IP Library Granted Patent US 12,592,963
Granted Patent B2
US 12,592,963 · App. 18/031,616 · Granted Mar 31, 2026

Detection device, detection method, and detection program

Inventors: Hiroki Nakano (Musashino, JP); Daiki Chiba (Musashino, JP)
Assignee: NTT, Inc.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,963
App. No.
18/031,616
Granted
Mar 31, 2026
Kind
B2
Abstract

A detection device includes processing circuitry configured to acquire user generated content generated in each service in a predetermined period, generate a search query using words appearing in the user generated content for each service, collect the user generated content generated in a plurality of services using the generated search query, calculate a feature amount of the collected user generated content of a predetermined service, perform learning using the feature amount of the user generated content generated by a normal user and a feature amount of content generated by a malicious user, determine whether the user generated content is generated by a malicious user based on a learned model, and access an entrance URL described in the user generated content and output a feature of an attack of the user generated content as threat information when the user generated content is determined to be generated by a malicious user.

Claims (53)

1 . A detection device, comprising:

processing circuitry configured to:

obtain user generated texts generated in an online service in a predetermined period;

extract a key phrase from the user generated texts, wherein the key phrase is a phrase representing a similar context that the user generated texts have;

generate a search query using words appearing in the key phrase;

calculate a degree of malignancy of the generated search query;

determine whether the degree of malignancy satisfies a threshold;

in response to a determination that the degree of malignancy satisfies the threshold, select the generated search query as a query for searching user generated texts generated by a malicious user;

collect, using the selected search query, user generated texts generated by the malicious user in another online service;

calculate features of the user generated texts generated by the malicious user;

calculate features of user generated texts generated by normal users in the other online service;

train a model using (i) the features of the user generated texts generated by the normal users and (ii) the features of the user generated texts generated by the malicious user;

determine whether a particular user generated text is generated by the malicious user based on the trained model; and

in response to a determination that the particular user generated text is generated by the malicious user:

access an entrance URL described in the particular user generated text; and

output a feature of an attack of the particular user generated text as threat information.

2 . The detection device according to claim 1 , wherein the processing circuitry is further configured to select a search query that may become malicious for each service.

3 . The detection device according to claim 1 , wherein the features of the user generated texts generated by the malicious user and the features of the user generated texts generated by the normal users include:

a text feature representing a combination of words co-occurring in a plurality of pieces of user generated content, and

a group feature related to similarity of words between the plurality of pieces of user generated content generated in a predetermined period.

4 . The detection device according to claim 1 , wherein the features of the user generated texts generated by the malicious user and the features of the user generated texts generated by the normal users include:

a feature related to Web content of an arrival web site at which a user will arrive, and

features related to a plurality of pieces of user generated content generated in a predetermined period.

5 . A detection method which is executed by a detection device, the detection method comprising:

obtaining user generated texts generated in an online service in a predetermined period;

extracting a key phrase from the user generated texts, wherein the key phrase is a phrase representing a similar context that the user generated texts have;

generating a search query using words appearing in the key phrase;

calculating a degree of malignancy of the generated search query;

determining whether the degree of malignancy satisfies a threshold;

in response to a determination that the degree of malignancy satisfies the threshold, selecting the generated search query as a query for searching user generated texts generated by a malicious user;

collecting, using the selected search query, user generated texts generated by the malicious user in another online service;

calculating features of the user generated texts generated by the malicious user;

calculating features of user generated texts generated by normal users in the other online service;

training a model using (i) the features of the user generated texts generated by the normal users and (ii) the features of the user generated texts generated by the malicious user;

determining whether a particular user generated text is generated by the malicious user based on the trained model; and

in response to a determination that the particular user generated text is generated by the malicious user:

accessing an entrance URL described in the particular user generated text; and

outputting a feature of an attack of the particular user generated text as threat information.

6 . A non-transitory computer-readable recording medium storing therein a detection program that causes a computer to execute a process comprising:

obtaining user generated texts generated in an online service in a predetermined period;

extracting a key phrase from the user generated texts, wherein the key phrase is a phrase representing a similar context that the user generated texts have;

generating a search query using words appearing in the key phrase;

calculating a degree of malignancy of the generated search query;

determining whether the degree of malignancy satisfies a threshold;

in response to a determination that the degree of malignancy satisfies the threshold, selecting the generated search query as a query for searching user generated texts generated by a malicious user;

collecting, using the selected search query, user generated texts generated by the malicious user in another online service;

calculating features of the user generated texts generated by the malicious user;

calculating features of user generated texts generated by normal users in the other online service;

training a model using (i) the features of the user generated texts generated by the normal users and (ii) the features of the user generated texts generated by the malicious user;

determining whether a particular user generated text is generated by the malicious user based on the trained model; and

in response to a determination that the particular user generated text is generated by the malicious user:

accessing an entrance URL described in the particular user generated text; and

outputting a feature of an attack of the particular user generated text as threat information.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: NAKANO, HIROKI; CHIBA, DAIKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 063309/0431 →
Continuity (1)
Related Publication 20230379359A1 · Nov 23, 2023
References Cited (20)
US 9083729B1 · Doshi et al. · 2015 [cited by applicant]
US 9298824B1 · Vinnik · 2016 [cited by examiner]
US 10078750B1 · Oliver · 2018 [cited by examiner]
US 10104113B1 · Stein · 2018 [cited by examiner]
US 10896473B2 · Hüffner · 2021 [cited by examiner]
US 11868722B1 · Tully · 2024 [cited by examiner]
US 20100095375A1 · Krishnamurthy · 2010 [cited by examiner]
US 20130124644A1 · Hunt · 2013 [cited by examiner]
US 20130179421A1 · Jeong et al. · 2013 [cited by applicant]
US 20190014148A1 · Foster · 2019 [cited by examiner]
US 20190356681A1 · Sandke · 2019 [cited by examiner]
US 20200234109A1 · Lee et al. · 2020 [cited by applicant]
US 20210312041A1 · Gururajan · 2021 [cited by examiner]
CN 109472027A · 2019 [cited by applicant]
CN 110427754A · 2019 [cited by examiner]
CN 107341268B · 2020 [cited by examiner]
Invernizzi, et al., “EVILSEED: A Guided Approach to Finding MaliciousWeb Pages”, Available Online At: https://sites.cs.ucsb.edu/˜vigna/publications/2012_SP_Evilseed.pdf, Retrieved from the net on: Jul. 27, 2020, 15 page… [cited by applicant]
Gao et al., “Towards Online Spam Filtering in Social Networks”, Available Online At: http://cucis.ece.northwestern.edu/publications/pdf/GaoChe12.pdf, Retrieved from the net on: Jul. 27, 2020, 16 pages. [cited by applicant]
Lee et al., “WARNINGBIRD: Detecting Suspicious URLs in Twitter Stream”, Available Online At: https://www.ndss-symposium.org/wp-content/uploads/2017/09/11_1.pdf, Retrieved from the net on: Jul. 27, 2020, 13 pages. [cited by applicant]
Rafique et al., “It's Free for a Reason: Exploring the Ecosystem of Free Live Streaming Services”, NDSS '16, Available Online At: https://www.ndss-symposium.org/wp-content/uploads/2017/09/free-reason-exploring-ecosystem… [cited by applicant]