US2022269784A1PendingUtilityA1

N-dimensional model techniques and architectures for data protection

Assignee: QUANTUM STAR TECH INCPriority: Feb 25, 2021Filed: Feb 25, 2021Published: Aug 25, 2022
Est. expiryFeb 25, 2041(~14.6 yrs left)· nominal 20-yr term from priority
G06N 3/09G06N 7/01G06F 21/44G06F 2221/033G06N 20/00G06F 21/562G06N 7/005
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques and architectures include representing data with one or more n-dimensional representations and using one or more analysis models to identify target properties associated with the one or more n-dimensional representations. For example, data can be represented as a plurality of points in a coordinate system. A set of points in the plurality of points can be identified and an n-dimensional model can be generated for the set of points. The n-dimensional model can be compared to a plurality of n-dimensional models that are tagged as including a target property associated with malicious behavior, benign behavior, and/or a vulnerability. Based on the comparison, a likelihood can be determined that the data includes the target property.

Claims

exact text as granted — not AI-modified
1 . A system comprising:
 control circuitry; and   memory communicatively coupled to the control circuitry and storing executable instructions that, when executed by the control circuitry, cause the control circuitry to perform operations comprising:
 receiving data; 
 representing at least a portion of the data as a plurality of points in a coordinate system, the representing including:
 extracting a first set of bits in the data and converting the first set of bits into a first coordinate for a first point of the plurality of points; 
 extracting a second set of bits in the data and converting the second set of bits into a second coordinate for the first point, the second set of bits being adjacent to the first set of bits; 
 extracting a third set of bits in the data and converting the third set of bits into a first coordinate for a second point of the plurality of points; and 
 extracting a fourth set of bits in the data and converting the fourth set of bits into a second coordinate for the second point, the fourth set of bits being adjacent to the third set of bits; 
 
 using a pattern recognition algorithm to identify a set of points in the plurality of points; 
 generating an n-dimensional model for the set of points; 
 comparing the n-dimensional model to a plurality of n-dimensional models that are tagged as including a target property associated with at least one of malicious behavior, benign behavior, or a vulnerability; and 
 based at least in part on the comparison, determining a likelihood that the data includes the target property. 
   
     
     
         2 . (canceled) 
     
     
         3 . The system of  claim 1 , wherein the n-dimensional model includes at least one of a 3D mesh or 3D wireframe. 
     
     
         4 . The system of  claim 1 , wherein the determining the likelihood is based on at least one of a shape of the n-dimensional model, a size of the n-dimensional model, a volume of the n-dimensional model, an area of the n-dimensional model, a number of surfaces of the n-dimensional model, a location of the n-dimensional model within the coordinate system, a position of the n-dimensional model relative to another n-dimensional model within the coordinate system, or a number of n-dimensional models within the coordinate system. 
     
     
         5 . The system of  claim 1 , wherein the operations further comprise:
 determining that the data includes the target property; and   determining at least one of a type of the target property or a source of the target property based on at least one of a shape of the n-dimensional model, a size of the n-dimensional model, a volume of the n-dimensional model, an area of the n-dimensional model, a number of surfaces of the n-dimensional model, a location of the n-dimensional model within the coordinate system, a position of the n-dimensional model to another n-dimensional model within the coordinate system, or a number of n-dimensional models within the coordinate system that are associated with the target property or another target property.   
     
     
         6 . The system of  claim 1 , wherein the operations further comprise:
 determining that the data includes the target property;   updating a portion of the data that includes the target property to generate updated data, the updating including at least one of removing the target property or replacing the target property; and   sending the updated data to a component.   
     
     
         7 . The system of  claim 1 , wherein the operations further comprise:
 representing predetermined data associated with the target property as multiple points;   processing the multiple points to generate one or more of the plurality of n-dimensional models that are tagged as associated with the target property; and   storing the plurality of n-dimensional models as signatures for the predetermined data.   
     
     
         8 . A method comprising:
 receiving, by control circuitry, data;   representing, by the control circuitry, at least a portion of the data as a first plurality of points in a coordinate system, the representing including:
 determining a first coordinate for a first point of the plurality of points based at least in part on a first group of bits in the data; and 
 determining a second coordinate for the first point based at least in part on a second group of bits in the data that is adjacent to the first group of bits; 
   analyzing, by the control circuitry, the first plurality of points to identify a set of points;   generating, by the control circuitry, a first n-dimensional model for the set of points; and   determining, by the control circuitry, a first likelihood that the data includes a target property based at least in part on an analysis of (i) the first n-dimensional model and (ii) a plurality of n-dimensional models that are tagged as being associated with the target property, the target property including at least one of malicious data, benign data, or vulnerability data.   
     
     
         9 . The method of  claim 8 , wherein the determining the first likelihood includes determining a likelihood that the data includes polymorphic malware. 
     
     
         10 . The method of  claim 8 , further comprising:
 generating a signature for the data that includes the first n-dimensional model.   
     
     
         11 . (canceled) 
     
     
         12 . The method of  claim 8 , further comprising:
 associating the first point with an indicator indicating a location of at least one of the first group of bits or the second group of bits within the data;   wherein the determining the first likelihood is based at least in part on the indicator.   
     
     
         13 . The method of  claim 8 , wherein the portion of the data includes first bits, and the method further comprises:
 representing second bits in the data as a second plurality of points, the second bits including a group of bits that overlap with the first bits;   generating a second n-dimensional model for the second plurality of points; and   determining a second likelihood that the data includes the target property based at least in part on an analysis of (i) the second n-dimensional model and (ii) the plurality of n-dimensional models that are tagged as being associated with the target property.   
     
     
         14 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by control circuitry, cause the control circuitry to perform operations comprising:
 receiving data;   representing at least a first portion of the data as a plurality of points in a coordinate system by:
 determining a first coordinate for a first point of the plurality of points based at least in part on a first group of bits in the data; and 
 determining a second coordinate for the first point based at least in part on a second group of bits in the data that is adjacent to the first group of bits; 
   identifying a set of points in the plurality of points;   generating an n-dimensional model for the set of points;   comparing the n-dimensional model to an n-dimensional model that is tagged as being associated with a target property; and   generating a first confidence value indicating a first likelihood that the data includes the target property.   
     
     
         15 . The one or more non-transitory computer-readable media of  claim 14 , wherein the operations further comprise:
 processing the plurality of points using a machine-trained model;   generating a second confidence value indicating a second likelihood that the data includes the target property; and   determining a composite confidence value for the data based at least in part on the first confidence value and the second confidence value.   
     
     
         16 . The one or more non-transitory computer-readable media of  claim 14 , wherein the first likelihood indicates a likelihood that the data includes malware. 
     
     
         17 . The one or more non-transitory computer-readable media of  claim 14 , wherein the operations further comprise:
 analyzing the data to generate entropy data indicating a randomness of the first portion of the data and a randomness of a second portion of the data; and   selecting the first portion of the data for processing based at least in part on the randomness of the first portion of the data;   wherein the representing the first portion of the data is based at least in part on selecting the first portion of the data.   
     
     
         18 . The one or more non-transitory computer-readable media of  claim 14 , wherein at least one of the representing, the identifying, the generating, or the comparing are part of implementing a first analysis model, and the operations further comprise:
 selecting a second analysis model based on at least one of a type of the data, where the first portion of the data is located within the data, or entropy data indicating a randomness of at least the first portion of the data, the second analysis model being different than the first analysis model; and   analyzing the data using the second analysis model.   
     
     
         19 . The one or more non-transitory computer-readable media of  claim 14 , wherein the n-dimensional model includes at least one of a mesh or wireframe. 
     
     
         20 . The one or more non-transitory computer-readable media of  claim 14 , wherein the generating the first confidence value is based on at least one of a shape of the n-dimensional model, a size of the n-dimensional model, a volume of the n-dimensional model, an area of the n-dimensional model, a number of surfaces of the n-dimensional model, a location of the n-dimensional model within the coordinate system, a position of the n-dimensional model relative to another n-dimensional model within the coordinate system, or a number of n-dimensional models within the coordinate system. 
     
     
         21 . A system comprising:
 control circuitry; and   memory communicatively coupled to the control circuitry and storing executable instructions that, when executed by the control circuitry, cause the control circuitry to perform operations comprising:
 receiving data; 
 analyzing the data to generate entropy data indicating a randomness of a first portion of the data and a randomness of a second portion of the data; 
 selecting the first portion of the data based at least in part on the entropy data; 
 representing at least the first portion of the data as a plurality of points in a coordinate system; 
 using a pattern recognition algorithm to identify a set of points in the plurality of points; 
 generating an n-dimensional model for the set of points; 
 generating a data signature for the data, the data signature including the n-dimensional model; 
 analyzing, using a machine-trained model, the n-dimensional model to determine a likelihood that the n-dimensional model includes malware; and 
 generating analysis data indicating the likelihood that the n-dimensional model includes malware. 
   
     
     
         22 . A method comprising:
 receiving, by control circuitry, data;   analyzing, by the control circuitry, the data to generate entropy data indicating a randomness of a first portion of the data and a randomness of a second portion of the data;   selecting, by the control circuitry, the first portion of the data based at least in part on the entropy data;   representing, by the control circuitry, at least the first portion of the data as a plurality of points in a coordinate system;   using, by the control circuitry, a pattern recognition algorithm to identify a set of points in the plurality of points;   generating, by the control circuitry, an n-dimensional model for the set of points; and   determining, by the control circuitry, a likelihood that the data includes a target property based at least in part on an analysis of (i) the n-dimensional model and (ii) a plurality of n-dimensional models that are tagged as being associated with the target property, the target property including at least one of malicious data, benign data, or vulnerability data.   
     
     
         23 . A system comprising:
 control circuitry; and   memory communicatively coupled to the control circuitry and storing executable instructions that, when executed by the control circuitry, cause the control circuitry to perform operations comprising:
 receiving data; 
 analyzing the data using a first analysis model by:
 representing at least a first portion of the data as a plurality of points in a coordinate system; 
 identifying a set of points in the plurality of points; 
 generating an n-dimensional model for the set of points; and 
 comparing the n-dimensional model to an n-dimensional model that is tagged as being associated with a target property; 
 
 selecting a second analysis model based on at least one of a type of the data, where the first portion of the data is located within the data, or entropy data indicating a randomness of at least the first portion of the data, the second analysis model being different than the first analysis model; 
 analyzing the data using the second analysis model; and 
 based at least in part on the analysis of the data using the first analysis model and the analysis of the data using the second analysis model, generating a confidence value indicating a likelihood that the data includes the target property. 
   
     
     
         24 . A method comprising:
 receiving, by control circuitry, data;   analyzing, by the control circuitry, the data using a first analysis model by:
 representing at least a first portion of the data as a plurality of points in a coordinate system; 
 identifying a set of points in the plurality of points; 
 generating an n-dimensional model for the set of points; and 
 comparing the n-dimensional model to an n-dimensional model that is tagged as being associated with a target property; 
   selecting a second analysis model based on at least one of a type of the data, where the first portion of the data is located within the data, or entropy data indicating a randomness of at least the first portion of the data, the second analysis model being different than the first analysis model;   analyzing, by the control circuitry, the data using the second analysis model; and   based at least in part on the analysis of the data using the first analysis model and the analysis of the data using the second analysis model, generating, by the control circuitry, a confidence value indicating a likelihood that the data includes the target property.

Join the waitlist — get patent alerts

Track US2022269784A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.