IP Library Granted Patent US 12,457,236
Granted Patent B2
US 12,457,236 · App. 18/031,620 · Granted Oct 28, 2025

Determination device, determination method, and determination program

Inventors: Hiroki Nakano (Musashino, JP); Daiki Chiba (Musashino, JP)
Assignee: NTT, Inc.
H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,236
App. No.
18/031,620
Granted
Oct 28, 2025
Kind
B2
Abstract

A determination device includes processing circuitry configured to calculate a characteristic amount of user-generated content generated by a user in a predetermined period, perform learning by using the calculated characteristic amount of the user-generated content generated by a legitimate user and a characteristic amount of content generated by a malicious user, and determine whether the user-generated content is generated by the malicious user using a learned model.

Claims (10)

1. A determination device, comprising: processing circuitry configured to: calculate (i) first features of user-generated texts generated by legitimate users in a predetermined period and (ii) second features of user generated texts generated by a malicious user in the predetermined time period, the first and second features including (a) text features which represent characteristics of a combination of words co-occurring in a plurality of user-generated texts and (b) group features which represent a characteristic relating to word similarity between a plurality of user-generated texts generated in the predetermined period; train a model using the calculated first and second; and determine a particular user-generated text is generated by the malicious user using the trained model.

2. The determination device according to claim 1 , wherein the group features include any one or more of a size of a set, a number of users in the set, a number of unique URLs described in the set, an average number of URLs described in the user-generated content in the set, or an average posting time interval in the set.

3. A determination method performed by a determination device, comprising: calculating (i) first features of user-generated texts generated by legitimate users in a predetermined period and (ii) second features of user generated texts generated by a malicious user in the predetermined time period, the first and second features including (a) text features which represent characteristics of a combination of words co-occurring in a plurality of user-generated texts and (b) group features which represent a characteristic relating to word similarity between a plurality of user-generated texts generated in the predetermined period; training a model using the calculated first and second features; and determining a particular user-generated text is generated by the malicious user using the trained model.

4. A non-transitory computer-readable recording medium storing therein a determination program that causes a computer to execute a process comprising: calculate (i) first features of user-generated texts generated by legitimate users in a predetermined period and (ii) second features of user generated texts generated by a malicious user in the predetermined time period, the first and second features including (a) text features which represent characteristics of a combination of words co-occurring in a plurality of user-generated texts and (b) group features which represent a characteristic relating to word similarity between a plurality of user-generated texts generated in the predetermined period; train a model using the calculated first and second features; and determine a particular user-generated text is generated by the malicious user using the trained model.

5. The determination device according to claim 1 , wherein the processing circuitry is further configured to: access a URL described in the user-generated texts; and extract features relating to web content of a website reached via the accessed URL, the features extracted being used in training the model.

6. The determination device according to claim 1 , wherein the processing circuitry is further configured to: generate a search query using words appearing in the user-generated texts; and collect user-generated content from a plurality of services using the search query, the collected user-generated content being used to calculate the first and second features.

7. The determination device according to claim 1 , wherein the processing circuitry is further configured to: output attack features of the particular user-generated text as threat information when the particular user-generated text is determined to be generated by the malicious user.

8. The determination device according to claim 1 , wherein the group features include a characteristic amount representing a size of a set of user-generated texts grouped based on a time threshold value and a similarity threshold value.

9. The determination device according to claim 1 , wherein the group features include a characteristic amount representing a posting time of the plurality of user-generated texts generated in the predetermined period.

10. The determination device according to claim 1 , wherein to calculate the text features, the processing circuitry is further configured to: segment words of a URL and text within the user-generated texts; generate word embeddings for the segmented words; and average the word embeddings to represent the text features.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: NAKANO, HIROKI; CHIBA, DAIKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 063309/0509 →
Continuity (1)
Related Publication 20230388337A1 · Nov 30, 2023
References Cited (9)
US 9083729B1 · Doshi et al. · 2015 [cited by applicant]
US 20130197421A1 · Sharvit et al. · 2013 [cited by applicant]
US 20140283139A1 · Anand · 2014 [cited by examiner]
US 20200234109A1 · Lee et al. · 2020 [cited by applicant]
US 20210136089A1 · Costea · 2021 [cited by examiner]
CN 109472027A · 2019 [cited by applicant]
Gao et al., “Towards Online Spam Filtering in Social Networks”, Available Online At: http://cucis.ece.northwestern.edu/publications/pdf/GaoChe12.pdf, Jul. 27, 2019, 16 pages. [cited by applicant]
Lee et al., “WARNINGBIRD: Detecting Suspicious URLs in Twitter Stream”, Available Online At: https://www.ndss-symposium.org/wp-content/uploads/2017/09/11_1.pdf, Jul. 27, 2019, 13 pages. [cited by applicant]
Extended European Search Report issued Mar. 6, 2024 in European Patent Application No. 20957650.3, 7 pages. [cited by applicant]