Sign In to Follow Application
View All Documents & Correspondence

Information Processing Device And Monitoring Method

Abstract: The present invention provides an information processing device that outputs information including the data transmission relationship between elements constituting an information processing system said information indicating the state of the information processing system. The information processing device comprises a graphing means for generating a relationship graph on the basis of an event log indicating the behavior of each of a plurality of processes operating in the system said relationship graph having said processes as the vertices thereof and having the data transmission relationship between said vertices as the sides thereof; and a graph output means for outputting the generated relationship graph.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
29 August 2016
Publication Number
03/2017
Publication Type
INA
Invention Field
COMPUTER SCIENCE
Status
Email
Parent Application

Applicants

NEC CORPORATION
7 1Shiba 5 chome Minato ku Tokyo 1088001

Inventors

1. NOMURA Takashi
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
2. KIDA Koji
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
3. KAMIMURA Junpei
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
4. SAKAE Yoshiaki
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
5. KATSUDA Etsuko
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
6. ISOYAMA Kazuhiko
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
7. YAMASAKI Kentaro
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001
8. KOBAYASHI Yuji
c/o NEC CORPORATION 7 1Shiba 5 chome Minato ku Tokyo 1088001

Specification

[Document Name] DESCRIPTION
[Ti t le of Invent ion] INFORMATION PROCESSING DEVICE AND
MONITORING METHOD
[Technical Field]
[5 0001]
The present invent ion relates to a technique for moni toring an
informat ion processing system equipped wi th, for example, a computer , a
server , a storage system, a communicat ion control system, a terminal , or
the l ike.
10 [Background Art]
[0002]
Various related-art techniques are known to moni tor informat ion
processing systems.
[0003]
15 For example, PTL 1 discloses a process moni toring device. The
process moni toring device disclosed in PTL 1 operates in the fol lowing
way.
[0004]
Fi rst , the process moni toring device extracts an at tent ion- requiring
20 process based on stat ic at t ributes for the process. Examples of the stat ic
at t ributes include a process name, a manufacturer 's name of a program for
implement ing the process, the program (software) name, a version, a name
of a parent process that act ivates the process, and a process size. The
process moni toring devi ce extracts a relevant process as the
25 at tent ion-requiring process in any of the fol lowing four cases : first , cur rent
stat ic at t ributes are different f rom past stat ic at t ributes; second, the past
stat ic at t ributes are unavai lable; thi rd, a parent process is unident i fiable;
and fourth, an external process serves as the parent process.
[0005]
3
Second, the process moni toring device issues an alarm for the
at tent ion-requiring process based on the dynamic at t ributes. Examples of
the dynamic at tributes include the number of dynamic dedicat ed memory
bytes, the number of dynamic shared memory bytes, redi rector sending, the
recept ion traffic rate, and the hard disk access rate. When the pas5 t
dynamic at t ributes may be discriminated f rom the current dynamic
at t ributes by using any stat ist ical method, the process moni tor ing device,
for example, generates an alarm for the relevant at tent ion- requiring
process or registers it as a process to be moni tored.
10 [0006]
Thi rd, the process moni toring device extracts an associated process
having a predetermined relevance to the at tent ion-requi ring process and
determines the associated process as a process to be moni tored.
Examples of the process having the predetermined relevance include a
15 process having a specif ic parent -chi ld relat ion, and a process always
act ivated when the process to be moni tored operates, al though not having a
speci fic parent -chi ld relat ion.
[Ci tat ion List]
[Patent Li terature]
20 [0007]
[PTL 1] Japanese Unexamined Patent Appl icat ion Publ icat ion No.
2008-021274
[Summary of Invent ion]
[Technical Problem]
25 [0008]
However, in the above-described technique disclosed in Ci tat ion
List , there is a problem such that i t is di fficul t to output informat ion which
indicates the state of the informat ion processing system including the data
transmission relat ionship between elements const i tut ing an informat ion
4
processing system.
[0009]
This is because the technique disclosed in PTL 1 is used to
individual ly detect processes respect ively cor responding to an
at tent ion-requiring process, a process to be moni tored, and a process whic5 h
requi res alarm generat ion. In other words, PTL 1 merely describes the
relat ionship between processes in relat ion to the parent -chi ld relat ionship
and act ivat ion synchrony.
[0010]
10 An object of the present invent ion is to provide an informat ion
processing device, a moni toring method, and a program therefor or a
non-transi tory computer- readable recording medium recording the program
which solves the above-ment ioned problem.
[Solut ion to Problem]
15 [0011]
An informat ion processing device according to an aspect of the
present invent ion includes graphing means for generat ing a relat ionship
graph based on an event log indicat ing a behavior of each of a plural i ty of
processes operat ing in a system, the relat ionship graph including the
20 processes as vert ices thereof and including data t ransmission relat ionships
between the vert ices as sides thereof , and graph output means for
output t ing the relat ionship graph.
[0012]
A moni tor ing method according to an aspect of the present
25 invent ion includes generat ing a relat ionship graph based on an event log
indicat ing a behavior of each of a plural i ty of processes operat ing in a
system, the relat ionship graph including the processes as vert ices thereof
and including data t ransmission relat ionships between the ver t ices as sides
thereof, and output t ing the relat ionship graph.
5
[0013]
A non-t ransi tory computer -readable recording medium according to
an aspect of the present invent ion records a program for causing a
computer to execute the processes of genera t ing a relat ionship graph based
on an event log indicat ing a behavior of each of a plural i ty of processe5 s
operat ing in a system, the relat ionship graph including the processes as
vert ices thereof and including data t ransmission relat ionships between the
vert ices as sides thereof, and output t ing the relat ionship graph.
10 [Advantageous Ef fects of Invent ion]
[0014]
The present invent ion may output informat ion which indicates the
state of the informat ion processing system including the data t ransmission
relat ionship between elements const i tut ing an informat ion processing
15 system.
[Brief Descript ion of Drawings]
[0015]
[Fig. 1] Fig. 1 is a block diagram i l lust rat ing a configurat ion of an
informat ion processing device according to a f irst exemplary embodiment
20 of the present invent ion.
[Fig. 2] Fig. 2 is a block diagram i l lust rat ing a configurat ion of an
informat ion processing system including the informat ion processing device
and a system to be moni tored according to the fi rst exemplary embodiment .
[Fig. 3] Fig. 3 is a view i l lustrat ing an exemplary event log in the f irst
25 exemplary embodiment .
[Fig. 4] Fig. 4 is a view i l lust rat ing an exemplary relat ionship graph in the
first exemplary embodiment .
[Fig. 5] Fig. 5 is a view i l lustrat ing another exemplary relat ionship graph
in the fi rst exemplary embodiment .
6
[Fig. 6] Fig. 6 is a view i l lustrat ing st i l l another exemplary relat ionship
graph in the first exemplary embodiment .
[Fig. 7] Fig. 7 is a conceptual view i l lust rat ing a relat ionship between
processes represented by the relat ionship graph in the fi rst exemplary
embodiment 5 .
[Fig. 8] Fig. 8 is a block diagram i l lust rat ing a hardware configurat ion of a
computer which implements the informat ion processing device according
to the fi rst exemplary embodiment .
[Fig. 9] Fig. 9 is a flowchart i l lustrat ing the operat ion of the informat ion
10 processing device in the fi rst exemplary embodiment .
[Fig. 10] Fig. 10 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing system including a system to be moni tored an d an
informat ion processing device according to a f irst exemplary modi ficat ion
to the fi rst exemplary embodiment .
15 [Fig. 11] Fig. 11 is a view i l lustrat ing an exemplary relat ionship graph in a
third exemplary modificat ion to the first exemplary embodiment .
[Fig. 12] Fig. 12 is a block diagram i l lust rat ing a configurat ion of an
informat ion processing device according to a second exemplary
embodiment of the present invent ion.
20 [Fig. 13] Fig. 13 is a block diagram i l lust rat ing a configurat ion of an
informat ion processing device according to a thi rd exemplary embodiment
of the present invent ion.
[Fig. 14] Fig. 14 is a block diagram i l lust rat ing a configurat ion of an
informat ion processing device according to a fourth exemplary
25 embodiment of the present invent ion.
[Fig. 15] Fig. 15 is a block diagram i l lust rat ing a configurat ion of an
informat ion processing device according to a f ifth exemplary embodiment
of the present invent ion.
[Fig. 16] Fig. 16 is a view i l lust rat ing an exemplary network diagram
7
relat ionship graph in the f ifth exemplary embodiment .
[Fig. 17] Fig. 17 is a view i l lust rat ing an exemplary mat rix relat ionship
graph in the fif th exemplary embodiment .
[Fig. 18] Fig. 18 is a view i l lust rat ing another exemplary network diagram
relat ionship graph in the f i fth exemplary embodiment 5 .
[Fig. 19] Fig. 19 is a view i l lust rat ing another exemplary mat rix
relat ionship graph in the f ifth exemplary embodiment .
[Fig. 20] Fig. 20 is a block diagram i l lust rat ing an exemplary internal
configurat ion of a history accumulat ion uni t in an exemplary modi ficat ion
10 to the second exemplary embodiment .
[Fig. 21] Fig. 21 is a flowchar t i l lust rat ing an operat ion of the history
accumulat ion uni t in the exemplary modif icat ion to the second exemplary
embodiment .
[Fig. 22] Fig. 22 is a chart for explaining how the relat ionship graph
15 reduces wi th t ime according to the exemplary modi ficat ion to the s econd
exemplary embodiment .
[Fig. 23] Fig. 23 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing device according to an exemplary modificat ion to
the thi rd exemplary embodiment .
20 [Fig. 24] Fig. 24 is a view i l lust rat ing an exemplary relat ionship graph on
which detected informat ion is superimposed in the exemplary modi ficat ion
to the thi rd exemplary embodiment .
[Fig. 25] Fig. 25 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing device according to a second exemplary
25 modi ficat ion to the fourth exemplary embodiment .
[Descript ion of Embodiments]
[0016]
Exemplary embodiments of the present invent ion wi l l be descr ibed
in detai l below wi th reference to the drawings. In each drawing and each
8
exemplary embodiment descr ibed in the present descript ion, the same
reference numerals denote the same components, and a descript ion thereof
wi l l be omi t ted as appropriate.
[0017]
<<>5 >
Fig. 1 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing device 100 according to a first exemplary
embodiment of the present invent ion.
[0018]
10 The informat ion processing device 100 according to the present
exemplary embodiment includes a graphing uni t 110 and a graph output
uni t 120, as i l lustrated in Fig. 1. Components i l lustrated in Fig. 1 may be
divided for each hardware-specif ic ci rcui t or each funct ion of a computer
device. Components i l lustrated in Fig. 1 are assumed herein to be
15 divided for each funct ion of a computer device.
[0019]
Fig. 2 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing system including the informat ion processing device
100 and a system to be moni tored ( to be also simply referred to as a
20 "system" hereinafter ) 900. A plural i ty of systems to be moni tored 900
may be connected to the informat ion processing device 100 wi thout
l imi tat ion to the example i l lustrated in Fig. 2 .
[0020]
===System to Be Moni tored 900===
25 The system to be moni tored 900 includes a plural i ty of hosts 910.
Examples of the hosts 910 include a computer, a server, a storage device,
and a communicat ion control ler. The system to be moni tored 900 may
include only one host 910 wi thout l imi tat ion to the example i l lustrated in
Fig. 2. Each host 910 and the informat ion processing device 100 are
9
connected to each other via a network (not i l lustrated).
[0021]
===Host 910===
The host 910 includes a process 920, a process generat ion
moni toring means 931, a fi le access moni toring means 932, an int ra-hos5 t
interprocess communicat ion moni toring means 933, and an inter-host
interprocess communicat ion moni toring means 934.
[0022]
Examples of each of the process generat ion moni toring means 931,
10 the fi le access moni toring means 932, the int ra-host interprocess
communicat ion moni toring means 933, and the inter-host interprocess
communicat ion moni toring means 934 include a moni toring agent which
operates on the host 910.
[0023]
15 The process generat ion moni toring means 931 moni tors the
generat ion of a new process 920 by the process 920 and the end of the
process 920. Upon detect ing each of the generat ion and the end, the
process generat ion moni toring means 931 sends an event log 810 indicat ing
detai ls.
20 [0024]
The f i le access moni toring means 932 moni tors an access to a fi le
by the process 920. Upon detect ing the access, the fi le access moni toring
means 932 sends an event log 810 indicat ing detai ls.
[0025]
25 Each of the int ra-host interprocess communicat ion moni toring
means 933 and the inter-host interprocess communicat ion moni toring
means 934 moni tors the communicat ion between processes , and sends an
event log 810 indicat ing detai ls upon detect ing the communicat ion.
Examples of int ra-host interprocess communicat ion include a pipe,
10
message queue, a shared memor y, and a UNIX® domain socket .
Examples of inter-host interprocess communicat ion include a TCP
(Transmission Cont rol Protocol ) socket , an RPC (Remote Procedure Cal l) ,
an HTTP (Hypertext Transfer Protocol) request , and an HTTP response.
[5 0026]
The process generat ion moni toring means 931, the fi le access
moni toring means 932, the int ra-host interprocess communicat ion
moni toring means 933, and the inter-host interprocess communicat ion
moni toring means 934 wi l l also be col lect ively refer red to as event
10 moni toring means 930 hereinafter.
[0027]
The host 910 may include only an arbi t rary part of the event
moni toring means 930 as an event moni toring means wi thout l imi tat ion to
the example i l lust rated in Fig. 2. The host 910 may further include an
15 event moni toring means for an arbi t rary event , other than the event
moni toring means 930, as an event moni toring means. Examples of the
arbi t rary event include events associated wi th a cl ipboard, a registry, and
an envi ronment variable.
[0028]
20 ===Graphing Uni t 110===
The graphing uni t 110 generates a relat ionship graph 820 based on
the event log 810 of the system to be moni tored 900.
[0029]
===Event Log 810===
25 Examples of the event log 810 include informat ion indicat ing the
behavior of each of a plural i ty of processes 920 operat ing in the system to
be moni tored 900. The graphing uni t 110, for example, obtains the event
log 810 f rom the event moni toring means 930 provided for each host 910.
[0030]
11
Fig. 3 is a view i l lustrat ing an event log 811 as a speci fic example
of the event log 810. The event log 811 i l lust rated in Fig. 3 represents an
event in which "a process 920 "P3" sent a request message associated wi th
data to a process 920 "P4" and the process 920 "P4" sent a response
message associated wi th data to the process 920 "P3."" Note that "P35 "
and "P4" are ident if iers for the process 920. For example, the process
920 "P3" indicates a process 920 having an ident i fier "P3."
[0031]
The event log 811 i l lustrated in Fig. 3 is sent by the int ra-host
10 interprocess communicat ion moni toring means 933 when the process 920
"P3" and the process 920 "P4" are processes 920 in the same host 910.
The event log 811 i l lustrated in Fig. 3 is sent by the inter-host interprocess
communicat ion moni toring means 934 when the process 920 "P3" and the
process 920 "P4" are processes 920 operat ing in different host s 910.
15 [0032]
===Relat ionship Graph 820===
The relat ionship graph 820 has each process 920 as i ts vertex (also
cal led a node or a node point) and the data t ransmi ssion relat ionships
between the processes 920 as i ts sides (also cal led l inks, edges, or
20 branches). The relat ionship graph 820 represents the relat ionship
between the processes 920 in the system to be moni tored 900. Examples
of this relat ionship include herein a data transmission relat ionship in
which "data is transmi t ted between processes during a certain period," and
a data t ransmission relat ionship in which "data transmission may take
25 place between processes at a certain moment (or during a certain per iod) ."
[0033]
More speci fical l y, the data t ransmission relat ionship means data
transfer from a given process 920 to a di fferent process 920 ( the "t ransfer"
means "send" for the given process 920 and "receive" for the different
12
process 920) . The data t ransmission relat ionship may be a relat ionship
between a plural i ty of processes 920 in which data are wri t ten into and
read f rom a specif ic fi le, obtained by the fi le access moni toring me ans 932.
The data t ransmission relat ionship may further be the generat ion and
delet ion of one process 920 (chi ld process) by another process 920 (paren5 t
process). The data transmission relat ionship may even be, for example,
an establ ishment of connect ion f rom one process 920 to another process
920 or a terminat ion of connect ion between one process 920 and another
process 920. The connect ion may be arbi trary connect ion such as
10 connect ion in a t ransport layer such as TCP, or connect ion implemented in
a session layer or an appl icat ion layer.
[0034]
===Relat ionship Graph 821===
Fig. 4 is a view i l lustrat ing a relat ionship graph 821 as a speci fic
15 example of the relat ionship graph 820. The relat ionship graph 821 is
defined by a record including vertex ident i fiers and sides , as i l lust rated in
Fig. 4. Examples of the vertex ident i fier s include ident i fiers for
processes 920 forming vert ices . The side includes informat ion indicat ing
the data t ransmission relat ionship s from a vertex (process 920) speci fied
20 by each vertex ident i fier to other ver t ices.
[0035]
For example, the ver tex ident i fier "P1" specifies a process 920
having the ident if ier "P1." The side "P2; SEND, P3; SEND; RECEIVE"
corresponding to the vertex ident i fier "P1" indicates the fol lowing
25 informat ion. First , the port ion "P2; SEND" indicates that a process 920
"P1" sent data to a process 920 "P2." Second, the port ion "P3; SEND"
indicates that the process 920 "P1" sent data to a process 920 "P3." Thi rd,
the port ion "P3; ; RECEIVE" indicates that th e process 920 "P1" received
data f rom the process 920 "P3."
13
[0036]
For example, the side "P4; RECEIVE" in a record having the vertex
ident if ier "P3" and the side "P3; SEND" in a record having the vertex
ident if ier "P4" are based on the event log 811 i l lust rated in Fig. 3.
[5 0037]
===Relat ionship Graph 822===
Fig. 5 is a view i l lustrat ing a relat ionship graph 822 as another
speci fic example of the relat ionship graph 820 .
[0038]
10 The relat ionship graph 822 is defined by a record including sides
each represent ing a pair of ver tex ident i fiers, and side at t ributes (types), as
i l lust rated in Fig. 5. The side represents a pair of ident i fiers for
processes 920 forming vert ices. The side at t ribute includes informat ion
indicat ing the data t ransmission relat ionship between vert ices (processes
15 920) speci fied by the side.
[0039]
===Relat ionship Graph 824===
Fig. 6 is a view i l lustrat ing a relat ionship graph 824 as st i l l another
speci fic example of the relat ionship graph 820 .
20 [0040]
Fig. 6 i l lustrates exemplary relat ionship graphs 820 cor responding
to the fol lowing first to fi fth event logs 810. In the fol lowing descript ion,
a process P1 is a process 920 in a fi rst host 910. A process P2 is a
process 920 in a second host 910. A f i le F1 is a fi le (one type of process
25 920) in the fi rst host 910. A fi le F2 is a fi le (one type of process 920) in
the second host 910.
[0041]
The f irst event log 810 indicates "the process P1 reads the fi le F1"
sent by the fi le access moni toring means 932 in the fi rst host 910. The
14
vertex ident i fier "P1" and the side "F1; READ" in the relat ionship graph
824 cor respond to the first event log 810.
[0042]
The second event log 810 indicates "the process P1 performs
bidi rect ional communicat ion wi th the process P2" sent by a first inter-hos5 t
interprocess communicat ion moni toring means 934 in the first host 910.
The vertex ident if ier "P1" and the side "P2; SEND/RECEIVE," and the
vertex ident i fier "P2" and the side "P1; SEND/RECEIVE" in the
relat ionship graph 824 correspond to the second event log 810.
10 [0043]
The thi rd event log 810 indicates "the process P2 reads/wri tes data
from/into the fi le F2" sent by the f i le access moni toring means 932 in the
second host 910. The vertex ident i fier "P2" and the side "F2;
READ/WRITE" in the relat ionship graph 824 cor respond to the third event
15 log 810.
[0044]
The fourth event log 810 indicates "the process P2 generates a
process P3 which uses the f i le F2 as an execut ion fi le" sent by the process
generat ion moni toring means 931 in the second host 910. The vertex
20 ident if ier "P2" and the side "P3; GENERATE" in the relat ionship graph 824
correspond to the fourth event log 810.
[0045]
The f ifth event log 810 indicates "the process P3 reads the fi le F2"
sent by the fi le access moni toring means 932 in the second host 910. The
25 vertex ident i fier "P3" and the side "F2; READ" in the relat ionship graph
824 cor respond to the fif th event log 810.
[0046]
The relat ionship graph 820 may take any form wi thout l imi tat ion to
the above-ment ioned examples. The relat ionship graph 820 may have, for
15
example, an adjacency mat rix data st ructure.
[0047]
===Relat ionship between Processes 920 Represented by
Relat ionship Graph 820===
Fig. 7 is a conceptual view i l lust rat ing the relat ionship between th5 e
processes 920 represented by the relat ionship graph 820, such as the
relat ionship graph 821, 822, or 823.
[0048]
Referr ing to Fig. 7, vert ices are represented in ci rcles and ver tex
10 ident if iers are marked wi thin the ci rcles . Sides are represented by l ine
segments which connect the ci r cles to each other. For example, each l ine
segment indicates "SEND" or "RECEIVE." The graph i l lust rated in Fig.
7 is a di rected graph and the direct ion pointed by an arrow of each l ine
segment is the direct ion in which data flows. A l ine segment having
15 ar rows at i ts two ends indicates that the side includes both "SEND" and
"RECEIVE."
[0049]
The sides may be di rected (wi th an ar row) or undi rected (wi thout an
ar row) wi thout l imi tat ion to the example i l lust rated in Fig. 7. For
20 example, the side between the process 920 "P1" and the process 920 "P2"
only indicat ing the presence of connect ion may be undi rected. When, for
example, the request and standby sides of connect ion need to be specified,
the side may be effect ive.
[0050]
25 ===Graph Output Uni t 120===
The graph output uni t 120 outputs a relat ionship graph 820
generated by the graphing uni t 110.
[0051]
Funct ion-speci fic components of the informat ion processing device
16
100 have been described above.
[0052]
Hardware-specific components of the informat ion processing
device 100 wi l l be described below.
[5 0053]
Fig. 8 is a block diagram i l lust rat ing the hardware configurat ion of
a computer 700 which implements the informat ion processing device 100
according to the present exemplary embodiment .
[0054]
10 The computer 700 includes a CPU (Central Processing Uni t ) 701, a
storage uni t 702, a storage device 703, an input uni t 704, an output uni t
705, and a communicat ion uni t 706, as i l lustrated in Fig. 8. The
computer 700 further includes an external ly suppl ied recording medium (or
storage medium) 707. For example, the recording medium 707 is a
15 non-volat i le recording medium (non-t ransi tory recording medium) which
non-transi tori ly stores informat ion. The recording medium 707 may be a
transi tory recording medium which holds informat ion as a signal .
[0055]
The CPU 701 runs the operat ing system (not i l lust rated) to control
20 the operat ion of the overal l computer 700. For example, the CPU 701
reads a program or data from the recording medium 707 mounted in the
storage device 703 and wr i tes the read program or data into the storage uni t
702. Examples of the program include a program for causing the
computer 700 to execute the operat ion in a flowchar t i l lust rated in Fig. 9
25 (to be descr ibed l ater) .
[0056]
The CPU 701 executes various types of processing as the graphing
uni t 110 and the graph output uni t 120 i l lustrated in Fig. 1, in accordance
wi th the read program and the read data.
17
[0057]
The CPU 701 may download the program or the data from an
external computer (not i l lustrated) connected to a communicat ion network
(not i l lustrated) to the storage uni t 702.
[5 0058]
The storage uni t 702 stores the program or the data. The storage
uni t 702 may store the event log 810 and the relat ionship graph 820.
[0059]
Examples of the storage device 703 include an arbi trary opt ical disk,
10 flexible disk, magneto-opt ical disk, external hard disk, and semiconductor
memor y. The storage device 703 stores the program in a
computer- readable manner. The storage device 703 may further store the
data. The storage device 703 may even store the event log 810 and the
relat ionship graph 820.
15 [0060]
The input uni t 704 receives operator 's operat ion input and external
informat ion input . Examples of a device used for input operat ions
include an arbi t rary mouse, keyboard, internal key but ton, and touch panel .
[0061]
20 The output uni t 705 is implemented in, for example, a display.
The output uni t 705 is used for an input request to the operator via a GUI
(Graphical User Interface), and output presentat io n to the operator, for
example.
[0062]
25 The communicat ion uni t 706 implements an inter face wi th the host
910 and an arbi t rary device 940 (to be described later) . The
communicat ion uni t 706 may be included as parts of the graphing uni t 110
and the graph output uni t 120.
[0063]
18
Funct ion-speci fic blocks of the informat ion processing device 100
i l lust rated in Fig. 1 are implemented by the computer 700 having the
hardware configurat ion i l lust rated in Fig. 8, as described above. Note,
however, that the means for implement ing each uni t of the computer 700 is
not l imi ted to the foregoing descript ion. In other words, the compute5 r
700 may be implemented in a single physical ly-coupled device or two or
more physical ly- isolated devices connected in a wi red or wi reles s fashion.
[0064]
When the recording medium 707 recording the code of the
10 above-ment ioned program is suppl ied to the computer 700, the CPU 701
may read and execute the program code stored in the recording medium 707.
Al ternat ively, the CPU 701 may store in the storage uni t 702 and/or the
storage device 703, the program code stored in the recording medium 707.
In other words, the present exemplary embodiment includes an exemplary
15 embodiment of a recording medium 707 which transi tori ly or
non-transi tori ly stores the program (software) executed by the computer
700 (CPU 701). A storage medium which non-t ransi tori ly stores
informat ion is also cal led a non-volat i le storage medium.
[0065]
20 Each hardware-speci fic component of the computer 700
implement ing the informat ion processing device 100 in the present
exemplary embodiment has been described above.
[0066]
An operat ion in the present exemplary embodiment wi l l be
25 described in detai l below wi th reference to the drawings.
[0067]
Fig. 9 is a flowchart i l lust rat ing an operat ion in the present
exemplary embodiment . Processing in the flowchar t may be executed on
the basis of program control by the CPU 701 ment ioned earl ier.
19
Processing steps are denoted by symbols, such as S601.
[0068]
The graphing uni t 110 automat ical ly starts up i ts operat ion upon the
complet ion of ini t ial izat ion of the informat ion processing device 100.
Upon the complet ion of ini t ial izat ion, the content of the relat ionship grap5 h
820 is empt y. The relat ionship graph 820 is held in, for example, the
storage uni t 702 or the storage device 703 i l lustrated in Fig. 8.
[0069]
The graphing uni t 110 determines whether an event log 810 is
10 received (step S601). The graphing uni t 110, for example, receives an
event log 810 from the system to be moni tored 900 via the communicat ion
uni t 706 i l lustrated in Fig. 8.
[0070]
If an event log 810 is received (YES in step S601), the graphing
15 uni t 110 generates or updates the content of the relat ionship graph 820
based on the received event log 810 (step S602). The process then
advances to step S603.
[0071]
If no event log 810 is received (NO in step S601) , the process
20 advances to step S603.
[0072]
The graph output uni t 120 determines whether i t is output t iming of
the relat ionship graph 820 (step S603). When, for example, an
instruct ion is received f rom the operator via the input uni t 704 i l lustrated
25 in Fig. 8, the graph output uni t 120 determines that i t is the output t iming.
When a predetermined t ime of day is detected using a t ime measuring
means (not i l lust rated), the graph output uni t 120 may determine that i t is
the output t iming. The graph output uni t 120 may determine whether i t is
the output t iming by using an arbi t rary method wi thout l imi tat ion to the
20
above-ment ioned examples.
[0073]
If the t iming is appropriate to output (YES in step S603), the graph
output uni t 120 outputs the relat ionship graph 820 (step S604) . The
process then returns to step S6015 .
[0074]
For example, the graph output uni t 120 outputs the relat ionship
graph 820 via the output uni t 705 i l lust rated in Fig. 8. The graph output
uni t 120 may send the relat ionship graph 820 to a device (not i l lust rated)
10 via the communicat ion uni t 706 i l lustrated in Fig. 8. The graph output
uni t 120 may record the relat ionship graph 820 on the recording medium
707 via the storage device 703 i l lust rated in Fig. 8.
[0075]
If the t iming is not appropriate to output (NO in step S603) , the
15 process returns to step S601.
[0076]
In the f lowchart i l lustrated in Fig. 9, the graphing uni t 110 and the
graph output uni t 120 operate sequent ial ly in series. The graphing uni t
110 and the graph output uni t 120 may operate in paral lel .
20 [0077]
In the f lowchart i l lustrated in Fig. 9, the graphing uni t 110 updates
the relat ionship graph 820 every t ime an event log 810 is received.
However, the graphing uni t 110 may accumulate the received event log 810
and generate or update a relat ionship graph 820 based on the accumulated
25 event log 810 at a specific t iming ( for example, immediately before the
graph output uni t 120 outputs the relat ionship graph 820).
[0078]
The graphing uni t 110 may obtain an event log 810 by using an
arbi t rary method wi thout l imi tat ion to the foregoing descript ion. For
21
example, the graphing uni t 110 may col lect ively obtain an event log 810
from each event moni toring means 930 at a predetermined t ime of day. In
this case, the event moni toring means 930 accumulates the event log 810
unt i l the predetermined t ime.
[5 0079]
An event log 810 may be stored in the storage uni t 702 or the
storage device 703 i l lustrated in Fig. 8 in advance. The graphing uni t 110
may obtain an event log 810 input by the operator via the input uni t 704
i l lust rated in Fig. 8. The graphing uni t 110 may receive an event log 810
10 from a device (not i l lustrated) via the communicat ion uni t 706 i l lustrated
in Fig. 8. The graphing uni t 110 may obtain an event log 810 recorded on
the recording medium 707 via the storage device 703 i l lustrated in Fig. 8.
[0080]
<<>>
The graphing uni t 110 generates a relat ionship graph 820 having a
predetermined device as i ts vertex based on an event log 810 indicat ing the
behavior of each such arbi trary device. Examples of the arbi trary device
include an arbi t rary host in which no moni toring agent can be located, a
20 router, a sensor, a pr inter, and a network device.
[0081]
In this case, the graphing uni t 110 further sets the data t ransmission
relat ionships between the predetermined devices and between the
predetermined devices and the processes 920 as sides .
25 [0082]
Fig. 10 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing system including the informat ion processing device
100 and a system to be moni tored 901 including hosts 910 and 911, a router
941, a sensor 942, a printer 943, and a network device 944. The router
22
941, the sensor 942, the pr inter 943, and the network device 944 wi l l also
be col lect ively referred to as arbi t rary devices 940 hereinafter.
[0083]
The graphing uni t 110 further obtains an event log 810 indicat ing a
behavior of each arbi trary device 940 f rom an event moni tor ing means fo5 r
moni toring the behavior of the arbi t rary device 940. The event
moni toring means may be a moni toring agent implemented in the arbi t rary
device 940 or a device which external ly moni tors the behavior of the
arbi t rary device 940.
10 [0084]
The host 911 i tsel f may not be equipped wi th a moni toring agent .
An appropriate external device for di rect ly moni toring the behavior of the
host 911 is unavai lable. However, the graphing uni t 110 may indi rect ly
recognize that a data transmission relat ionship has occur red between the
15 process 920 and the host 911 based on a log which may be obtained f rom
the event moni toring means 930 on the host 910. More speci fical l y, the
host 911 may serve as, for example, a mission cri t ical server or an external
web server.
[0085]
20 <<>>
The graphing uni t 110 generates a relat ionship graph 820 having
arbi t rary f i les accessed by the processes 920 as i ts vert ices, and accesses to
the vert ices as i ts sides.
25 [0086]
More speci fical l y, the relat ionships between the processes 920 and
the fi les, represented by sides, are arbi t rary relat ionships such as the open,
close, read, and wri te of the fi les by the processes 920 and the generat ion
and delet ion of the fi les.
23
[0087]
In other words, the above-ment ioned arbi trary f i les are those for
which the graphing uni t 110 may not obtain event logs 810 direct ly
indicat ing the behavior s of the fi les.
[5 0088]
<<>>
The graphing uni t 110 may generate a relat ionship graph 820
aggregat ing event logs 810 indicat ing the same or simi lar behaviors .
10 [0089]
For example, the graphing uni t 110 may generate a relat ionship
graph 820 having only one side between a pair of a f irst speci f ic process
920 and a second specif ic process 920. In this case, the graphing uni t 110
may add, to the side, stat ist ical informat ion indicat ing the number of
15 connect ion establ ishments, the data volume, and the frequency of access or
the l ike.
[0090]
The graphing uni t 110 may calculate a cri ter ion for determining
whether a new event is normal or abnormal when the new event occurs ,
20 based on these pieces of stat ist ical informat ion, and add the calculated
cri terion to the side. For example, the graphing uni t 110 may calculate a
threshold for the deviat ion of the frequency of access f rom the average as a
cri terion for determining whether, the access is abnormal when the next
access occurs, based on the average and standard deviat ion of the
25 frequency of access, and add the threshold to the side.
[0091]
The graphing uni t 110 may set a plural i ty of data t ransmissions for
the same di rect ion between a fi rst specif ic process 920 and a second
speci fic process 920 as a single side.
24
[0092]
===Relat ionship Graph 823===
Fig. 11 is a view i l lustrat ing a relat ionship graph 823 as a specif ic
example of the relat ionship graph 820 that aggregates event logs 810.
The relat ionship graph 823 includes informat ion indicat ing "the number o5 f
aggregated event logs" added to the sides, as i l lust rated in Fig. 11.
[0093]
For example, the side "P2; SEND[1] , P3; SEND[3] ; RECEIVE[2]"
in a record having the vertex ident i fier "P1" indicates the fol lowing
10 informat ion. First , the port ion "P2; SEND[1]" indicates that the process
920 "P1" has t ransmi t ted data to the process 920 "P2" once. Second, the
port ion "P3; SEND[3]" indicates that the process 920 "P1" has transmi t ted
data to the process 920 "P3" three t imes. Thi rd, the port ion "P3; ;
RECEIVE[2]" indicates that the process 920 "P1" has received data f rom
15 the process 920 "P3" twice.
[0094]
The graphing uni t 110 may generate a relat ionship graph 820 having
each type of data t ransmission relat ionship individual ly as i ts side.
[0095]
20 The types may be arbi trary types such as fi le access, int ra-host
interprocess communicat ion, interprocess communicat ion between
different hosts, and process generat ion.
[0096]
The graphing uni t 110 may generate a relat ionship graph 820 having
25 an arbi t rary combinat ion of data t ransmission relat ionships as i ts side.
The arbi trary combinat ion of data transmission relat ionships may be, for
example, the above-ment ioned uni t of connect ion.
[0097]
The graphing uni t 110 may generate a relat ionship graph 820 based
25
on an event log 810 selected based on an arbi t rary cri terion.
[0098]
More speci fical l y, the graphing uni t 110 may generate a
relat ionship graph 820 having only the establ ishment and terminat ion of
connect ion between the processes 920 as i ts sides. The graphing uni t 115 0
may generate a relat ionship graph 820 having only the establ ishment and
end of connect ion between the processes 920 and the open and close of
fi les as i ts sides.
[0099]
10 The graphing uni t 110 may add an at t ribute (property) associated
wi th the data t ransmission relat ionship to the side. Examples of the
at t ribute include informat ion concerning the type of data t ransmission
relat ionship and t ime informat ion.
[0100]
15 For example, the graphing uni t 110 may set informat ion concerning
the volume of t ransfer red data in the data transmission relat ionship as an
at t ribute for the side. The informat ion concerning the volume of
transfer red data may be arbi t rary informat ion concerning the volume of
transfer red data, such as the transfer di rect ion, the average or maximum
20 value of the transfer volume per uni t t ime, or the sum of t ransfer volumes
during a predetermined period.
[0101]
The graphing uni t 110 may set informat ion concerning the number
of accesses in the data t ransmission relat ionship as an at tribute for the side.
25 The informat ion concerning the number of accesses may be arbi trary
informat ion concerning the number of accesses , such as the access
direct ion, the average number of accesses (average f requency) or the
maximum number of accesses (maximum f requency) per uni t t ime, or the
total number of accesses during a predetermined period.
26
[0102]
The graphing uni t 110 may generate a relat ionship graph 820
including a side aggregat ing event logs 810, based on the defini t ion of the
same or simi lar arbi t rary behaviors by using an arbi t rary method. Both
"the same behaviors" and "simi lar behaviors" wi l l also be col lect ivel5 y
refer red to as "simi lar behaviors" hereinaf ter. The graphing uni t 110 may
even generate a relat ionship graph 820 wi thout aggregat ing event logs 810.
[0103]
The "defini t ion of the same behavior or simi lar behavior" may be
10 the defini t ion of the establ ishment and terminat ion of connect ion between
the processes 920 or the open and close of fi les, for example. The
"defini t ion of the same behavior or simi lar behavior" may also be the
defini t ion of a communicat ion protocol . The "defini t ion of the same
behavior or simi lar behavior" may further be the defini t ion of arbi t rary
15 informat ion concerning the volume of t ransferred data, such as the data
transfer direct ion, the average or maximum value of the t ransfer volume
per uni t t ime upon division of the data volume, or the sum of t ransfer
volumes during a predetermined period. The "defini t ion of the same
behavior or simi lar behavior" may even be the defini t ion of arbi trary
20 informat ion concerning the number of accesses, such as the average
number of accesses (average f requency) or the maximum number of
accesses (maximum f requency) per uni t t ime upon division of the number
in the data transmission relat ionship, or the total number of accesses
during a predetermined period. The "defini t ion of the same behavior or
25 simi lar behavior" may even be the defini t ion of a t ime zone , which is
divided into di fferent ranges .
[0104]
Aggregat ing event logs for each set of the same or simi lar behaviors
may clarify the graph characterist ics whi le reducing the informat ion
27
volume to be managed.
[0105]
Individual ly aggregat ing event logs indicat ing di fferent behaviors
may faci l i tate the operat ion of event logs indicat ing the same or simi lar
speci fic behaviors whi le aggregat ing event logs indicat ing the same o5 r
simi lar behaviors. Assume, for example, that communicat ion based on
protocol B has occur red due to an abnormal i ty on a side where
communicat ion based on protocol A is normal ly per formed. In such a
case, af ter the abnormal i ty is deal t wi th, an event log indicat ing
10 communicat ion based on protocol B may be easi ly deleted.
[0106]
When a side aggregat ing event logs 810 is included in the
relat ionship graph 820, the graphing uni t 110 may generate an at tribute for
the side aggregat ing the event logs 810 based on the aggregated event logs
15 810.
[0107]
The graphing uni t 110 may delete a side where no event has
occurred for a predetermined t ime f rom the relat ionship graph. Assume,
for example, that one computer is discarded and the informat ion of th e
20 computer becomes no longer necessary for the relat ionship graph . Then,
when the graphing uni t 110 detects that communicat ion wi th the computer
has not been per formed for a predetermined t ime, the graphing uni t 110
may delete a side having the computer as i ts node.
[0108]
25 As a fi rst effect in the above-ment ioned present exemplary
embodiment , informat ion including the data t ransmission relat ionship
between elements const i tut ing a system to be moni tored (system to be
moni tored 900 or sys tem to be moni tored 901) and indicat ing the state of
the system to be moni tored may be output .
28
[0109]
This is because the graphing uni t 110 generates a relat ionship graph
820 represent ing the structure of the system to be moni tored based on the
event log 810, and the graph output uni t 120 outputs the relat ionship graph
5 820.
[0110]
As a second effect in the above -ment ioned present exemplary
embodiment , the data t ransmission relat ionship between external elements
and elements const i tut ing a system to be moni tored may be exhaust ively
10 covered.
[0111]
This is because the graphing uni t 110 further generates a
relat ionship graph 820 having arbi t rary f i les and arbi t rary devices as i ts
vert ices.
15 [0112]
As a third effect in the above-ment ioned present exemplary
embodiment , the fi rst effect may be obtained regardless of the scale or
complexi ty of a system to be moni tored.
This is because the graphing uni t 110 generates a relat ionship graph
20 820 aggregat ing event logs 810.
[0113]
As a fourth effect in the above -ment ioned present exemplary
embodiment , informat ion including the data t ransmission relat ionship
between elements const i tut ing a system to be moni tored, and more
25 appropriately indicat ing the state of the system to be moni tored may be
output .
[0114]
This is because the graphing uni t 110 generates a relat ionship graph
820 based on a arbi t rary selected event log 810.
29
[0115]
<<>>
A second exemplary embodiment of the present invent ion wi l l be
described in detai l below wi th reference to the drawings. A descript ion
of detai ls which are the same as in the foregoing descript ion wi l l b5 e
omi t ted hereinafter wi thin the range in which an explanat ion of the present
exemplary embodiment does not become unclear.
[0116]
Fig. 12 is a block diagram i l lust rat ing the configurat ion of an
10 informat ion processing device 200 according to the second exemplary
embodiment of the present invent ion.
[0117]
The informat ion processing device 200 in the present exemplary
embodiment is di fferent f rom the informat ion processing device 100 in the
15 first exemplary embodiment in that the former includes a graphing uni t 210
in place of the graphing uni t 110 and a graph output uni t 220 in place of the
graph output uni t 120, as i l lust rated in Fig. 12. The informat ion
processing device 200 is further different from the informat ion processing
device 100 in that the former includes a history accumulat ion uni t 230.
20 [0118]
===Graphing Uni t 210===
The graphing uni t 210 records , at a predetermined t iming,
informat ion capable of restoring a relat ionship graph 820 avai lable at the
point in t ime in the history accumulat ion uni t 230 in associat ion wi th, for
25 example, the t ime of day at the point in t ime. Examples of the
predetermined t iming include a predetermined t ime of day. The
predetermined t iming may be the t iming at which the number of processes
of an event log 810 reaches a predetermined threshold. The
predetermined t iming may be an arbi t rary t iming wi t hout l imi tat ion to the
30
above-ment ioned examples. Examples of the informat ion capable of
restoring a relat ionship graph 820 avai lable at the point in t ime include the
difference from a relat ionship graph 820 avai lable at any previous point in
t ime ( for example, one point in t ime before the predetermined point in
time). The informat ion capable of restoring a relat ionship graph 825 0
avai lable at the point in t ime may even be the relat ionship graph 820 i tself
avai lable at the point in t ime.
[0119]
The graphing uni t 210 may record the latest relat ionship graph 820
10 in the history accumulat ion uni t 230 as a temporary relat ionship graph, and
update the temporary relat ionship graph and i ts associated t ime of day
every t ime an event log 810 is obtained. In this cas e, the graphing uni t
210 may stop updat ing the temporary relat ionship graph at the
predetermined t iming and determine the temporary relat ionship graph as a
15 final relat ionship graph 820.
[0120]
The graphing uni t 210 is equivalent to the graphing uni t 110
i l lust rated in Fig. 1 except for the aforement ioned respect .
[0121]
20 ===History Accumulat ion Uni t 230===
The history accumulat ion uni t 230 stores the relat ionship graph 820.
The history accumulat ion uni t 230 may further store the above -ment ioned
temporary relat ionship graph.
[0122]
25 ===Graph Output Uni t 220===
The graph output uni t 220 outputs, in step S604 of Fig. 9, for
example, any of the relat ionship graph 820 stored in the history
accumulat ion uni t 230 and the latest relat ionship graph 820 that is
generated by the graphing uni t 210 and has not yet been stored in the
31
history accumulat ion uni t 230. The graph output uni t 220 may output the
temporary relat ionship graph stored in the history accumulat ion uni t 230.
[0123]
As an effect in the above -ment ioned present exemplary embodiment ,
the past and current relat ionship graphs 820 may be output , in addi t ion t5 o
the effect of the fi rst exemplary embodiment .
[0124]
This is because the graphing uni t 210 records a relat ionship graph
820 in the history accumulat ion uni t 230 at a predetermined t iming, and the
10 graph output uni t 220 outputs the relat ionship graph 820 stored in the
history accumulat ion uni t 230.
[0125]
<<>>
Fig. 20 is a block diagram i l lust rat ing an exemplary internal
15 configurat ion of the history accumulat ion uni t 230 in the present
exemplary modi ficat ion.
[0126]
The history accumulat ion uni t 230 according to the present
exemplary modi ficat ion includes a database 2001, a t imer 2002, a graph
20 informat ion aggregat ion/ reduct ion uni t 2003, and a cache 2004, as
i l lust rated in Fig. 20.
[0127]
Fig. 21 is a f lowchar t i l lustrat ing the operat ion of the history
accumulat ion uni t 230 in the present exemplary modificat ion.
25 [0128]
The graphing uni t 210 wri tes a relat ionship graph 820 into the
database 2001 asynchronously to the operat ion in the flowchart i l lust rated
in Fig. 21. Simi lar ly, the graph output uni t 220 reads the relat ionship
graph 820 from the database 2001.
32
[0129]
The t imer 2002 measures t ime and detects the elapse of a
predetermined t ime (S2102).
[0130]
Then, the t imer 2002 act ivates the graph informat io5 n
aggregat ion/reduct ion uni t 2003 (2103) . When the t imer 2002
simul taneously detects the elapse of a plural i ty of predetermined t imes, the
graph informat ion aggregat ion/reduct ion uni t 2003 is act ivated in turn in
correspondence wi th each of the plural i ty of predetermined t imes.
10 [0131]
Then, the graph informat ion aggregat ion/ reduct ion uni t 2003
sequent ial ly executes the fol lowing processes in steps S2105 to S2111 for
al l relat ionship graphs 820 cor responding to the predetermined t imes and
recorded in the database 2001 (S2104) . The relat ionship graph 820
15 recorded in the database 2001 wi l l also be referred to as a history
relat ionship graph hereinafter.
[0132]
The graph informat ion aggregat ion/ reduct ion uni t 2003 reads one of
the relat ionship graphs 820 cor responding to the predetermined t imes f rom
20 the database 2001 (S2105).
[0133]
The graph informat ion aggregat ion/reduct ion uni t 2003 determines
whether the relat ionship graph 820 is to be deleted (S2106) . Examples of
the determinat ion method may include a method for generat ing random
25 numbers to stochast ical ly determine whether the relat ionship graph 820 is
to be deleted based on the random numbers.
[0134]
If i t is determined that "the relat ionship graph 820 is to be deleted"
(YES in step S2106) , the graph informat ion aggregat ion/reduct ion uni t
33
2003 retains the relat ionship graph 820 in the cache (S2107) .
[0135]
Then, the graph informat ion aggregat ion/ reduct ion uni t 2003
deletes the relat ionship graph 820 from the database (S2108) .
[5 0136]
If i t is determined that "the relat ionship graph 820 is not to be
deleted" (NO in step S2106), the graph informat ion aggregat ion/reduct ion
uni t 2003 aggregates the relat ionship graph 820 read in step S2105 and the
cached relat ionship graph 820 together (S2109). Examples of the method
10 for aggregat ing the relat ionship graphs 820 may include holding pieces of
ident ical informat ion ( for example, the same "node-edge-node"
relat ionship) not separately but as one such piece of informat ion and
adding the number of such pieces of informat ion.
[0137]
15 Then, the graph informat ion aggregat ion/ reduct ion uni t 2003
updates the relat ionship graph 820 in the database 2001 (S2110).
[0138]
The graph informat ion aggregat ion/reduct ion uni t 2003 clears the
cache 2004 (S2111) . In other words, the graph informat ion
20 aggregat ion/reduct ion uni t 2003 deletes the relat ionship graph 820 in the
cache 2004 (that is, the aggregated relat ionship graphs 820) .
[0139]
Fig. 22 is a chart for explaining how the relat ionship graph 820 in
the database 2001 reduces wi th t ime according to the present exemplary
25 modi ficat ion.
[0140]
Referr ing to Fig. 22, sol id rectangles ( for example, 2201) represent
held relat ionship graphs 820 plot ted at the posi t ions of the t imes of
occurrence, and dot ted rectangles ( for example, 2202) represent deleted,
34
aggregated relat ionship graphs 820.
[0141]
Al l late relat ionship graphs 820 (in a predetermined t ime 2203a
preceding the current t ime) are held. In contrast to this, relat ionship
graphs 820 after the elapse of the predetermined t ime 2203a (5 in a
predetermined t ime 2203b preceding the star t of the predetermined t ime
2203a) are stochast ical ly deleted. The informat ion of the relat ionship
graph 820 to be deleted is aggregated wi th the ident ical informat ion of the
subsequent relat ionship graph 820. Relat ionship graphs 820 after the
10 further elapse of the predetermined t ime 2203b (in a predetermined t ime
2203c preceding the start of the predetermined t ime 2203b) are further
stochast ical ly deleted and aggregated.
[0142]
The predetermined t imes ( for example, the predetermined t ime
15 2203b preceding the start of the predetermined t ime 2203a, and the
predetermined t ime 2203c preceding the star t of the predetermined t ime
2203b) may be the same as or di fferent f rom each other. For example, as
going back to the past , the predetermined t ime may be prolonged.
[0143]
20 The probabi l i t ies that the relat ionship graph s 820 wi l l be deleted
corresponding to the respect ive predetermined t imes may be the same as or
different f rom each other.
[0144]
As a fi rst effect in the above-ment ioned present exemplary
25 embodiment , the data volume of the history accumulat ion uni t 230
(database 2001) that inf ini tely increases when the history of the
relat ionship graph 820 is accumulated wi thout specific regulat ion may be
kept less.
[0145]
35
This is because the graph informat ion aggregat ion/ reduct ion uni t
2003 deletes the relat ionship graph 820 recorded in the database 2001,
based on the elapse of t ime.
[0146]
As a second effect in the above -ment ioned present exemplar5 y
embodiment , increase in the data volume of the history accumulat ion uni t
230 may be more appropriately suppressed.
[0147]
This is because the graph informat ion aggregat ion/ reduct ion uni t
10 2003 stochast ical ly deletes the relat ionship graph 820 recorded in the
database 2001.
[0148]
As a third effect in the above-ment ioned present exemplary
embodiment , for the relat ionship graph 820 recorded in the history
15 accumulat ion uni t 230, increase in the data volume of the history
accumulat ion uni t 230 may be suppressed whi le reducing decay of the
informat ion recorded in the history accumulat ion uni t 230.
[0149]
This is because the graph informat ion aggregat ion/ reduct ion uni t
20 2003 aggregates informat ion included in a relat ionship graph 820 to be
deleted wi th a relat ionship graph 820 that is not to be deleted.
[0150]
<<>>
A thi rd exemplary embodiment of the present invent ion wi l l be
25 described in detai l below wi th reference to the drawings. A descript ion
of detai ls which are the same as in the foregoing descript ion wi l l be
omi t ted hereinafter wi thin the range in which an explanat ion of the present
exemplary embodiment does not become unclear.
[0151]
36
Fig. 13 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing device 300 according to the thi rd exemplary
embodiment of the present invent ion.
[0152]
The informat ion processing device 300 in the present exemplar5 y
embodiment is di fferent f rom the informat ion processing device 200 in the
second exemplary embodiment in that the former includes a graphing uni t
310 in place of the graphing uni t 210 and further includes a query
processing uni t 340, as i l lust rated in Fig. 13.
10 [0153]
===Graphing Uni t 310===
The graphing uni t 310 further outputs a generated relat ionship
graph 820 to the query processing uni t 340. The graphing uni t 310 is
equivalent to the graphing uni t 210 i l lust rated in Fig. 12 except for the
15 aforement ioned respect .
[0154]
===Query Processing Uni t 340===
The query processing uni t 340 receives a query 830 and outputs a
query response 840 in response to the query 830.
20 [0155]
The query 830 includes arbi trary condi t ions for, for example, the
vert ices, sides, and subgraphs of the relat ionship graph 820. The query
830 may fur ther include condi t ions for the t ime of day associated wi th a
relat ionship graph 820 stored in a history accumulat ion uni t 230 and
25 generated or updated by the graphing uni t 310.
[0156]
The query processing uni t 340 retr ieves the history accumulat ion
uni t 230 by using the condi t ions as keys , and the graphing uni t 310
confi rms a relat ionship graph 820 to be generated or updated and detects,
37
for example, ver t ices, sides, and subgraphs of the relat ionship graph 820
that sat isfy the condi t ions. The query processing uni t 340 outputs a
query response 840 including the relat ionship graph 820 and the presence
or absence and number of vert ices, sides, and subgraphs of the relat ionship
graph 820 which are freely selected based on the detect ion resul 5 t .
[0157]
For example, the query processing uni t 340 outputs the query
response 840 via the output uni t 705 i l lust rated in Fig. 8. The query
processing uni t 340 may further send the query response 840 to a device
10 (not i l lustrated) via the communicat ion uni t 706 i l lust rated in Fig. 8. The
query processing uni t 340 may even record the query response 840 on the
recording medium 707 via the storage device 703 i l lust rated in Fig. 8.
[0158]
The query processing uni t 340 may even store the received query
15 830, store the query 830, and conf irm a relat ionship graph 820 to be
generated or updated by the graphing uni t 310 during a predetermined
period based on the condi t ions included in the query 830.
[0159]
The query processing uni t 340 outputs the query response 840 based
20 on the detect ion resul t when, for example, the query processing uni t 340
detects vert ices, sides, and subgraphs of the relat ionship graph 820 that
sat isfy the condi t ions for the first t ime,. Al ternat ivel y, the query
processing uni t 340 may cont inuously detect vert ices, sides, and subgraphs
of the relat ionship graph 820 that sat isfy the condi t ions and output the
25 query response 840 based on the detect ion resul t .
[0160]
As described above, when the query processing uni t 340 stores the
query 830 and the graphing uni t 310 retrieves a relat ionship graph 820 to
be generated or updated, the informat ion processing device 300 may
38
include no history accumulat ion uni t 230.
[0161]
When the query processing uni t 340 excludes a relat ionship graph
820 to be generated or updated by the graphing uni t 310 as a target for the
query 830, the graphing uni t 310 may output no relat ionship graph 820 t5 o
the query processing uni t 340. In other words, in this case, the graphing
uni t 310 may be equivalent to the graphing uni t 210.
[0162]
The query processing uni t 340 may be appl ied to the informat ion
10 processing device 100 i l lustrated in Fig. 1. In this case, the query
processing uni t 340 executes the above-ment ioned operat ion for, for
example, a relat ionship graph 820 to be generated or updated by the
graphing uni t 110.
[0163]
15 As an effect in the above -ment ioned present exemplary embodiment ,
informat ion including the data transmission relat ionship between elements
const i tut ing an informat ion processing system, and more appropriately
indicat ing the state of the informat ion processing system may be output , in
addi t ion to the effect of the second exemplary embodiment .
20 [0164]
This is because the query processing uni t 340 outputs a query
response 840 including informat ion concerning the relat ionship graph 820
that sat isfies the condi t ions included in the query 830.
[0165]
25 <<>>
Fig. 23 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing device 301 according to the present exemplary
modi ficat ion.
[0166]
39
The informat ion processing device 301 according to the present
exemplary modi ficat ion is di fferent f rom the informat ion processing
device 300 in that in the former the query response 840 is input to the
graph output uni t 320, as i l lust rated in Fig. 23.
[5 0167]
The graph output uni t 320 superimposes the informat ion of the
query response 840 to the query 830 on the relat ionship graph 820 which is
output from the graphing uni t 310 and the history accumulat ion uni t 230,
and outputs the obtained informat ion.
10 [0168]
Assume, for example, that a query 830 "when Send occurs f rom a
node P3 to a node P2, not i fy to that effect" is input as a quer y, and an event
simi lar to that i l lust rated in Fig. 11 occurs. Then, the graphing uni t 310
generates a relat ionship graph 820 based on the event , outputs i t to the
15 graph output uni t 320, and further outputs i t to the query processing uni t
340.
[0169]
The query processing uni t 340 searches for the relat ionship graph
820 based on the query 830 and outputs the detected informat ion (in this
20 case, "Send f rom the node P3 to the node P2") to the graph output uni t 320 .
[0170]
The graph output uni t 320 superimposes the relat ionship graph 820
and the detected informat ion on each other and outputs the relat ionship
graph 820 superimposed wi th the detected informat ion to, for example, a
25 display.
[0171]
Fig. 24 is a view i l lustrat ing an example of a network diagram
relat ionship graph 2425 ( relat ionship graph 820) superimposed wi th the
detected informat ion. When any query 830 is unavai lable, the output is
40
as i l lust rated in Fig. 7. However, when a query 830 is avai lable, as in the
present exemplary embodiment , an edge 2408 indicat ing Send f rom P3 to
P2 is highl ighted, as i l lust rated in Fig. 24. The highl ight ing method may
be, for example, display in a color di fferent f rom those of other edges,
bl inking, display wi th a change in type of l ine ( thickness or pat tern), o5 r
animat ion, but this method is not l imi ted to such specific examples.
[0172]
As an effect in the above-ment ioned present exemplary
modi ficat ion, the posi t ion of a port ion matching the query in the ent ire
10 relat ionship graph 820 may be recognizable at a glance.
[0173]
This is because the query processing uni t 340 outputs informat ion
concerning a relat ionship graph 820 cor responding to the query 830, and
the graph output uni t 320 outputs the relat ionship graph 820 superimposed
15 wi th the informat ion.
[0174]
<<>>
A fourth exemplary embodiment of the present invent ion wi l l be
described in detai l below wi th reference to the drawings. A descript ion
20 of detai ls which are the same as in the foregoing descript ion wi l l be
omi t ted hereinafter wi thin the range in which an explanat ion of the present
exemplary embodiment does not become unclear.
[0175]
Fig. 14 is a block diagram i l lust rat ing the configurat ion of an
25 informat ion processing device 400 according to the four th exemplary
embodiment of the present invent ion.
[0176]
The informat ion processing device 400 in the present exemplary
embodiment is di fferent f rom the informat ion processing device 100 in the
41
first exemplary embodiment in that the former includes a graphing uni t 410
in place of the graphing uni t 110 and further includes a mining uni t 450, as
i l lust rated in Fig. 14.
[0177]
===Graphing Uni t 410==5 =
The graphing uni t 410 further outputs a generated relat ionship
graph 820 to the mining uni t 450. The graphing uni t 410 is equivalent to
the graphing uni t 110 i l lustrated in Fig. 1 except for the aforement ioned
respect .
10 [0178]
===Mining Uni t 450===
The mining uni t 450 receives a mining request 850. The mining
uni t 450 executes analysis (mining) for the relat ionship graph 820 received
from the graphing uni t 410 based on the mining request 850. The mining
15 uni t 450 sends, as a response to the mining request 850, an analysis resul t
860 which is obtained as a resul t of the analysis .
[0179]
The mining request 850 designates detai ls of analysis executed for
the relat ionship graph 820. Examples of the detai ls of analysis include
20 graph clustering, frequently-appear ing pat tern detect ion, and betweenness
cent rality.
[0180]
Graph clustering is analysis for dividing the vert ices of the
relat ionship graph 820 into "communi t ies." For example, the vert ices of
25 the relat ionship graph 820 are divided into "communi t ies" such that sides
are densely populated between vert ices belonging to the same communi t ies
and sparsely populated between vert ices that do not belong to the same
communi t ies.
[0181]
42
Frequent ly-appearing pat tern detect ion is analysis for detect ing
pat terns of subgraphs f requent ly appearing in the relat ionship graph 820 .
For example, subgraph pat terns appearing at the fi rst to k-th highest
frequencies are extracted.
[5 0182]
Betweenness cent rality is analysis for obtaining the number of
t imes each vertex is posi t ioned midway on the shortest routes for al l pai rs
of vert ices. For example, the number of t imes corresponding to each
vertex is counted.
10 [0183]
The mining request 850 may designate detai ls of arbi trary mining
(also cal led graph mining, graph st ructure mining, or graph structure
analysis) wi thout l imi tat ion to the above -ment ioned examples.
[0184]
15 The mining uni t 450 executes mining for the relat ionship graph 820
generated by the graphing uni t 410 based on detai ls of analysis included in
the mining request 850. The mining uni t 450 outputs the mining
execut ion resul t as the analysis resul t 860.
[0185]
20 For example, the mining uni t 450 outputs the analysis resul t 860 via
the output uni t 705 i l lustrated in Fig. 8. The mining uni t 450 may further
send the analysis resul t 860 to a device (not i l lust rated) via the
communicat ion uni t 706 i l lust rated in Fig. 8. The mining uni t 450 may
even record the analysis resul t 860 on the recording medium 707 via the
25 storage device 703 i l lustrated in Fig. 8.
[0186]
The mining uni t 450 may be appl ied to the informat ion processing
device 200 i l lustrated in Fig. 2. In this case, the mining uni t 450 may
simi larly execute the above-ment ioned operat ion for the relat ionship graph
43
820 stored in the history accumulat ion uni t 230.
[0187]
As an effect in the above -ment ioned present exemplary embodiment ,
informat ion more appropriately indicat ing the state of an informat ion
processing system, which includes the data t ransmission relat ionshi5 p
between elements const i tut ing the informat ion processing system, may be
output , in addi t ion to the effect of the f irst exemplary embodiment .
[0188]
This is because the mining uni t 450 analyzes (mines) the
10 relat ionship graph 820 based on detai ls of analysis included in the mining
request 850 and outputs the resul t as an analysis resul t 860.
[0189]
<<>>
15 The technique according to the exemplary modificat ion to the thi rd
exemplary embodiment may be appl ied to the four th exemplary
embodiment .
[0190]
In other words, the analysis resul t 860 output f rom the mining uni t
20 450 in the present exemplary modif icat ion may be input to the graph output
uni t 120 in the present exemplary modi ficat ion . The graph output uni t
120 in the present exemplary modificat ion superimposes the informat ion of
the analysis resul t 860 on the relat ionship graph 820 output f rom the
graphing uni t 410 and outputs the obtained informat ion.
25 [0191]
As an effect in the above-ment ioned present exemplary
modi ficat ion, the posi t ion of a port ion matching the mining request 850 in
the ent ire relat ionship graph 820 may be recognizable at a glance.
[0192]
44
This is because the mining uni t 450 outputs informat ion concerning
a relat ionship graph 820 cor responding to the mining request 850, and the
graph output uni t 120 outputs the relat ionship graph 820 superimposed
wi th the informat ion.
[5 0193]
<<>>
Fig. 25 is a block diagram i l lust rat ing the configurat ion of an
informat ion processing device 401 according to the present exemplary
10 modi ficat ion.
[0194]
As a feature of the present exemplary modificat ion, the cur rent and
past relat ionship graphs 820 are analyzed individual ly and the respect ive
analysis resul ts are compared wi th each other to detect the di fference in
15 network state f rom the usual state.
[0195]
The informat ion processing device 40 1 according to the present
exemplary modi ficat ion includes a history accumulat ion uni t 430, a second
mining uni t 451, a comparison uni t 460, and a graph output uni t 420, as
20 wel l as a graphing uni t 410 and a fi rst mining uni t 450, as i l lust rated in Fig.
25.
[0196]
The graphing uni t 410 according to the present exemplary
modi ficat ion outputs the generated relat ionship graph 820 to the history
25 accumulat ion uni t 430 and the mining uni t 450.
[0197]
The history accumulat ion uni t 430 according to the present
exemplary modi ficat ion is equivalent to the history accumulat ion uni t 230
i l lust rated in Fig. 12 except that the former may be accessed even by the
45
mining uni t 451.
[0198]
The first mining uni t 450 receives a relat ionship graph 820 (current
relat ionship graph 820) f rom the graphing uni t 410 and analyzes the
current relat ionship graph 8205 .
[0199]
The second mining uni t 451 receives a relat ionship graph 820 (past
relat ionship graph 820) f rom the history accumulat ion uni t 430 and
analyzes the past relat ionship graph 820.
10 [0200]
The comparison uni t 460 compares the analysis resul ts obtained by
the fi rst mining uni t 450 and the second mining uni t 451 wi th each other,
extracts thei r di fference, and outputs the difference.
[0201]
15 The graph output uni t 420 superimposes the di fference on the
relat ionship graph 820 and outputs the obtained relat ion graph 820. For
example, the graph output uni t 420 outputs the relat ionship graph 820 wi th
its port ion cor responding to the di fference being highl ighted in the current
relat ionship graph 820 from the graphing uni t 410 or the past relat ionship
20 graph 820 from the history accumulat ion uni t 430 .
[0202]
As an effect in the above-ment ioned present exemplary
modi ficat ion, a port ion of the current relat ionship graph 820 stat ist ical ly
different f rom the past relat ionship graph 820, that is, a relat ionship graph
25 port ion di fferent f rom the usual one may be visual ly obviously
discriminable.
[0203]
This is because the fol lowing configurat ion is incorporated. First ,
each of the mining uni ts 450 and 451 analyzes the relat ionship graphs 820
46
respect ively received f rom the graphing uni t 410 and the history
accumulat ion uni t 430. Second, the comparison uni t 460 extracts the
difference between the analysis resul ts obtained by each of the mining
uni ts 450 and 451. Thi rd, the graph output uni t 420 displays the
relat ionship graph 820 further based on the di fference5 .
[0204]
<<>>
A fi fth exemplary embodiment of the present invent ion wi l l be
described in detai l below wi th reference to the drawings. A descript ion
10 of detai ls which are the same as in the foregoing descript ion wi l l be
omi t ted hereinafter wi thin the range in which an explanat ion of the present
exemplary embodiment does not become unclear.
[0205]
Fig. 15 is a block diagram i l lust rat ing t he configurat ion of an
15 informat ion processing device 500 according to the fi fth exemplary
embodiment of the present invent ion.
[0206]
The informat ion processing device 500 in the present exemplary
embodiment is di fferent f rom the informat ion processing device 100 in the
20 first exemplary embodiment in that the former includes a graph output uni t
520 in place of the graph output uni t 120, as i l lustrated in Fig. 15.
[0207]
===Graph Output Uni t 520===
The graph output uni t 520 generates and outputs a relat ionship
25 graph 820 represented in a diagram. The graph output uni t 520 is
equivalent to the graph output uni t 120 i l lustrated in Fig. 1 except for the
aforement ioned respect .
[0208]
Examples of the diagram include a network diagram and a matr ix.
47
An example of the relat ionship graph 820 represented in a diagram wi l l be
described below.
[0209]
Fig. 16 is a view i l lustrat ing a network diagram relat ionship graph
825 as a speci fic example of the relat ionship graph 820 represented in 5 a
network diagram, cor responding to the relat ionship graph 823 i l lust rated in
Fig. 11.
[0210]
Referr ing to Fig. 16, circles represent vert ices and character str ings
10 marked wi thin the ci rcles represent the vertex ident ifiers . Line segments
which connect the ci rcles to each other represent sides. A character
string (for example, [1] ) added to each side represents an at tr ibute for the
side.
[0211]
15 Fig. 17 is a view i l lustrat ing a mat rix relat ionship graph 826 as a
speci fic example of the relat ionship graph 820 represented in a mat rix,
corresponding to the relat ionship graph 823 i l lust rated in Fig. 11.
[0212]
Fig. 17 i l lust rates a mat rix having vert ices speci fied by a l ist of
20 vertex ident i fiers on the vert ical axis (leftmost vertex ident i fiers) as i ts
FROM (start) -side vert ices of the sides, and ver t ices specif ied by a l ist of
vertex ident i fiers on the horizontal axis (vertex ident i fiers on the top row)
as i ts TO (end) -side vert ices of the sides. Numerical values ( for example,
"1") in the cel ls of the mat rix represent the numbers of ac cesses f rom the
25 FROM-side vert ices to the TO-side vert ices.
[0213]
Fig. 18 is a view i l lustrat ing a network diagram relat ionship graph
827 as a speci fic example of the relat ionship graph 820 represented in a
network diagram, cor responding to the relat ionship graph 824 i l lust rated in
48
Fig. 6.
[0214]
Referr ing to Fig. 18, circles represent vert ices and character str ings
marked wi thin the ci rcles represent vertex ident i fiers. Line segments
which connect the ci rcles to each other represent sides5 .
[0215]
Fig. 19 is a view i l lustrat ing a mat rix relat ionship graph 828 as a
speci fic example of the relat ionship graph 820 represented in a mat rix,
corresponding to the relat ionship graph 824 i l lust rated in Fig. 6.
10 [0216]
Fig. 19 is a view i l lustrat ing a mat rix having vert ices specified by a
l ist of vertex ident i fiers on the vert ical axis (leftmost vertex ident i fiers) as
i ts FROM-side (request -side) vert ices of the sides, and vert ices specif ied
by a l ist of vertex ident i fiers on the horizontal axis (vertex ident i fiers on
15 the top row) as i ts TO-side (standby-side) vert ices of the sides.
Character st rings ( for example, "READ") in the cel ls of the matrix
represent the presence or absence (NL: the absence of sides, others: the
presence of sides) of sides f rom the FROM-side vert ices to the TO-side
vert ices or at t ributes (L0, L1, and L2).
20 [0217]
The matr ix may be of an arbi t rary type wi thout l imi tat ion to the
example i l lust rated in Fig. 19. The network diagram may also be of an
arbi t rary type wi thout l imi tat ion to the example i l lust rated in Fig. 18.
The graph output uni t 520 may output relat ionship graphs 820 represented
25 in arbi trary types of diagrams, freely in combinat ion or independent l y,
wi thout l imi tat ion to the above-ment ioned example.
[0218]
The graph output uni t 520 may be appl ied to the informat ion
processing device 200 i l lustrated in Fig. 12. In this case, the graph
49
output uni t 520 may simi larly generate and output a relat ionship graph 820
represented in a diagram, for the relat ionship graph 820 stored in the
history accumulat ion uni t 230.
[0219]
Simi larl y, the technique disclosed in the present exemplar5 y
embodiment may be appl ied to the informat ion processing device 200
i l lust rated in Fig. 13, the informat ion processing device 400 i l lustrated in
Fig. 14, the informat ion processing device 301 i l lust rated in Fig. 23, and
the informat ion processing device 401 i l lustrated in Fig. 25.
10 [0220]
<<>>
The graph output uni t 520 may output display informat ion
indicat ing a temporal change in relat ionship graph 820.
[0221]
15 The display informat ion may be, for example, informat ion
indicat ing a moving image of a change in state of the relat ionship graph
820. The display informat ion may further be informat ion indicat ing a
part icular ar rangement of the states of the relat ionship graph 820 avai lable
at a plural i ty of points in t ime.
20 [0222]
The display informat ion may be updated in real t ime in associat ion
wi th the current t ime. When the graph output uni t 520 is appl ied to the
informat ion processing device 200, the display informat ion may be
associated wi th the required t ime range.
25 [0223]
As an effect in the above -ment ioned present exemplary embodiment ,
a relat ionship graph 820 may be provided in a form easier for the user to
recognize, in addi t ion to the effect of the first exemplary embodiment .
[0224]
50
This is because the graph output uni t 520 generates and outputs a
relat ionship graph 820 represented in a diagram. Note also that the graph
output uni t 520 outputs display informat ion indicat ing a temporal change
in relat ionship graph 820.
[5 0225]
Al though the present invent ion has been described above wi th
reference to each exemplary embodiment , the present invent ion is not
l imi ted to the above-described exemplary embodiments. Various changes
which would be understood by those ski l led in the art may be made to the
10 configurat ions or detai ls of the present invent ion wi thin the scope of the
present invent ion.
[0226]
This appl icat ion claims priori ty based on Japanese Patent
Appl icat ion No. 2014-058496 fi led on March 20, 2014 and PCT
15 Internat ional Appl icat ion No. PCT/JP2014/003014 fi led on June 6, 2014,
the disclosure of which is incorporated herein by reference in thei r
ent i ret y.
[ Industrial Appl icabi l i ty]
[0227]
20 The present invent ion is appl icable to an informat ion processing
device which per forms , for example, configurat ion management ,
operat ional management , and securi ty management of an informat ion
processing system, a moni toring method, and a program therefor.
[Reference signs List]
25 [0228]
100 informat ion processing device
110 graphing uni t
120 graph output uni t
200 informat ion processing device
51
210 graphing uni t
220 graph output uni t
230 history accumulat ion uni t
300 informat ion processing device
301 informat ion processing devic5 e
310 graphing uni t
320 graph output uni t
340 query processing uni t
400 informat ion processing device
10 401 informat ion processing device
410 graphing uni t
420 graph output uni t
430 history accumulat ion uni t
450 mining uni t
15 451 mining uni t
460 comparison uni t
500 informat ion processing device
520 graph output uni t
700 computer
20 701 CPU
702 storage uni t
703 storage device
704 input uni t
705 output uni t
25 706 communicat ion uni t
707 recording medium
810 event log
811 event log
820 relat ionship graph
52
821 relat ionship graph
822 relat ionship graph
823 relat ionship graph
824 relat ionship graph
825 network diagram relat ionship grap5 h
826 mat rix relat ionship graph
827 network diagram relat ionship graph
828 mat rix relat ionship graph
830 query
10 840 query response
850 mining request
860 analysis resul t
900 system to be moni tored
901 system to be moni tored
15 910 host
911 host
920 process
930 event moni toring means
931 process generat ion moni toring means
20 932 fi le access moni toring means
933 intra-host interprocess communicat ion moni toring means
934 inter -host interprocess communicat ion moni toring means
940 arbi t rary device
941 router
25 942 sensor
943 printer
944 network device
2001 database
2002 t imer
53
2003 graph informat ion aggregat ion/reduct ion uni t
2004 cache
2408 edge
2425 network diagram relat ionship graph

WE CLAIM:
[CLAIM 1]
An informat ion processing device comprising:
graphing means for generat ing a relat ionship graph based on an
event log indicat ing a behavior of each of a plural i ty of processe5 s
operat ing in a system, the relat ionship graph including the processes as
vert ices thereof and including data t ransmission relat ionships between the
vert ices as sides thereof; and
graph output means for output t ing the relat ionship graph.
10 [CLAIM 2]
The informat ion process ing device according to claim 1, wherein
the system includes a plural i ty of hosts which are connected to each
other via a network and in which each arbi trary process of the processes
operates, and
15 the graphing means at least obtains the event log from a moni toring
agent located in each of the hosts.
[CLAIM 3]
The informat ion processing device according to claim 1 or 2,
wherein the graphing means fur ther generates the relat ionship graph
20 including the predetermined device as a vertex thereof based on an ev ent
log indicat ing a behavior of each of arbi t rary devices.
[CLAIM 4]
The informat ion processing device according to any one of claims 1
to 3, wherein the graphing means further generates the relat ionship graph
25 including an arbi t rary fi le and a device acc essed by the processes as the
vert ices, and the accesses as the sides.
[CLAIM 5]
The informat ion processing device according to any one of claims 1
to 4, wherein the graphing means further generates the relat ionship graph
Amendment under Article 19
55
including generat ion of a new process by the process as a side thereof.
[CLAIM 6]
The informat ion processing device according to any one of claims 1
to 5, wherein the graphing means generates the relat ionship graph
including the side aggregat ing the event log indicat ing a simi lar behavio 5 r.
[CLAIM 7]
The informat ion processing device according to claim 6, wherein a
cri terion for determining whether the event is normal or abnormal when a
new event occurs is calculated based on the relat ionship graph.
10 [CLAIM 8] (Amended)
The informat ion processing device according to claim 6 or 7,
wherein the graphing means sets informat ion of the simi lar behavior on the
side as an at t ribute for the side, .
[CLAIM 9]
15 The informat ion processing device according to any one of claims 6
to 8, wherein the graphing means deletes a speci fic side of the sides when
an event corresponding to the speci fic side has not occurred for a
predetermined period.
[CLAIM 10]
20 The informat ion processing device according to any one of claims 1
to 9, wherein the graphing means gene rates the relat ionship graph
including informat ion concerning a volume of transferred data on the side
as an at tribute for the side.
[CLAIM 11]
25 The informat ion processing device according to any one of claims 1
to 10, wherein the graphing means generates the relat ionship graph
including informat ion concerning the number of accesses on the side as an
at t ribute for the side.
[CLAIM 12]
56
The informat ion processing device according to any one of claims 1
to 11, wherein the graphing means generates the relat ionship graph
including types of the data t ransmission relat ionships individual ly as the
sides.
[CLAIM 135 ]
The informat ion processing device according to any one of claims 1
to 12, wherein the graphing means generates the relat ionship graph
including an arbi t rary combinat ion of the data transmission relat ionships
as the side.
10 [CLAIM 14]
The informat ion processing device according to any one of claims 1
to 13, wherein the graphing means generates the relat ionship graph based
on the event log selected based on an arbi trary cri terion.
[CLAIM 15]
15 The informat ion processing device according to any one of claims 1
to 14, wherein the side includes a property associated wi th a relat ionship
between the vert ices.
[CLAIM 16]
The informat ion processing device according to any one of claims 1
20 to 15, further comprising:
history accumulat ion means for storing the relat ionship graph as a
history relat ionship graph,
wherein the graphing means outputs the relat ionship graph to be
generated by updat ing the history relat ionship graph based on the history
25 relat ionship graph and the event log.
[CLAIM 17]
The informat ion processing device according to claim 16, wherein
the history accumulat ion means deletes the history relat ionship graph
based on elapse of t ime.
57
[CLAIM 18]
The informat ion processing device according to claim 17, wherein
the history accumulat ion means stochast ical ly deletes the history
relat ionship graph when the history relat ionship graph is deleted.
[CLAIM 195 ]
The informat ion processing device according to cla im 17 or 18,
wherein when the history relat ionship graph is deleted, the history
accumulat ion means aggregates informat ion included in the history
relat ionship graph to be deleted wi th the history relat ionship graph that is
10 not to be deleted.
[CLAIM 20]
The informat ion processing device according to any one of claims 1
to 19, further comprising: query processing means for receiving a query
and sending informat ion concerning the relat ionship graph corresponding
15 to the query.
[CLAIM 21]
The informat ion processing device according to claim 20, wherein
the query processing means outputs to the graph output means, the
informat ion concerning the relat ionship graph cor responding to the query,
20 and
the graph output means highl ights a port ion of the relat ionship
graph cor responding to the query.
[CLAIM 22]
The informat ion processing device according to any one of claims 1
25 to 21, further comprising: mining means for analyzing the relat ionship
graph based on a mining request and output t ing a resul t of the analysis.
[CLAIM 23]
The informat ion processing device according to claim 22, wherein
the mining means inputs the resul t of the analysis to the graph
58
output means, and
the graph input means highl ights a port ion of the relat ionship graph
corresponding to the mining request .
[CLAIM 24]
The informat ion processing device according to claim 22 or 235 ,
wherein
the mining means is first mining means for analyzing a cur rent
relat ionship graph and output t ing a resul t of the analysis, and
the informat ion processing device further compr ises:
10 second mining means for analyzing a past relat ionship graph and
output t ing a resul t of the analysis; and
comparison means for comparing the resul t of the analysis output
from the fi rst mining means and the resul t of the analysis output f rom the
second mining means wi th each other, based on one mining request of the
15 mining request , and output t ing a di f ference based on a resul t of the
comparison.
[CLAIM 25]
The informat ion processing device according to claim 24, wherein
the compar ison means inputs the di f ference to the graph output
20 means, and
the graph input means highl ights a port ion of the relat ionship graph
corresponding to the dif ference.
[CLAIM 26]
The informat ion processing device according to any one of claims
25 21, 23, and 25, wherein the graph output means highl ights the port ion by
using at least one of display in a di fferent color , bl inking, a di fferent l ine
thickness, a di f ferent l ine pat tern, and animat ion.
[CLAIM 27]
The informat ion processing device according to any one of claims 1
59
to 26, wherein the graph output uni t generates and outputs the relat ionship
graph represented in a diagram.
[CLAIM 28]
An informat ion processing system compr ising:
the informat ion processing device according to any one of claims 5 1
to 27; and
event moni toring means for moni toring an event of at least one of
process generat ion, f i le access, and interprocess communicat ion.
[CLAIM 29]
10 A moni toring method comprising:
generat ing a relat ionship graph based on an event log indicat ing a
behavior of each of a plural i ty of processes operat ing in a system, the
relat ionship graph including the processes as vert ices thereof and
including data t ransmission relat ionships between the ver t ices as sides
15 thereof; and
output t ing the relat ionship graph.
[CLAIM 30]
A non-volat i le, non- t ransi tory computer -readable recording
medium recording a program for causing a computer to execute the
20 processes of:
generat ing a relat ionship graph based on an event log indicat ing a
behavior of each of a plural i ty of processes op erat ing in a system, the
relat ionship graph including the processes as vert ices thereof and
including data t ransmission relat ionships between the ver t ices as sides
25 thereof; and
output t ing the relat ionship graph.

Documents

Application Documents

# Name Date
1 Priority Document [29-08-2016(online)].pdf 2016-08-29
2 Power of Attorney [29-08-2016(online)].pdf 2016-08-29
3 Form 5 [29-08-2016(online)].pdf 2016-08-29
4 Form 3 [29-08-2016(online)].pdf 2016-08-29
5 Form 18 [29-08-2016(online)].pdf_74.pdf 2016-08-29
6 Form 18 [29-08-2016(online)].pdf 2016-08-29
7 Form 1 [29-08-2016(online)].pdf 2016-08-29
8 Drawing [29-08-2016(online)].pdf 2016-08-29
9 Description(Complete) [29-08-2016(online)].pdf 2016-08-29
10 201617029363-Power of Attorney-020916.pdf 2016-09-05
11 201617029363-OTHERS-020916.pdf 2016-09-05
12 201617029363-Correspondence-020916.pdf 2016-09-05
13 abstract.jpg 2016-09-10
14 201617029363.pdf 2016-09-21
15 Other Patent Document [24-10-2016(online)].pdf 2016-10-24
16 201617029363-OTHERS-021116.pdf 2016-11-04
17 201617029363-Correspondence-021116.pdf 2016-11-04
18 Form 3 [18-01-2017(online)].pdf 2017-01-18
19 201617029363-FER.pdf 2021-10-17

Search Strategy

1 201617029363E_05-03-2020.pdf