Malware Detection Model Testing via Time-Shifted Dataset Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection systems lack regimented neural network model testing procedures, which hinders the assurance of correct functioning in detecting and classifying malware.

Innovation Solution

A method and apparatus for testing a malware detection machine learning model by training it with a first dataset and then testing it using a time-shifted version of the same dataset, allowing the model to learn from new malware samples and repeat the process until all samples are used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If malware detection models are trained using traditional datasets without time-shifting, then the training process is simpler and faster, but the model's ability to detect new and evolving malware is compromised

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidtesting procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing time-shifting on the dataset before testing the model. The dataset is pre-processed to create time-shifted versions that simulate future malware threats, allowing the model to be tested on data it hasn't seen before in a realistic temporal context. This preliminary preparation of the test data ensures the model is properly validated against evolving threats.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If regimented neural network model testing procedures are implemented, then model reliability is improved, but the testing process becomes more complex and time-consuming

Engineering Contradiction:
Improvemodel functioning assuranceVSAvoidtesting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action by repeatedly testing the model on multiple time-shifted versions of the dataset. The testing process is structured to systematically apply different time-shifted datasets in sequence, allowing comprehensive validation of the model's ability to detect malware across different time periods and threat evolutions, while maintaining an organized and efficient testing rhythm.

Inventive Principle:
Principle #19Periodic action

3Productivity

If the model is tested on the same dataset used for training, then the testing process is simpler, but the model's effectiveness against new malware cannot be properly evaluated

Engineering Contradiction:
Improvetesting efficiencyVSAvoiddetection capability validation
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies segmentation by dividing the original dataset into multiple time-based segments and creating time-shifted versions. The dataset is segmented into training portions and testing portions with different temporal characteristics, allowing the model to be trained on one time period's malware patterns and tested on another time period's patterns, thereby validating its ability to generalize to new threats.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12278833B2Method and apparatus for testing a malware detection machine learning model
Publication Date: 2025.04.15 UAB 360 IT
  • US12278833B2 patent drawing
  • US12278833B2 patent drawing
  • US12278833B2 patent drawing

AI summary

A method and apparatus for testing a malware detection machine learning model. The method trains a malware detection model using a first dataset containing malware samples from a particular time period. The trained model is then tested using a second dataset that is a time shifted version of the first dataset.