Hybrid Malware Classifier Using Deep Learning and Supervised Mining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional data mining methods struggle to effectively detect malware, especially with unstructured and complex data, leading to difficulties in identifying both known and unknown malware threats.
Innovation Solution
The integration of deep learning neural networks with supervised data mining methods creates a classifier that can analyze and classify data for malware, using techniques like hierarchical feature extraction and semi-supervised machine learning to identify potential malware and trigger security actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional data mining methods are used to analyze structured data for malware detection, then detection of known malware patterns is improved, but the ability to process unstructured and complex data deteriorates
Solution Approach 1:
The patent combines deep learning neural networks with supervised data mining methods into a hybrid classifier that integrates the pattern recognition strength of traditional data mining with the ability to process unstructured data through deep learning feature extraction, thereby resolving the contradiction between detection accuracy and data processing versatility
Solution Approach 2:
The classifier is constructed as a composite system combining multiple algorithmic approaches (deep learning, supervised learning, data mining) that work together to handle both structured and unstructured data types, enabling the system to maintain high detection accuracy while expanding adaptability to diverse data formats
2Ease of manufacture
If strict categories are defined to classify malware data, then structured data analysis is improved, but information from unstructured data is lost
Solution Approach 1:
The system performs preliminary feature extraction using deep learning on raw unstructured data before applying supervised classification, preserving information from unstructured data while preparing it for structured analysis in subsequent processing stages
Solution Approach 2:
The classification process is segmented into multiple stages: initial deep learning-based feature extraction from unstructured data, followed by supervised classification of extracted features, allowing the system to maintain information from unstructured data while applying structured classification methods
3Adaptability or versatility
If a hybrid classifier combining deep learning and supervised data mining is used, then the ability to process complex and unstructured data is improved, but system complexity increases
Solution Approach 1:
The hybrid classifier is segmented into distinct functional modules: a deep learning component for feature extraction from unstructured data and a supervised learning component for classification, allowing each module to be optimized independently while working together to reduce overall system complexity
4Productivity
If traditional data mining methods are used, then processing of structured data is efficient, but detection of unknown malware deteriorates
Solution Approach 1:
The system performs preliminary unsupervised feature extraction from data using deep learning before supervised classification, enabling the detection of unknown malware patterns in unstructured data while maintaining efficient processing of structured data through the subsequent supervised learning stage
Data Source
AI summary
A computer-implemented method for detecting malware using machine learning may include (1) identifying data to be analyzed for malware, (2) classifying, using a classifier created by a combination of at least one deep learning neural network and at least one supervised data mining method, the data to be analyzed for malware, (3) determining, based on a predefined threshold, that the classification of the data indicates potential malware on the computing device, and (4) performing a security action based on the determination of potential malware on the computing device. Various other methods, systems, and computer-readable media are also disclosed.


