Microsoft and Intel are turning malware into images

(Image credit: Andriano.cz / Shutterstock)

Researchers from the Microsoft Threat Protection Intelligence Team and Intel Labs have come together to work on a new research project that utilized a novel approach to detect and classify malware.

The project, called STAtic Malware-as-Image Network Analysis (STAMINA), used a new technique to convert malware samples into grayscale images which were then scanned for textural and structural patterns specific to known malware samples.

During the first part of their collaboration, the researchers built on Intel's previous work on deep transfer learning for static malware classification and used a real-world dataset from Microsoft to better understand the practical value of approaching malware classification as a computer vision task.

The STAMINA approach makes the argument that malware can be classified at scale by performing static analysis on malware codes represented as images. 

Turning malware into images

The researchers first prepared the malware binaries by converting them into two-dimensional images using pixel conversion, reshaping and resizing. The binaries were then converted into a one-dimensional pixel stream by assigning each byte a value between 0 and 255 which corresponded to pixel intensity. Each Pixel stream was then transformed into a two-dimensional image by using the file size to determine the width and height of each image.

These resized images were then fed into a pre-trained deep neural network (DNN) that scanned the 2D representations of malware strains and classified them as either clean or infected. To serve as a base for the research, Microsoft provided a sample of 2.2m infected Portable Executable (PE) file hashes.

Microsoft and Intel researchers used 60 percent of the known malware samples to train the original DNN algorithm, 20 percent of the files were used to validate the DNN and the other 20 percent were used for the actual testing process. According to the research team, STAMINA was able to achieve an accuracy rate of 99.07 percent in identifying and classifying malware samples with a false positive rate of only 2.58 percent. When working with smaller files, STAMINA was accurate and fast though the project wavered when working with larger images. 

Based on the project's success at identifying malware, Microsoft could one day end up using STAMINA to spot malware on Windows PCs or even in its antivirus software Window Defender.

Via ZDNet

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras