Machine Learning Threat Discernment Model Version Mismatch Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional computer security detection methods relying on signatures, filters, and human-generated classifications struggle to keep pace with rapidly changing threats, particularly advanced threats that use 'exploits and evasion' tactics, leading to potential disruptions and inefficiencies due to mismatches in threat assessments between different versions of machine learning models.

Innovation Solution

Implementing a cloud-based, non-signature, non-heuristic machine learning threat discernment system that uses advanced mathematical analysis and ensemble models to provide real-time threat assessments, allowing for dynamic feature collection and enforcement, with mechanisms to handle mismatches between model versions by prioritizing human-generated classifications and enabling flexible user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional signature-based detection methods are used, then implementation simplicity is maintained, but detection effectiveness against advanced threats deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces traditional signature-based mechanical detection methods with machine learning-based probabilistic models. The system uses supervised learning algorithms that analyze dynamic features and behavioral patterns of files, substituting static signature matching with adaptive mathematical models that can identify advanced threats through probabilistic classification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If machine learning model versions are updated frequently to improve threat detection, then detection accuracy improves, but model mismatch and classification inconsistency worsen

Engineering Contradiction:
Improvedetection accuracyVSAvoidmodel consistency
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The patent implements preliminary actions by maintaining multiple versions of machine learning models and pre-establishing mismatch detection mechanisms. Before deploying a new model version, the system detects mismatches between different model versions and implements corrective actions to ensure consistent classification, preventing instability before it occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors classification results across different model versions and implements feedback loops. When mismatches are detected between model versions, the system analyzes the discrepancies and adjusts classifications to maintain consistency, ensuring that detection accuracy improvements do not compromise model stability.

Inventive Principle:
Principle #23Feedback

3Reliability

If real-time threat analysis is performed on all files, then security coverage is improved, but system performance and user operation efficiency deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoiduser operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by performing comprehensive machine learning-based threat analysis only on files that exhibit suspicious characteristics or fail initial filtering stages. Rather than analyzing every file in real-time, the system selectively applies intensive analysis to high-risk candidates, maintaining security coverage while preserving user operation efficiency for normal files.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3469777B1Deployment of machine learning models for discernment of threats
Publication Date: 2022.08.03 CYLANCE INC
  • EP3469777B1 patent drawingFigure 1
  • EP3469777B1 patent drawingFigure 2
  • EP3469777B1 patent drawingFigure 3

AI summary

A mismatch between model-based classifications produced by a first version of a machine learning threat discernment model and a second version of a machine learning threat discernment model for a file is detected. The mismatch is analyzed to determine appropriate handling for the file, and taking an action based on the analyzing. The analyzing includes comparing a human-generated classification status for a file, a first model version status that reflects classification by the first version of the machine learning threat discernment model, and a second model version status that reflects classification by the second version of the machine learning threat discernment model. The analyzing can also include allowing the human-generated classification status to dominate when it is available.