Skip to content

Identifying Security Platform Product Abuse with Machine Learning

Sep 2026 · 0 citations · 40 references
Computer Science

TL;DR

This work provides the first study of such a whole-system defense, especially with respect to a deployed and operational capability, and shows an increase in product abuse coverage, a 30% reduction in monthly alerts, and adaptability to changes in malicious actors'behavior.

Abstract

Product abuse is an individually rare, but growing, problem across the SaaS industry. Highly sophisticated threat actors can misuse security platforms within customer environments or conduct bypass experiments on the product itself. Threat actors can leverage living-off-the-land (LOTL) attacks to avoid using cumbersome, frequently detected malware. Remediating this threat requires collecting multiple data modalities across different types of databases, addressing a cold-start problem in the intrinsic rarity of such sophisticated but dangerous events, and designing within the constraints of real-world deployment (e.g., cost, user behavior, performance, etc). To wit, we provide the first study of such a whole-system defense, especially with respect to a deployed and operational capability. Our results show an increase in product abuse coverage by 35\%, a 30\% reduction in monthly alerts, and adaptability to changes in malicious actors'behavior. We review both the constraints we considered in designing the system to meet operational requirements and a retrospective evaluation of the value of explainable features and counterfactual performance on previously identified attacks.

View source

Similar papers

Preprint Sep 2026

Windows Malware Detector as a Compound AI System: Trade-Offs in Accuracy, Efficiency, and Adversarial Robustness

Industrial Windows malware detectors are commonly described as Compound AI Systems composed of multiple heterogeneous components, including rule-based mechanisms as well as machine-learning-based static and dynamic analyses. However, due to industrial secrecy and limited public disclosure, the internal architectures of...

Andrea Ponte, Luca Demetrio, Luca Oneto et al. · 0 citations
Preprint Sep 2026

Breaking Windows Malware Detection: A Comprehensive Evaluation of Problem-Space Adversarial Robustness

Problem-space evasion attacks have exposed critical weaknesses in machine learning-based malware detectors; yet, their evaluation remains fragmented across models, datasets, and attack methodologies, often neglecting domain-specific requirements such as executability and functionality preservation. We address this gap...

Mashal Zainab, Salijona Dyrmishi, Hamid Bostani et al. · 0 citations
Open access Sep 2026

AI-Enhanced Email Security: A Novel Pipeline for Phishing Campaign Detection and Profiling

In recent years, phishing attacks have grown exponentially in scale, frequency, and sophistication, placing a significant burden on organizations and security personnel. Attackers leverage advanced obfuscation techniques to evade detection systems and ensure their emails reach users’ inboxes. Additionally, attackers di...

Tarini Saka, Kami Vaniea, Nadin Kokciyan · 0 citations
Open access Sep 2026

Base Semantics—A Novel Approach for Minimizing Malware Detection Rules

The rapid evolution of malware variants has increasingly undermined traditional signature‐based detection techniques, which are easily evaded through obfuscation and polymorphism that preserve malicious functionality. This challenge is particularly acute in Internet of Things (IoT) environments, where device heteroge...

Khizar Hayat, S. Hina, Fabiha Hashmat et al. · 0 citations
#artificial intelligence Preprint Sep 2026

SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs

This work presents SCRIPTIOC-BENCH, a benchmark for measuring static IOC extraction capability on real-world malicious scripts, and evaluates a broad range of proprietary and open-weight LLMs, showing that IOC recovery without execution remains challenging across model scales.

Hanna Kim, Jian Cui, Minkyoo Song et al. · 0 citations
Review Aug 2026

Machine Learning in Cyber Security: A Systematic Literature Review of Intrusion Detection, Malware Analysis, and Adversarial Robustness

A conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight is proposed by outlining directions for future research.

C. Thilagavathy, Saeed Mudether Saeed Taha, Krithik M. S. et al. · 0 citations

Related blog posts

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.