Container File Analysis Using Convolutional Neural Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for classifying container files are inefficient due to the need for extended feature spaces and misclassification risks when analyzing entire container files, as a single malicious file can render an entire container file malicious, and benign files combined can also render a container file malicious, leading to misclassification.
Innovation Solution
A trained convolutional neural network is used to analyze individual files within a container file, applying kernels to overlapping groups of feature vectors to identify prominent features and classify the container file as malicious or benign, utilizing a pooling layer to combine features efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the entire container file is analyzed using extended feature spaces, then comprehensive classification is achieved, but computational complexity and processing time increase significantly
Solution Approach 1:
The patent segments the container file into individual files and extracts features from each file separately. Instead of analyzing the entire container file as a single entity with extended feature spaces, the system processes each constituent file independently, extracting relevant features from individual files while maintaining the ability to classify the overall container file. This segmentation approach reduces computational complexity while preserving classification accuracy.
2Productivity
If individual files within container file are analyzed separately, then processing efficiency improves, but misclassification risk increases due to inability to detect combined malicious effects
Solution Approach 1:
The patent merges the classification results from individual file analyses to determine the overall classification of the container file. The system combines features and classification outcomes from multiple individual files, enabling detection of malicious patterns that emerge from file combinations. This merging approach maintains processing efficiency while ensuring reliable classification by considering both individual and combined file characteristics.
3Ease of operation
If traditional classification methods are used on container files, then simplicity is maintained, but detection precision decreases due to malicious files being concealed within otherwise innocuous containers
Solution Approach 1:
The patent extracts and analyzes individual files from within container files to detect malicious content. Instead of applying traditional classification methods directly to the entire container file, the system extracts features from individual files within the container, enabling detection of concealed malicious files while maintaining operational simplicity through a systematic extraction and analysis process.
Data Source
AI summary
A system is provided for training a machine learning model to detect malicious container files. The system may include at least one processor and at least one memory. The memory may include program code which when executed by the at least one processor provides operations including: processing a container file with a trained machine learning model, wherein the trained machine learning is trained to determine a classification for the container file indicative of whether the container file includes at least one file rendering the container file malicious; and providing, as an output by the trained machine learning model, an indication of whether the container file includes the at least one file rendering the container file malicious. Related methods and articles of manufacture, including computer program products, are also disclosed.


