AI Poised to Drive New Wave of Exploits

  /     /     /  
Publicated : 23/11/2024   Category : security


AI Poised to Drive New Wave of Exploits


Criminals are ready to use AI to dramatically speed the process of finding zero-day vulnerabilities in systems.



Artificial intelligence has significant potential for use in cybersecurity – on both sides of the security battle lines. And you dont have to wait for scenarios out of The Terminator to see its impact.
According to Derek Manky, Fortinets chief, security insights & global threat alliances, AIs use by attackers is a simple matter of economics. Looking forward, cybercriminals will be looking at increasing their ROI. I think what well start to see is the concept of AI fuzzing, he says. Weve seen some interesting research on this.
Fuzzing – among a series of predictions in 
Fortinets Q3 2018 Security Prediction Report
 – is a technique that has its roots in software quality testing.   The system (or component) being tested is given random input until it crashes, and then the crash is analyzed. From an attackers point of view, fuzzing can uncover vulnerabilities to exploit.
Discovering vulnerabilities is still quite manual, very human-driven, Manky says, which makes finding them an expensive process. AI can dramatically speed up the fuzzing process, and its already been proved in other contexts. Groups have applied this to gaming, using AI to hack the game and exploit a weakness, Manky says. Moving that experience to finding security exploits is a natural next step.
Attackers can use AI to dramatically shorten the time from finding a problem to creating an exploit, as well. Groups will be using AI to study code and systems to find vulnerabilities, and then using AI to find the best exploit of those vulnerabilities, Manky says. This is automatically creating zero-days.
AI, in this context, is a tool for finding the vulnerabilities and exploits, not orchestrating attacks. As that tool is used by more criminal organizations, Manky sees detecting and exploiting zero-days becoming faster and easier, with the cost of those exploits becoming lower and lower on the black market. From a cybercriminal perspective, the AI becomes a commodity with zero-day mining systems. Zero-days become less expensive and more accessible to hackers, he explains.
Defending a more porous and exploited attack surface is a matter of getting all the basics right, Manky says. From the CISO perspective, it becomes more important for your patch management to be good, and open collaboration becomes more important, he says. In addition, designing zero-trust architectures that are thoroughly segmented is critical. You dont want a successful attack gaining access to the rest of the network, Manky explains.
Related Content
:
Cryptojacking, Mobile Malware Growing Threats to the Enterprise
Teach Your AI Well: A Potential New Bottleneck for Cybersecurity
5 Things the Most Secure Software Companies Do (and How You Can Be Like Them)
Black Hat Europe Speaker Q&A: SoarTech’s Fernando Maymi on ‘Synthetic Humans’
 
 
Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the
conference
 and
to register.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
AI Poised to Drive New Wave of Exploits