Classifier Generator for Cybersecurity Rule Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems face challenges in integrating and updating machine learning classifiers within commercial security products, limiting the sharing, improvement, and deployment of community-developed machine learning models across different security infrastructure products from various vendors.

Innovation Solution

A rule generator is developed to automatically create machine-learning-powered detection systems as text-based, pastable rules that can be interpreted by rules engines, allowing for rapid distribution and integration into existing cybersecurity infrastructure, enabling the same machine-learning-powered rules to be implemented across different security infrastructure components and vendors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning classifiers are deeply embedded within commercial security products, then detection capability is improved, but adaptability and ease of updating are worsened

Engineering Contradiction:
Improvedetection capabilityVSAvoidease of updating
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the machine learning classifier into a separate, modular component that can be independently updated and replaced. The classifier is extracted from the core security product into a standalone module that interfaces through defined APIs, allowing the detection engine to remain while the ML model can be independently trained, validated, and deployed without affecting the core product stability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal classifier interface that can accommodate multiple types of machine learning models and algorithms. The system is designed to work with various ML frameworks and model formats, allowing different vendors and community developers to contribute diverse classifiers through a common interface, thereby improving both adaptability and detection capability across multiple security contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If machine learning classifiers are deeply embedded within commercial security products, then detection capability is improved, but ease of sharing and deployment across different products is worsened

Engineering Contradiction:
Improvedetection capabilityVSAvoidease of deployment
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent establishes a universal classifier interface and standardized data formats that enable the same machine learning model to be deployed across multiple different security products and vendors. The system uses common file formats, API specifications, and validation protocols that allow classifiers to be ported between different security infrastructure components without requiring vendor-specific rework or customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If rules engines are used for static analysis, then interpretability is improved, but detection power is worsened

Engineering Contradiction:
ImproveinterpretabilityVSAvoiddetection power
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the interpretability of rules engines with the detection power of machine learning by creating a hybrid system. The machine learning classifier makes high-level decisions about malicious content, while rules engines provide interpretable validation and explanation of detection logic. This combination allows the system to maintain the analytical depth of ML while preserving the transparency and explainability of rule-based systems through layered architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12067120B2Classifier generator
Publication Date: 2024.08.20 SOPHOS LTD
  • US12067120B2 patent drawing
  • US12067120B2 patent drawing
  • US12067120B2 patent drawing

AI summary

A rule generator can automatically generate a machine-learning-powered detection system capable of recognizing a new malicious object or family of malicious objects and deployable as a text-based, pastable detection rule. The text may be quickly distributed and integrated into existing cybersecurity infrastructure, for example, if the cybersecurity infrastructure supports a rules engine. After initial distribution, the identity may be refined, updated, and replaced. This allows for rapid development and distribution of an initial level of protection, and for updating and improvement over time.