Organization-Specific Forest Model for Malware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing forest-based malware detection systems are not optimized for specific organizations, leading to varying performance and increased false positives, which can compromise the effectiveness of malware identification and security within organizational networks.
Innovation Solution
A method that adjusts a general use forest model using organization-specific data to generate an organization-specific forest model, optimizing weights and conviction thresholds to enhance malware detection accuracy and reduce false positives, thereby improving the detection of malicious files within the organization's computer network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a general use forest model is used for malware detection across multiple organizations, then the model can be utilized by a wide variety of end users and organizations, but the model performs better for some end users and organizations than for others, leading to varying detection accuracy
Solution Approach 1:
The patent applies local quality by creating organization-specific forest models that are customized to each organization's unique data characteristics and threat landscape. Instead of using a single general model for all organizations, the system generates tailored models with organization-specific weights, thresholds, and parameters based on local data patterns, thereby improving detection accuracy for each specific organization while maintaining the ability to serve multiple organizations through the customization process
2Adaptability or versatility
If forest models are trained using data from a wide variety of files and locations including multiple organizations, then the models can be utilized by a wide variety of end users, but the models may perform better for some end users and organizations than for others, increasing false positive rates
Solution Approach 1:
The patent applies parameter changes by adjusting the forest model parameters (weights, thresholds, conviction levels) based on organization-specific data characteristics. The system dynamically modifies model parameters to match the local data distribution and threat patterns of each organization, thereby reducing false positives while maintaining the model's ability to serve multiple organizations through personalized parameter configuration
Data Source
AI summary
The disclosed computer-implemented method for improving forest-based malware detection within an organization may include (i) receiving, at a backend computing system, organization data from at least one organization computing device within an organization computer network, (ii) adjusting, at the backend computing system, a general use forest model based on the organization data to generate an organization-specific forest model for detecting malicious computer files within the organization computer network, and (iii) sending, from the backend computing system, the organization-specific forest model to the at least one organization computing device. Various other methods, systems, and computer-readable media are also disclosed.


