Steganographic modification detection and mitigation for enhanced enterprise security
Aspects of the disclosure relate to mitigation and detection of steganographic modifications embedded in images. A computing platform may receive an image embedded with steganographic modifications. The computing platform may change or modify any number of bits of one or more color components of one or more pixels of an image, rendering the steganographic modifications ineffective. The computing platform may cause at an isolation zone system, execution of an image, including steganographic modifications, to identify images embedded with steganographic modifications. The computing platform may also compare an image with image stored in an image storage module. The computing platform may store an image from the image storage module with a highest visual comparison score rather than the image.
1 . A computing platform, comprising:
at least one processor;
a communication interface communicatively coupled to the at least one processor; and
a memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
generate a copy of a first image, embedded with steganographic modifications comprising modifications to one or bits of a plurality of pixels of the first image, wherein the steganographic modifications comprise malicious software;
generate a safe first image of the copy of the first image by changing or modifying one or more bits beginning from a least significant bit of at least one pixel of the copy of the first image, wherein generating the safe first image of the copy of the first image renders the steganographic modifications ineffective, wherein generating the safe first image comprises inverting bit values of one or more bits beginning from a least significant bit of at least one color component of a plurality of pixels of the copy of the first image by:
changing bits with a 0 value to a 1 value, and
changing bits with a 1 value to a 0 value;
route the safe first image to an isolation zone system;
based on receiving an indication from the isolation zone system indicating that the safe first image remains embedded with effective steganographic modifications, modify the safe first image by inverting an increased number of bits beginning from a least significant bit of at least one color component of a plurality of pixels of the safe first image until a presence of the effective steganographic modifications is no longer detected;
after identifying that the presence of the effective steganographic modifications is no longer detected, route the safe first image to a first user device;
route the first image to the isolation zone system; and
perform, based on results of execution of the steganographic modifications of the first image in the isolation zone system, one or more security actions.
2 . The computing platform of claim 1 , wherein the one or more security actions comprise:
flagging an outside source of the first image as a malicious entity.
3 . The computing platform of claim 2 , wherein embedding the first image with the steganographic modifications comprises accessing a stored image at the computing platform, and modifying the stored image through steganography.
4 . The computing platform of claim 2 , wherein embedding the first image with the steganographic modifications comprises directing the computing platform to store an image with steganographic modifications.
5 . The computing platform of claim 1 , wherein the steganographic modifications embedded in the first image comprise modifications to one or more color components of the plurality of pixels.
6 . The computing platform of claim 5 , wherein the safe first image is generated by changing or modifying at least one of four bits beginning from a least significant bit of at least one color component of all pixels of the first image.
7 . The computing platform of claim 1 , wherein the memory stores computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
store the safe first image rather than the first image.
8 . The computing platform of claim 1 , wherein routing the safe first image to the first user device is responsive to receiving a request from the first user device to view the first image.
9 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
receive a third image;
compare the third image to a plurality of stored verified images;
identify that the third image matches an image from the plurality of stored verified images;
store the identified image rather than the third image, wherein storing the identified image rather than the third image renders any steganographic modifications of the third image ineffective; and
route the identified image to the first user device based on a request from the first user device to view the third image.
10 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
receive the first image.
11 . The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
automatically cause, at the isolation zone system through one or more commands directing the isolation zone system to execute the steganographic modifications of the first image, execution of the steganographic modifications of the first image.
12 . A method comprising:
at a computing platform, the computing platform having at least one processor and memory:
generating a copy of a first image, embedded with steganographic modifications comprising modifications to one or bits of a plurality of pixels of the first image, wherein the steganographic modifications comprise malicious software;
generating a safe first image of the copy of the first image by changing or modifying one or more less significant bits of at least one pixel of the copy of the first image, wherein generating the safe first image of the copy of the first image renders the steganographic modifications ineffective, wherein generating the safe first image comprises inverting bit values of one or more bits beginning from a least significant bit of at least one color component of a plurality of pixels of the copy of the first image by:
changing bits with a 0 value to a 1 value, and
changing bits with a 1 value to a 0 value;
routing the safe first image to an isolation zone system;
based on receiving an indication from the isolation zone system indicating that the safe first image remains embedded with effective steganographic modifications, modifying the safe first image by inverting an increased number of bits beginning from a least significant bit of at least one color component of a plurality of pixels of the safe first image until a presence of the effective steganographic modifications is no longer detected;
after identifying that the presence of the effective steganographic modifications is no longer detected, routing the safe first image to a first user device;
routing the first image to the isolation zone system; and
performing, based on results of execution of the steganographic modifications of the first image in the isolation zone system, one or more security actions.
13 . The method of claim 12 , wherein the one or more security actions comprises:
flagging an outside source of the first image as malicious entity.
14 . The method of claim 13 , wherein embedding the first image with steganographic modifications comprises accessing a stored image at the computing platform, and modifying the stored image through steganography.
15 . The method of claim 14 , wherein embedding the first image with the steganographic modifications comprises directing the computing platform to store an image with the steganographic modifications.
16 . The method of claim 12 , wherein the steganographic modifications embedded in the first image comprise modifications to one or more color components of the plurality of pixels.
17 . The method of claim 16 , wherein the safe first image is generated by changing or modifying at least one of four bits beginning from a least significant bit of at least one color component of all pixels of the first image.
18 . One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to:
generate a copy of a first image, embedded with steganographic modifications comprising modifications to one or bits of a plurality of pixels of the first image, wherein the steganographic modifications comprise malicious software;
generate a safe first image by changing or modifying one or more bits beginning from a least significant bit of at least one pixel of the copy of the first image, wherein generating the safe first image of the copy of the first image renders the steganographic modifications ineffective;, wherein generating the safe first image comprises inverting bit values of one or more bits beginning from a least significant bit of at least one color component of a plurality of pixels of the copy of the first image by:
changing bits with a 0 value to a 1 value, and
changing bits with a 1 value to a 0 value;
route the safe first image to an isolation zone system;
based on receiving an indication from the isolation zone system indicating that the safe first image remains embedded with effective steganographic modifications, modify the safe first image by inverting an increased number of bits beginning from a least significant bit of at least one color component of a plurality of pixels of the safe first image until a presence of the effective steganographic modifications is no longer detected;
after identifying that the presence of the effective steganographic modifications is no longer detected, route the safe first image to a first user device;
route the first image to an isolation zone system; and
perform, based on results of execution of the steganographic modifications of the first image in the isolation zone system, one or more security actions.
19 . The computing platform of claim 9 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:
identify that a visual comparison score, assigned to the identified image, meets or exceeds a minimum visual comparison threshold score, wherein storing the identified image rather than the third image is further in response to identifying that the visual comparison score meets or exceeds the minimum visual comparison threshold score.
20 . The computing platform of claim 1 , wherein routing the first safe image to the isolation zone system includes sending commands directing the isolation zone system to execute the first safe image over a duration of time to identify latent malicious software that is not immediately identifiable upon execution of the first safe image.