File Cluster Curation for Zero-Day Threat Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional computer security systems face difficulties in accurately classifying unknown files, also known as zero-day threats, and often require human intervention for decision-making, but lack sufficient information to enable informed decisions by security analysts.

Innovation Solution

The system curates file clusters by identifying suspicious files, clustering them based on shared characteristics, prioritizing files based on contextual value, and providing a graphical representation to security analysts for informed decision-making and subsequent security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional computer security systems rely on automated classification algorithms, then they can process files quickly, but they fail to accurately classify unknown files (zero-day threats)

Engineering Contradiction:
Improvefile classification speedVSAvoidthreat classification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces a human security analyst as an intermediary between automated classification algorithms and final threat determination. When automated systems cannot confidently classify a file, it is escalated to a human analyst who reviews contextual information and makes the final decision, thereby improving accuracy for unknown threats while maintaining automated processing for routine cases

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the file classification process into multiple stages: initial automated classification, confidence assessment, selective human review for low-confidence cases, and final determination. This segmentation allows the system to apply different processing methods based on the specific needs of each file, improving overall accuracy without sacrificing productivity for all files

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If traditional security systems escalate unknown files to human security analysts, then classification accuracy may improve, but analysts lack sufficient contextual information to make informed decisions

Engineering Contradiction:
Improvethreat classification accuracyVSAvoidcontextual information availability
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent merges multiple information sources including file metadata, behavioral analysis data, cluster information from similar files, and contextual relationships into a comprehensive view presented to the security analyst. This consolidation of diverse data sources ensures analysts have sufficient contextual information to make informed decisions about unknown files

Inventive Principle:
Principle #5Merging (Combining)

3Loss of information

If security systems present all files in a cluster to analysts, then complete information is provided, but analysts become overwhelmed by excessive information

Engineering Contradiction:
Improvecompleteness of file informationVSAvoidanalyst workload management
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent applies local quality by prioritizing and highlighting specific files within a cluster based on their relevance, risk level, and contextual importance. Rather than treating all files equally, the system emphasizes key files that require immediate attention while organizing less critical files separately, allowing analysts to focus on the most important information first

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9842219B1Systems and methods for curating file clusters for security analyses
Publication Date: 2017.12.12 GEN DIGITAL INC
  • US9842219B1 patent drawing
  • US9842219B1 patent drawing
  • US9842219B1 patent drawing

AI summary

The disclosed computer-implemented method for curating file clusters for security analyzes may include (1) identifying a suspicious file that exists on at least one computing system within a computing community, (2) clustering a set of files that includes the suspicious file into a file cluster based at least in part on at least one characteristic shared by the set of files, (3) prioritizing at least one file included in the file cluster based at least in part on a contextual value of the file relative to the file cluster, (4) providing, for presentation to a security analyst, a graphical representation of the file cluster that highlights the prioritized file relative to the file cluster, and then (5) performing at least one security action on the suspicious file based at least in part on feedback received from the security analyst. Various other methods, systems, and computer-readable media are also disclosed.