IP Library › Granted Patent US 12,518,008
Granted Patent B2
US 12,518,008 · App. 17/970,677 · Granted Jan 6, 2026

Method and apparatus for creating a dataset using file creation dates

Inventors: Aleksandr Ševčenko (Vilnius, LT); Mantas Briliauskas (Vilnius, LT)
Assignee: UAB 360 IT
G06F21/565G06F16/164G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,008
App. No.
17/970,677
Filed
Oct 21, 2022
Granted
Jan 6, 2026
Kind
B2
Art Unit
2446
USPC
726/23
Abstract

A method and apparatus for generating a content detection dataset using file creation dates. The method accesses a database comprising data files. The files are analyzed by a machine learning model to determine file creation dates. The creation dates are used to identify relevant content files. The most relevant files are included into a content detection dataset as content samples. The dataset may be used for training machine learning based content detectors.

Claims (22)

1 . A method for generating a content detection dataset comprising:

accessing a database comprising a plurality of data files including malware files and clean files;

accessing content of the data files and metadata associated with the data files;

analyzing, using a machine learning model, the content of the data files and the metadata to determine an estimate of a creation date for each data file, wherein the creation date is an indicia of file relevance;

selecting particular data files of the plurality of data files as content samples for a content detector based upon the creation dates and associated file relevance; and

storing the selected content samples and associated creation dates in the content detection dataset which is configured to train a machine learning model of the content detector to identify malware.

2 . The method of claim 1 , wherein the metadata comprises at least one of a creation date or indicia of a creation date.

3 . The method of claim 2 , wherein the indicia comprise at least one of references to specific dates in the data files, references to operating systems or application versions that were available after particular dates, header information, or compiler information.

4 . The method of claim 1 , wherein files having a recent creation date are more relevant than an older creation date.

5 . The method of claim 4 , wherein the malware files having the most recent creation dates are selected as content samples.

6 . The method of claim 1 , wherein analyzing the metadata and file content comprises processing the metadata using a machine learning model.

7 . Apparatus for generating a content detection dataset comprising at least one processor coupled to at least one non-transitory computer readable medium having instructions stored thereon, which, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

accessing a database comprising a plurality of data files including malware files and clean files;

accessing content of the data files and metadata associated with the data files;

analyzing, using a machine learning model, the content of the data files and the metadata to determine an estimate of a creation date for each data file, wherein the creation date is an indicia of file relevance;

selecting particular data files of the plurality of data files as content samples for a content detector based upon the creation dates and associated file relevance; and

storing the selected content samples and associated creation dates in the content detection dataset which is configured to train a machine learning model of the content detector to identify malware.

8 . The apparatus of claim 7 , wherein the metadata comprises at least one of a creation date or indicia of a creation date.

9 . The apparatus of claim 8 , wherein the indicia comprise at least one of references to specific dates in the data files, references to operating systems or application versions that were available after particular dates, header information, or compiler information.

10 . The apparatus of claim 7 , wherein the malware files having a recent creation date are more relevant than an older creation date.

11 . The apparatus of claim 10 , wherein the malware files having the most recent creation dates are selected as content samples.

12 . The apparatus of claim 7 , wherein analyzing the metadata comprises processing the metadata using a machine learning model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2023
From: SEVCENKO, ALEKSANDR; BRILIAUSKAS, MANTAS
To: UAB 360 IT
Reel/Frame 062451/0628 →
Continuity (2)
Related Publication 20240134977A1 · Apr 25, 2024
Related Publication 20240232348A9 · Jul 11, 2024
References Cited (13)
US 10642977B1 · Ren · 2020 [cited by examiner]
US 10885188B1 · Batur · 2021 [cited by examiner]
US 11227047B1 · Vashisht · 2022 [cited by examiner]
US 11522889B2 · Annen · 2022 [cited by examiner]
US 20180041536A1 · Berlin · 2018 [cited by examiner]
US 20190132344A1 · Lem · 2019 [cited by examiner]
US 20190228151A1 · Schmugar · 2019 [cited by examiner]
US 20200204569A1 · Komarek · 2020 [cited by examiner]
US 20200257992A1 · Achin · 2020 [cited by examiner]
US 20200293655A1 · Long · 2020 [cited by examiner]
US 20220253526A1 · Sanders · 2022 [cited by examiner]
US 20230098919A1 · Kulaga · 2023 [cited by examiner]
US 20230205877A1 · Ulasen · 2023 [cited by examiner]