Neutral Domain Data Selection for Cybersecurity ML

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity approaches are reactive and struggle to timely address constantly changing security vulnerabilities and attack vectors, making it difficult for human analysts to effectively predict and mitigate malicious domains before damage occurs.

Innovation Solution

The Enhanced Predictive Security System (EPSS) employs a domain-centric approach combined with advanced machine learning algorithms and a multi-level machine learning architecture, using ensemble master classifiers and improved neutral data sets to predictively identify malicious domains, enabling proactive threat intelligence and reducing reliance on human analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reactive cybersecurity approaches (blocklists, firewall security) are used to prohibit known bad actor domains and malware, then implementation is straightforward and immediate, but detection and response time is too late as damage has already occurred

Engineering Contradiction:
Improveeffectiveness of threat mitigationVSAvoidtime to detect and respond to threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by training machine learning models on historical threat data and neutral domain data before threats occur. The system performs prospective analysis to identify potentially malicious domains before they are exploited, enabling preventive rather than reactive security measures. The models are trained in advance to recognize patterns and characteristics of malicious domains, allowing the system to predict and block threats before damage occurs.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If human security analysts manually analyze security vulnerabilities and attack vectors, then detailed expertise and judgment can be applied, but the volume and constant changes make it impossible to timely address all threats

Engineering Contradiction:
Improveaccuracy of threat characterizationVSAvoidspeed of threat analysis
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent replaces the mechanical system of human analyst review with machine learning models that automatically analyze domain data. The system uses trained models to evaluate potentially malicious domains, extracting features and making predictions without human intervention. This substitution maintains high accuracy through sophisticated pattern recognition while dramatically increasing productivity by processing vast volumes of data at machine speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system applies self-service by enabling automated threat detection and classification without requiring continuous human analysis. The machine learning models independently evaluate domains, identify threats, and generate predictions autonomously. The system serves itself by continuously learning from data and improving its analytical capabilities without manual intervention for each threat assessment.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If traditional machine learning training data approaches are used, then implementation is simpler, but the models lack the precision needed to accurately distinguish malicious from neutral domains in complex cybersecurity contexts

Engineering Contradiction:
Improvesimplicity of model trainingVSAvoidaccuracy of domain classification
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent applies local quality by curating specific types of training data with particular characteristics suited for cybersecurity classification. The system uses neutral domain data from specific sources and applies targeted feature extraction techniques that focus on locally relevant attributes of domains. This localized approach to data quality and feature selection enhances classification precision by emphasizing the specific qualities that distinguish malicious from benign domains in cybersecurity contexts.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11770404B2Enhanced neutral domain data selection for cybersecurity machine learning applications
Publication Date: 2023.09.26 DOMAINTOOLS LLC
  • US11770404B2 patent drawing
  • US11770404B2 patent drawing
  • US11770404B2 patent drawing

AI summary

Methods, systems, and techniques for producing and using enhanced machine learning models and computer-implemented tools to investigate cybersecurity related data and threat intelligence data are provided. Example embodiments provide an Enhanced Predictive Security System, for building, deploying, and managing applications for evaluating threat intelligence data that can predict malicious domains associated with bad actors before the domains are known to be malicious. In one example, the EPSS comprises one or more components that work together to provide an architecture and a framework for building and deploying cybersecurity threat analysis application, including machine learning algorithms, feature class engines, tuning systems, ensemble classifier engines, and validation and testing engines. These components cooperate and act upon domain data and feature class vectors to create sampled test, training, and validation data and to build model subsets and applications using a trained model library, which stores definitions of each model subset for easy re-instantiation.