Malicious Object Classification Framework with Automated Model Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security systems rely on manually initiated updates for classification engines, which are prone to human error and result in inadequate detection capabilities against rapidly evolving malicious software, leading to prolonged update cycles and increased false negative events.

Innovation Solution

A framework that includes a training engine to automatically detect the need for updates in classification engines by analyzing discrepancies between detection and classification engines, modifying predictive models based on detected features, and generating an updated reference model to reduce false negatives and false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If manually initiated updates are used for classification engines, then system complexity is reduced, but update timeliness and detection effectiveness deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidupdate cycle time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The classification engine automatically initiates its own updates by monitoring its own performance metrics and triggering retraining when degradation is detected, eliminating the need for manual intervention and reducing update delays

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback loop where classification results are continuously evaluated, and performance degradation automatically triggers update processes, creating a self-correcting mechanism that responds to changing threat landscapes

Inventive Principle:
Principle #23Feedback

2Extent of automation

If manual updates are used for classification engines, then automation requirements are reduced, but detection accuracy and reliability worsen

Engineering Contradiction:
Improveautomation levelVSAvoiddetection accuracy
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The classification engine autonomously monitors its own performance, identifies when retraining is needed, and executes updates without human intervention, ensuring consistent and timely maintenance of detection accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system maintains continuous monitoring and periodic updating of the classification engine, ensuring that detection capabilities are constantly refined and maintained at optimal levels rather than relying on intermittent manual updates

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If update frequency is increased to match evolving malware, then detection effectiveness improves, but system resource consumption increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidsystem resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The update frequency and intensity are dynamically adjusted based on detected threat levels and performance degradation rates, allowing the system to intensify updates when needed and conserve resources during stable periods

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters such as retraining frequency, data sampling rates, and model complexity based on current threat conditions, optimizing the balance between detection effectiveness and resource consumption

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10902117B1Framework for classifying an object as malicious with machine learning for deploying updated predictive models
Publication Date: 2021.01.26 MAGENTA SECURITY HOLDINGS LLC
  • US10902117B1 patent drawing
  • US10902117B1 patent drawing
  • US10902117B1 patent drawing

AI summary

According to one embodiment, a computerized method for acquiring updated predictive model is described. The updated predictive model is achieved through machine learning analyses of information by a training engine, which issues a control message in response to a discrepancy in a determination of the suspect object as malicious or non-malicious by a detection engine and a classification engine. The detection engine analyzes a content of a suspect object to determine whether the suspect object is malicious or non-malicious. Similarly, the classification engine analyses the suspect object based on the predictive model to determine whether the suspect object is malicious or non-malicious. The control message causes the training engine to update the predictive model based on machine learning analyses of information provided via the control message and to return an updated predictive model to the classification engine.