CPC H04L 63/1425 (2013.01) [H04L 43/04 (2013.01); H04L 43/16 (2013.01)] | 8 Claims |
1. An abnormality detection device comprising:
a memory; and
a processor coupled to the memory and programmed to execute a process comprising:
acquiring a communication feature for normal communication of communication equipment;
amplifying, if a data count or a data acquisition period for the acquired communication feature exceeds a predetermined value, the data count for a communication feature by a plurality of predetermined schemes in accordance with data counts for respective groups, each group sharing a same 5-tuple;
creating, for each of the predetermined schemes, reference value information for normal communication of the communication equipment through learning using the amplified communication feature;
determining accuracy of abnormality detection for each of the predetermined schemes using an anomaly score representing a deviation of test data representing a communication feature for abnormal communication from the reference value information; and
selecting the reference value information created by one of the schemes, the determined accuracy for which is highest.
|