Antivirus Rule Selectivity Assessment Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing antivirus systems face inefficiencies and potential human errors due to the large number of heuristic rules and signatures needed for effective detection of computer threats, often resulting in false activations and a burden on developers.
Innovation Solution
A system that assesses the selectivity of categorization rules using a computer with a processor, data storage medium, and input/output facilities, including a categorization rule application engine, selectivity determination engine, and algorithm training engine, to produce a numerical selectivity score and ensure accurate categorization of objects without false activations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the number of heuristic rules and signatures is increased to improve threat detection capability, then detection accuracy is improved, but the number of false activations increases
Solution Approach 1:
The patent applies parameter changes by introducing a selectivity score as a new parameter to evaluate and rank detection rules. Instead of using a fixed threshold for rule activation, the system dynamically adjusts the threshold based on the selectivity score, which is calculated using statistical parameters from training data. This allows the system to maintain high detection accuracy while reducing false activations by only activating rules with sufficiently high selectivity scores.
Solution Approach 2:
The patent implements feedback mechanisms by using training data to evaluate detection rules and adjust their activation thresholds. The system continuously monitors the performance of detection rules and uses this feedback to refine the selectivity scores, thereby optimizing the balance between detection accuracy and false activation reduction over time.
2Reliability
If manual analysis of detection rules is performed to reduce false activations, then rule selectivity is improved, but developer workload and human errors increase
Solution Approach 1:
The patent applies self-service by enabling the system to automatically evaluate and rank detection rules using training data and statistical analysis. The automated rule evaluation process eliminates the need for manual developer analysis, reducing workload and minimizing human errors while maintaining high rule selectivity through objective, data-driven assessment.
Solution Approach 2:
The patent replaces the mechanical system of manual developer analysis with an automated computational system. The selectivity determination engine uses algorithms to automatically calculate selectivity scores based on training data, substituting human expertise with automated processing that is both more efficient and less error-prone.
3Measurement precision
If a representative collection of safe files is used for rule testing, then rule accuracy is improved, but the collection cannot cover entire variety of files encountered by users
Solution Approach 1:
The patent applies dimensionality change by transitioning from a two-dimensional approach (testing rules against a fixed collection of safe files) to a three-dimensional approach (incorporating both safe and malicious files in the training data). This allows the system to evaluate rule accuracy across a broader spectrum of file types, including malicious files, thereby improving both measurement precision and adaptability to real-world file variety.
Data Source
AI summary
Assessment of selectivity of categorization rules. One or more categorization rules are applied to a set of un-categorized objects to produce a categorization result set representing assignment of objects the set into at least two categories. A selectivity score for the at least one categorization rule is obtained based on statistical information. The numerical selectivity score represents an estimation of accuracy of the at least one categorization rule, and is produced as a result of application of at least one trained selectivity determination algorithm, which is based on application of a plurality of specially-selected categorization rules to a set of pre-categorized training data, with the application of each one producing a uniform grouping of objects.


