File Cluster Curation for Zero-Day Threat Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional computer security systems face difficulties in accurately classifying unknown files, also known as zero-day threats, and often require human intervention for decision-making, but lack sufficient information to enable informed decisions by security analysts.
Innovation Solution
The system curates file clusters by identifying suspicious files, clustering them based on shared characteristics, prioritizing files based on contextual value, and providing a graphical representation to security analysts for informed decision-making and subsequent security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional computer security systems rely on automated classification algorithms, then they can process files quickly, but they fail to accurately classify unknown files (zero-day threats)
Solution Approach 1:
The patent introduces a human security analyst as an intermediary between automated classification algorithms and final threat determination. When automated systems cannot confidently classify a file, it is escalated to a human analyst who reviews contextual information and makes the final decision, thereby improving accuracy for unknown threats while maintaining automated processing for routine cases
Solution Approach 2:
The patent segments the file classification process into multiple stages: initial automated classification, confidence assessment, selective human review for low-confidence cases, and final determination. This segmentation allows the system to apply different processing methods based on the specific needs of each file, improving overall accuracy without sacrificing productivity for all files
2Measurement precision
If traditional security systems escalate unknown files to human security analysts, then classification accuracy may improve, but analysts lack sufficient contextual information to make informed decisions
Solution Approach 1:
The patent merges multiple information sources including file metadata, behavioral analysis data, cluster information from similar files, and contextual relationships into a comprehensive view presented to the security analyst. This consolidation of diverse data sources ensures analysts have sufficient contextual information to make informed decisions about unknown files
3Loss of information
If security systems present all files in a cluster to analysts, then complete information is provided, but analysts become overwhelmed by excessive information
Solution Approach 1:
The patent applies local quality by prioritizing and highlighting specific files within a cluster based on their relevance, risk level, and contextual importance. Rather than treating all files equally, the system emphasizes key files that require immediate attention while organizing less critical files separately, allowing analysts to focus on the most important information first
Data Source
AI summary
The disclosed computer-implemented method for curating file clusters for security analyzes may include (1) identifying a suspicious file that exists on at least one computing system within a computing community, (2) clustering a set of files that includes the suspicious file into a file cluster based at least in part on at least one characteristic shared by the set of files, (3) prioritizing at least one file included in the file cluster based at least in part on a contextual value of the file relative to the file cluster, (4) providing, for presentation to a security analyst, a graphical representation of the file cluster that highlights the prioritized file relative to the file cluster, and then (5) performing at least one security action on the suspicious file based at least in part on feedback received from the security analyst. Various other methods, systems, and computer-readable media are also disclosed.


