IP Library Granted Patent US 12,500,913
Granted Patent B2
US 12,500,913 · App. 18/266,807 · Granted Dec 16, 2025

Classification device, classification method, and classification program

Inventors: Taishi Nishiyama (Musashino, JP); Kazunori Kamiya (Musashino, JP)
Assignee: NTT, Inc.
H04L63/1425H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,913
App. No.
18/266,807
Granted
Dec 16, 2025
Kind
B2
Abstract

A classification device includes processing circuitry configured to determine whether or not an input URL or domain is an existing benign URL or domain, output pseudo data determined not to be an existing benign URL or domain by the annotator unit among pseudo data of benign URLs or domains generated by a generator, add the pseudo data output by the data generation unit to learning data of a malicious URL or domain, and learn a classifier for classifying the input URL or domain as being malicious or benign using the learning data of the malicious URL or domain to which the pseudo data has been added.

Claims (40)

1 . A classification device comprising:

processing circuitry configured to:

generate, by a generator, pseudo data of benign uniform resource locators (URLs) or domains,

determine whether the generated pseudo data of the benign URLs or domains includes an existing benign URL or domain, including:

calculating, by a discriminator operating in a generative adversarial network (GAN) including the generator, a probability that a URL or domain of the generated pseudo data is the existing benign URL or domain,

when the probability is between a first value and a second value, determining whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon data external to the classification device,

when the probability is not between the first value and the second value, determining whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon the probability,

feeding back a result of the determination as to whether the URL or domain of the generated pseudo data is the existing benign URL or domain to the generator and the discriminator, and

when the probability is less than a predetermined threshold value, determining that the URL or domain of the generated pseudo data is not the existing benign URL or domain;

add the generated pseudo data of the benign URLs or domains determined not to include the existing benign URL or domain to learning data of a malicious URL or domain; and

learn a classifier for classifying an input URL or domain as being malicious or benign using the learning data of the malicious URL or domain to which the generated pseudo data has been added.

2 . The classification device according to claim 1 , wherein the processing circuitry is further configured to classify the input URL or domain as being malicious or benign using the classifier.

3 . The classification device according to claim 1 , wherein the processing circuitry is further configured to determine whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon data external to the classification device by performing processing for searching for a domain name referring to a management service of a predetermined domain name or processing for searching for an URL using a search engine.

4 . The classification device according to claim 1 , wherein to determine whether the generated pseudo data of the benign URLs or domains includes the existing benign URL or domain the processing circuitry is further configured to:

learn a model for determining whether the generated pseudo data of the benign URLs or domains includes the existing benign URL or domain or pseudo data through active learning using a result of determination; and

add the generated pseudo data of the benign URLs or domains determined not to include the existing benign URL or domain by the model.

5 . The classification device according to claim 4 , wherein

the processing circuitry is further configured to learn the model through active learning using:

information in which information on an URL or domain determined to be an existing benign URL or domain has been added to information on a benign URL or domain, and

information in which information on an URL or domain determined not to be an existing benign URL or domain has been added to the generated pseudo data.

6 . A classification method executed by a classification device, the classification method comprising:

generating, by a generator, pseudo data of benign uniform resource locators (URLs) or domains,

determining whether the generated pseudo data of the benign URLs or domains includes an existing benign URL or domain, including:

calculating, by a discriminator operating in a generative adversarial network (GAN) including the generator, a probability that a URL or domain of the generated pseudo data is the existing benign URL or domain,

when the probability is between a first value and a second value, determining whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon data external to the classification device,

when the probability is not between the first value and the second value, determining whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon the probability,

feeding back a result of the determination as to whether the URL or domain of the generated pseudo data is the existing benign URL or domain to the generator and the discriminator, and

when the probability is less than a predetermined threshold value, determining that the URL or domain of the generated pseudo data is not the existing benign URL or domain;

adding the generated pseudo data of the benign URLs or domains determined not to include the existing benign URL or domain to learning data of a malicious URL or domain; and

learning a classifier for classifying an input URL or domain as being malicious or benign using the learning data of the malicious URL or domain to which the generated pseudo data has been added.

7 . A non-transitory computer-readable recording medium storing therein a classification program that causes a computer to execute a process comprising:

generating, by a generator, pseudo data of benign uniform resource locators (URLs) or domains,

determining whether the generated pseudo data of the benign URLs or domains includes an existing benign URL or domain, including:

calculating, by a discriminator operating in a generative adversarial network (GAN) including the generator, a probability that a URL or domain of the generated pseudo data is the existing benign URL or domain,

when the probability is between a first value and a second value, determining whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon data external to the classification device,

when the probability is not between the first value and the second value, determining whether the URL or domain of the generated pseudo data is the existing benign URL or domain based upon the probability,

feeding back a result of the determination as to whether the URL or domain of the generated pseudo data is the existing benign URL or domain to the generator and the discriminator, and

when the probability is less than a predetermined threshold value, determining that the URL or domain of the generated pseudo data is not the existing benign URL or domain;

adding the generated pseudo data of the benign URLs or domains determined not to include the existing benign URL or domain to learning data of a malicious URL or domain; and

learning a classifier for classifying an input URL or domain as being malicious or benign using the learning data of the malicious URL or domain to which the generated pseudo data has been added.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2023
From: NISHIYAMA, TAISHI; KAMIYA, KAZUNORI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 063929/0318 →
Continuity (1)
Related Publication 20240048577A1 · Feb 8, 2024
References Cited (12)
US 7698442B1 · Krishnamurthy · 2010 [cited by examiner]
US 8806622B2 · Waterson · 2014 [cited by examiner]
US 8856937B1 · Wuest · 2014 [cited by examiner]
US 10104113B1 · Stein · 2018 [cited by examiner]
US 20160261608A1 · Hu · 2016 [cited by examiner]
US 20170353480A1 · Gao · 2017 [cited by examiner]
US 20200151481A1 · Yoo · 2020 [cited by examiner]
US 20200242407A1 · Gandhi · 2020 [cited by examiner]
US 20220182410A1 · Tupsamudre · 2022 [cited by examiner]
Anderson et al., “DeepDGA: Adversarially-Tuned Domain Generation and Detection”, arXiv:1610.01969v1, Proceedings of the ACM Workshop on Artificial Intelligence and Security, Oct. 6, 2016, pp. 13-21. [cited by applicant]
Gould et al., “Domain Generation Algorithm Detection Utilizing Model Hardening Through GAN-Generated Adversarial Examples”, Part of the Communications in Computer and Information Science book series (CCIS), vol. 1271, 2… [cited by applicant]
Yun et al., “Khaos: An Adversarial Neural Network DGA with High Anti-Detection Ability”, IEEE Transactions on Information Forensics and Security, vol. 15, 2020, pp. 2225-2240. [cited by applicant]