IP Library Granted Patent US 12,242,520
Granted Patent B2
US 12,242,520 · App. 18/476,484 · Granted Mar 4, 2025

Training a multi-label classifier

Inventors: Ravindra K. Balupari (San Jose, CA); Sandeep Yadav (South San Francisco, CA)
Assignee: Netskope, Inc.
G06F16/313G06F16/35G06F16/951G06F18/2411G06N20/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,520
App. No.
18/476,484
Granted
Mar 4, 2025
Kind
B2
Abstract

The technology disclosed includes a system to perform multi-label support vector machine (SVM) classification of a document. The system creates document features representing frequencies or semantics of words in the document. Trained SVM classification parameters for a plurality of labels are applied to the document features for the document. The system determines positive and negative distances between SVM hyperplanes for the labels and the feature vector. Labels with positive distance to the feature vector are harvested. When the distribution of negative distances is characterized by a mean and standard deviation, the system further harvests the labels with a negative distance such that the harvested labels include the labels with a negative distance between the mean negative distance and zero and separated from the mean negative distance by a predetermined first number of standard deviations.

Claims (56)

1. A method, comprising:

training a multi-label classifier, the training comprising:

accessing training examples for documents belonging to a plurality of label classes, wherein a number of the plurality of label classes is more than fifty (50) label classes;

creating document features representing aspects of words in each of the documents;

training a support vector machine with the document features for one-vs-the-rest classification using the plurality of label classes, the training comprising:

training a one-vs-the-rest classifier the number of times such that the one-vs-the-rest classifier is trained one time for each of the plurality of label classes, each training including:

providing the training examples belonging to the respective label class to the support vector machine running the one-vs-the-rest classifier to obtain training output labels, and

comparing the training output labels using a linear support vector machine classifier to generate the number of hyperplane determinations that separate each label class of the plurality of label classes from the rest of the plurality of label classes; and

storing parameters of the trained support vector machine, the parameters comprising the hyperplane determinations.

2. The method of claim 1 , further comprising:

deploying the trained multi-label classifier and the stored parameters of the trained support vector machine to a production environment.

3. The method of claim 1 , further comprising:

classifying a document with multiple label classes of the plurality of label classes using the trained multi-label classifier.

4. The method of claim 1 , further comprising:

classifying a document with a label class of the plurality of label classes using the trained multi-label classifier.

5. The method of claim 1 , wherein the document features comprise frequency features based on term frequency-inverse document frequency.

6. The method of claim 1 , wherein the document features comprise semantic features based on embedding in a multi-dimensional vector space using Word2Vec.

7. The method of claim 1 , wherein the document features comprise semantic features based on embedding in a multi-dimensional vector space using global vectors for word representation.

8. The method of claim 1 , further comprising:

selecting support vector machine hyper parameters across regularization, class weight, and loss function in a predetermined search range to generate an at-least-one (ALO) score within ten percent of maximum attainable over the predetermined search range.

9. The method of claim 8 , wherein the ALO score is calculated based on a ratio of a count of the documents with at least one pairwise match between inferred labels and ground truth labels to a total number of documents with at least one ground truth label.

10. The method of claim 1 , wherein a first label class of the plurality of label classes is parked domain to classify documents posted on parked domains, the method further comprising:

identifying parked domains and collecting documents posted on the parked domains, the identifying comprising:

crawling uniform resource locators (URLs) that are within a predetermined edit distance of selected URL names;

determining for at least some of the crawled URLs that URL resolution is referred to an authoritative nameserver that appears in a list of parked domain nameservers identified as dedicated to parked domains; and

collecting the documents posted on the crawled URLs that are referred to the parked domain nameservers; and

labeling the collected documents as collected from the parked domains and storing the documents and parked domain labels for use in training.

11. A system, comprising:

one or more processors; and

one or more memories having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to:

train a multi-label classifier, the training comprising:

accessing training examples for documents belonging to a plurality of label classes, wherein a number of the plurality of label classes is more than fifty (50) label classes;

creating document features representing aspects of words in each of the documents;

training a support vector machine with the document features for one-vs-the-rest classification using the plurality of label classes, the training comprising:

training a one-vs-the-rest classifier the number of times such that the one-vs-the-rest classifier is trained one time for each of the plurality of label classes, each training including:

 providing the training examples belonging to the respective label class to the support vector machine running the one-vs-the-rest classifier to obtain training output labels, and

comparing the training output labels using a linear support vector machine classifier to generate the number of hyperplane determinations that separate each label class of the plurality of label classes from the rest of the plurality of label classes; and

storing parameters of the trained support vector machine, the parameters comprising the hyperplane determinations.

12. The system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

deploy the trained multi-label classifier and the stored parameters of the trained support vector machine to a production environment.

13. The system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

classify a document with multiple label classes of the plurality of label classes using the trained multi-label classifier.

14. The system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

classify a document with a label class of the plurality of label classes using the trained multi-label classifier.

15. The system of claim 11 , wherein the document features comprise frequency features based on term frequency-inverse document frequency.

16. The system of claim 11 , wherein the document features comprise semantic features based on embedding in a multi-dimensional vector space using Word2Vec.

17. The system of claim 11 , wherein the document features comprise semantic features based on embedding in a multi-dimensional vector space using global vectors for word representation.

18. The system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

select support vector machine hyper parameters across regularization, class weight, and loss function in a predetermined search range to generate an at-least-one (ALO) score within ten percent of maximum attainable over the predetermined search range.

19. The system of claim 18 , wherein the ALO score is calculated based on a ratio of a count of the documents with at least one pairwise match between inferred labels and ground truth labels to a total number of documents with at least one ground truth label.

20. The system of claim 11 , wherein a first label class of the plurality of label classes is parked domain to classify documents posted on parked domains, and wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

identify parked domains and collecting documents posted on the parked domains, the identifying comprising:

crawling uniform resource locators (URLs) that are within a predetermined edit distance of selected URL names;

determining for at least some of the crawled URLs that URL resolution is referred to an authoritative nameserver that appears in a list of parked domain nameservers identified as dedicated to parked domains; and

collecting the documents posted on the crawled URLs that are referred to the parked domain nameservers; and

label the collected documents as collected from the parked domains and storing the documents and parked domain labels for use in training.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2024
From: YADAV, SANDEEP; BALUPARI, RAVINDRA K.
To: NETSKOPE, INC.
Reel/Frame 066720/0428 →
Continuity (3)
Continuation 17396503 · Aug 6, 2021
Continuation 16226394 · Dec 19, 2018
Related Publication 20240028625A1 · Jan 25, 2024
References Cited (129)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6006221A · Liddy · 1999 [cited by examiner]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 6701294B1 · Ball · 2004 [cited by examiner]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7139754B2 · Goutte · 2006 [cited by examiner]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7356187B2 · Shanahan · 2008 [cited by examiner]
US 7376635B1 · Porcari · 2008 [cited by examiner]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7386527B2 · Harris · 2008 [cited by examiner]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7835902B2 · Gamon · 2010 [cited by examiner]
US 7912805B2 · Brown · 2011 [cited by examiner]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 7974984B2 · Reuther · 2011 [cited by examiner]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8112421B2 · Sun · 2012 [cited by examiner]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8548951B2 · Solmer · 2013 [cited by examiner]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20040111438A1 · Chitrapura · 2004 [cited by examiner]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050228783A1 · Shanahan · 2005 [cited by examiner]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080046486A1 · Huang · 2008 [cited by examiner]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090119572A1 · Koivunen · 2009 [cited by examiner]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100223261A1 · Sarkar · 2010 [cited by examiner]
US 20100287160A1 · Pendar · 2010 [cited by examiner]
US 20100332475A1 · Birdwell · 2010 [cited by examiner]
US 20110078099A1 · Weston · 2011 [cited by examiner]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120011120A1 · Burnand · 2012 [cited by examiner]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130097166A1 · Fink · 2013 [cited by examiner]
US 20130158982A1 · Zechner · 2013 [cited by examiner]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150242486A1 · Chari · 2015 [cited by examiner]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html# :˜: text=mode of communication.-, What are the different email prot… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits? Offer=a… [cited by applicant]
Fortinet, FortiGate - 3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]