HomeSecurityMicrosoft-Intel: They convert malware into images before analyzing it!

Microsoft-Intel: They convert malware into images before analyzing it!

Microsoft and Intel recently collaborated on a new research project, testing a new approach to malware detection and classification. This project is called STAMINA (STAtic Malware-as-Image Network Analysis), and it is based on a new technique that converts malware into grayscale images and then scans the image for structural patterns that point to malware samples. In developing this project, the Microsoft and Intel research team followed a number of steps. The first of these was to take an input file and convert its binary format into a stream of raw pixel data. The researchers then took this 1D pixel stream and converted it into a 2D photo so that regular image analysis algorithms could analyze it. The researchers then resized the resulting photo, making it smaller.

Microsoft-Intel: They convert malware into images before analyzing it!

The Microsoft and Intel team said that resizing the raw image did not negatively affect the classification result, noting that this was a necessary step so that computing resources did not have to work with images consisting of billions of pixels, which would likely slow down processing. The images were then passed to a pre-trained deep neural network (DNN), which scanned them with a 2D representation of the malware strain and then classified them as “clean” or “infected.” Microsoft said it used a sample of 2.2 million infected fragmented PE (Portable Executable) files as the basis for the research. Specifically, the researchers used 60% of the known malware samples to train the original DNN algorithm, 20% of the files for DNN validation, and the other 20% for the actual testing process. The research team said that STAMINA achieved 99.07% accuracy in detecting and classifying malware samples, with a false positive rate of 2.58%.

Microsoft-Intel: They convert malware into images before analyzing it!

This research is part of Microsoft’s recent efforts to improve malware detection using machine learning. STAMINA used a technique called deep learning. It’s essentially a subset of machine learning (ML), a branch of artificial intelligence (AI) that refers to intelligent networks that can learn on their own from input data stored in an unstructured or unlabeled form – in this case, a random malware binary. Microsoft said that while STAMINA was accurate and fast when working with smaller files, the same wasn’t true for larger files. Specifically, Microsoft pointed out that for larger applications, STAMINA is less efficient, due to the fact that there are limitations in converting billions of pixels into JPEG images and then resizing them. However, this probably doesn’t matter, as the project could be used for small files with excellent results. In an interview with ZDNet, Tanmay Ganacharya, Director of Security Research for Microsoft Threat Protection, said that Microsoft is now relying heavily on machine learning to detect emerging threats, and that this system uses different machine learning modules that are deployed on customer systems or on servers . For now, Microsoft can make this approach work better than other companies, mainly because of the vast data it has from hundreds of millions of Windows Defender.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS