149265A1 WO 2022149265 A1 WO2022149265 A1 WO 2022149265A1 JP 2021000509 W JP2021000509 W JP 2021000509W WO 2022149265 A1 WO2022149265 A1 WO 2022149265A1
Authority
WO
WIPO (PCT)
Prior art keywords
operator
series
operations
extraction
computer
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2021/000509
Other languages
English (en)
French (fr)
Inventor
楊 鐘本
俊樹 芝原
満昭 秋山
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NTT Inc
Original Assignee
Nippon Telegraph and Telephone Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nippon Telegraph and Telephone Corp filed Critical Nippon Telegraph and Telephone Corp
Priority to PCT/JP2021/000509 priority Critical patent/WO2022149265A1/ja
Priority to JP2022573880A priority patent/JP7517474B2/ja
Priority to US18/271,059 priority patent/US12609948B2/en
Publication of WO2022149265A1 publication Critical patent/WO2022149265A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425—Traffic logging, e.g. anomaly detection
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00—Error detection; Error correction; Monitoring
    • G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00—Error detection; Error correction; Monitoring
    • G06F11/30—Monitoring
    • G06F11/34—Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation ; Recording or statistical evaluation of user activity, e.g. usability assessment
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00—Administration; Management
    • G06Q10/06—Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
    • G06Q10/063—Operations research, analysis or management
    • G06Q10/0631—Resource planning, allocation, distributing or scheduling for enterprises or organisations
    • G06Q10/06312—Adjustment or analysis of established resource schedule, e.g. resource or task levelling, or dynamic rescheduling
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00—Administration; Management
    • G06Q10/06—Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
    • G06Q10/063—Operations research, analysis or management
    • G06Q10/0633—Workflow analysis
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00—Administration; Management
    • G06Q10/10—Office automation; Time management

Definitions

  • the present invention relates to an extraction device, an extraction method, and an extraction program for extracting a series of operations common to a plurality of operators.
  • logs acquired from various devices by human operators are investigated in order to determine whether there is a security breach or network failure.
  • Non-Patent Document 1 a technique for clarifying the investigation procedure
  • RPA Robot Process Automation
  • Non-Patent Document 1 is not general-purpose because it requires the use of an original GUI (Graphical User Interface) operation tool. Further, the technique described in Non-Patent Document 2 merely records the operation of the computer by the individual operator as it is, and does not specify the search procedure shared as tacit knowledge among a plurality of operators.
  • GUI Graphic User Interface
  • the present invention shows the operation of each operator's computer when each operator operates the computer to conduct an investigation from the OS (Operating System) of the computer operated by each operator. It is provided with a collection unit that collects operation logs and an extraction unit that extracts a series of operations common to each operator from the collected operation logs of each operator and outputs the extracted series of operations. It is a feature.
  • FIG. 1 is a diagram showing a configuration example of a system including the extraction device of the first embodiment.
  • FIG. 2 is a diagram illustrating an outline of operation of the extraction device of the first embodiment.
  • FIG. 3 is a diagram showing a configuration example of the extraction device of each embodiment.
  • FIG. 4 is a diagram showing an example of an operation acquired by the collection unit of FIG. 3 and an acquisition target of the operation.
  • FIG. 5 is a diagram illustrating an example of an operation log.
  • FIG. 6 is a flowchart showing an example of the processing procedure of the extraction device of FIG.
  • FIG. 7 is a flowchart showing an example of the process of S2 of FIG.
  • FIG. 8 is a diagram illustrating an operation log abstraction process.
  • FIG. 1 is a diagram showing a configuration example of a system including the extraction device of the first embodiment.
  • FIG. 2 is a diagram illustrating an outline of operation of the extraction device of the first embodiment.
  • FIG. 3 is a diagram showing a configuration example of the extraction
  • FIG. 9 is a diagram illustrating a process of applying the longest substring (LCS) a plurality of times to each operation sequence of operators A, B, and C to obtain a common operation string C.
  • FIG. 10 is a flowchart showing an example of the processing procedure of the extraction device of the second embodiment.
  • FIG. 11 is a diagram illustrating an example of processing of the extraction device of the second embodiment.
  • FIG. 12 is a flowchart showing an example of the processing procedure of the extraction device of the third embodiment.
  • FIG. 13 is a diagram illustrating an example of processing of the extraction device according to the third embodiment.
  • FIG. 14 is a diagram showing a configuration example of a computer that executes an extraction program.
  • the system includes, for example, a log DB that stores logs of security devices and network devices (devices A and B), an operator terminal device that conducts a survey using the logs stored in the log DB, and an extraction device 10. ..
  • the extraction device 10 collects an operation log indicating the operation of the terminal device of each operator at the time of checking the log. Then, the extraction device 10 extracts and outputs a series of operations common to each operator from the collected operation logs of each operator.
  • the collection unit 131 of the extraction device 10 collects the operation logs (operation logs A, B, C) of the terminal devices of the operators A, B, and C at the time of the investigation.
  • the extraction unit 132 of the extraction device 10 abstracts the operations indicated by the collected operation logs of the operators A, B, and C, and creates an operation sequence for each of the operators A, B, and C.
  • the extraction unit 132 extracts a series of operations common to the operation sequences of the operators A, B, and C, respectively.
  • the extraction unit 132 extracts a series of operations common to operators A, B, and C by applying the longest common subsequence to each operation sequence of operators A, B, and C.
  • the extraction device 10 can clarify the operation procedure shared as tacit knowledge among a plurality of operators without using a unique GUI operation tool.
  • the extraction device 10 includes an input / output unit 11, a storage unit 12, and a control unit 13.
  • the input / output unit 11 controls the input / output of various data.
  • the input / output unit 11 accepts the input of the operation log of each operator and outputs the extraction result of a series of operations common to each operator.
  • the storage unit 12 stores information referred to when the control unit 13 executes various processes.
  • the control unit 13 controls the entire extraction device 10.
  • the control unit 13 includes a collection unit 131 and an extraction unit 132.
  • the collection unit 131 collects an operation log indicating the operation of the terminal device of each operator at the time of checking the log.
  • the collecting unit 131 uses the window function of the OS (Operating System) of the operator's terminal device to acquire the minimum particle size operations that can be recognized by humans, such as the operator's click operation and key input.
  • OS Operating System
  • FIG. 4 shows an operation acquired by the collection unit 131, supplementary information on the operation, and an example of the acquisition target by the operation.
  • the collecting unit 131 also acquires an operation of browsing a Web page and switching attention dubs in addition to a click operation and a key input.
  • the collecting unit 131 acquires the information indicated by reference numeral 503 as an operation log from the terminal device.
  • the operator sets the Alert window as the active window, selects the displayed text 1.2.3.4, saves the character string in the clipboard by copying, and activates the Search window.
  • a series of operations such as switching to a window, pasting the text saved in the clipboard, and clicking the submit button are recorded in chronological order.
  • the extraction unit 132 extracts and outputs a series of operations common to each operator from the operation log of each operator collected by the collection unit 131.
  • the extraction unit 132 creates an operation sequence showing a series of operations of each operator from the operation log of each operator. Then, the extraction unit 132 extracts a series of operations common to each operator by applying the longest common subsequence to the operation sequence of each operator.
  • the extraction unit 132 creates an operation sequence 201 showing a series of operations of operators A, B, and C from the operation logs A, B, and C shown in FIG. Then, the extraction unit 132 extracts a series of operations C common to the operators A, B, and C by applying the longest common subsequence to the operation series 201 of the operators A, B, and C.
  • the extraction unit 132 first extracts a series of operations common to the operation sequences of the operators A and B by applying the longest common subsequence to the operation sequence of the operator A and the operation sequence of the operator B. Next, the extraction unit 132 applies the longest common subsequence to the operation sequence of the operators A and B and the operation sequence of the operator C, so that the extraction unit 132 has a series of operations common to the operators A, B, and C. Operation C is extracted.
  • the collection unit 131 of the extraction device 10 collects the operation log of each operator at the time of checking the log of each device from the terminal device of each operator (S1).
  • the extraction unit 132 extracts a series of operations common to each operator based on the operation log collected in S1 (S2).
  • the extraction unit 132 outputs a series of operations extracted in S2 (S3).
  • the extraction unit 132 performs an abstraction process on the operation log collected by the collection unit 131 (S201).
  • the extraction unit 132 erases the time in the operation log, replaces a number with a code representing a number, and replaces a selected character string with a code representing a character string type. To convert to. As a result, for example, the operation log shown on the left side of reference numeral 802 is converted into the operation log shown on the right side.
  • the extraction unit 132 converts the operation log abstracted in S201 into an identifier representing the content of the operation log (S202 in FIG. 7).
  • the extraction unit 132 converts the operation log shown on the left side of reference numeral 803 in FIG. 8 into an identifier shown on the right side.
  • the extraction unit 132 can obtain an operation sequence that abstracts the operation performed by each operator from the operation log of each operator.
  • the extraction unit 132 extracts a series of operations common to each operator by applying the longest substring to the operation sequence of each operator (S203).
  • the extraction unit 132 applies the longest substring (LCS) to the operation sequences of the operators A, B, and C shown in FIG. 9 a plurality of times to obtain the common operation sequence C. Then, the extraction unit 132 sets the common operation sequence C as a series of operations common to the operators A, B, and C.
  • LCS longest substring
  • the extraction device 10 can extract a series of operations for investigation, which was tacit knowledge between operators.
  • the extraction device extracts an operation sequence by n-gram from the operation sequence of each operator, and obtains a commonality between the extracted operation series by n-gram, thereby performing a series of operations common to each operator. May be extracted.
  • the extraction device in this case will be described as the extraction device 10a (see FIG. 3) of the second embodiment.
  • the same configurations as those of the first embodiment are designated by the same reference numerals, and the description thereof will be omitted.
  • the extraction unit 132a extracts the n-gram sequence shown on the left side of reference numeral 112 from the operation sequences of operators A, B, and C shown by reference numeral 111 in FIG. Then, the extraction unit 132a calculates the degree of commonality among the operators A, B, and C of the extracted n-gram series.
  • the extraction unit 132a extracts the n-gram operation sequence whose commonality calculated in S214 is equal to or greater than the threshold value T as a series of operations common to each operator (S215).
  • the extraction unit 132a has a series of operation sequences shown by reference numeral 113 from the operation sequence of n-gram shown by reference numeral 112 in FIG. 11 which are common to operators A, B, and C. Extract as an operation.
  • the extraction device 10a can extract a series of operations for investigation, which was tacit knowledge between operators.
  • the extraction device may create a state transition model showing the state transition of the operation from the operation sequence of each operator, and extract the regular expression of the created state transition model as a series of operations common to each operator.
  • the extraction device in this case will be described as the extraction device 10b (see FIG. 3) of the third embodiment.
  • the same configurations as those of the first embodiment and the second embodiment are designated by the same reference numerals, and the description thereof will be omitted.
  • the extraction unit 132b creates a state transition model showing the transition state of the operation from the operation sequence of each operator (S223).
  • the extraction unit 132b creates a state transition model shown by reference numeral 1302 from the operation sequences of operators A, B, and C shown by reference numeral 1301 in FIG.
  • the extraction unit 132b creates a regular expression from the state transition model created in S223 (S224). Then, the extraction unit 132b uses the regular expression created in S224 as a series of operations common to each operator (S225).
  • the extraction unit 132b extracts the common operation shown by the reference numeral 1303 in the manner of creating a regular expression from the state transition model shown by the reference numeral 1302 in FIG.
  • "*" in the regular expression shown by reference numeral 1302 indicates that anything may be entered.
  • the extraction device 10b can extract a series of operations for investigation, which was tacit knowledge between operators.
  • each component of each of the illustrated parts is a functional concept, and does not necessarily have to be physically configured as shown in the figure. That is, the specific form of distribution / integration of each device is not limited to the one shown in the figure, and all or part of them may be functionally or physically distributed / physically in arbitrary units according to various loads and usage conditions. Can be integrated and configured. Further, each processing function performed by each device may be realized by a CPU and a program executed by the CPU, or may be realized as hardware by wired logic.
  • the extraction devices 10, 10a, and 10b described above can be implemented by installing a program as package software or online software on a desired computer.
  • the information processing device can function as the extraction devices 10, 10a, 10b of each embodiment.
  • the information processing device referred to here includes a desktop type or notebook type personal computer.
  • information processing devices include smartphones, mobile communication terminals such as mobile phones and PHS (Personal Handyphone System), and terminals such as PDAs (Personal Digital Assistants).
  • the extraction devices 10, 10a and 10b can be implemented as a server device in which the terminal device used by the user is a client and the service related to the above processing is provided to the client.
  • the server device may be implemented as a Web server, or may be implemented as a cloud that provides services related to the above processing by outsourcing.
  • FIG. 10 is a diagram showing an example of a computer that executes an extraction program.
  • the computer 1000 has, for example, a memory 1010 and a CPU 1020.
  • the computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. Each of these parts is connected by a bus 1080.
  • the memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012.
  • the ROM 1011 stores, for example, a boot program such as a BIOS (Basic Input Output System).
  • BIOS Basic Input Output System
  • the hard disk drive interface 1030 is connected to the hard disk drive 1090.
  • the disk drive interface 1040 is connected to the disk drive 1100.
  • a removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100.
  • the serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120.
  • the video adapter 1060 is connected to, for example, the display 1130.
  • the hard disk drive 1090 stores, for example, OS1091, application program 1092, program module 1093, and program data 1094. That is, the program that defines each process executed by the extraction devices 10, 10a, and 10b is implemented as a program module 1093 in which a code that can be executed by a computer is described.
  • the program module 1093 is stored in, for example, the hard disk drive 1090.
  • the program module 1093 for executing the same processing as the functional configuration in the extraction devices 10, 10a, 10b is stored in the hard disk drive 1090.
  • the hard disk drive 1090 may be replaced by an SSD.
  • each data used in the processing of the above-described embodiment is stored as program data 1094 in, for example, a memory 1010 or a hard disk drive 1090. Then, the CPU 1020 reads the program module 1093 and the program data 1094 stored in the memory 1010 and the hard disk drive 1090 into the RAM 1012 and executes them as needed.
  • the program module 1093 and the program data 1094 are not limited to those stored in the hard disk drive 1090, but may be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and the program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). Then, the program module 1093 and the program data 1094 may be read from another computer by the CPU 1020 via the network interface 1070.
  • LAN Local Area Network
  • WAN Wide Area Network

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Human Resources & Organizations (AREA)
  • Theoretical Computer Science (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Strategic Management (AREA)
  • Economics (AREA)
  • Quality & Reliability (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Business, Economics & Management (AREA)
  • Marketing (AREA)
  • Operations Research (AREA)
  • Tourism & Hospitality (AREA)
  • Computer Hardware Design (AREA)
  • Game Theory and Decision Science (AREA)
  • Educational Administration (AREA)
  • Development Economics (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Mining & Analysis (AREA)
  • Debugging And Monitoring (AREA)

Abstract

抽出装置は、収集部(131)および抽出部(132)を備える。収集部(131)は、各オペレータが操作するコンピュータのOS(Operating System)から、各オペレータがコンピュータを操作して調査を行う際における、各オペレータのコンピュータの操作を示す操作ログを収集する。抽出部(132)は、収集された各オペレータの操作ログから、各オペレータに共通する一連の操作を抽出し、抽出した一連の操作を出力する。例えば、抽出部(132)は、オペレータそれぞれの一連の操作を示す操作系列に対し、最長共通部分列を適用することにより、各オペレータに共通する一連の操作を抽出する。

Description

抽出装置、抽出方法、および、抽出プログラム
 本発明は、複数のオペレータに共通する一連の操作を抽出する、抽出装置、抽出方法、および、抽出プログラムに関する。
 セキュリティやネットワークのオペレーションでは、セキュリティ侵害やネットワーク障害があるか否かの判断を行うため、オペレータである人間が様々な機器から取得したログを調査することが行われている。
 これらの調査には、明確な手順が示されているものもあれば、明確な手順が示されていないものもある。つまり、オペレータが行う調査手順の中には、暗黙知として存在するものもある。チームや複数名のオペレータが調査を行う際の全体的な効率性を考えると、調査手順は明示化されることが望ましい。そのため、暗黙知として存在する調査手順についても明示化されることが望ましい。
 ここで、調査手順を明示化する技術として、オペレータがコンピュータを用いて調査を行う際にコンピュータの操作のログ(操作ログ)を記録し、記録された操作ログに基づき、オペレータが調査を行う際の行動モデルを作成する技術(非特許文献1参照)がある。また、オペレータによるコンピュータの操作をそのまま記録するRPA(Robotic Process Automation)技術(非特許文献2参照)がある。
Zhong, Chen, et al., "Learning from Experts’ Experience: Towards Automated Cyber Security Data Triage", IEEE 2nd International Conference on Big Data Security on Cloud (BigDataSecurity) 2016. RPA(ロボティック・プロセス・オートメーション)とは?基本から導入の進め方までまとめて解説、[online]、[2020年12月9日検索],インターネット <URL:https://winactor.com/column/about_rpa>
 しかし、非特許文献1に記載の技術は、独自のGUI(Graphical User Interface)操作ツールを用いる必要があるため、汎用的ではない。また、非特許文献2に記載の技術は、オペレータ個人によるコンピュータの操作をそのまま記録するものに過ぎず、複数のオペレータ間に暗黙知として共有される調査手順を明示化するものではない。
 そこで、本発明は、前記した問題を解決し、独自のGUI操作ツールを用いることなく、複数のオペレータ間に暗黙知として共有される調査手順を明示化することを課題とする。
 前記した課題を解決するため、本発明は、各オペレータが操作するコンピュータのOS(Operating System)から、前記各オペレータがコンピュータを操作して調査を行う際における、前記各オペレータのコンピュータの操作を示す操作ログを収集する収集部と、 収集された前記各オペレータの操作ログから、前記各オペレータに共通する一連の操作を抽出し、前記抽出した一連の操作を出力する抽出部と、を備えることを特徴とする。
 本発明によれば、独自のGUI操作ツールを用いることなく、複数のオペレータ間に暗黙知として共有される手順を明示化することできる。
図1は、第1の実施形態の抽出装置を含むシステムの構成例を示す図である。 図2は、第1の実施形態の抽出装置の動作概要を説明する図である。 図3は、各実施形態の抽出装置の構成例を示す図である。 図4は、図3の収集部が取得する操作および当該操作の取得対象の例を示す図である。 図5は、操作ログの例を説明する図である。 図6は、図3の抽出装置の処理手順の例を示すフローチャートである。 図7は、図6のS2の処理の例を示すフローチャートである。 図8は、操作ログの抽象化処理を説明する図である。 図9は、オペレータA,B,Cそれぞれの操作系列に対して、最長部分文字列(LCS)を複数回適用して、共通操作列Cを求める処理を説明する図である。 図10は、第2の実施形態の抽出装置の処理手順の例を示すフローチャートである。 図11は、第2の実施形態の抽出装置の処理の例を説明する図である。 図12は、第3の実施形態の抽出装置の処理手順の例を示すフローチャートである。 図13は、第3の実施形態の抽出装置の処理の例を説明する図である。 図14は、抽出プログラムを実行するコンピュータの構成例を示す図である。
 以下、図面を参照しながら、本発明を実施するための形態(実施形態)を第1の実施形態から第3の実施形態に分けて説明する。本発明は、各実施形態に限定されない。
[第1の実施形態]
 まず、図1を用いて第1の実施形態の抽出装置を含むシステムの構成例を説明する。システムは、例えば、セキュリティ機器やネットワーク機器(機器A,B)のログを蓄積するログDBと、ログDBに蓄積されたログを用いて調査を行うオペレータの端末装置と、抽出装置10とを備える。
 抽出装置10は、ログの調査時における各オペレータの端末装置の操作を示す操作ログを収集する。そして、抽出装置10は、収集した各オペレータの操作ログから、各オペレータに共通する一連の操作を抽出し、出力する。
 例えば、図2に示すように、抽出装置10の収集部131は、調査時におけるオペレータA,B,Cの端末装置の操作ログ(操作ログA,B,C)を収集する。その後、抽出装置10の抽出部132は、収集されたオペレータA,B,Cそれぞれの操作ログの示す操作を抽象化し、オペレータA,B,Cそれぞれ操作系列を作成する。そして、抽出部132は、オペレータA,B,Cそれぞれの操作系列に共通する一連の操作を抽出する。例えば、抽出部132は、オペレータA,B,Cそれぞれの操作系列に最長共通部分列を適用することにより、オペレータA,B,Cに共通する一連の操作を抽出する。
 これにより抽出装置10は、独自のGUI操作ツールを用いることなく、複数のオペレータ間に暗黙知として共有される操作手順を明示化することできる。
 次に、図3を用いて、抽出装置10の構成例を説明する。なお、抽出装置10a、抽出部132aについては、第2の実施形態で説明する。また、抽出装置10b、抽出部132bについては、第3の実施形態で説明する。
 抽出装置10は、入出力部11と、記憶部12と、制御部13とを備える。入出力部11は、各種データの入出力を司る。例えば、入出力部11は、各オペレータの操作ログの入力を受け付けたり、各オペレータに共通する一連の操作の抽出結果を出力したりする。記憶部12は、制御部13が各種処理を実行する際に参照する情報を記憶する。
 制御部13は、抽出装置10全体の制御を司る。制御部13は、収集部131と、抽出部132とを備える。収集部131は、ログの調査時における各オペレータの端末装置の操作を示す操作ログを収集する。
 例えば、収集部131は、オペレータの端末装置のOS(Operating System)のウインドウ機能を利用して、オペレータのクリック操作やキー入力等、人間が認識することができる最小の粒度の操作を取得する。
 収集部131が取得する操作、操作の補足情報、当該操作による取得対象の例を図4に示す。なお、操作がWebブラウザ(browser)に対する操作である場合、収集部131は、クリック操作やキー入力以外に、Webページの閲覧や注目ダブ切り替えの操作も取得する。
 例えば、オペレータの端末装置において、図5に示す符号501に示すAlert windowと符号502に示すSearch windowとが起動している場合を考える。この場合、収集部131は、当該端末装置から操作ログとして符号503に示す情報を取得する。
 この符号503に示す操作ログには、オペレータが、端末装置において、Alert windowをアクティブウインドウとし、表示されているテキスト1.2.3.4を選択し、コピーで文字列をクリップボードに保存し、Search windowをアクティブウインドウに切り替え、クリップボードに保存されたテキストをペーストし、submitボタンをクリックした、という一連の操作が時系列に記録されている。
 図2の説明に戻る。抽出部132は、収集部131により収集された各オペレータの操作ログから、各オペレータに共通する一連の操作を抽出し、出力する。
 例えば、抽出部132は、各オペレータの操作ログから、各オペレータの一連の操作を示す操作系列を作成する。そして、抽出部132は、各オペレータの操作系列に対し、最長共通部分列を適用することにより、各オペレータに共通する一連の操作を抽出する。
 例えば、抽出部132は、図2に示す操作ログA,B,Cから、オペレータA,B,Cの一連の操作を示す操作系列201を作成する。そして、抽出部132は、オペレータA,B,Cの操作系列201に対し、最長共通部分列を適用することにより、オペレータA,B,Cに共通する一連の操作Cを抽出する。
 例えば、抽出部132は、まず、オペレータAの操作系列とオペレータBの操作系列に対し、最長共通部分列を適用することにより、オペレータA,Bの操作系列に共通する一連の操作を抽出する。次に、抽出部132は、オペレータA,Bの操作系列に共通する一連の操作と、オペレータCの操作系列とに最長共通部分列を適用することにより、オペレータA,B,Cに共通する一連の操作Cを抽出する。
[処理手順の例]
 次に、図6を用いて、抽出装置10の処理手順の例を説明する。例えば、抽出装置10の収集部131は、各オペレータの端末装置から、各機器のログの調査時における各オペレータの操作ログを収集する(S1)。次に、抽出部132は、S1で収集された操作ログに基づき、各オペレータに共通する一連の操作を抽出する(S2)。そして、抽出部132はS2で抽出した一連の操作を出力する(S3)。
 次に、図7を用いて、図6のS2の処理を詳細に説明する。まず、抽出部132は、収集部131により収取された操作ログに対して、抽象化処理を行う(S201)。
 例えば、抽出部132は、図8の符号801に示すように、操作ログにおける時刻を消去したり、数字を、数字を表す符号に置換したり、選択文字列を、文字列の型を表す符号に変換したりする。これにより、例えば、符号802の左側に示す操作ログは右側に示す操作ログに変換される。
 図7のS201の後、抽出部132は、S201で抽象化された操作ログを、その操作ログの内容を表す識別子に変換する(図7のS202)。
 例えば、抽出部132は、図8の符号803の左側に示す操作ログを、右側に示す識別子に変換する。
 以上の処理により、抽出部132は、各オペレータの操作ログから、各オペレータの行った操作を抽象化した操作系列を得ることができる。
 図7のS202の後、抽出部132は、各オペレータの操作系列に対し、最長部分文字列を適用することにより、各オペレータに共通する一連の操作を抽出する(S203)。
 例えば、抽出部132は、図9に示す、オペレータA,B,Cそれぞれの操作系列に対して、最長部分文字列(LCS)を複数回適用して、共通操作列Cを求める。そして、抽出部132は、共通操作列CをオペレータA,B,Cに共通する一連の操作とする。
 このようにすることで抽出装置10は、オペレータ間での暗黙知であった、調査のための一連の操作を抽出することができる。
[第2の実施形態]
 また、抽出装置は、各オペレータの操作系列から、n-gramずつ操作系列を抽出し、抽出したn-gramずつの操作系列間での共通度を求めることにより、各オペレータに共通する一連の操作を抽出してもよい。この場合の抽出装置を第2の実施形態の抽出装置10a(図3参照)として説明する。第1の実施形態と同じ構成は同じ符号を付して、説明を省略する。
 図10を用いて、図3に示す抽出装置10aにおける抽出部132aの処理手順の例を説明する。図10のS211、S212の処理は、図7のS201、S202の処理と同様なので説明を省略し、図10のS213から説明する。
 S212の後、抽出部132aは、各オペレータの操作系列からn-gramずつ操作系列を抽出する(S213)。そして、抽出部132aは、各オペレータ間でのn-gramの操作系列の共通度を算出する(S214)。抽出部132は、上記のS213、S214の処理をn=[a,b]で繰り返す。
 例えば、n=[3,3]の場合、抽出部132aは、図11の符号111に示すオペレータA,B,Cの操作系列から、符号112の左側に示すn-gram系列を抽出する。そして、抽出部132aは、抽出したn-gram系列のオペレータA,B,C間での共通度を算出する。
 図10のS214の後、抽出部132aは、S214で算出した共通度が閾値T以上のn-gramの操作系列を、各オペレータに共通する一連の操作として抽出する(S215)。
 例えば、閾値T=1.0とした場合、抽出部132aは、図11の符号112に示すn-gramの操作系列から、符号113に示す操作系列をオペレータA,B,Cに共通する一連の操作として抽出する。
 このようにすることでも抽出装置10aは、オペレータ間での暗黙知であった、調査のための一連の操作を抽出することができる。
[第3の実施形態]
 また、抽出装置は、各オペレータの操作系列から、操作の状態遷移を示す状態遷移モデルを作成し、作成した状態遷移モデルの正規表現を各オペレータに共通する一連の操作として抽出してもよい。この場合の抽出装置を第3の実施形態の抽出装置10b(図3参照)として説明する。第1の実施形態、第2の実施形態と同じ構成は同じ符号を付して、説明を省略する。
 図12を用いて、図3に示す抽出装置10bにおける抽出部132bの処理手順の例を説明する。図12のS221、S222の処理は、図7のS201、S202の処理と同様なので説明を省略し、図12のS223から説明する。
 図12のS222の後、抽出部132bは、各オペレータの操作系列から、操作の遷移状態を示す状態遷移モデルを作成する(S223)。
 例えば、抽出部132bは、図13の符号1301に示すオペレータA,B,Cの操作系列から、符号1302に示す状態遷移モデルを作成する。
 図12のS223の後、抽出部132bは、S223で作成した状態遷移モデルから正規表現を作成する(S224)。そして、抽出部132bは、S224で作成した正規表現を、各オペレータに共通する一連の操作とする(S225)。
 例えば、抽出部132bは、図13の符号1302に示す状態遷移モデルから正規表現を作成する要領で、符号1303に示す共通操作を抽出する。なお、符号1302に示す正規表現における「*」は、何が入ってもよいことを表す。
 このようにすることでも抽出装置10bは、オペレータ間での暗黙知であった、調査のための一連の操作を抽出することができる。
[システム構成等]
 また、図示した各部の各構成要素は機能概念的なものであり、必ずしも物理的に図示のように構成されていることを要しない。すなわち、各装置の分散・統合の具体的形態は図示のものに限られず、その全部又は一部を、各種の負荷や使用状況等に応じて、任意の単位で機能的又は物理的に分散・統合して構成することができる。さらに、各装置にて行われる各処理機能は、その全部又は任意の一部が、CPU及び当該CPUにて実行されるプログラムにて実現され、あるいは、ワイヤードロジックによるハードウェアとして実現され得る。
 また、前記した実施形態において説明した処理のうち、自動的に行われるものとして説明した処理の全部又は一部を手動的に行うこともでき、あるいは、手動的に行われるものとして説明した処理の全部又は一部を公知の方法で自動的に行うこともできる。この他、上記文書中や図面中で示した処理手順、制御手順、具体的名称、各種のデータやパラメータを含む情報については、特記する場合を除いて任意に変更することができる。
[プログラム]
 前記した抽出装置10,10a,10bは、パッケージソフトウェアやオンラインソフトウェアとしてプログラムを所望のコンピュータにインストールさせることによって実装できる。例えば、上記のプログラムを情報処理装置に実行させることにより、情報処理装置を各実施形態の抽出装置10,10a,10bとして機能させることができる。ここで言う情報処理装置には、デスクトップ型又はノート型のパーソナルコンピュータが含まれる。また、その他にも、情報処理装置にはスマートフォン、携帯電話機やPHS(Personal Handyphone System)等の移動体通信端末、さらには、PDA(Personal Digital Assistant)等の端末等がその範疇に含まれる。
 また、抽出装置10,10a,10bは、ユーザが使用する端末装置をクライアントとし、当該クライアントに上記の処理に関するサービスを提供するサーバ装置として実装することもできる。この場合、サーバ装置は、Webサーバとして実装することとしてもよいし、アウトソーシングによって上記の処理に関するサービスを提供するクラウドとして実装することとしてもかまわない。
 図10は、抽出プログラムを実行するコンピュータの一例を示す図である。コンピュータ1000は、例えば、メモリ1010、CPU1020を有する。また、コンピュータ1000は、ハードディスクドライブインタフェース1030、ディスクドライブインタフェース1040、シリアルポートインタフェース1050、ビデオアダプタ1060、ネットワークインタフェース1070を有する。これらの各部は、バス1080によって接続される。
 メモリ1010は、ROM(Read Only Memory)1011及びRAM(Random Access Memory)1012を含む。ROM1011は、例えば、BIOS(Basic Input Output System)等のブートプログラムを記憶する。ハードディスクドライブインタフェース1030は、ハードディスクドライブ1090に接続される。ディスクドライブインタフェース1040は、ディスクドライブ1100に接続される。例えば磁気ディスクや光ディスク等の着脱可能な記憶媒体が、ディスクドライブ1100に挿入される。シリアルポートインタフェース1050は、例えばマウス1110、キーボード1120に接続される。ビデオアダプタ1060は、例えばディスプレイ1130に接続される。
 ハードディスクドライブ1090は、例えば、OS1091、アプリケーションプログラム1092、プログラムモジュール1093、プログラムデータ1094を記憶する。すなわち、上記の抽出装置10,10a,10bが実行する各処理を規定するプログラムは、コンピュータにより実行可能なコードが記述されたプログラムモジュール1093として実装される。プログラムモジュール1093は、例えばハードディスクドライブ1090に記憶される。例えば、抽出装置10,10a,10bにおける機能構成と同様の処理を実行するためのプログラムモジュール1093が、ハードディスクドライブ1090に記憶される。なお、ハードディスクドライブ1090は、SSDにより代替されてもよい。
 また、上述した実施形態の処理で用いられる各データは、プログラムデータ1094として、例えばメモリ1010やハードディスクドライブ1090に記憶される。そして、CPU1020が、メモリ1010やハードディスクドライブ1090に記憶されたプログラムモジュール1093やプログラムデータ1094を必要に応じてRAM1012に読み出して実行する。
 なお、プログラムモジュール1093やプログラムデータ1094は、ハードディスクドライブ1090に記憶される場合に限らず、例えば着脱可能な記憶媒体に記憶され、ディスクドライブ1100等を介してCPU1020によって読み出されてもよい。あるいは、プログラムモジュール1093及びプログラムデータ1094は、ネットワされたーク(LAN(Local Area Network)、WAN(Wide Area Network)等)を介して接続他のコンピュータに記憶されてもよい。そして、プログラムモジュール1093及びプログラムデータ1094は、他のコンピュータから、ネットワークインタフェース1070を介してCPU1020によって読み出されてもよい。
10,10a,10b 抽出装置
11 入出力部
12 記憶部
13 制御部
131 収集部
132 抽出部

Claims (6)

  1.  各オペレータが操作するコンピュータのOS(Operating System)から、前記各オペレータがコンピュータを操作して調査を行う際における、前記各オペレータのコンピュータの操作を示す操作ログを収集する収集部と、
     収集された前記各オペレータの操作ログから、前記各オペレータに共通する一連の操作を抽出し、前記抽出した一連の操作を出力する抽出部と、
     を備えることを特徴とする抽出装置。
  2.  前記抽出部は、
     前記オペレータそれぞれの一連の操作を示す操作系列に対し、最長共通部分列を適用することにより、前記各オペレータに共通する一連の操作を抽出する
     ことを特徴とする請求項1に記載の抽出装置。
  3.  前記抽出部は、
     前記オペレータそれぞれの一連の操作を示す操作系列から、n-gramずつ操作系列を抽出し、抽出したn-gramの操作系列について前記各オペレータ間での共通度が所定の閾値以上のn-gramの操作系列を、前記各オペレータに共通する一連の操作として抽出する
     ことを特徴とする請求項1に記載の抽出装置。
  4.  前記抽出部は、
     前記オペレータそれぞれの一連の操作を示す操作系列から、前記操作の状態遷移を示す状態遷移モデルを作成し、作成した状態遷移モデルから作成した正規表現を前記各オペレータに共通する一連の操作とする
     ことを特徴とする請求項1に記載の抽出装置。
  5.  抽出装置により実行される抽出方法であって、
     各オペレータが操作するコンピュータのOS(Operating System)から、前記各オペレータがコンピュータを操作して調査を行う際における、前記各オペレータのコンピュータの操作を示す操作ログを収集する工程と、
     収集された前記各オペレータの操作ログから、前記各オペレータに共通する一連の操作を抽出し、前記抽出した一連の操作を出力する工程と、
     を含むことを特徴とする抽出方法。
  6.  各オペレータが操作するコンピュータのOS(Operating System)から、前記各オペレータがコンピュータを操作して調査を行う際における、前記各オペレータのコンピュータの操作を示す操作ログを収集する工程と、
     収集された前記各オペレータの操作ログから、前記各オペレータに共通する一連の操作を抽出し、前記抽出した一連の操作を出力する工程と、
     をコンピュータに実行させることを特徴とする抽出プログラム。
PCT/JP2021/000509 2021-01-08 2021-01-08 抽出装置、抽出方法、および、抽出プログラム Ceased WO2022149265A1 (ja)

Priority Applications (3)

Application Number Priority Date Filing Date Title
PCT/JP2021/000509 WO2022149265A1 (ja) 2021-01-08 2021-01-08 抽出装置、抽出方法、および、抽出プログラム
JP2022573880A JP7517474B2 (ja) 2021-01-08 2021-01-08 抽出装置、抽出方法、および、抽出プログラム
US18/271,059 US12609948B2 (en) 2021-01-08 2021-01-08 Extracting device, extracting method, and extracting program

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2021/000509 WO2022149265A1 (ja) 2021-01-08 2021-01-08 抽出装置、抽出方法、および、抽出プログラム

Publications (1)

Publication Number Publication Date
WO2022149265A1 true WO2022149265A1 (ja) 2022-07-14

Family

ID=82357850

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2021/000509 Ceased WO2022149265A1 (ja) 2021-01-08 2021-01-08 抽出装置、抽出方法、および、抽出プログラム

Country Status (3)

Country Link
US (1) US12609948B2 (ja)
JP (1) JP7517474B2 (ja)
WO (1) WO2022149265A1 (ja)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006259891A (ja) * 2005-03-15 2006-09-28 Nec Corp システム運用管理支援装置、システム運用管理支援方法、およびシステム運用管理支援プログラム
JP2013054000A (ja) * 2011-09-06 2013-03-21 Clarion Co Ltd ナビゲーション装置、ヘルプ情報表示方法
US20190057148A1 (en) * 2015-10-21 2019-02-21 Beijing Hansight Tech Co., Ltd. Method and equipment for determining common subsequence of text strings

Family Cites Families (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7974849B1 (en) * 2002-08-12 2011-07-05 Oracle America, Inc. Detecting and modeling temporal computer activity patterns
US20080148398A1 (en) * 2006-10-31 2008-06-19 Derek John Mezack System and Method for Definition and Automated Analysis of Computer Security Threat Models
CA2776434A1 (en) * 2011-07-01 2013-01-01 Certusview Technologies, Llc Methods, apparatus and systems for chronicling the activities of field technicians
US8803884B2 (en) * 2012-02-24 2014-08-12 Florida Institute for Human and Machine Cognition Event data visualization tool
US9921136B2 (en) * 2014-08-05 2018-03-20 01dB-Metravib, Societe Par Actions Simplifee Wireless collection and analysis of machine data
KR101685495B1 (ko) * 2014-12-03 2016-12-28 한국과학기술연구원 이종 센서 매시업 방법, 이를 수행하기 위한 기록 매체 및 장치
US20160292373A1 (en) * 2015-04-06 2016-10-06 Preventice, Inc. Adaptive user interface based on health monitoring event
WO2018226888A1 (en) * 2017-06-06 2018-12-13 Diffeo, Inc. Knowledge operating system
US11627193B2 (en) * 2017-12-07 2023-04-11 Oracle International Corporation Method and system for tracking application activity data from remote devices and generating a corrective action data structure for the remote devices
US11783084B2 (en) * 2021-06-18 2023-10-10 Microsoft Technology Licensing, Llc Sampling of telemetry events to control event volume cost and address privacy vulnerability
US12237089B2 (en) * 2021-12-23 2025-02-25 GE Precision Healthcare LLC Online monitoring of clinical data drifts

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006259891A (ja) * 2005-03-15 2006-09-28 Nec Corp システム運用管理支援装置、システム運用管理支援方法、およびシステム運用管理支援プログラム
JP2013054000A (ja) * 2011-09-06 2013-03-21 Clarion Co Ltd ナビゲーション装置、ヘルプ情報表示方法
US20190057148A1 (en) * 2015-10-21 2019-02-21 Beijing Hansight Tech Co., Ltd. Method and equipment for determining common subsequence of text strings

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
WATANABE, AKIO ET AL.: "Multiple isolating actions extraction from action logs for clarifying trouble-shooting process", IEICE TECHNICAL REPORT, vol. 116, no. 124 (ICM2016-13), 30 June 2016 (2016-06-30), JP , pages 27 - 32, XP009538980, ISSN: 0913-5685 *

Also Published As

Publication number Publication date
US12609948B2 (en) 2026-04-21
JP7517474B2 (ja) 2024-07-17
JPWO2022149265A1 (ja) 2022-07-14
US20240305656A1 (en) 2024-09-12

Similar Documents

Publication Publication Date Title
JP7641752B2 (ja) Cti分析支援システム、cti分析支援方法
CN115080039A (zh) 前端代码生成方法、装置、计算机设备、存储介质和产品
CN112269666B (zh) 小程序死链检测方法及设备、计算设备和介质
CN108647224A (zh) 页面显示方法、装置、存储介质和电子装置
CN117591624A (zh) 一种基于语义索引关系的测试用例推荐方法
CN108985052A (zh) 一种恶意程序识别方法、装置和存储介质
CN111831536B (zh) 一种自动化测试方法和装置
KR102914318B1 (ko) 개인에게 최적화된 정책을 추천하는 방법 및 장치
CN116150766A (zh) 设备漏洞的修复方法及装置
CN111291288A (zh) 网页链接抽取方法及系统
JP7517474B2 (ja) 抽出装置、抽出方法、および、抽出プログラム
CN112597377A (zh) 信息提取模块生成方法、信息提取方法及装置
WO2020209227A1 (ja) 解析装置、解析方法、及びプログラム
CN113179183B (zh) 服务开关状态控制装置及方法
KR102855416B1 (ko) 자연어 처리된 정책 데이터를 기초로 기업에게 정책을 추천하기 위한 태깅 과정 수행 방법 및 장치
JP7127601B2 (ja) 類似遷移特定装置、類似遷移特定方法及びプログラム
WO2021205589A1 (ja) テストスクリプト生成装置、テストスクリプト生成方法及びプログラム
CN117033410A (zh) 一种数据的血缘关系的管理方法和系统
US20190095538A1 (en) Method and system for generating content from search results rendered by a search engine
CN114611039A (zh) 异步加载规则的解析方法、装置、存储介质和电子设备
US12566658B1 (en) System and method for root cause analysis using tree structure analysis
JP7509318B2 (ja) 抽出装置、抽出方法、および、抽出プログラム
JP7691482B1 (ja) 情報提供装置、情報提供方法及び情報提供プログラム
WO2024228293A1 (ja) 分析装置、分析方法及び分析プログラム
HK40088383A (zh) 应用程序的病毒检测方法、装置、设备、介质及程序产品

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21917491

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022573880

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 18271059

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21917491

Country of ref document: EP

Kind code of ref document: A1

WWG Wipo information: grant in national office

Ref document number: 18271059

Country of ref document: US