Data Package Classification via Normalization and Permutation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transmission of data packages between sending and receiving devices is resource-intensive and time-consuming due to the need for thorough security checks, leading to user frustration and increased risk of malicious or erroneously composed messages.

Innovation Solution

A method and system using a framework with classifiers, data models, and mappings to normalize and permute data packages, enabling efficient detection of potential threats by generating a single search term for multiple malicious representations, and applying data models to detect known security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If thorough security checks are performed on data packages, then security and threat detection are improved, but processing time and resource consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing normalization on data packages before security analysis. The normalization process standardizes various malicious data representations into a common format, creating a unified search term that can be efficiently checked against security databases. This preprocessing step reduces the complexity of subsequent security checks while maintaining thorough detection capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by transforming the data package through normalization and permutation operations. By changing the representation parameters of malicious data into standardized forms, the system enables more efficient pattern matching and classification. The data model applies various transformations to generate permutations that are then classified using machine learning models, improving both speed and accuracy.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple different potentially malicious data representations are checked individually, then detection accuracy is improved, but processing requirements and storage needs increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies merging by combining multiple different potentially malicious data representations into a single normalized form. The normalization process consolidates various obfuscation techniques, character variations, and encoding methods into a unified search term. This allows the system to detect multiple malicious patterns using a single classification operation, significantly reducing processing requirements while maintaining comprehensive detection accuracy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universality through the normalization framework that handles multiple types of malicious data representations with a single unified approach. The data model and machine learning classifiers are designed to work with normalized data regardless of the original representation, enabling the system to detect phishing attempts, obfuscated malware, and other threats through a universal classification mechanism rather than requiring separate detection systems for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12609941B2Method and system for processing data packages
Publication Date: 2026.04.21 EGRESS SOFTWARE TECH
  • US12609941B2 patent drawing
  • US12609941B2 patent drawing
  • US12609941B2 patent drawing

AI summary

A method, system and non-transitory computer-readable medium for classifying a received data package using a framework. The framework comprises at least one classifier; a processing component for processing the received data package using the at least one classifier, and a database for storing at least a data model and a data set of mappings. The at least one classifier is configured to obtain data of the received data package and apply the data set of mappings to the obtained data to generate normalised data. The data model is then applied to the normalised data to generate at least one permutation of the normalised data, and the data package is classified based on the at least one permutation of the normalised data.