Microsoft Uses Deep Learning For Malicious PowerShell Detection
Microsoft bets on deep learning to enhance the Microsoft Defender Advanced Threat Protection (ATP) malicious PowerShell detection feature using a new technique originally developed for natural language processing (NLP). The new deep learning model is "now adopted and applied to expand our coverage of detecting malicious PowerShell scripts, which continue to be a critical attack vector," says Microsoft. Microsoft's deep learning model used for malicious PowerShell script detection "combines several deep learning building blocks such as Convolutional Neural Networks (CNNs) and Long Short-Term Memory Recurrent Neural Networks (LSTM-RNN)." The company adopted the best performing model designed for NLP and trained on collections of PowerShell scripts the Microsoft Defender ATP platform observed via the Antimalware Scan Interface (AMSI). After its first deployment on Microsoft Defender ATP, this deep learning model specifically trained for spotting malicious scripts was able to find malicious PowerShell behavior that bypassed other Microsoft Defender ATP monitoring features.
Sep-8-2019, 11:26:47 GMT