Machine learning data filtering in a cross-domain environment

US2020036732A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2020036732-A1
Application numberUS-201816047926-A
CountryUS
Kind codeA1
Filing dateJul 27, 2018
Priority dateJul 27, 2018
Publication dateJan 30, 2020
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for transferring data from a first domain to a second domain in a cross-domain environment are presented. The techniques can include accepting computer readable data in the first domain for transfer to the second domain, passing the computer readable data to a first machine learning classifier at the first domain trained with at least malware files publicly identified as malicious, passing the computer readable data to a second machine learning classifier at the first domain trained with at least malware files specific to the first domain, and transferring the computer readable data to a destination in the second domain.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method of transferring data from a first domain to a second domain in a cross-domain environment, the method comprising: accepting computer readable data in the first domain for transfer to the second domain; passing the computer readable data to a first machine learning classifier at the first domain trained with at least malware files publicly identified as malicious; passing the computer readable data to a second machine learning classifier at the first domain trained with at least malware files specific to the first domain; and transferring the computer readable data to a destination in the second domain. 2 . The method of claim 1 , further comprising: passing the computer readable data to a third machine learning classifier at the second domain trained with at least malware files publicly identified as malicious; and passing the computer readable data to a fourth machine learning classifier at the second domain trained with at least malware files specific to the second domain. 3 . The method of claim 1 , further comprising passing the computer readable data to at least one filter configured to filter computer files based on at least one of: malware file signatures, sandbox behavior, metadata, or normalization. 4 . The method of claim 1 , wherein the malware files publicly identified as malicious comprise files of malware used to generate signatures for a signature-based malware detection system. 5 . The method of claim 1 , wherein the malware publicly identified as malicious comprise files with well formed formats. 6 . The method of claim 1 , wherein the malware files specific to the first domain comprise malformed files. 7 . The method of claim 1 , wherein the malware specific to the first domain comprise camera data. 8 . The method of claim 7 , wherein the camera data comprises camera control data. 9 . The method of claim 1 , wherein the malware files specific to the first domain comprise command and control data. 10 . The method of claim 1 , wherein the malware files specific to the first domain comprise audio sensor data. 11 . A computer system for transferring data from a first domain to a second domain in a cross-domain environment, the system comprising: an interface at the first domain for accepting computer readable data in the first domain for transfer to the second domain; a first machine learning classifier at the first domain trained with at least malware files publicly identified as malicious; and a second machine learning classifier at the first domain trained with at least malware files specific to the first domain; wherein the interface is configured to accept computer readable data and pass it to at least the first machine learning classifier and the second machine learning classifier before passing the computer readable data to the second cross-domain environment. 12 . The system of claim 11 , further comprising: a third machine learning classifier at the second domain trained with at least malware files publicly identified as malicious; and a fourth machine learning classifier at the second domain trained with at least malware files specific to the second domain; wherein the system is configured to pass the computer readable data to at least the third machine learning classifier and to the fourth machine learning classifier in the second cross-domain environment. 13 . The system of claim 11 , further comprising at least one filter communicatively coupled to receive the computer readable data and configured to filter computer files based on at least one of: malware file signatures, sandbox behavior, metadata, or normalization. 14 . The system of claim 11 , wherein the malware files publicly identified as malicious comprise files of malware used to generate signatures for a signature-based malware detection system. 15 . The system of claim 11 , wherein the malware files publicly identified as malicious comprise files with well formed formats. 16 . The system of claim 11 , wherein the malware files specific to the first domain comprise malformed files. 17 . The system of claim 11 , wherein the malware files specific to the first domain comprise camera data. 18 . The system of claim 17 , wherein the camera data comprises camera control data. 19 . The system of claim 11 , wherein the malware files specific to the first domain comprise command and control data. 20 . The system of claim 11 , wherein the malware specific to the first domain comprise audio sensor data.

Assignees

Inventors

Classifications

  • involving covert channels, i.e. data leakage between processes (inhibiting the analysis of circuitry or operation with measures against power attack G06F21/755) · CPC title

  • Multi-level security, e.g. mandatory access control · CPC title

  • G06F21/564Primary

    by virus signature recognition · CPC title

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • H04L63/145Primary

    the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2020036732A1 cover?
Techniques for transferring data from a first domain to a second domain in a cross-domain environment are presented. The techniques can include accepting computer readable data in the first domain for transfer to the second domain, passing the computer readable data to a first machine learning classifier at the first domain trained with at least malware files publicly identified as malicious, p…
Who is the assignee on this patent?
Boeing Co
What technology area does this patent fall under?
Primary CPC classification G06F21/564. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jan 30 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).