Microsoft’s Project Ire Shows Promise in Early Malware Tests

Microsoft is testing Project Ire, an AI prototype that analyzes unfamiliar files for malware and explains its findings. Early results show high precision but inconsistent recall, highlighting a trade-off between limiting false alarms and catching more threats. Microsoft plans to improve the system before considering it for malware detection and software classification in Defender.

USAGEFUTURETOOLS

The AI Maker

10/12/20262 min read

Glowing digital shield blocks streams of red and gray data fragments while blue data lines pass beyond it.
Glowing digital shield blocks streams of red and gray data fragments while blue data lines pass beyond it.

Microsoft is developing Project Ire, an AI prototype designed to identify and reverse engineer malware without prior information about a file’s origin or purpose. The company says it could eventually serve as a “Binary Analyzer” in Microsoft Defender, examining files in memory when they are first encountered.

Early results suggest the system can identify suspicious files with relatively few false alarms, but its ability to catch malware varies substantially by test. In Microsoft’s real-world scenario testing, Project Ire scanned 4,000 files it had not previously encountered. Its precision was close to 90%, while recall was just above one quarter; the false positive rate was 4%.

Those measures describe different parts of detection performance. Precision indicates how often files flagged by the tool were actually malicious. Recall measures how much of the malware in a test set it found. High precision can help limit unnecessary investigations, but low recall means many threats may go undetected. The initial results therefore point to potential, not readiness for broad deployment.

Microsoft said the tool produces a report for each file it considers potentially malicious, explaining which parts of the file contributed to that assessment. Such explanations could help security teams review detections and understand why an unfamiliar binary was flagged, although the available results do not establish how the reports perform in day-to-day operations.

A second evaluation, using a public dataset containing both legitimate and malicious Windows drivers, produced stronger recall. Project Ire reached a reported precision of about 90%, a false positive rate of 2%, and a recall score of 0.83. The difference between the two tests underlines how performance can depend on the files being analyzed; the driver result should not be treated as a general measure across all malware.

The proposed Defender role would focus on analyzing binaries in memory from any source at first encounter. That could offer another way to assess unfamiliar software, including files that do not match known threat signatures. For businesses, the practical value would depend on whether the system can maintain useful detection rates at scale while fitting into existing security workflows and keeping false alarms manageable.

Microsoft says it will continue working to improve Project Ire’s speed and accuracy before considering its use in Defender as a threat-detection and software-classification tool. The prototype arrives as threat actors increasingly use AI tools to create malicious files at scale, while cybersecurity teams are also applying AI to detection. Whether Project Ire can contribute meaningfully will depend on further testing, particularly whether it can improve recall without eroding its precision.

Cited: https://www.techradar.com/pro/security/microsofts-new-ai-security-tool-can-spot-malware-early-and-even-reverse-engineer-it-to-crack-the-code

Your Data, Your Insights

Unlock the power of your data effortlessly. Update it continuously. Automatically.

Answers

Sign up NOW

info at aimaker.com

© 2024. All rights reserved. Terms and Conditions | Privacy Policy