Hybrid Malware Classifier Using Deep Learning and Supervised Mining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data mining methods struggle to effectively detect malware, especially with unstructured and complex data, leading to difficulties in identifying both known and unknown malware threats.

Innovation Solution

The integration of deep learning neural networks with supervised data mining methods creates a classifier that can analyze and classify data for malware, using techniques like hierarchical feature extraction and semi-supervised machine learning to identify potential malware and trigger security actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional data mining methods are used to analyze structured data for malware detection, then detection of known malware patterns is improved, but the ability to process unstructured and complex data deteriorates

Engineering Contradiction:
Improvemalware detection accuracyVSAvoiddata processing capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines deep learning neural networks with supervised data mining methods into a hybrid classifier that integrates the pattern recognition strength of traditional data mining with the ability to process unstructured data through deep learning feature extraction, thereby resolving the contradiction between detection accuracy and data processing versatility

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The classifier is constructed as a composite system combining multiple algorithmic approaches (deep learning, supervised learning, data mining) that work together to handle both structured and unstructured data types, enabling the system to maintain high detection accuracy while expanding adaptability to diverse data formats

Inventive Principle:
Principle #40Composite materials

2Ease of manufacture

If strict categories are defined to classify malware data, then structured data analysis is improved, but information from unstructured data is lost

Engineering Contradiction:
Improveclassification process efficiencyVSAvoiddata information retention
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The system performs preliminary feature extraction using deep learning on raw unstructured data before applying supervised classification, preserving information from unstructured data while preparing it for structured analysis in subsequent processing stages

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The classification process is segmented into multiple stages: initial deep learning-based feature extraction from unstructured data, followed by supervised classification of extracted features, allowing the system to maintain information from unstructured data while applying structured classification methods

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If a hybrid classifier combining deep learning and supervised data mining is used, then the ability to process complex and unstructured data is improved, but system complexity increases

Engineering Contradiction:
Improvedata processing capabilityVSAvoidclassifier system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The hybrid classifier is segmented into distinct functional modules: a deep learning component for feature extraction from unstructured data and a supervised learning component for classification, allowing each module to be optimized independently while working together to reduce overall system complexity

Inventive Principle:
Principle #1Segmentation

4Productivity

If traditional data mining methods are used, then processing of structured data is efficient, but detection of unknown malware deteriorates

Engineering Contradiction:
Improvedata processing speedVSAvoidunknown malware detection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary unsupervised feature extraction from data using deep learning before supervised classification, enabling the detection of unknown malware patterns in unstructured data while maintaining efficient processing of structured data through the subsequent supervised learning stage

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10250617B1Systems and methods for detecting malware using machine learning
Publication Date: 2019.04.02 GEN DIGITAL INC
  • US10250617B1 patent drawing
  • US10250617B1 patent drawing
  • US10250617B1 patent drawing

AI summary

A computer-implemented method for detecting malware using machine learning may include (1) identifying data to be analyzed for malware, (2) classifying, using a classifier created by a combination of at least one deep learning neural network and at least one supervised data mining method, the data to be analyzed for malware, (3) determining, based on a predefined threshold, that the classification of the data indicates potential malware on the computing device, and (4) performing a security action based on the determination of potential malware on the computing device. Various other methods, systems, and computer-readable media are also disclosed.