Server and method for detecting attack of abnormal message

The server system uses AI to analyze SMS authentication features, addressing AIT attacks by accurately identifying fraudulent requests and reducing financial losses for SMS relay companies and telecommunications providers.

WO2025230220A1PCT designated stage Publication Date: 2025-11-06SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/005535
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-10-24
Filing Date
2025-04-24
Publication Date
2025-11-06

AI Technical Summary

Technical Problem

Existing systems are vulnerable to artificially inflated traffic (AIT) attacks where fraudsters use bots to register fake accounts and generate fake SMS verification requests, leading to financial losses for SMS relay companies and telecommunications providers due to inflated costs.

Method used

A server system that utilizes an artificial intelligence model to analyze features derived from SMS authentication requests, including single-event, multi-event, and country-specific features, to detect abnormal message attacks by comparing these features against a threshold value, thereby reducing false positives and enhancing detection accuracy.

Benefits of technology

The system effectively identifies AIT attacks with high accuracy by leveraging AI models, reducing financial losses and improving security by distinguishing legitimate from fraudulent SMS verification requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025005535_06112025_PF_FP_ABST
    Figure KR2025005535_06112025_PF_FP_ABST
Patent Text Reader

Abstract

A server according to an embodiment may comprise at least one processor, and a memory for storing instructions, wherein the instructions, when executed individually or collectively by the at least one processor, are configured to cause the server to: receive a first message for an authentication request; identify information included in the first message; acquire at least one feature among a first feature acquired using information related to the authentication request among the information included in the first message, a second feature acquired using information related to a device and a phone number among information included in a plurality of first messages received for a designated time period, and a third feature acquired using information related to a device and a phone number among information included in a plurality of first messages received from a designated country for a designated time period; input the at least one feature as an input value of an artificial intelligence model; and identify the first message as an attack of an abnormal message on the basis that an output value output from the artificial intelligence model is equal to or greater than a threshold value.
Need to check novelty before this filing date? Find Prior Art

Description

Server and method for detecting attacks using abnormal messages

[0001] The present disclosure relates to a server and method for detecting attacks of abnormal messages.

[0002] An artificially inflated traffic (AIT) attack occurs when fraudsters use bots to register fake accounts on a server and trigger a large number of fake SMS verification requests.

[0003] A user can access the server via an electronic device or the web to register an account or log in, in which case the user can make an SMS authentication request to the server via the electronic device or the web.

[0004] The server may send an SMS through an SMS relay company or a telecommunications company in response to an SMS authentication request, and the server may pay the SMS relay company or telecommunications company the cost of sending the SMS through the SMS relay company or telecommunications company.

[0005] However, SMS brokers or malicious carriers can collude with fraudsters to generate a large number of fake SMS authentication requests, and they can make a profit by charging their servers for the cost of requesting a large amount of fake SMS traffic.

[0006] By combining features obtained based on information included in the first message requesting authentication, complex AIT (artificially inflated traffic) attacks can be detected with high accuracy and false positives can be reduced.

[0007] A server according to an embodiment may include at least one processor including a processing circuit, and a memory storing instructions. The instructions according to an embodiment, when individually or collectively executed by the at least one processor, may cause the server to receive a first message for an authentication request and verify information included in the first message. The instructions according to an embodiment, when individually or collectively executed by the at least one processor, may cause the server to acquire at least one of the following features: first features obtained using information related to an authentication request included in the first message; second features obtained using information related to a device and a phone number included in a plurality of first messages received during a specified time; or third features obtained using information related to a device and a phone number included in a plurality of first messages received during a specified time in a specified country. The commands according to one embodiment, when individually or collectively executed by the at least one processor, can cause the server to input the at least one feature as an input value of an artificial intelligence model. The commands according to one embodiment, when individually or collectively executed by the at least one processor, can cause the server to identify an abnormal message attack based on an output value from the artificial intelligence model being greater than or equal to a threshold value.

[0008] A method for detecting an attack of an abnormal message according to an embodiment may include an operation of verifying information included in a first message for an authentication request based on reception of the first message. The method according to an embodiment may include an operation of acquiring at least one feature from among first features obtained using information related to the authentication request among information included in the first message, second features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time, or third features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time in a specified country. The method according to an embodiment may include an operation of inputting the at least one feature as an input value of an artificial intelligence model. The method according to an embodiment may include an operation of identifying an attack of an abnormal message based on an output value equal to or greater than a threshold value output from the artificial intelligence model.

[0009] In one embodiment, a non-volatile storage medium storing commands is provided, wherein the commands, when executed by a server, are configured to cause the server to perform at least one operation, wherein the at least one operation may include an operation of verifying information included in a first message based on receipt of a first message for an authentication request. In one embodiment, the at least one operation may include an operation of acquiring at least one feature from among first features obtained by using information related to an authentication request included in the first message, second features obtained by using information related to a device and a phone number included in a plurality of first messages received during a specified time, or third features obtained by using information related to a device and a phone number included in a plurality of first messages received during a specified time in a specified country. In one embodiment, the at least one operation may include an operation of inputting the at least one feature as an input value of an artificial intelligence model. At least one action according to one embodiment may include an action of identifying an abnormal message as an attack based on an output value output from the artificial intelligence model being greater than or equal to a threshold value.

[0010] The above and other aspects, features and advantages of specific embodiments of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0011] FIG. 1 is a block diagram showing an exemplary configuration of a server according to various embodiments.

[0012] FIG. 2 is a flowchart illustrating an exemplary operation for detecting an attack of an abnormal message on a server according to various embodiments.

[0013] Figure 1 is a block diagram showing an exemplary configuration of a server according to various examples.

[0014] Referring to the above drawing 1, the server (101) may include a processor (e.g., including processing circuitry) (120), a memory (130), and a communication circuit (190).

[0015] According to one embodiment, the processor (120) may include various processing circuitry and perform overall control operations of the server (101). The processor (120) according to one embodiment may execute software to control at least one other component (e.g., hardware or software component) of the server (101) connected to the processor (120), and may perform data processing or calculations based on instructions. An instruction according to one embodiment may include an instruction configured in a machine language that can be processed by the server (101) or the processor (120). For example, an instruction may include an instruction corresponding to an operation instruction used in a program. Herein, the term "processor" or "model" includes processing circuitry, or may include multiple processors. For example, the term "processor" or "model" used in this document (including the claims) may mean various processing circuitry including at least one processor, and may include one of the one or more processors. The above may be configured to perform the various functions described in this document, either singly or collectively in a distributed manner. When the expressions "processor," "at least one processor," "model," "at least one model," or "one or more processors" are described herein as being configured to perform various functions, these terms encompass various situations, including (but not limited to) the following. For example, one processor and / or model may perform some functions, another processor and / or model may perform other functions, or one processor and / or model may perform all functions. Furthermore, at least one processor may be a combination of processors that perform multiple functions, such as in a distributed manner.At least one processor may execute program instructions to implement or perform various functions. Similarly, at least one model may be a combination of circuits and / or processors that perform various functions in a distributed manner. At least one processor and / or model may execute program instructions to implement or perform various functions.

[0016] According to one embodiment, when a processor (120) receives a first message (e.g., SMS) requesting authentication, it may obtain (calculate) at least one feature for detecting an attack of an abnormal message based on information included in the first message.

[0017] According to one embodiment, the first message may include basic authentication request information such as user identifier information, user account email, target phone number information, authentication request time information via the first message, Internet Protocol (IP) address information, device identifier information (e.g., unique IMEI (International Mobile Equipment Identity) number), device model information, client and OS version information, authentication service type information (e.g., account login or two-step authentication setup), application or service in use information, target country information from which the first message (e.g., SMS) was sent, operation type (e.g., request sent or verification successful), and billing information for the first message.

[0018] According to one embodiment, the first message may include information about the type of client used to initially register for the account, information about whether the particular user has previously registered a "trusted device" (e.g., excluding a two-factor authentication operation via the first message), and information about whether ownership of the particular phone number has been previously verified. The "trusted device" may refer to, for example, a device (e.g., at least one of a smartphone, a tablet, or a PC) that is registered so that only the user has access to it, and when logging in using the trusted device, the feature allows for quick logging in by entering only a username and password, without requiring a two-factor authentication operation via SMS.

[0019] According to one embodiment, the processor (120) may acquire at least one feature from among a first feature obtained (calculated) using information related to an authentication request among information included in the first message, a second feature obtained (calculated) using information related to a device and a phone number among information included in a plurality of first messages received during a specified time (e.g., 24 hours), or a third feature obtained (calculated) using information related to a device and a phone number among information included in a plurality of first messages received during a specified time (e.g., 24 hours) in a specified country.

[0020] According to one embodiment, the processor (120) can obtain (calculate) the first feature (e.g., single-event feature) by using information related to an authentication request among the information included in a single first message.

[0021] According to one embodiment, the processor (120) may obtain (calculate) the first characteristic by using information included in the first message (e.g., SMS), such as billing information for the first message or information on whether disposable email is used.

[0022] According to one embodiment, the processor (120) may obtain (calculate) the first characteristic by using at least one of the following information: billing information of the first message (e.g., SMS), device information registered as the user's account at the time of requesting authentication through the first message, difference information between the time of requesting authentication through the first message and the time of generating the domain of the email, or difference information between the time of requesting authentication through the first message and the time of release of the device that sent the first message.

[0023] According to one embodiment, the processor (120) can obtain the first feature by calculating the information included in the first message as shown in and below.

[0024] below shows, as an example, a calculation method for obtaining the first feature from the first message sent through the web, and below shows, as an example, a calculation method for obtaining the first feature from the first message sent through the device.

[0025] According to one embodiment, the processor (120) can obtain the first characteristic through the following and .

[0026] Type of first characteristic Calculation method for obtaining first characteristic sms_cost Get the per SMS billing cost for the SMS target country have_trust_dvce Verify that at least one trusted device is registered to the user account at the time the SMS request is made domain_sms_td SMS request date - the date and time the email domain first appeared jn_sms_td SMS request date - the date and time the user account was created is_same_cnty The country code of the user account is the same as the country code of the SMS request service_id The type of service associated with the SMS request join_channel The web or mobile channel used to initially sign up (sign up)

[0027] In the above , "sms_cost" indicates the country-specific billing rate for sending a single SMS, "have_trust_dvce" verifies whether at least one trusted device is registered to the user account, "domain_sms_td" indicates the time difference between the date of the authentication request via SMS and the date on which the (in-use) email domain first appears in the SMS record database of the memory (130), and "jn_sms_td" indicates the time difference between the date of the authentication request via SMS and the date on which the user first created the account. In the above , "is_same_cnty" verifies whether the country code of the user account and the SMS request are the same, "service_id" indicates the type of service related to the SMS request, and "join_channel" indicates the web or mobile channel used to initially sign up (join).

[0028] Type of first feature Calculation method to obtain first feature sms_cost SMS Get single SMS billing rate by target country dvce_age SMS request date - device first release date (converted to months) dvce_user_cnt Calculate the number of unique user IDs associated with a specific IMEI ph_reg_sms_td SMS request date - date the target phone number was first registered ph_reg_user_cnt Calculate the number of unique user IDs associated with a specific phone number osver_sms_td SMS request date - date the OS version was first released clver_sms_td SMS request date - date the app client version was first released is_ph_vrf Check if successful phone number verification count is greater than 0 os_td Release date of used OS version - release date of latest OS version available for that device model dvce_vld_sms_td SMS request date - last value of successful verification date on a specific device model and OS version is_same_cnty Check if IP country is same as target SMS country

[0029] In the above , "sms_cost" may represent a country-specific billing rate for sending a single SMS, "dvce_age" may represent a time difference between the date of an authentication request via SMS and the date of the initial release of the device, "dvce_user_cnt" may represent the number of user IDs associated with a specific device IMEI, and "ph_reg_sms_td" may represent a time difference between the date of an authentication request via SMS and the date of the initial registration of the target phone number. In the above , "ph_reg_user_cnt" may represent a number of user IDs associated with a specific phone number, "osver_sms_td" may represent a time difference between the date of an authentication request via SMS and the date of the initial release of the OS version (used to submit the request), and "clver_sms_td" may represent a time difference between the date of an authentication request via SMS and the date of the initial release of the app client version (used to submit the request).

[0030] In the above , "is_ph_vrf" indicates checking whether the target phone number has been previously authenticated, "os_td" indicates the time difference between the release date of the OS version used in the SMS authentication request and the release date of the latest OS version available for the same device model, "dvce_vld_sms_td" indicates the time difference between the date of the authentication request via SMS and the date of the last successful verification completed by the same device model and OS version (used in the current request), and "is_same_cnty" may indicate checking whether the IP country and the SMS target country are the same.

[0031] According to one embodiment, the processor (120) can obtain (calculate) the second feature (e.g., multi-event feature) by using information related to a device and a phone number among information included in a plurality of first messages continuously received during a specified time (e.g., 24 hours).

[0032] According to one embodiment, the processor (120) can detect a plurality of first messages (e.g., SMS) stored in an SMS record database of a memory (130) that are received continuously for a specified period of time (e.g., 24 hours) before the current first message is received.

[0033] According to an embodiment, the processor (120) may obtain (calculate) the second feature by using at least one of information included in a plurality of first messages (e.g., SMS), including information on the number of unique IPs associated with a specific phone number, information on the sum of charges for the first message for a specific phone number, information on the number of unique IPs associated with a specific IMEI, information on the number of unique phone numbers associated with a specific IMEI, or information on the sum of charges for the first message for a specific IMEI.

[0034] According to one embodiment, the processor (120) can obtain the second feature by calculating the information included in the first message as shown in and below.

[0035] below shows an example of a calculation method for obtaining a second feature from a first message sent through the web, and below shows an example of a calculation method for obtaining a second feature from a first message sent through a device.

[0036] According to one embodiment, the processor (120) can obtain the second feature through and below.

[0037] Types of Secondary Features Calculation Method for Obtaining Secondary Features user_ip_cnt Number of unique IPs associated with a specific user user_ph_cnt Number of unique phone numbers associated with a specific user user_cost Sum of all SMS charges for a specific user user_conv Number of successful SMS verifications (for a specific user) / Number of SMS requests (for a specific user) user_sms Number of SMS sent by a user user_td_med MED (all time difference values ​​of two consecutive SMS requests measured for a specific user) user_td_avg MEAN (all time difference values ​​of two consecutive SMS requests measured for a specific user) user_td_std STDEV (all time difference values ​​of two consecutive SMS requests measured for a specific user) ph_ip_cnt Number of unique IPs associated with a specific phone number ph_user_cnt Number of unique user IDs associated with a specific phone number ph_cost Sum of all SMS charges for a specific phone number ph_conv Number of successful SMS verifications (for a specific phone number) / Number of SMS requests (for a specific phone number) ph_sms Number of SMS sent to a specific phone number ph_td_medMED (all time difference values ​​of two consecutive SMS requests measured for a specific phone number) ph_td_avgMEAN (all time difference values ​​of two consecutive SMS requests measured for a specific phone number)

[0038] In the above , "user_ip_cnt" represents the number of unique IPs associated with a specific user, "user_ph_cnt" represents the number of unique phone numbers associated with a specific user, and "user_cost" represents the sum of all SMS charges for a specific user. In the above , "user_conv" represents a conversion rate (SMS verification success rate) measured for a specific user, "user_sms" represents the number of SMSs sent by the user, "user_td_med" represents a median time difference value among all time difference values ​​calculated for a specific user, and each time difference value represents a value calculated between the date and time of two consecutive authentication requests via SMS, and "user_td_avg" may represent an average time difference value of all time difference values ​​calculated for a specific user.

[0039] In the above , “user_td_std” represents the standard deviation of all time difference values ​​calculated for a specific user, “ph_ip_cnt” represents the number of unique IPs associated with a specific phone number, “ph_user_cnt” represents the number of unique user IDs associated with a specific phone number, and “ph_cost” may represent the sum of all SMS charges for a specific phone number.

[0040] In the above , "ph_conv" represents the conversion rate (SMS verification success rate) measured for a specific phone number, "ph_sms" represents the number of SMS sent to a specific phone number, "ph_td_med" represents the median time difference value among all time difference values ​​calculated for a specific phone number, and each time difference value represents the time (date and time) calculated between two consecutive authentication request dates via SMS, and "ph_td_avg" may represent the standard deviation of all time difference values ​​calculated for a specific phone number.

[0041] Second feature type Calculation method for obtaining the second featureimei_ip_cntThe number of unique IPs associated with a specific IMEIimei_ph_cntThe number of unique phone numbers associated with a specific IMEIip_imei_cntThe number of unique IMEIs associated with a specific IP addressph_xmodel_cntFirst, concatenate the device model and OS version into one string, and count the number of unique concatenation strings associated with a specific phone numberimei_xmodel_cntFirst, concatenate the device model and OS version into one string, and count the number of unique concatenation strings associated with a specific IMEIimei_costThe sum of all SMS charges for a specific IMEIph_costThe sum of all SMS charges for a specific phone numberimei_smsThe number of SMS requests sent by a specific IMEIph_smsThe number of SMS requests sent by a specific phone numberimei_convThe number of successful SMS verifications / SMS requests for a specific IMEIph_convThe number of successful SMS verifications / SMS requests for a specific phone numberph_ph_vrf_cntThe number of successful verification operations occurring for a specific phone number countimei_max_vld_cnt Concatenates all actions for a specific IMEI and service type, and finds the longest consecutive occurrence of successful validations. ph_max_vld_cnt Concatenates all actions for a specific phone number and service type, and finds the longest consecutive occurrence of successful validations. ip_sms Number of SMS requests sent via a specific IP address. imei_td_avg The time difference value measured between all consecutive SMS requests for a specific IMEI.

[0042] In the above , "imei_ip_cnt" may represent the number of unique IPs associated with a specific IMEI, "imei_ph_cnt" may represent the number of unique phone numbers associated with a specific IMEI, and "ip_imei_cnt" may represent the number of unique IMEIs associated with a specific IP address. In the above , "ph_xmodel_cnt" may represent the number of combinations of unique device models and OS versions associated with a specific phone number, "imei_xmodel_cnt" may represent the number of combinations of unique device models and OS versions associated with a specific IMEI, "imei_cost" may represent the sum of all SMS charges for a specific IMEI, "ph_cost" may represent the sum of all SMS charges for a specific phone number, "imei_sms" may represent the number of SMS requests sent by a specific IMEI, "ph_sms" may represent the number of SMS requests sent by a specific phone number, and "imei_conv" may represent the conversion rate (SMS verification) for a specific IMEI. "ph_conv" can represent the conversion rate (SMS verification success rate) for a specific phone number.

[0043] In the above , "ph_ph_vrf_cnt" represents the number of times a specific phone number has been successfully verified, "imei_max_vld_cnt" represents the maximum number of authentication requests via SMS that a specific IMEI has been continuously verified for the same service type, and "ph_max_vld_cnt" may represent the maximum number of SMS requests that a specific phone number has been continuously verified for the same service type.

[0044] In the above , <ip_sms" 은, 특정 IP 주소를 통해 발송된 SMS 요청 개수를 나타내고, "imei_td_avg "은 특정 IMEI에 대해 계산된 모든 시간 차이 값에 대한 평균 시간 차이 값을 나타낼 수 있다.

[0045] According to one embodiment, the processor (120) may obtain (calculate) the third feature (e.g., country-event feature) by using information related to a device and a phone number among information included in a plurality of first messages sent from a designated country (region) during a designated time (e.g., 25 hours).

[0046] According to an embodiment, the processor (120) may obtain (calculate) the third feature by using at least one of information included in a plurality of first messages (e.g., SMS), including information on the difference between the usage rate of a domain of a specific email and the average usage rate of the domain of the specific email in a specified country during a specified time, information on the difference between the usage rate of a specific application or service and the average usage rate of the specific application or service in a specified country during a specified time, information on the number of phone numbers having the same prefix in the specified country, information on the number of times authentication was requested through a first message using an IMEI having the same prefix in the specified country, or information on the number of IMEIs having the same prefix in the specified country.

[0047] According to one embodiment, the processor (120) may specify the number of prefixes of a telephone number.

[0048] According to one embodiment, the processor (120) can obtain the third feature by calculating the information included in the first message as shown in and below.

[0049] below shows an example of a calculation method for obtaining a third feature from a first message sent through the web, and below shows an example of a calculation method for obtaining a third feature from a first message sent through a device.

[0050] According to one embodiment, the processor (120) can obtain the second feature through and below.

[0051] Type of third feature Calculation method for obtaining third feature domain_prop_inc Percentage of a specific email domain used in a 24-hour period in a specific country - trimmed average daily percentage of the specific email domain used app_prop_inc Percentage of a specific application or service used in a 24-hour period in a specific country - trimmed average daily percentage of the specific application / service used gmail_prop_dec Percentage of SMS requests sent via a specific email (e.g. gmail) in general traffic - percentage of SMS requests sent via a specific email (e.g. gmail) tld_prop_inc Percentage of SMS requests sent by top-level representations of a specific email domain - percentage of SMS requests sent by top-level representations of a specific domain in general traffic ph_prefix_cnt Extracts the prefix of a phone number and counts the unique number of phone numbers containing the same prefix within a specific country

[0052] In the above , "domain_prop_inc" may represent a change in the percentage of a specific email domain (extracted from current SMS requests) used over a 24-hour period compared to a trimmed average value for a specific country, and "app_prop_inc" may represent a change in the percentage of a specific application and / or service (extracted from current SMS requests) used over a 24-hour period compared to a trimmed average value for a specific country. In the above , "gmail_prop_dec" may represent a decrease in the percentage of SMS requests sent via a specific email (e.g., Gmail) compared to a pre-computed baseline percentage from general traffic (the percentage is calculated based on the last 24-hour SMS traffic volume for the given country), "tld_prop_inc" may represent an increase in the percentage of SMS requests sent to a top-level domain representation of a specific email (e.g., .com) compared to a pre-computed baseline percentage from general traffic (the percentage is calculated based on the last 24-hour SMS traffic for the given country), and "ph_prefix_cnt" may represent a change in the percentage of SMS requests sent via a specific email (e.g., Gmail) compared to a pre-computed baseline percentage from general traffic (the percentage is calculated based on the last 24-hour SMS traffic for the given country), and "ph_prefix_cnt" may represent a change in the percentage of SMS requests sent via a specific email (e.g., .com) compared to a pre-computed baseline percentage from general traffic. It can represent a count of the number of specific phone numbers containing the same phone number prefix (extracted from the current SMS request) within the same country over a 24-hour period.

[0053] Types of Third Features Calculation Methods for Obtaining Third Features peak_label Checks whether the amount of traffic generated in a given country within a 24-hour period is significantly greater than the [average and / or median daily traffic], and whether the conversion rate is significantly less than the [average / median daily conversion rate] ph_prefix_cnt Extracts the prefix of a phone number and counts the number of unique phone numbers with the same prefix within a given country.imei_prefix_sms Extracts the prefix of an IMEI and counts the number of occurrences of said prefix within the same country and device model imei_prefix_cnt Extracts the prefix of an IMEI and counts the number of unique IMEIs with said prefix within the same country and device model xmodel_sms_dist Number of SMS requests submitted by a specific device model or total number of SMS requests from a specific country ph_sim Measures the string similarity between the phone numbers of the current request and the phone numbers of previous requests selected based on the same country and device model imei_sim Measures the string similarity between the IMEIs of the current request and the IMEIs of previous requests selected based on the same country and device model ph_prefix_sms_prop Extracts the prefix of a phone number and counts [number of occurrences of prefix within a specific country / total number of SMS requests for a specific country] ph_prefix_conv Number of successful SMS verifications (for a specific phone number prefix) / number of SMS requests (for a specific phone number prefix) imei_prefix_sms_prop of an IMEI Extract the prefix and compute [number of occurrences of prefix within a given country and device model / total number of SMS requests for a given country]imei_prefix_conv(number of successful SMS verifications for a given IMEI prefix) / number of SMS requests for a given IMEI); If the IMEI is empty, fill in the IMEI prefix with empty value and compute xmodel_conv(number of successful SMS verifications for a given device model) / number of SMS requests for a given device model) for the prefix of the empty IMEI.

[0054] In the above , "peak_label" indicates that the authentication request via SMS is sent during a peak traffic period (clearly visible in the target country), "ph_prefix_cnt" indicates a count of the number of unique phone numbers having the prefix of the same phone number (extracted from the current SMS request) within the same country, "imei_prefix_sms" indicates a count of the number of SMS requests sent using the prefix of the same IMEI (extracted from the current SMS request) within the same country, and "imei_prefix_cnt" may indicate a count of the number of unique IMEIs having the prefix of the same IMEI (extracted from the current SMS request) within the same country. In the above , "xmodel_sms_dist" indicates the proportion of authentication requests via SMS submitted by a specific device model (extracted from the current SMS request) in the total SMS traffic volume of a specific country, and "ph_sim" indicates a similarity distance for a string measured between the phone number used in the current authentication request via SMS and the phone number of a previous request, the previous request being within the country. It can be selected based on the code and device model, and "imei_sim" represents the string similarity distance measured between the IMEI used in the current SMS authentication request and the IMEI of the previous request, which can be selected based on the country code and device model.

[0055] In the above , "ph_prefix_sms_prop" represents the proportion of SMS requests sent with the prefix of the same phone number (extracted from the current SMS request) within the same country in the past 24 hours, "ph_prefix_conv" represents the measured conversion rate (SMS confirmation success rate) for the prefix of the same phone number (extracted from the current SMS request) within the same country in the past 24 hours, "imei_prefix_sms_prop" represents the proportion of SMS requests sent with the prefix of the same IMEI (extracted from the current SMS request) within the same country and device model in the past 24 hours, "imei_prefix_conv" represents the measured conversion rate (SMS confirmation success rate) for the prefix of the same IMEI (extracted from the current SMS request) within the same country and device model in the past 24 hours, and "xmodel_conv" represents the measured conversion rate (SMS confirmation success rate) for the prefix of the same IMEI (extracted from the current SMS request) within the same country in the past 24 hours. It shows the measured conversion rate (SMS confirmation success rate) for the model.

[0056] According to one embodiment, the processor (120) may input at least one feature among the first feature (e.g., single-event feature), the second feature (e.g., multi-event feature), and the third feature (e.g., country-event resources) as an input value (e.g., feature vector) of an artificial intelligence model.

[0057] According to one embodiment, the processor (120) may obtain at least one feature as a specified number of numerical values ​​used for learning the artificial intelligence model, sort the numerical values ​​in the order used for learning the artificial intelligence model, and then input the input of the artificial intelligence model as values.

[0058] According to one embodiment, the processor (120), when receiving an output value (e.g., a value between 1 and 0) from the artificial intelligence model, compares a score (e.g., a value between 1 and 0) corresponding to the output value with a threshold value (e.g., 0.5), and, as a result of the comparison, if the output value is greater than the threshold value, determines that it is an attack of an abnormal message and rejects the authentication request.

[0059] According to one embodiment, the processor (120) may pre-train an artificial intelligence model to detect an attack of an abnormal message based on at least one of the first feature, the second feature, or the third feature.

[0060] A processor (120) according to one embodiment may label a first time point at which a first message requesting authentication is excessively received as an attack time point of an abnormal message, and may label a second time point other than the first time point as reception of a normal message, based on a peak traffic detection rule that may be arbitrarily designated to detect an attack section of an abnormal message and an arbitrarily designated labeling rule for labeling an attack of an abnormal message.

[0061] According to one embodiment, the processor (120) can detect at least one of the first feature, the second feature, or the third feature from information included in the abnormal message received at the first point in time, and train the artificial intelligence model using the at least one detected feature.

[0062] According to one embodiment, the processor (120) can detect at least one of the first feature, the second feature, or the third feature from information included in the normal message received at the second point in time, and train the artificial intelligence model using the at least one detected feature.

[0063] According to one embodiment, a plurality of artificial intelligence models may be stored in the memory (130).

[0064] According to an embodiment, each of the plurality of artificial intelligence models may be models learned based on a designated type of learning algorithm, and may be artificial intelligence models implemented to input various types of data (or content), perform operations, and output (or obtain) result data. According to an embodiment, the plurality of artificial intelligence models may include a generative artificial intelligence model. For example, in the server (101), learning may be performed to output a specific type of result data as output data by using designated types of data as input data based on a machine learning algorithm or a deep learning algorithm, and a plurality of artificial intelligence models (e.g., machine learning models and deep learning models) may be generated and stored in the server (101), or artificial intelligence models learned from an external electronic device may be transmitted to the server (101) and stored. For example, the server (101) may output input data (input data) as output data of a model learned through designated types of artificial intelligence based on a machine learning algorithm or a deep learning algorithm. The machine learning algorithms include supervised learning algorithms such as linear regression and logistic regression, unsupervised learning algorithms such as clustering, visualization and dimensionality reduction, and association rule learning, and reinforcement learning algorithms, and the deep learning algorithms may include artificial neural networks (ANNs), deep neural networks (DNNs), and convolution neural networks (CNNs), and may further include various learning algorithms without being limited to those described.The above-mentioned learned artificial intelligence model includes a plurality of computational operations (e.g., convolutional layers or pooling layers) for computing input data, and can be implemented to output result data by performing computations on input data based on the plurality of computational operations.

[0065] A communication circuit (190) according to one embodiment can form a communication connection with an external electronic device (e.g., another electronic device or a server) using various types of communication methods and transmit and / or receive data.

[0066] According to an embodiment, a server (e.g., a server (101) of FIG. 1) includes at least one processor (e.g., a processor (120) of FIG. 2) including a processing circuit and a memory (e.g., a memory (130) of FIG. 2) storing instructions, wherein the instructions, when individually or collectively executed by the at least one processor, cause the server to receive a first message for an authentication request and verify information included in the first message. According to an embodiment, the instructions, when individually or collectively executed by the at least one processor, cause the server to obtain at least one of the following features: first features obtained by using information related to an authentication request among information included in the first message; second features obtained by using information related to a device and a phone number among information included in a plurality of first messages received during a specified time; or third features obtained by using information related to a device and a phone number among information included in a plurality of first messages received during a specified time in a specified country. In one embodiment, The above commands, when individually or collectively executed by the at least one processor, may cause the server to input the at least one feature as an input value of an artificial intelligence model. In one embodiment, the above commands, when individually or collectively executed by the at least one processor, may cause the server to identify the first message as an attack of an abnormal message based on an output value output from the artificial intelligence model being greater than or equal to a threshold value.

[0067] The first features according to one embodiment may include features obtained using information related to an authentication request included in a single first message.

[0068] The information related to the authentication request used to obtain the first features according to one embodiment may include at least one of: a billing fee for the first message, device information registered to the user's account at the time of the authentication request via the first message, difference information between the time of the authentication request via the first message and the time of creation of the domain of the email, or difference information between the time of the authentication request via the first message and the release date of the device that sent the first message.

[0069] The second features according to one embodiment may represent features obtained by using information related to a device and a phone number among information included in a plurality of first messages received continuously during a specified period of time.

[0070] The information related to the device and the phone number used to obtain the second features according to one embodiment may include at least one of information on the number of unique IPs associated with a specific phone number, information on the sum of charges for a first message for a specific phone number, information on the number of unique IPs associated with a specific IMEI, information on the number of unique phone numbers associated with a specific IMEI, or information on the sum of charges for a first message for a specific IMEI.

[0071] The third feature according to one embodiment may represent a feature obtained by using information related to the device and phone number among information included in a plurality of first messages sent from a specified country during a specified time.

[0072] The information related to the device and the phone number used to obtain the third features according to an embodiment may include at least one of: information on the difference between the usage rate of a domain of a specific email and the average usage rate of the domain of the specific email in a specified country during a specified time; information on the difference between the usage rate of a specific application or service and the average usage rate of the specific application or service in a specified country during a specified time; information on the number of phone numbers having the same prefix in the specified country; information on the number of times authentication was requested through a first message using an IMEI having the same prefix in the specified country; or information on the number of IMEIs having the same prefix in the specified country.

[0073] The instructions according to one embodiment, when individually or collectively executed by the at least one processor, may be configured to cause the server to obtain a numerical value corresponding to the at least one feature and input the obtained numerical value as an input value of the artificial intelligence model.

[0074] The instructions according to one embodiment, when individually or collectively executed by the at least one processor, may be configured to cause the server to sort the at least one feature in an order used for learning the artificial intelligence model, and input the sorted at least one feature as an input value of the artificial intelligence model.

[0075] According to one embodiment, the artificial intelligence model may be trained to detect an attack of an abnormal message based on at least one of the first feature, the second feature, or the third feature.

[0076] Figure 2 is a flowchart illustrating an example of operations for detecting an attack with an abnormal message on a server according to various embodiments. The operations for detecting an attack with an abnormal message may include operations 201 to 211. In the exemplary embodiments below, the operations may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations may be changed, at least two operations may be performed in parallel, or other operations may be added.

[0077] In operation 201, when a server (e.g., server (101) of FIG. 1 and / or processor (120) of FIG. 1) receives a first message requesting authentication, it can check the information included in the first message.

[0078] According to one embodiment, the first message may include basic authentication request information such as user identifier information, user account email, target phone number information, authentication request time information via the first message, Internet Protocol (IP) address information, device identifier information (e.g., unique IMEI (International Mobile Equipment Identity) number), device model information, client and OS version information, authentication service type information (e.g., account login or two-step authentication setup), application or service in use information, target country information from which the first message (e.g., SMS) was sent, operation type (e.g., request sent or verification successful), and billing information for the first message.

[0079] The first message according to one embodiment may include information about the type of client used to initially register for the account, information about whether the particular user has previously registered a "trusted device" (e.g., excluding two-step verification operations via the first message), and information about whether ownership of the particular phone number has been previously verified.

[0080] In operation 203, a server (e.g., server (101) of FIG. 1 and / or processor (120) of FIG. 1) may obtain (calculate) at least one feature among the first feature, the second feature, or the third feature for detecting an attack of an abnormal message based on information included in the first message.

[0081] According to one embodiment, the server may acquire at least one feature from among a first feature obtained (calculated) using information related to an authentication request among information included in the first message, a second feature obtained (calculated) using information related to a device and a phone number among information included in a plurality of first messages received during a specified time (e.g., 24 hours), or a third feature obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time (e.g., 24 hours) in a specified country.

[0082] According to one embodiment, the server can obtain (calculate) the first feature (e.g., single-event feature) by using information related to an authentication request among the information included in a single first message.

[0083] According to one embodiment, the server may obtain (calculate) the first characteristic by using information included in the first message (e.g., SMS), such as information on the billing rate of the first message or information on whether disposable email is used.

[0084] According to one embodiment, the server may obtain (calculate) the first characteristic by using at least one of the following information included in the first message (e.g., SMS): billing information of the first message, device information registered as the user's account at the time of requesting authentication through the first message, difference information between the time of requesting authentication through the first message and the time of creation of the domain of the email, or difference information between the time of requesting authentication through the first message and the release date of the device that sent the first message.

[0085] According to one embodiment, the server can obtain the first feature by calculating the information included in the first message as in and .

[0086] According to one embodiment, the server can obtain (calculate) the second feature (e.g., multi-event feature) by using information related to a device and a phone number among information included in a plurality of first messages received continuously during a specified time (e.g., 24 hours).

[0087] According to one embodiment, the server can detect a plurality of first messages (e.g., SMS) stored in an SMS record database of a memory (e.g., memory (130) of FIG. 1) that are received consecutively for a specified period of time (e.g., 24 hours) before the current first message is received.

[0088] According to one embodiment, the server may obtain (calculate) the second feature by using at least one of information included in a plurality of first messages (e.g., SMS), including information on the number of unique IPs associated with a specific phone number, information on the sum of charges for the first message for a specific phone number, information on the number of unique IPs associated with a specific IMEI, information on the number of unique phone numbers associated with a specific IMEI, or information on the sum of charges for the first message for a specific IMEI.

[0089] According to one embodiment, the server can obtain the second feature by calculating the information included in the first message as in and .

[0090] According to one embodiment, the server may obtain (calculate) the third feature (e.g., country-event feature) by using information related to a device and a phone number among information included in a plurality of first messages sent from a specified country (region) during a specified time (e.g., 25 hours).

[0091] According to one embodiment, the server may obtain (calculate) the third feature by using at least one of information included in a plurality of first messages (e.g., SMSs), including information on the difference between the usage rate of a domain of a specific email and the average usage rate of the domain of the specific email in a specified country during a specified time, information on the difference between the usage rate of a specific application or service and the average usage rate of the specific application or service in a specified country during a specified time, information on the number of phone numbers having the same prefix in the specified country, information on the number of times authentication was requested through the first message using an IMEI having the same prefix in the specified country, or information on the number of IMEIs having the same prefix in the specified country.

[0092] According to one embodiment, the server can obtain the third feature by calculating the information included in the first message as in and .

[0093] In operation 205, a server (e.g., server (101) of FIG. 1 and / or processor (120) of FIG. 1) may input at least one feature as an input value of a learned artificial intelligence model.

[0094] According to one embodiment, the server may input at least one feature among the first feature (e.g., single-event feature), the second feature (e.g., multi-event feature), and the third feature (e.g., country-event resources) as an input value (e.g., feature vector) of an artificial intelligence model.

[0095] According to one embodiment, the server may obtain at least one feature as a specified number of numerical values ​​used for learning the artificial intelligence model, sort the numerical values ​​in the order used for learning the artificial intelligence model, and then input the values ​​as inputs to the artificial intelligence model.

[0096] According to one embodiment, the server may pre-train an artificial intelligence model to detect an attack of an abnormal message based on at least one of the first feature, the second feature, or the third feature.

[0097] In operation 207, a server (e.g., server (101) of FIG. 1 and / or processor (120) of FIG. 1) may compare an output value of an artificial intelligence model with a threshold value.

[0098] In the above operation 207, the server (e.g., the server (101) of FIG. 1 and / or the processor (120) of FIG. 1) can confirm that the output value of the artificial intelligence model is greater than or equal to a threshold value as an attack of an abnormal message in operation 209.

[0099] According to one embodiment, the server, when receiving an output value from the artificial intelligence model, compares a score (e.g., a value between 1 and 0) corresponding to the output value with a threshold value (e.g., 0.5), and if the output value as a result of the comparison is greater than the threshold value, determines that it is an attack of an abnormal message and rejects the authentication request.

[0100] In the above operation 207, the server (e.g., the server (101) of FIG. 1 and / or the processor (120) of FIG. 1) can confirm that the output value of the artificial intelligence model is below a threshold value as a normal message in operation 211.

[0101] According to one embodiment, the server, when receiving an output value from the artificial intelligence model, compares a score (e.g., a value between 1 and 0) corresponding to the output value with a threshold value (e.g., 0.5), and if the output value as a result of the comparison is less than or equal to the threshold value, confirms it as a normal message and performs an authentication operation.

[0102] A method for detecting an attack of an abnormal message according to an embodiment may include an operation of verifying information included in a first message for an authentication request based on reception of the first message. The method according to an embodiment may include an operation of acquiring at least one feature from among first features obtained using information related to the authentication request among information included in the first message, second features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time, or third features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time in a specified country. The method according to an embodiment may include an operation of inputting the at least one feature as an input value of an artificial intelligence model. The method according to an embodiment may include an operation of determining an attack of an abnormal message if an output value output from the artificial intelligence model is greater than or equal to a threshold value.

[0103] In the method according to one embodiment, the first features may include features obtained using information related to an authentication request included in a single first message.

[0104] In the method according to one embodiment, the information related to the authentication request used to obtain the first features may include at least one of a billing fee for the first message, device information registered with the user's account at the time of the authentication request via the first message, difference information between the time of the authentication request via the first message and the time of creation of the domain of the email, or difference information between the time of the authentication request via the first message and the release time of the device that sent the first message.

[0105] In the method according to one embodiment, the second features may represent features obtained by using information related to a device and a telephone number among information included in a plurality of first messages received continuously during a specified period of time.

[0106] In the method according to one embodiment, the device and the information related to the phone number used to obtain the second features may include at least one of information on the number of unique IPs related to a specific phone number, information on the sum of the billing charges for the first message for the specific phone number, information on the number of unique IPs related to a specific IMEI, information on the number of unique phone numbers related to a specific IMEI, or information on the sum of the billing charges for the first message for the specific IMEI.

[0107] In the method according to one embodiment, the third features may represent features obtained by using information related to the device and the telephone number among information included in a plurality of first messages sent from a specified country during a specified time.

[0108] In the method according to one embodiment, the information related to the device and the phone number used to obtain the third features may include at least one of information on the difference between the usage rate of a domain of a specific email and the average usage rate of the domain of the specific email in a specified country during a specified time, information on the difference between the usage rate of a specific application or service and the average usage rate of the specific application or service in a specified country during a specified time, information on the number of phone numbers having the same prefix in the specified country, information on the number of times authentication was requested through a first message using an IMEI having the same prefix in the specified country, or information on the number of IMEIs having the same prefix in the specified country.

[0109] The method according to one embodiment may further include an operation of obtaining a numerical value corresponding to the at least one feature and inputting the obtained numerical value as an input value of the artificial intelligence model.

[0110] According to one embodiment, the method may further include an operation of arranging the at least one feature in an order used for learning the artificial intelligence model, and inputting the at least one sorted feature as an input value of the artificial intelligence model.

[0111] Electronic devices according to embodiments disclosed herein may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to embodiments disclosed herein are not limited to the aforementioned devices.

[0112] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0113] The term "module" used in one embodiment of this document may include a unit implemented as hardware, software, firmware, or a combination thereof, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0114] An embodiment of the present document may be implemented as software comprising one or more instructions stored on a machine-readable storage medium. For example, the device may call at least one of the one or more instructions stored from the storage medium and execute it. This enables the device to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, "non-transitory" only means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and this term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily in the storage medium.

[0115] According to one embodiment, the method according to one embodiment disclosed in the present document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0116] According to one embodiment, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to one embodiment, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to one embodiment, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

[0117] While the present disclosure has been described and illustrated with reference to various exemplary embodiments, it should be understood that these various exemplary embodiments are illustrative and not limiting. Furthermore, those skilled in the art will appreciate that various modifications, alternatives, and / or variations may be made to the exemplary embodiments without departing from the true spirit and scope of the present disclosure, including the appended claims and their equivalents. Furthermore, it should be understood that any one embodiment described in the present disclosure may be combined with other embodiments.

Claims

1. In the server (101 in Fig. 1), At least one processor (120 in FIG. 2) including a processing circuit; and It includes a memory (130 in Fig. 2) that stores commands, The above instructions, when individually or collectively executed by the at least one processor, cause the server to: Receive a first message for authentication request, and verify the information included in the first message; Acquire at least one of the following features: first features obtained using information related to an authentication request among information included in the first message, second features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time, and / or third features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time in a specified country; Input at least one of the above features as an input value of an artificial intelligence model, An electronic device configured to identify the first message as an attack of an abnormal message based on an output value from the artificial intelligence model being greater than a threshold value.

2. In paragraph 1, A server comprising the above first features, wherein the first features are obtained using information related to an authentication request included in a single first message.

3. In any one of paragraphs 1 to 2, A server comprising at least one of the following information related to the authentication request used to obtain the first features: a billing fee for the first message, device information registered to the user's account at the time of the authentication request via the first message, difference information between the time of the race request via the first message and the time of creation of the domain of the email, or difference information between the time of the authentication request via the first message and the release date of the device that sent the first message.

4. In any one of paragraphs 1 to 3, The above second features are a server that represents features obtained by using information related to a device and a phone number among information included in a plurality of first messages received continuously during a specified period of time.

5. In any one of paragraphs 1 to 4, A server in which the device and the information related to the phone number used to obtain the second features include at least one of information on the number of unique IPs associated with a specific phone number, information on the sum of charges for a first message for a specific phone number, information on the number of unique IPs associated with a specific IMEI, information on the number of unique phone numbers associated with a specific IMEI, or information on the sum of charges for a first message for a specific IMEI.

6. In any one of paragraphs 1 to 5, The above third features are a server that represents features obtained by using information related to the device and phone number among information included in a plurality of first messages sent from a specified country during a specified time.

7. In any one of paragraphs 1 to 6, A server including at least one of the following information related to the device and the phone number used to obtain the third features: information on the difference between the usage rate of a domain of a specific email and the average usage rate of the domain of the specific email in a specific country during a specific time period; information on the difference between the usage rate of a specific application or service and the average usage rate of the specific application or service in a specific country during a specific time period; information on the number of phone numbers having the same prefix in a specific country; information on the number of requests for authentication through a first message using IMEIs having the same prefix in a specific country; or information on the number of IMEIs having the same prefix in a specific country.

8. In any one of paragraphs 1 to 7, The above instructions, when individually or collectively executed by the at least one processor, cause the server to: A server configured to obtain a numerical value corresponding to at least one of the above features and input the obtained numerical value as an input value of the artificial intelligence model.

9. In any one of paragraphs 1 to 8, The above instructions, when individually or collectively executed by the at least one processor, cause the server to: A server configured to sort at least one feature in the order used for learning the artificial intelligence model and input the sorted at least one feature as an input value of the artificial intelligence model.

10. In any one of paragraphs 1 to 9, The above artificial intelligence model is a server trained to detect an attack of an abnormal message based on at least one of the first feature, the second feature, or the third feature.

11. In a method for detecting an attack of an abnormal message, An action of verifying information included in a first message based on receipt of a first message for an authentication request; An operation of acquiring at least one of the following features: first features acquired using information related to an authentication request among information included in the first message, second features acquired using information related to a device and a phone number among information included in a plurality of first messages received during a specified time, and / or third features acquired using information related to a device and a phone number among information included in a plurality of first messages received during a specified time in a specified country; An operation of inputting at least one of the above features as an input value of an artificial intelligence model; and A method including an action of confirming an abnormal message attack based on an output value from the artificial intelligence model exceeding a threshold value.

12. In paragraph 11, A method in which the first features include features obtained using information related to an authentication request included in a single first message.

13. In any one of paragraphs 11 to 12, A method according to claim 1, wherein the information related to the authentication request used to obtain the first features comprises at least one of: a billing fee for the first message, device information registered to the user's account at the time of the authentication request via the first message, difference information between the time of the authentication request via the first message and the time of creation of the domain of the email, or difference information between the time of the authentication request via the first message and the release date of the device that sent the first message.

14. In any one of paragraphs 11 to 13, The above second features are a method for representing features obtained by using information related to a device and a telephone number among information included in a plurality of first messages received continuously during a specified period of time.

15. In a non-volatile storage medium storing commands, the commands are configured to cause the server to perform at least one action when executed by the server, wherein the at least one action is: An action of verifying information included in a first message based on receipt of a first message for an authentication request; An operation of verifying at least one of the following features: first features obtained using information related to an authentication request among information included in the first message, second features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time, or third features obtained using information related to a device and a phone number among information included in a plurality of first messages received during a specified time in a specified country; An operation of inputting at least one of the above features as an input value of an artificial intelligence model; and A storage medium including an operation for confirming an abnormal message attack based on an output value from the artificial intelligence model exceeding a threshold value.

Citation Information

Patent Citations

  • Apparatus for detecting fraudulent transactions using machine learning and method thereof

    KR1020170083330A

  • System and method for security threats anomaly detection based on artificial intelligence

    KR102433830B1

  • Anomaly detection for access control events

    US20160112397A1

  • Mechanisms for anomaly detection and access management

    US20200267162A1

  • Systems and methods for detecting anomalous behavior

    US20220303296A1