IP Library › Granted Patent US 10,657,258
Granted Patent B2
US 10,657,258 · App. 16/425,662 · Granted May 19, 2020

Deployment of machine learning models for discernment of threats

Inventors: Kristopher William Harms (Kailua, HI); Renee Song (Irvine, CA); Raj Rajamani (Irvine, CA); Braden Rusell (Ladera Ranch, CA); Yoojin Sohn (Irvine, CA); Kiefer Ipsen (Irvine, CA)
Assignee: Cylance Inc.
G06F21/568G06F21/51G06F21/562G06F21/566G06N20/00H04L63/1425H04L63/1441G06F3/048G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,657,258
App. No.
16/425,662
Granted
May 19, 2020
Kind
B2
Abstract

A mismatch between model-based classifications produced by a first version of a machine learning threat discernment model and a second version of a machine learning threat discernment model for a file is detected. The mismatch is analyzed to determine appropriate handling for the file, and taking an action based on the analyzing. The analyzing includes comparing a human-generated classification status for a file, a first model version status that reflects classification by the first version of the machine learning threat discernment model, and a second model version status that reflects classification by the second version of the machine learning threat discernment model. The analyzing can also include allowing the human-generated classification status to dominate when it is available.

Claims (56)

1. A method for implementation by one or more data processors forming part of at least one computing device, the method comprising:

detecting, by at least one data processor, a mismatch between model-based classifications produced by a first version of a computer-implemented machine learning threat discernment model and a second version of a computer-implemented machine learning threat discernment model for a file, each of the first version of the machine learning threat discernment model and the second version of the machine learning threat discernment model for a file output a respective threat score based on a same set of features extracted from the file, wherein the mismatch is based on a difference between the respective threat scores; and

executing or accessing, by at least one data processor, the file if the difference between the respective threat scores is below a pre-defined threshold; or

analyzing, by at least one data processor, the mismatch to determine appropriate handling for the file if the difference between the respective threat scores is equal to or above a pre-defined threshold.

2. The method of claim 1 wherein:

the analyzing comprises comparing (i) a human-generated classification for a file, (ii) a first model version status that reflects classification by the first version of the machine learning threat discernment model, and (iii) a second model version status that reflects classification by the second version of the machine learning threat discernment model,

the analyzing further comprises allowing the human-generated classification to dominate when it is available; and

the method further comprises: taking, by at least one data processor, an action based on the analyzing.

3. The method of claim 2 , wherein the action comprises:

presenting, by at least one data processor, the file via user interface functionality of an administrative interface with a choice of creating a new human-generated classification of the file as safe or allowing the second model version classification to govern when the file is deemed safe by the first model version but unsafe by the second model version, and when the human-generated classification is unavailable for the file;

quarantining, by at least one data processor, a file deemed unsafe by the first version of the machine learning threat discernment model but safe by the second version of the machine learning threat discernment model when the human-generated classification is unavailable for the file; and

presenting, by at least one data processor, the file via the user interface functionality of the administrative interface with a second choice of designating the file for local analysis and/or allowing the second model version classification to continue to block use of the file until the human-generated classification becomes available when the file is deemed unsafe by the second model version and the human human-generated classification is unavailable and when the first model version has not previously classified the file.

4. The method of claim 2 , wherein the action comprises:

presenting, by at least one data processor, the file via user interface functionality of an administrative interface with a choice of creating a new human-generated classification of the file as safe or allowing the second model version classification to govern when the file is deemed safe by the first model version but unsafe by the second model version, and when the human-generated classification is unavailable for the file.

5. The method of claim 2 , wherein the action comprises:

quarantining, by at least one data processor, a file deemed unsafe by the first version of the machine learning threat discernment model but safe by the second version of the machine learning threat discernment model when the human-generated classification is unavailable for the file.

6. The method of claim 2 , wherein the action comprises:

presenting, by at least one data processor, the file via user interface functionality of an administrative interface with a second choice of designating the file for local analysis and/or allowing the second model version classification to continue to block use of the file until the human-generated classification becomes available when the file is deemed unsafe by the second model version and the human human-generated classification is unavailable and when the first model version has not previously classified the file.

7. The computer-implemented method of claim 1 , wherein the first version of a computer-implemented machine learning threat discernment model and the second version of a computer-implemented machine learning threat discernment model for the file are on different and remote computing systems.

8. The computer-implemented method of claim 1 , wherein the first version of a computer-implemented machine learning threat discernment model and the second version of a computer-implemented machine learning threat discernment model for the file are on the same computing system.

9. A system comprising:

at least one data processor; and

memory storing instructions which, when executed by the at least one data processor, result in operations comprising:

detecting a mismatch between model-based classifications produced by a first version of a computer-implemented machine learning threat discernment model and a second version of a computer-implemented machine learning threat discernment model for a file, each of the first version of the machine learning threat discernment model and the second version of the machine learning threat discernment model for a file output a respective threat score based on a same set of features extracted from the file, wherein the mismatch is based on a difference between the respective threat scores; and

executing or accessing the file if the difference between the respective threat scores is below a pre-defined threshold; or

analyzing the mismatch to determine appropriate handling for the file if the difference between the respective threat scores is equal to or above a pre-defined threshold.

10. The system of claim 9 wherein:

the analyzing comprises comparing a human-generated classification for a file, a first model version status that reflects classification by the first version of the machine learning threat discernment model, and a second model version status that reflects classification by the second version of the machine learning threat discernment model,

the analyzing further comprises allowing the human-generated classification to dominate when it is available; and

the operations further comprise: taking an action based on the analyzing.

11. The system of claim 10 , wherein the action comprises:

presenting the file via user interface functionality of an administrative interface with a choice of creating a new human-generated classification of the file as safe or allowing the second model version classification to govern when the file is deemed safe by the first model version but unsafe by the second model version, and when the human-generated classification is unavailable for the file;

quarantining a file deemed unsafe by the first version of the machine learning threat discernment model but safe by the second version of the machine learning threat discernment model when the human-generated classification is unavailable for the file; and

presenting the file via the user interface functionality of the administrative interface with a second choice of designating the file for local analysis and/or allowing the second model version classification to continue to block use of the file until the human-generated classification becomes available when the file is deemed unsafe by the second model version and the human human-generated classification is unavailable and when the first model version has not previously classified the file.

12. The system of claim 10 , wherein the action comprises:

presenting the file via user interface functionality of an administrative interface with a choice of creating a new human-generated classification of the file as safe or allowing the second model version classification to govern when the file is deemed safe by the first model version but unsafe by the second model version, and when the human-generated classification is unavailable for the file.

13. The system of claim 10 , wherein the action comprises:

quarantining a file deemed unsafe by the first version of the machine learning threat discernment model but safe by the second version of the machine learning threat discernment model when the human-generated classification is unavailable for the file.

14. The system of claim 10 , wherein the action comprises:

presenting the file via user interface functionality of an administrative interface with a second choice of designating the file for local analysis and/or allowing the second model version classification to continue to block use of the file until the human-generated classification becomes available when the file is deemed unsafe by the second model version and the human human-generated classification is unavailable and when the first model version has not previously classified the file.

15. The system of claim 9 , wherein the first version of a computer-implemented machine learning threat discernment model and the second version of a computer-implemented machine learning threat discernment model for the file are on different and remote computing systems.

16. The system of claim 9 , wherein the first version of a computer-implemented machine learning threat discernment model and the second version of a computer-implemented machine learning threat discernment model for the file are on the same computing system.

17. A computer program product comprising non-transitory media storing instructions which, when executed by the at least one data processor, result in operations comprising:

detecting a mismatch between model-based classifications produced by a first version of a computer-implemented machine learning threat discernment model and a second version of a computer-implemented machine learning threat discernment model for a file, each of the first version of the machine learning threat discernment model and the second version of the machine learning threat discernment model for a file output a respective threat score based on a same set of features extracted from the file, wherein the mismatch is based on a difference between the respective threat scores; and

executing or accessing the file if the difference between the respective threat scores is below a pre-defined threshold; or

analyzing the mismatch to determine appropriate handling for the file if the difference between the respective threat scores is equal to or above a pre-defined threshold.

18. The computer program product of claim 17 wherein:

the analyzing comprises comparing a human-generated classification for a file, a first model version status that reflects classification by the first version of the machine learning threat discernment model, and a second model version status that reflects classification by the second version of the machine learning threat discernment model,

the analyzing further comprises allowing the human-generated classification to dominate when it is available; and

the operations further comprise: taking an action based on the analyzing.

19. The computer program product of claim 18 , wherein the action comprises:

presenting the file via user interface functionality of an administrative interface with a choice of creating a new human-generated classification of the file as safe or allowing the second model version classification to govern when the file is deemed safe by the first model version but unsafe by the second model version, and when the human-generated classification is unavailable for the file;

quarantining a file deemed unsafe by the first version of the machine learning threat discernment model but safe by the second version of the machine learning threat discernment model when the human-generated classification is unavailable for the file; and

presenting the file via the user interface functionality of the administrative interface with a second choice of designating the file for local analysis and/or allowing the second model version classification to continue to block use of the file until the human-generated classification becomes available when the file is deemed unsafe by the second model version and the human human-generated classification is unavailable and when the first model version has not previously classified the file.

20. The computer program product of 18 , wherein the action comprises:

presenting the file via user interface functionality of an administrative interface with a choice of creating a new human-generated classification of the file as safe or allowing the second model version classification to govern when the file is deemed safe by the first model version but unsafe by the second model version, and when the human-generated classification is unavailable for the file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2019
From: HARMS, KRISTOPHER WILLIAM; SONG, RENEE; RAJAMANI, RAJ; RUSELL, BRADEN; SOHN, YOOJIN; IPSEN, KIEFER
To: CYLANCE INC.
Reel/Frame 049311/0723 →
Continuity (3)
Continuation 15615609 · Jun 6, 2017
Provisional Application 62347428 · Jun 8, 2016
Related Publication 20190294797A1 · Sep 26, 2019
Cited By (1)
US 12,625,972