Invention Grant
- Patent Title: Methods and apparatus for identifying an impact of a portion of a file on machine learning classification of malicious content
-
Application No.: US15884542Application Date: 2018-01-31
-
Publication No.: US11941491B2Publication Date: 2024-03-26
- Inventor: Richard Harang , Joshua Daniel Saxe
- Applicant: Sophos Limited
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: COOLEY LLP
- Main IPC: G06N20/00
- IPC: G06N20/00 ; G06F21/56 ; G06F16/80

Abstract:
In some embodiments, a non-transitory processor-readable medium stores code representing instructions to be executed by a processor. The code includes code to cause the processor to receive a structured file for which a machine learning model has made a malicious content classification. The code further includes code to remove a portion of the structured file to define a modified structured file that follows a format associated with a type of the structured file. The code further includes code to extract a set of features from the modified structured file. The code further includes code to provide the set of features as an input to the machine learning model to produce an output. The code further includes code to identify an impact of the portion of the structured file on the malicious content classification of the structured file based on the output.
Public/Granted literature
Information query