Graph Neural Threat Classification for Malware Behavior Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional machine learning techniques are not well-suited for handling non-Euclidean data associated with malware behavior, which contains complex relationships and sequencing, making real-time threat classification and detection challenging.

Innovation Solution

Employing graph neural networks (GNNs) and transformers to process non-Euclidean structured data directly, modeling the relationships and sequencing within behavior-based data to enhance malware detection and classification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional machine learning techniques are used to process malware behavior data, then the system is simpler to implement, but the detection accuracy and ability to handle complex relationships deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional machine learning algorithms with graph neural networks that are specifically designed to process non-Euclidean data structures. This substitution enables the system to capture complex relationships and sequencing in malware behavior data, thereby improving detection accuracy while maintaining manageable system complexity through the use of specialized architectures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the data representation from traditional Euclidean formats to non-Euclidean graph structures, adding a new dimensional perspective to how malware behavior data is organized and processed. This dimensional change allows the model to preserve complex relationships and sequencing information that would be lost in traditional representations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If behavior-based analysis is used to monitor all relevant activity, then detection capability improves, but time and resources required for investigation increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidinvestigation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service through automated machine learning models that perform threat classification and detection without requiring extensive manual investigation. The system autonomously analyzes behavior data, identifies suspicious patterns, and classifies threats, significantly reducing the time and resources needed for manual security analysis while maintaining high detection capability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual investigation processes with automated graph neural network-based analysis. This substitution enables the system to process and classify threats in real-time, eliminating the need for time-consuming manual review of behavior patterns while preserving comprehensive detection capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If traditional machine learning is adapted to handle non-Euclidean data, then compatibility improves, but the straightforward application of ML techniques becomes difficult

Engineering Contradiction:
Improvedata handling compatibilityVSAvoidimplementation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent replaces traditional machine learning approaches with graph neural networks that are natively designed to handle non-Euclidean data structures. This substitution eliminates the need for complex adaptations of traditional ML techniques, as GNNs naturally accommodate graph-structured data while maintaining implementation feasibility through established frameworks and methodologies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12468810B2Classifying cybersecurity threats using machine learning on non-euclidean data
Publication Date: 2025.11.11 SENTINELONE INC
  • US12468810B2 patent drawing
  • US12468810B2 patent drawing
  • US12468810B2 patent drawing

AI summary

Systems, methods, and devices for cybersecurity are disclosed herein that can employ machine learning approaches with a better understanding of the complex relationships and sequencing associated with behavior-based data, and that can effectively apply machine learning for behavior-based analysis, malware detection, and identifying and classifying threats in real-time.