IP Library Granted Patent US 12,045,343
Granted Patent B2
US 12,045,343 · App. 18/047,204 · Granted Jul 23, 2024

System and method for heterogeneous transferred learning for enhanced cybersecurity threat detection

Inventors: Scott Eric Coull (Cary, NC); David Krisiloff (Arlington, VA); Giorgio Severi (Brookline, MA)
Assignee: GOOGLE LLC
G06F21/554G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,045,343
App. No.
18/047,204
Granted
Jul 23, 2024
Kind
B2
Abstract

A method includes training a first machine learning model with a first dataset, to produce a first trained machine learning model to infer cybersecurity-oriented file properties and/or detect cybersecurity threats within a first domain. The first dataset includes labeled files associated with the first domain. The first trained machine learning model includes multiple layers, some of which are trainable. A second trained machine learning model is generated, via a transfer learning process, using (1) at least one trainable layer from the multiple trainable layers of the first trained machine learning model, and (2) a second dataset different from the first dataset. The second dataset includes labeled files associated with a second domain. The first domain has a different syntax, different semantics, and/or a different structure than that of the second domain. The second trained machine learning model (e.g., a deep neural network model) is then available for use in inferring cybersecurity-oriented properties of the file in the second domain and/or detecting cybersecurity threats in the second domain.

Claims (42)

1. A processor-readable medium storing instructions that, when executed by a processor, cause the processor to:

train a first machine learning model with a first dataset including labeled files associated with a first domain, to produce a first trained machine learning model to infer cybersecurity-oriented file properties within the first domain, the first trained machine learning model including a plurality of trainable layers; and

generate a second trained machine learning model via a transfer learning process (1) based on the first trained machine learning model, and (2) using a second dataset different from the first dataset, the second dataset including labeled files associated with a second domain,

the first domain differing from the second domain.

2. The processor-readable medium of claim 1 , wherein the instructions to generate the second training machine learning model includes instructions to generate the second training machine learning model using at least one trainable layer from the plurality of trainable layers of the first trained machine learning model, each trainable layer from the plurality of trainable layers includes a matrix of weights.

3. The processor-readable medium of claim 1 , wherein at least one of the first dataset or the second dataset does not include data packets.

4. The processor-readable medium of claim 1 , further storing instructions that, when executed by the processor, cause the processor to:

select the first machine learning model for use in the transfer learning process, based on a detected overlap between the first dataset and the second dataset, prior to the generation of the second trained machine learning model.

5. The processor-readable medium of claim 1 , wherein the second dataset is smaller than the first dataset.

6. The processor-readable medium of claim 1 , wherein the second dataset includes an unrepresentative sample of subpopulations of the second domain.

7. The processor-readable medium of claim 1 , further storing instructions that, when executed by the processor, cause the processor to:

analyze a labeled file associated with the second domain, using the second trained machine learning model, to determine a cybersecurity risk associated with the labeled file.

8. The processor-readable medium of claim 1 , further storing instructions that, when executed by the processor, cause the processor to:

select the at least one trainable layer from the plurality of trainable layers of the first trained machine learning model based on a resource constraint of a compute device,

the instructions to generate the second training machine learning model including instructions to generate the second training machine learning model using at least one trainable layer from the plurality of trainable layers of the first trained machine learning model.

9. An apparatus, comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions that, when executed by the processor, cause the processor to:

receive a first trained machine learning model to infer cybersecurity-oriented file properties within a first domain;

train the first trained machine learning model via a transfer learning process using a dataset including labeled files associated with a second domain different from the first domain to produce a second trained machine learning model; and

analyze a labeled file associated with the second domain, using the second trained machine learning model, to determine a cybersecurity risk associated with the labeled file.

10. The apparatus of claim 9 , wherein the first trained machine learning model includes a plurality of trainable layers, each trainable layer from the plurality of trainable layers including a matrix of weights.

11. The apparatus of claim 9 , wherein the dataset does not include data packets.

12. The apparatus of claim 9 , wherein the dataset is a second dataset, the memory further storing instructions that, when executed by the processor, cause the processor to:

select the first machine learning model for use in the transfer learning process, based on a detected overlap between (1) a first dataset associated with the first trained machine learning model and (2) the second dataset, prior to the generation of the second trained machine learning model.

13. The apparatus of claim 9 , wherein the dataset is a second dataset that is smaller than a first dataset associated with the first trained machine learning model.

14. The apparatus of claim 9 , wherein the dataset includes an unrepresentative sample of subpopulations of the second domain.

15. The apparatus of claim 9 , wherein the memory further storing instructions that, when executed by the processor, cause the processor to:

detect that the cybersecurity risk has a value above a specified threshold; and

transmit a signal representing an alert in response to detecting that the cybersecurity risk has the value above the specified threshold.

16. A processor-readable medium storing instructions that, when executed by a processor, cause the processor:

train a first machine learning model with a first dataset including labeled files associated with a first domain, to produce a first trained machine learning model to infer cybersecurity-oriented file properties within the first domain; and

generate a second trained machine learning model via a transfer learning process by:

modify the first trained machine learning model to produce a modified first trained machine learning model, and

train the modified first trained machine learning model with a second dataset different from the first dataset, the second dataset including labeled files associated with a second domain, to produce the second trained machine learning model,

the first domain differing from the second domain.

17. The processor-readable medium of claim 16 , wherein at least one of the first dataset or the second dataset does not include data packets.

18. The processor-readable medium of claim 16 , further storing instructions that, when executed by the processor, cause the processor to:

select the first machine learning model for use in the transfer learning process, based on a detected overlap between the first dataset and the second dataset, prior to the generation of the second trained machine learning model.

19. The processor-readable medium of claim 16 , further storing instructions that, when executed by the processor, cause the processor to:

analyze a labeled file associated with the second domain, using the second trained machine learning model, to determine a cybersecurity risk associated with the labeled file.

20. The processor-readable medium of claim 16 , wherein the instructions to modify the first trained machine learning model includes instructions to modify the first trained machine learning model based on a resource constraint of a compute device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MANDIANT, INC.
To: GOOGLE LLC
Reel/Frame 063238/0555 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2022
From: COULL, SCOTT ERIC; KRISILOFF, DAVID; SEVERI, GIORGIO
To: FIREEYE, INC.
Reel/Frame 061467/0920 →
CHANGE OF NAME Recorded Oct 19, 2022
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 061710/0435 →
Continuity (2)
Continuation 16542739 · Aug 16, 2019
Related Publication 20230185907A1 · Jun 15, 2023
Cited By (3)
US 12,476,994 US 12,554,847 US 12,659,324