Information processing apparatus and program
The information processing device addresses spoofing by calculating an index value based on message similarity analysis, enhancing user detection of impersonation attempts and protecting against account hijacking.
Patent Information
- Application Number
- JP2024114357
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-17
- Publication Date
- 2026-01-29
- Estimated Expiration
- 2044-07-17
AI Technical Summary
Spoofing in communication services poses a significant threat, leading to privacy violations, financial misuse, and credibility damage, as attackers impersonate legitimate users by hijacking accounts to send messages or emails.
An information processing device calculates an index value indicating the likelihood of spoofing by analyzing message similarities using natural language processing and similarity calculations, providing users with an 'impersonation index value' to determine message authenticity.
The solution effectively quantifies the similarity between messages, enabling users to identify potential spoofing attempts and protect against impersonation.
Smart Images

Figure 2026013780000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device and a program. [Background technology]
[0002] As the Internet has become more widespread, spoofing has become a serious problem for individuals and organizations. For example, in messenger services, spoofing refers to an attacker taking over a social networking service account and sending a message pretending to be the legitimate user who owns the account. In short message services, spoofing refers to an attacker spoofing a phone number and sending a short message pretending to be the legitimate user who owns the phone number. In email services, spoofing an email address and sending an email pretending to be the legitimate user who owns the email address.
[0003] If personal information is obtained illegally through impersonation, it can lead to violations of privacy and the misuse of personal financial information.If a company falls victim to impersonation, it can suffer damage to its credibility and brand image, and the digital assets of individuals and organizations can be put at risk in connection with phishing scams and the distribution of malware, among other damages. Summary of the Invention [Problem to be solved by the invention]
[0004] The purpose is to provide information that allows users to recognize the possibility of impersonation. [Means for solving the problem]
[0005] The information processing device according to this embodiment includes a receiving unit that receives messages from a user terminal via a specific SNS account, a calculation unit that calculates multiple similarities of a message to multiple past messages received via the SNS account, and a calculation unit that calculates, based on the similarities, an index value that indicates the likelihood that the message was sent by someone who illegally obtained the SNS account and impersonated a legitimate user who owns the SNS account. [Brief explanation of the drawings]
[0006] [Figure 1] FIG. 1 is a configuration diagram of an entire system including an information processing device according to the first embodiment (messenger service). [Figure 2] FIG. 2 is a diagram showing the physical configuration of the information processing apparatus of FIG. [Figure 3] FIG. 3 is a diagram illustrating a functional configuration of a processor of the information processing device of FIG. [Figure 4] FIG. 4 is a diagram showing the data flow of the entire system of FIG. 1 and the processing of the information processing device. [Figure 5] FIG. 5 is a diagram showing an example of a display of the "spoofing index value" on the messenger screen in step S15 of FIG. [Figure 6] FIG. 6 is a diagram showing an example of the feature amount (N-dimensional vector) in step S12 of FIG. [Figure 7] FIG. 7 is a diagram showing the calculation process of the "spoofing index value" in steps S11 to S14 of FIG. [Figure 8] FIG. 8 is a configuration diagram of an entire system including an information processing device according to the second embodiment (messenger service). [Figure 9] FIG. 9 is a diagram illustrating a functional configuration of a processor of the information processing device of FIG. [Figure 10] FIG. 10 is a diagram showing the data flow of the entire system of FIG. 8 and the processing of the information processing device. [Figure 11]FIG. 11 is a configuration diagram of an entire system including an information processing device according to the third embodiment (short mail service). [Figure 12] FIG. 12 is a diagram showing the data flow of the entire system of FIG. 11 and the processing of the information processing device. [Figure 13] FIG. 13 is a diagram showing an example of a display that displays the "spoofing index value" in step S35 of FIG. [Figure 14] FIG. 14 is a configuration diagram of an entire system including an information processing device according to the fourth embodiment (email service). [Figure 15] FIG. 15 is a diagram showing the data flow of the entire system of FIG. 14 and the processing of the information processing device. [Figure 16] FIG. 16 is a diagram showing an example of a display that displays the "spoofing index value" in step S45 of FIG. DETAILED DESCRIPTION OF THE INVENTION
[0007] The present embodiment will be described below with reference to the drawings. In the following description, components having substantially the same functions and configurations are designated by the same reference numerals, and redundant description will be given only when necessary.
[0008] "Spoofing" refers to, for example, illegally obtaining another person's social media account and falsifying a phone number or email address to send messages, short messages, or emails pretending to be that person. When a user receives a message from a known account or a short message or email with a known email address or phone number, the user may not be sure whether the message is the result of "spoofing" or whether it is actually from the legitimate person. This embodiment is characterized by calculating an index value that indicates the likelihood that a message is the result of "spoofing," presenting it to the user, and allowing the user to use it as information to determine whether the message is the result of "spoofing." (First embodiment) This embodiment deals with "impersonation" in messenger services provided by social networking services (hereinafter referred to as "SNS") such as Facebook (registered trademark), LINE (registered trademark), etc. "Impersonation" in messenger services refers to, for example, an attacker (user C) illegally obtaining the SNS account of a certain user (user B) by hijacking or the like, and sending a message to another person (user A) while pretending to be the legitimate user (user B) who owns the SNS account.
[0009] As shown in FIG. 1, an information processing device 1 serving as a computer according to this embodiment is connected to a social networking service (hereinafter referred to as "SNS") server 2 that provides a messenger service linked to the SNS and user terminals 3-1, 3-2, and 3-3 via a communication network, typically the Internet network 4. User terminal 3-1 refers to a terminal owned by a user (user A) who receives a potentially "spoofed" message. User terminal 3-2 refers to a terminal owned by a legitimate user (user B) who owns the above-mentioned SNS account. User terminal 3-3 refers to a terminal owned by an attacker (user C) who illegally obtains the above-mentioned SNS account by hijacking or the like and sends a message to user A while impersonating the legitimate user (user B).
[0010] 2, in the information processing device 1, a RAM 12, a ROM 13, a storage unit 14, an input device 15, a display 16, and a communication unit 17 are connected to a processor 11 via a system bus 10. The processor 11 is configured by, for example, a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit).
[0011] The memory unit 14 stores an operating system program (OS), an "impersonation index value" calculation processing program configured to calculate an index value that indicates the possibility that an SNS account has been illegally obtained and a message has been sent to user A by impersonating legitimate user B who owns the SNS account, other programs for realizing various functions, and various data required for these processes.
[0012] By executing the "impersonation index value calculation processing program" loaded from the memory unit 14 to the RAM 12, the processor 11 calculates an index value that indicates the possibility that an SNS account has been illegally obtained and a message has been sent to user A by impersonating legitimate user B who owns the SNS account.
[0013] The RAM 12 functions as the main memory, work area, etc. of the processor 11. The ROM 13 stores the BIOS (Basic Input Output System), etc. The input device 15 includes a keyboard (KB), a mouse, a touch panel, or other pointing device, etc. The display 19 is typically realized by an LCD (Liquid Crystal Display).
[0014] As shown in Figure 3, the processor 11 executes the "impersonation index value" calculation processing program, thereby functioning as a control unit 21, a message receiving unit 22, a natural language analysis processing unit 23, a feature calculation unit 24, a similarity calculation unit 25, an impersonation index value calculation unit 26, and an impersonation index value transmission unit 27.
[0015] The message receiving unit 22 receives from the user terminal 3-1 of user A a request for the "spoofing index value" related to the latest message received from the user terminal 3-1 using user B's account as the sender, along with the latest message (the most recently received message) and past messages received by the user terminal 3-1 of user A using user B's account as the sender. In practice, an extension installed on the user terminal 3-1, for example, as an SNS app or a browser plug-in, exports the latest message and past messages received using user B's SNS account as the sender and transmits them to the information processing device 1. From the perspective of improving the reliability of the "spoofing index value," it is preferable that all past messages be transmitted as past messages. However, the number of past messages to be transmitted is arbitrary; for example, the most recent 100 messages may be transmitted. The data of the latest message and past messages are stored in the storage unit 14, along with a message ID for identifying the message.
[0016] The natural language analysis processor 23 performs natural language analysis on each message, including the latest message and past messages, extracts words from the messages, assigns parts of speech (nouns, verbs, adjectives, etc.), and performs syntactic analysis. The feature calculation unit 24 calculates features reflecting content and syntactic features, such as the words and parts of speech appearing in each message, as well as sentence structure, vocabulary choice, rhythm, tone, and narrative style, as an N-dimensional vector based on the results of the natural language analysis. The feature calculation method may be any conventional method used in natural language analysis, such as "Bag of Words (BoW)," which counts the number of times a word appears in a sentence; "TF-IDF (Term Frequency-Inverse Document Frequency)," which calculates the importance of words by weighting them based on the frequency and inverse document frequency of the words appearing in the sentence; or "Word Embedding," which vectorizes words by taking into account their semantic similarity. Alternatively, the inventor's own method may be employed.
[0017] The inventor's unique method involves classifying a large number of word-part-of-speech pairs that may appear in a message into N types based on their meaning, and assigning each type to an axis in an N-dimensional space. The N axes in the N-dimensional space are ordered and arranged according to the semantic proximity of the corresponding type. On each of the N axes in the N-dimensional space, a large number of word-part-of-speech pairs representing specific subconcepts belonging to the assigned type are ordered according to their mutual semantic proximity, and each is pre-assigned a numerical value (coordinate value). An axis in the N-dimensional space is identified for each word-part-of-speech pair extracted from the message, and the word-part-of-speech pair extracted from the message is compared with the many word-part-of-speech pairs on that axis, and the coordinate value assigned to the corresponding word-part-of-speech pair is obtained. When multiple coordinate values are assigned to the same axis, the average value, etc., is calculated. By identifying the axis and the coordinate values on that axis for all multiple word-part-of-speech pairs extracted from the message, an N-dimensional vector is determined as a feature of the message.
[0018] The similarity calculation unit 25 calculates the similarity of the latest message to each of the past messages individually based on the feature amounts of the past messages and the latest message, i.e., the same number of similarities as the number of past messages are calculated.
[0019] For example, the similarity is calculated as cosine similarity CSn as shown in the following formula. Cosine similarity CSn is an index for evaluating the similarity between two vectors, and is expressed in the range of -1.0 to +1.0. The closer it is to +1.0, the closer the content features and syntactic features of the latest message are to past messages, and the higher the similarity, and the closer it is to -1.0, the lower the similarity of the latest message to past messages.
[0020] The N-dimensional vector representing the feature of the latest message is denoted as F0, and the N-dimensional vector representing the feature of past messages is denoted as Fn (n is a natural number greater than or equal to 1 that distinguishes past messages). F1 represents the past message received just before the latest message, F2 represents the past message received just before the past message F1, and so on, with item numbers being assigned going backward.
[0021] CSn=(F0·Fn) / (||F0||×||Fn||) F0·Fn is the dot product of vector F0 and vector Fn ||F0|| is the norm of vector F0 (vector length) ||Fn|| is the norm of vector Fn (vector length) The similarity is not limited to the cosine similarity CSn, but may be the Euclidean distance indicating the linear distance between two vectors F0 and Fn, or other similarity.
[0022] The spoofing index calculation unit 26 calculates an "spoofing index" that indicates the possibility that an SNS account has been illegally obtained and a message has been sent by impersonating a legitimate user who owns the SNS account, based on the multiple similarities CSn. For each of the multiple similarities CSn, the range that it can take (-1.0 to +1.0) is scaled to (100% to 0%), and the average, minimum, median, etc. of these values is determined as the "spoofing index."
[0023] In this case, the closer the "spoofing index value" is to 100%, the more likely the latest message is a spoof, and the closer it is to 0%, the less likely the latest message is a spoof. Note that the range of similarity CSn (-1.0 to +1.0) that it can take may be scaled to (0% to 100%), so that the closer the "spoofing index value" is to 0%, the more likely the latest message is a spoof, and the closer it is to 100%, the less likely the latest message is a spoof.
[0024] The "spoofing index value" can quantify and determine the degree to which the content and syntactic features of the latest message received via the same account are similar to or different from previous messages. The closer the "spoofing index value" is to 0%, the more the content and syntactic features of the latest message are different from previous messages, and therefore it can be determined that the latest message is more likely to be a spoof. On the other hand, the closer the "spoofing index value" is to 100%, the more the content and syntactic features of the latest message are similar to previous messages, and therefore it can be determined that the latest message is less likely to be a spoof.
[0025] The spoofing index value sending unit 27 sends the calculated "spoofing index value" data to the user terminal 3-1 of user A together with a message ID that identifies the message represented by the "spoofing index value." The user terminal 3-1 displays the transmitted "spoofing index value," typically near the most recent message, in a state in which the correspondence between the transmitted "spoofing index value" and the most recent message represented by the "spoofing index value" can be easily determined. The user terminal 3-1 stores all "spoofing index values" that have been transmitted up to that point, and displays all "spoofing index values" near the corresponding messages. This allows the user to recognize the transition of the "spoofing index value," and can use this information to determine whether the "spoofing index value" of the most recent message is higher or lower than the "spoofing index values" of previous messages, that is, to determine the possibility of spoofing.
[0026] 4 shows the calculation process of the "spoofing index value" by the information processing device 1 according to this embodiment, along with the data flow for user terminals 3-1, 3-2, and 3-3. User B logs in to the SNS service from user terminal 3-2 using his / her own legitimate SNS account, and sends a message (genuine message) to user A's user terminal 3-1 via SNS server 2. User C, acting as an attacker, fraudulently obtains user B's SNS account by hijacking or the like, and then fraudulently logs in to the SNS service using user B's SNS account fraudulently obtained from user terminal 3-3, and sends a message (fake message) to user A's user terminal 3-1 via SNS server 2. Here, we assume that the fake message is the most recent, and that genuine messages have been sent repeatedly before that.
[0027] When user A's user terminal 3-1 receives a new message (latest message), it exports multiple past messages that it has received previously from the same SNS account as the latest message, and transmits a request for an "impersonation index value" related to the latest message, along with data on the latest message and the multiple past messages, to the information processing device 1. The information processing device 1 receives the request for an "impersonation index value" related to the latest message, along with data on the latest message and the multiple past messages, via the message receiving unit 22.
[0028] The control unit 21 of the information processing device 1 stores data of the latest message and multiple past messages received via the message receiving unit 22 in the storage unit 14, and causes the natural language analysis processing unit 23 to perform natural language analysis processing on each of the latest message and multiple past messages. Here, the latest message is represented as M0, and the past messages are represented as Mn, where n is an item number indicating how many messages before the latest message it is.
[0029] The natural language analysis processing unit 23 performs natural language analysis processing for each of the latest message M0 and past messages Mn (S11). Words are extracted from each message M0 and Mn, and parts of speech (nouns, verbs, adjectives, etc.) are assigned to them. As shown in FIG. 6, based on the results of the natural language analysis processing, feature quantities F0 and Fn, which reflect the content and syntactic characteristics of each message, are calculated as N-dimensional vectors by the feature quantity calculation unit 24 (S12). An axis in N-dimensional space is identified for each pair of extracted words and parts of speech, and the word and part of speech pairs extracted from the message are compared with the multiple word and part of speech pairs on that axis, and the coordinate values assigned to the corresponding word and part of speech pair are assigned. By identifying an axis and the coordinate values on that axis for all pairs of multiple words and parts of speech extracted from the message, an N-dimensional vector is determined as the feature quantities F0 and Fn of the message. When different coordinate values on the same axis are identified, the average value, etc., of those coordinate values is assigned as the coordinate value on that axis.
[0030] 7, based on the feature quantity Fn of the multiple past messages Mn and the feature quantity F0 of the latest message M0, the similarity calculation unit 25 calculates multiple similarities CSn of the latest message M0 to each of the multiple past messages Mn. As described above, the similarities are calculated, for example, as cosine similarities CSn. The cosine similarities CSn make it possible to quantify and determine whether the latest message M0 is similar to each of the multiple past messages Mn in terms of content features and syntactic features, such as words, content, meaning, wording, sentence structure, vocabulary choice, rhythm, tone, and style of speech, or whether they are different.
[0031] The spoofing index calculation unit 26 calculates an "spoofing index" that indicates the possibility that an SNS account has been illegally obtained and a message has been sent by impersonating a legitimate user who owns the SNS account, based on the multiple similarities CSn (S14). Specifically, each similarity CSn, which is expressed in the range of (-1.0 to +1.0), is scaled to (100% to 0%), and the average, minimum, median, etc. of these are determined as the "spoofing index."
[0032] The calculated "impersonation index value" allows user A to roughly determine whether the latest message M0 tends to diverge or resemble the previous messages Mn received from the same account in terms of content and syntactic features.
[0033] The closer the "spoofing index value" is to 0%, the stronger the tendency for the content and syntactic features of the latest message to deviate from past messages, allowing user A to roughly determine that the latest message is likely to be a spoof. On the other hand, the closer the "spoofing index value" is to 100%, the stronger the tendency for the content and syntactic features of the latest message to resemble past messages, allowing user A to roughly determine that the latest message is unlikely to be a spoof.
[0034] The calculated "spoofing index value" is sent together with the message ID by the spoofing index value sending unit 27 to the user terminal 3-1 of user A (S15). As shown in FIG. 5, in the user terminal 3-1, the "spoofing index value" is displayed near the latest message that it represents. In the user terminal 3-1, all "spoofing index values" that have been sent so far are displayed near the corresponding messages. User A can recognize the changes in the "spoofing index value" and use this as information to determine whether the "spoofing index value" of the latest message is higher or lower than the "spoofing index values" of previous messages, that is, to determine the possibility of spoofing.
[0035] As described above, according to this embodiment, it is possible to calculate and provide an index value that indicates whether the latest (current) message is similar in content and syntax to or deviates from past messages received from the same account, i.e., the likelihood that the message was sent by someone who illegally obtained an SNS account and impersonated a legitimate user who owns the SNS account. (Second embodiment) In the first embodiment described above, the information processing device 1 performs the natural language analysis process, the feature calculation process, and the similarity calculation process, but these processes may be performed by an external generation AI.
[0036] As shown in FIG. 8, an information processing device 1 according to this embodiment is connected via an internet network 4 to an SNS server 2, user terminals 3-1, 3-2, and 3-3, and a generating AI 5.
[0037] As shown in Figure 9, the information processing device 1 functions as a control unit 21, a message receiving unit 22, an impersonation index value calculation unit 26, an impersonation index value transmission unit 27, as well as a prompt creation unit 28 that creates a prompt that instructs an external generation AI 5 to calculate multiple similarities of the latest message to multiple past messages received through user B's SNS account, a prompt sending unit 29 that sends the created prompt to the generation AI 5, and a similarity receiving unit 30 that receives multiple similarities calculated by the generation AI 5 from the generation AI 5.
[0038] The prompt created by the prompt creation unit 28 is typically created to instruct the calculation of the similarity between each of a plurality of past messages and the latest message through the natural language analysis process, feature calculation process, and similarity calculation process in the first embodiment. As a result, the generation AI 5, as in the first embodiment, calculates feature quantities that reflect content and syntactic features such as words and parts of speech that appear in each message, as well as sentence structure, vocabulary choice, rhythm, tone, and narrative style, as an N-dimensional vector between each of a plurality of past messages and the latest message.
[0039] 10, a prompt is generated in the prompt generation unit 28 (S21), and the spoofing index calculation unit 26 calculates an "spoofing index" based on the multiple similarities CSn calculated by and received from the generation AI 5 (S22). The calculated "spoofing index" is transmitted from the spoofing index transmission unit 27 to the user terminal 3-1 of user A, and is displayed on the user terminal 3-1 near the latest message, as shown in FIG. 5 (S23).
[0040] The second embodiment can achieve the same effects as the first embodiment. (Third embodiment) As shown in FIG. 11, an information processing device 1 according to this embodiment is connected via an internet network 4 to an SMS server 6 that provides a short mail service (SMS) using telephone numbers, and user terminals 3-1, 3-2, and 3-3.
[0041] The first and second embodiments described above target "impersonation" in messenger services provided by SNS, and calculate the "impersonation index value" of the latest message based on the similarity between a past message and the latest message sent from the same account.
[0042] In this embodiment, the target is "spoofing" in the short message service (SMS), and the "spoofing index value" of the latest short message is calculated based on the similarity between the body of a past short message and the body of the latest short message that was sent with the same phone number disguised as the phone number of the sender.
[0043] As shown in Figure 12, when user A's user terminal 3-1 receives a new short message (the latest short message), it exports multiple past short messages that it has previously received with the same phone number as the sender phone number of the latest short message, and sends a request for the "spoofing index value" for the latest short message to the information processing device 1, along with data on the latest short message and the multiple past short messages.
[0044] The natural language analysis processing unit 23 of the information processing device 1 performs natural language analysis processing on the body of the latest short mail and the body of past short mails individually (S31), and based on the results of the natural language analysis processing, feature quantities reflecting the content and syntactic features of each short mail body are calculated as an N-dimensional vector by the feature quantity calculation unit 24 (S32). In the next step S33, based on the feature quantities of the bodies of the past short mails and the feature quantity of the body of the latest short mail, multiple similarities of the body of the latest short mail to each of the bodies of the past short mails are calculated by the similarity calculation unit 25 (S33).
[0045] The impersonation index value calculation unit 26 calculates an "impersonation index value" that indicates the possibility that the short mail was sent by disguising the phone number and pretending to be the legitimate user who legitimately owns the phone number, based on the multiple similarities (S34).
[0046] The calculated "spoofing index value" is sent together with the short mail ID by the spoofing index value sending unit 27 to the user terminal 3-1 of user A, and the "spoofing index value" is displayed near the body of the latest short mail that it represents on the user terminal 3-1, as shown in Fig. 13. On the user terminal 3-1, all "spoofing index values" that have been sent so far are displayed near the bodies of the corresponding short mails.
[0047] User A can recognize the changes in the "spoofing index value" and use this information to determine whether the "spoofing index value" of the latest short message is higher or lower than the "spoofing index value" of previous short messages, that is, to determine the possibility of spoofing.
[0048] As described above, according to this embodiment, it is possible to calculate and provide an index value that indicates whether the body of the latest (current) short mail is similar in content and syntax to or different from the body of a past short mail in which the same phone number was displayed as the sender's phone number, i.e., the possibility that the phone number was spoofed and the short mail was sent by impersonating the legitimate user who legitimately owns the phone number. Note that in this embodiment, as in the second embodiment, the natural language analysis process, feature calculation process, and similarity calculation process may be performed by an external generation AI. (Fourth embodiment) As shown in FIG. 14, an information processing device 1 according to this embodiment is connected via an internet network 4 to an email server 7 that provides email services, and user terminals 3-1, 3-2, and 3-3.
[0049] In this embodiment, the target is "spoofing" in email services, and the "spoofing index value" of the latest email is calculated based on the similarity between the body of a past email and the body of the latest email that was sent with the same email address disguised as the email address of the sender.
[0050] As shown in FIG. 15, when user A's user terminal 3-1 receives a new email (latest email), it exports multiple past emails that it has previously received with the same email address as the latest email as the sender email address, and sends a request for the "spoofing index value" for the latest email to the information processing device 1, along with data on the latest email and the multiple past emails.
[0051] The natural language analysis processing unit 23 of the information processing device 1 performs natural language analysis processing on the body of the latest email and the body of past emails individually (S41), and based on the results of the natural language analysis processing, feature quantities reflecting the content and syntactic features of the body of each email are calculated as an N-dimensional vector by the feature quantity calculation unit 24 (S42). In the next step S43, based on the feature quantities of the bodies of the multiple past emails and the feature quantity of the body of the latest email, multiple similarities of the body of the latest email to each of the multiple past emails are calculated by the similarity calculation unit 25 (S43).
[0052] The spoofing index value calculation unit 26 calculates an "spoofing index value" that indicates the possibility that the email address has been forged and the email has been sent by pretending to be the legitimate user who legitimately owns the email address, based on the multiple similarities (S44).
[0053] The calculated "spoofing index value" is sent together with the mail ID by the spoofing index value sending unit 27 to the user terminal 3-1 of user A, and the "spoofing index value" is displayed near the body of the latest e-mail that it represents on the user terminal 3-1, as shown in Figures 16(a) and 16(b). On the user terminal 3-1, all the "spoofing index values" that have been sent so far are displayed near the bodies of the e-mails that correspond to them.
[0054] User A can check the history of the "spoofing index value" and use this information to determine whether the "spoofing index value" of the latest email is higher or lower than the "spoofing index value" of previous emails, that is, to determine the possibility of spoofing.
[0055] As described above, according to this embodiment, it is possible to calculate and provide an index value that indicates whether the body of the latest (current) email is similar in content and syntax to or different from the body of a past email in which the same email address was displayed as the sender's email address, i.e., whether the email address has been forged and the email has been sent, for example, as direct mail, by impersonating a legitimate user who legitimately owns the email address.In this embodiment, as in the second embodiment, the natural language analysis process, feature calculation process, and similarity calculation process may be performed by an external generation AI.
[0056] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, as well as within the scope of the invention described in the claims and their equivalents. [Explanation of symbols]
[0057] 1...information processing device, 2...SNS server, 3-1...user terminal (receiver), 3-2...user terminal (legitimate user), 3-3...user terminal (attacker).
Claims
1. a receiving unit that receives a message from a user terminal through a specific SNS account; a calculation unit that calculates a plurality of similarities of the message with respect to a plurality of past messages received through the SNS account; and a calculation unit that calculates, based on the similarity, an index value that indicates the likelihood that the SNS account has been fraudulently obtained and the message has been sent by impersonating a legitimate user who owns the SNS account.
2. The information processing apparatus according to claim 1 , wherein the calculation unit calculates an average value, a maximum value, or a median value of the plurality of similarities as the index value.
3. 2. The information processing device according to claim 1, wherein the calculation unit individually performs natural language analysis processing on the message and the plurality of past messages, calculates feature quantities (N-dimensional vectors) of the message and each of the plurality of past messages based on the results of the natural language analysis processing, and calculates a cosine similarity between the feature quantities of the message and each of the plurality of past messages as the similarity.
4. a message receiving unit that receives a message from a user terminal through a specific SNS account; a generation unit that generates a prompt that instructs an external generation AI to calculate a plurality of similarities of the message with respect to a plurality of past messages received through the SNS account; a sender for sending the prompt to the external generating AI; a similarity receiving unit that receives the similarity from the external generation AI; and a calculation unit that calculates, based on the similarity, an index value that indicates the likelihood that the SNS account has been fraudulently obtained and the message has been sent by impersonating a legitimate user who owns the SNS account.
5. a receiving unit that receives a short message from a user terminal using a specific telephone number; a calculation unit that calculates a plurality of similarities of the body of the short mail with respect to the body of a plurality of past short mails in which the telephone number is written as the telephone number of the sender; and a calculation unit that calculates, based on the similarity, an index value that indicates the likelihood that the short mail was sent by spoofing the phone number and impersonating a legitimate user who owns the phone number.
6. a receiving unit that receives emails from a user terminal using a specific email address; a calculation unit that calculates a plurality of similarities of the body of the email to the bodies of a plurality of past emails in which the email address is written as the email address of a sender; and a calculation unit that calculates, based on the similarity, an index value that indicates the likelihood that the email was sent by spoofing the email address and impersonating a legitimate user who owns the email address.
7. A means for receiving a message from a user terminal through a specific SNS account; means for calculating a plurality of similarities of the message to a plurality of past messages received through the SNS account; A program that causes a computer to function as a means for calculating, based on the similarity, an index value that indicates the likelihood that the SNS account has been hijacked and the message has been sent by impersonating a legitimate user who owns the SNS account.
Citation Information
Patent Citations
Phishing fraud prevention system
JP2006285844A
System and method for using relationship structures for email classification
JP2023515910A
Intgrated control apparatus for display panel with two or more floor type pedestrian traffice lights
KR102744171B1
Automated detection of deception in short and multilingual electronic messages
US20120254333A1
Automatic phishing email detection based on natural language processing techniques
US20150067833A1