IP Library › Granted Patent US 12,462,027
Granted Patent B2
US 12,462,027 · App. 18/401,364 · Granted Nov 4, 2025

Robust feature selection for computer security applications

Inventors: Stefan Smeu (Bacau, RO); Elena Burceanu (Buchare, RO); Emanuela Haller (Buchare, RO)
Assignee: Bitdefender IPR Management Ltd.
G06F21/56G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,027
App. No.
18/401,364
Granted
Nov 4, 2025
Kind
B2
Abstract

A diverse collection of data samples harvested for computer security applications is divided into a plurality of training corpora according to criteria such as an identity of the data source, among others. An initial set of features for characterizing the collected data samples is reduced to an optimal subset. For each candidate feature, a frequency distribution of feature values is determined over each of the training corpora. A feature selection procedure favors features whose frequency distribution is relatively similar across multiple corpora. A detector module is then trained to detect computer security threats according to the reduced set of features.

Claims (54)

1 . A computer system comprising at least one hardware processor configured to:

select a reduced subset of features from a plurality of features available for characterizing data samples, wherein selecting the reduced subset of features comprises:

dividing a collection of data samples acquired from a plurality of computing devices into a plurality of training corpora;

selecting a candidate feature from the plurality of features,

determining a first frequency distribution of feature values of the candidate feature over members of a first training corpus of the plurality of training corpora,

determining a second frequency distribution of feature values of the candidate feature over a second training corpus of the plurality of training corpora, and

determining whether to include the candidate feature into the reduced subset of features according to a similarity between the first and second frequency distributions; and

in response to selecting the reduced subset of features, train a threat detector to determine whether a target data sample is indicative of a computer security threat according to the reduced subset of features.

2 . The computer system of claim 1 , wherein the at least one hardware processor is configured to divide the collection of data samples into the plurality of training corpora according to a location of a computing device providing each respective data sample.

3 . The computer system of claim 1 , wherein the at least one hardware processor is configured to divide the collection of data samples into the plurality of training corpora according to an identity of a user of a computing device providing each respective data sample.

4 . The computer system of claim 1 , wherein the at least one hardware processor is configured to divide the collection of data samples into the plurality of training corpora according to a time of acquisition of each respective data sample.

5 . The computer system of claim 1 , wherein the at least one hardware processor is configured to divide the collection of data samples into the plurality of training corpora according to a device type of a computing device providing each respective data sample.

6 . The computer system of claim 1 , wherein the plurality of computing devices is divided among a plurality of corporate owners, and wherein the at least one hardware processor is configured to divide the collection of data samples into the plurality of training corpora according to an owner of a computing device providing each respective data sample.

7 . The computer system of claim 1 , wherein the at least one hardware processor is configured to divide the collection of data samples into the plurality of training corpora according to a software profile of the computing device providing each respective data sample, the software profile comprising a set of computer programs installed for execution on the respective computing device.

8 . The computer system of claim 1 , wherein determining whether to include the candidate feature into the reduced subset of features further comprises:

determining a plurality of similarity measures, each similarity measure of the plurality of similarity measures quantifying a similarity between a pair of frequency distributions of values of the candidate feature, each of the pair of probability measures evaluated over a distinct corpus of the plurality of training corpora; and

selecting the candidate feature into the reduced subset of features according to an average of the plurality of similarity measures.

9 . The computer system of claim 8 , wherein the at least one hardware processor is configured to select the candidate feature into the reduced subset of features further according to a dispersion of the plurality of similarity measures.

10 . The computer system of claim 1 , wherein determining whether to include the candidate feature into the reduced subset of features further comprises:

for each feature of the plurality of features, evaluating a feature-specific frequency distribution of feature values of the respective feature over the first training corpus;

ranking the plurality of features according to the evaluated feature-specific frequency distributions; and

selecting the candidate feature into the reduced subset of features according to a result of the ranking.

11 . The computer system of claim 1 , wherein the plurality of features is constructed automatically by a machine learning procedure comprising training another threat detector to identify members of the collection of data samples that are indicative of the computer security threat.

12 . A computer security method comprising employing at least one hardware processor of a computer system to:

select a reduced subset of features from a plurality of features available for characterizing data samples, wherein selecting the reduced subset of features comprises:

dividing a collection of data samples acquired from a plurality of computing devices into a plurality of training corpora;

selecting a candidate feature from the plurality of features,

determining a first frequency distribution of feature values of the candidate feature over members of a first training corpus of the plurality of training corpora,

determining a second frequency distribution of feature values of the candidate feature over a second training corpus of the plurality of training corpora, and

determining whether to include the candidate feature into the reduced subset of features according to a similarity between the first and second frequency distributions; and

in response to selecting the reduced subset of features, train a threat detector to determine whether a target data sample is indicative of a computer security threat according to the reduced subset of features.

13 . The method of claim 12 , comprising dividing the collection of data samples into the plurality of training corpora according to a location of a computing device providing each respective data sample.

14 . The method of claim 12 , comprising dividing the collection of data samples into the plurality of training corpora according to an identity of a user of a computing device providing each respective data sample.

15 . The method of claim 12 , comprising dividing the collection of data samples into the plurality of training corpora according to a time of acquisition of each respective data sample.

16 . The method of claim 12 , comprising dividing the collection of data samples into the plurality of training corpora according to a device type of a computing device providing each respective data sample.

17 . The method of claim 12 , comprising dividing the collection of data samples into the plurality of training corpora according to a software profile of the computing device providing each respective data sample, the software profile comprising a set of computer programs installed for execution on the respective computing device.

18 . The method of claim 12 , wherein the plurality of computing devices is divided among a plurality of corporate owners, the method comprising dividing the collection of data samples into the plurality of training corpora according to an owner of a computing device providing each respective data sample.

19 . The method of claim 12 , wherein determining whether to include the candidate feature into the reduced subset of features further comprises:

determining a plurality of similarity measures, each similarity measure of the plurality of similarity measures quantifying a similarity between a pair of frequency distributions of values of the candidate feature, each of the pair of probability measures evaluated over a distinct corpus of the plurality of training corpora; and

selecting the candidate feature into the reduced subset of features according to an average of the plurality of similarity measures.

20 . The method of claim 19 , comprising select the candidate feature into the reduced subset of features further according to a dispersion of the plurality of similarity measures.

21 . The method of claim 12 , wherein determining whether to include the candidate feature into the reduced subset of features further comprises:

for each feature of the plurality of features, evaluating a feature-specific frequency distribution of feature values of the respective feature over the first training corpus;

ranking the plurality of features according to the evaluated feature-specific frequency distributions; and

selecting the candidate feature into the reduced subset of features according to a result of the ranking.

22 . The method of claim 12 , wherein the plurality of features is constructed automatically by a machine learning procedure comprising training another threat detector to identify members of the collection of data samples that are indicative of the computer security threat.

23 . A non-transitory computer-readable medium storing instructions which, when executed by at least one hardware processor of a computer system, cause the computer system to:

select a reduced subset of features from a plurality of features available for characterizing data samples, wherein selecting the reduced subset of features comprises:

dividing a collection of data samples acquired from a plurality of computing devices into a plurality of training corpora;

selecting a candidate feature from the plurality of features,

determining a first frequency distribution of feature values of the candidate feature over members of a first training corpus of the plurality of training corpora,

determining a second frequency distribution of feature values of the candidate feature over a second training corpus of the plurality of training corpora, and

determining whether to include the candidate feature into the reduced subset of features according to a similarity between the first and second frequency distributions; and

in response to selecting the reduced subset of features, train a threat detector to determine whether a target data sample is indicative of a computer security threat according to the reduced subset of features.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2024
From: SMEU, STEFAN; BURCEANU, ELENA; HALLER, EMANUELA
To: BITDEFENDER IPR MANAGEMENT LTD.
Reel/Frame 066000/0901 →
Continuity (2)
Provisional Application 63582278 · Sep 13, 2023
Related Publication 20250086279A1 · Mar 13, 2025
References Cited (16)
US 20060179017A1 · Forman · 2006 [cited by applicant]
US 20090171870A1 · Dasgupta · 2009 [cited by applicant]
US 20090222389A1 · Hido · 2009 [cited by applicant]
US 20090300765A1 · Moskovitch · 2009 [cited by applicant]
US 20100036782A1 · Zhao · 2010 [cited by applicant]
US 20150235139A1 · Sharma · 2015 [cited by applicant]
US 20210241140A1 · Sadashiva · 2021 [cited by applicant]
US 20210342652A1 · Glassman · 2021 [cited by applicant]
US 20220027780A1 · Butvinik · 2022 [cited by applicant]
US 20220050928A1 · Shukla · 2022 [cited by examiner]
European Patent Office (EPO), International Search Report and Written Opinion mailed Nov. 28, 2024 for PCT International Application No. PCT/EP2024/075366, International Filing Date Sep. 11, 2024, Priority Date Sep. 13,… [cited by applicant]
Masud et al., “Cloud-Based Malware Detection for Evolving Data Streams,” ACM Transactions on Management Information Systems (TMIS), ACM 2(3):1-27, Oct. 18, 2008. [cited by applicant]
Gupta et al., “Eagle: User Profile-Based Anomaly Detection for Securing Hadoop Clusters,” 2015 IEEE International Conference on Big Data, IEEE, pp. 1336-1343, Oct. 29, 2015. [cited by applicant]
Dean, “Systematic Assessment of the Impact of User Roles on Network Flow Patterns,” Dissertation, Naval Postgraduate School, Monterey, USA, Sep. 1, 2017. [cited by applicant]
Ye et al., “Towards a Theoretical Framework of Out-of-Distribution Generalization,” Advances in Neural Information Processing Systems 34(2021): 23519-23531, Dec. 6, 2021. [cited by applicant]
Wikipedia, “Feature Selection,” https://en.wikipedia.org/w/index.php?title=Feature_selection&oldid=1185233924, downloaded Dec. 20, 2023. [cited by applicant]