The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 05, 2021

Filed:

Oct. 02, 2017
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Jan Brabec, Rakovnik, CZ;

Lukas Machlica, Prague, CZ;

Assignee:

Cisco Technology, Inc., San Jose, CA (US);

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06N 20/00 (2019.01); G06F 21/56 (2013.01); G06N 5/04 (2006.01); G06K 9/62 (2006.01); G06N 5/02 (2006.01); H04L 29/06 (2006.01); G06N 5/00 (2006.01); G06N 20/20 (2019.01);
U.S. Cl.
CPC ...
G06N 20/00 (2019.01); G06F 21/56 (2013.01); G06F 21/562 (2013.01); G06K 9/6256 (2013.01); G06K 9/6267 (2013.01); G06K 9/6282 (2013.01); G06N 5/003 (2013.01); G06N 5/025 (2013.01); G06N 5/04 (2013.01); G06N 20/20 (2019.01); H04L 63/145 (2013.01); G06F 2221/2145 (2013.01);
Abstract

In one embodiment, a device trains a machine learning-based malware classifier using a first randomly selected subset of samples from a training dataset. The classifier comprises a random decision forest. The device identifies, using at least a portion of the training dataset as input to the malware classifier, a set of misclassified samples from the training dataset that the malware classifier misclassifies. The device retrains the malware classifier using a second randomly selected subset of samples from the training dataset and the identified set of misclassified samples. The device adjusts prediction labels of individual leaves of the random decision forest of the retrained malware classifier based in part on decision changes in the forest that result from assessing the entire training dataset with the classifier. The device sends the malware classifier with the adjusted prediction labels for deployment into a network.


Find Patent Forward Citations

Loading…