Technology

Microsoft Claims That Its AI Can Accurately Detect Security Bugs

Microsoft has released a new program that says it can accurately differentiate 99 percent of the time between security and non-security software bugs

A data collection of 13 million work items and bugs from 47,000 developers stored across AzureDevOps and GitHub repositories was used by Microsoft to build a process and machine learning model that correctly distinguishes between security and non-security bugs. 

Additionally, the program can reliably detect critical, high-priority security bugs 97 percent of the time on average.

Also read: Google started listing COVID-19 testing centers in search results

The company plans to open source the technique on GitHub in the coming months along with examples of models and other tools so the program can be used to help human experts. 

The training data and the statistical samples used to provide them with a manageable amount of data to review were accepted by security experts when designing their model. This data was then encoded into representations called feature vectors, as Microsoft researchers used a two-step method to construct the device. 

Also read: Netflix puts a bunch of documentaries on YouTube for free

The model first learned to distinguish security and non-security bugs, and then learned to apply safety labels (critical, significant or low-impact) to those bugs.

In a blog post announcing the new system, Microsoft explained how it used machine learning models and security experts to better identify security bugs, saying:

“Every day, software developers stare down a long list of features and bugs that need to be addressed. Security professionals try to help by using automated tools to prioritize security bugs, but too often, engineers waste time on false positives or miss a critical security vulnerability that has been misclassified. To tackle this problem data science and security teams came together to explore how machine learning could help. We discovered that by pairing machine learning models with security experts, we can significantly improve the identification and classification of security bugs.”

Recent Posts

End of the PlayStation disc: Angry fans are now planning a mass boycott

The announced disc shutdown on PlayStation is currently heating up fans' minds. While Sony plays…

16 hours ago

GTA 6 codes are region-specific and even have an expiration date in Japan

In the future or initially, physical GTA 6 cases will only contain a download code…

16 hours ago

Samsung Galaxy: There will be two new premium smartphones in 2027

Samsung customers will be able to enjoy a wider selection of premium smartphones next year…

16 hours ago

Blade Runner 2099: Amazon shows the teaser trailer for the miniseries

Amazon has released the first teaser trailer for Blade Runner 2099, which already gives a…

16 hours ago

Marvel: Ryan Gosling introduced as Ghost Rider, new Black Panther

Marvel relies on well-known brands in the film universe, but deliberately swaps out the faces…

16 hours ago

Google Pixel user in court over the functionality of his custom ROM

A US citizen is on trial because he used a special security feature of his…

16 hours ago