Dynamic ML Model Selection for Cyber Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems are inadequate in detecting polymorphic malware and zero-day attacks, as they rely on signature-based detection methods that are ineffective against evolving threats, leading to delayed identification of cyber-intrusions and potential irreparable harm.

Innovation Solution

A self-adapting cybersecurity system that employs machine learning models to detect and remediate cyber threats by continuously tuning and deploying finely-tuned models based on datasets from multiple compute devices, ensuring real-time threat detection and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If signature-based detection methods are used, then the system is simple to implement, but it cannot detect polymorphic malware and zero-day attacks

Engineering Contradiction:
Improvedetection capability against evolving threatsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic model selection where the system automatically switches between different machine learning models based on the characteristics of the input data and current performance metrics. This allows the system to adapt to evolving threats by selecting the most appropriate detection model for each scenario, resolving the contradiction between adaptability and complexity through automated dynamic adjustment rather than static configuration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters by adjusting which machine learning model is active based on performance validation. When validation shows improved detection accuracy, the system transitions to the new model configuration. This parameter change approach enables the system to improve threat detection capability while managing complexity through automated parameter adjustment rather than manual system redesign

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple machine learning models are validated and deployed, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidmodel management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs multiple machine learning models that are trained on different datasets and validation procedures, allowing the system to test multiple detection approaches simultaneously. Models that fail validation are discarded, while successful models become the active detection mechanism. This approach improves detection accuracy by exploring multiple hypotheses while managing complexity through automated validation-based model selection and replacement

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system implements feedback loops where detection performance is continuously monitored and validated. Based on this feedback, the system automatically determines whether to switch between models or retain the current model. This feedback mechanism resolves the contradiction by using performance data to guide model selection, improving accuracy while keeping complexity manageable through automated decision-making based on validation results

Inventive Principle:
Principle #23Feedback

3Reliability

If the system continuously adapts to new threats, then detection effectiveness improves, but the time to identify and respond to intrusions increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary validation of machine learning models before deployment. Models are pre-trained and validated on historical threat data before being activated for real-time detection. This preliminary action ensures that only proven effective models are used in production, improving reliability while maintaining fast response times by avoiding the need for real-time model training and validation during actual threat incidents

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11921851B1System and method for improved end-to-end cybersecurity machine learning and deployment
Publication Date: 2024.03.05 MAGENTA SECURITY HOLDINGS LLC
  • US11921851B1 patent drawing
  • US11921851B1 patent drawing
  • US11921851B1 patent drawing

AI summary

The presently disclosed subject matter includes an apparatus that receives a dataset with values associated with different digital resources captured from a group of compute devices. The apparatus includes a feature extractor, to generate a set of feature vectors, each feature vector from the set of feature vectors associated with a set of data included in the received dataset. The apparatus uses the set of feature vectors to validate multiple machine learning models trained to determine whether a digital resource is associated with a cyberattack. The apparatus selects at least one active machine learning model and sets the remaining trained machine learning models to operate in an inactive mode. The active machine learning model generates a signal to alert a security administrator, blocks a digital resource from loading at a compute device, or executes other remedial action, upon a determination that the digital resource is associated with a cyberattack.