IP Library Granted Patent US 12,388,785
Granted Patent B2
US 12,388,785 · App. 17/491,209 · Granted Aug 12, 2025

User sentiment analysis for URL reputations

Inventors: John Wagener (West Lakeland, MN); Joanna Negrete (Brentwood, CA)
Assignee: McAfee, LLC
H04L63/0236G06F40/40G06N3/04H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,785
App. No.
17/491,209
Granted
Aug 12, 2025
Kind
B2
Abstract

A computing apparatus includes a hardware platform comprising a processor and a memory; and instructions encoded within the memory to receive a user-generated comment related to a uniform resource locator (URL); analyze the comment with a trained machine learning (ML) model to determine a user sentiment for the comment; assign a predicted reputation to the URL according to the user sentiment; and use the predicted reputation as an input to an analysis of the URL.

Claims (36)

1. A computing apparatus, comprising:

a hardware platform comprising a processor circuit and a memory; and

instructions encoded within the memory to:

receive a human-generated comment including a user sentiment about a uniform resource locator (URL);

analyze the human-generated comment with a trained machine learning (ML) model to determine the user sentiment, wherein the user sentiment relates to whether the URL hosts malicious or phishing content;

after analyzing the human-generated comment, assign a predicted reputation to the URL based on the analysis by the machine learning model;

compute a security reputation for the URL, wherein the security reputation accounts for a probability that the URL hosts malicious or phishing content and is based on a feature vector including a plurality of features, wherein the feature vector includes the predicted reputation as one of the plurality of features; and

update a cloud-based URL reputation service with the computed security reputation.

2. The computing apparatus of claim 1 , wherein the ML model is a convolutional neural network.

3. The computing apparatus of claim 1 , wherein the instructions are further to vectorize the human-generated comment by applying a term frequency-inverse document frequency (TF-IDF) vectorizer.

4. The computing apparatus of claim 3 , wherein vectorizing the human-generated comment comprises parsing the human-generated comment into equal length vectors.

5. The computing apparatus of claim 1 , wherein the instructions are further to assign a sentiment strength to the human-generated comment.

6. The computing apparatus of claim 5 , wherein the instructions are further to provide the sentiment strength as a feature input to computing the security reputation for the URL.

7. The computing apparatus of claim 5 , wherein the instructions are to preserve capitalization and punctuation of the human-generated comment.

8. The computing apparatus of claim 1 , wherein the instructions are further to assign a collective sentiment score to a plurality of human-generated comments related to the URL.

9. The computing apparatus of claim 8 , wherein the instructions are to ignore the user sentiment if the user sentiment deviates from the collective sentiment score beyond a threshold.

10. The computing apparatus of claim 9 , wherein the threshold is a selected number of standard deviations.

11. A computer-implemented method of assigning a reputation to a uniform resource locator (URL), comprising:

receiving a human-generated comment including a user sentiment about a uniform resource locator (URL);

analyzing the human-generated comment with a trained machine learning (ML) model to determine the user sentiment, wherein the user sentiment relates to whether the URL hosts malicious or phishing content;

after analyzing the human-generated comment, assign a predicted reputation to the URL based on the analysis by the machine learning model;

computing a security reputation for the URL, wherein the security reputation accounts for a probability that the URL hosts malicious or phishing content and is based on a feature vector including a plurality of features, wherein the feature vector includes the predicted reputation as one of the plurality of features; and

updating a cloud-based URL reputation service with the computed security reputation.

12. The method of claim 11 , further comprising vectorizing the human-generated comment by applying a term frequency-inverse document frequency (TF-IDF) vectorizer.

13. The method of claim 11 , further comprising assigning a sentiment strength to the human-generated comment.

14. The method of claim 13 , further comprising providing the sentiment strength as a feature input to computing the security reputation for the URL.

15. The method of claim 11 , further comprising assigning a collective sentiment score to a plurality of human-generated comments related to the URL.

16. The method of claim 15 , further comprising ignoring the user sentiment if the user sentiment deviates from the collective sentiment score beyond a threshold.

17. The method of claim 16 , wherein the threshold is a selected number of standard deviations.

18. One or more tangible, non-transitory computer-readable storage media having stored thereon executable instructions that, when executed by at least one processor, cause a computer system to:

receive a human-generated comment including a user sentiment about a uniform resource locator (URL);

analyze the human-generated comment with a trained machine learning (ML) model to determine the user sentiment, wherein the user sentiment relates to whether the URL hosts malicious or phishing content;

after analyzing the human-generated comment, assign a predicted reputation to the URL based on the analysis by the machine learning model;

compute a security reputation for the URL, wherein the security reputation accounts for a probability that the URL hosts malicious or phishing content and is based on a feature vector including a plurality of features, wherein the feature vector includes the predicted reputation as one of the plurality of features; and

update a cloud-based URL reputation service with the computed security reputation.

19. The one or more tangible, non-transitory computer-readable storage media of claim 18 , wherein the executable instructions are further to vectorize the human-generated comment by applying a term frequency-inverse document frequency (TF-IDF) vectorizer.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: WAGENER, JOHN; NEGRETE, JOANNA
To: MCAFEE, LLC
Reel/Frame 057662/0184 →
Continuity (1)
Related Publication 20230106639A1 · Apr 6, 2023
References Cited (5)
US 20050289520A1 · Overall · 2005 [cited by examiner]
US 20160328401A1 · Dhawan · 2016 [cited by examiner]
US 20210006592A1 · Heyman · 2021 [cited by examiner]
US 20210334466A1 · Campos Ortega · 2021 [cited by examiner]
US 20220358529A1 · Rawat · 2022 [cited by examiner]