Synthetic intelligence (AI) has lengthy been a cornerstone of cybersecurity. From malware detection to community site visitors evaluation, predictive machine studying fashions and different restricted AI purposes have been utilized in cybersecurity for many years. As we transfer nearer to synthetic basic intelligence (AGI), AI’s potential to automate defenses and remediate vulnerabilities turns into much more highly effective.
However to make the most of such advantages, we should additionally perceive and mitigate the dangers of more and more refined AI. abuse To allow or improve cyber-attacks. our new framework To evaluate new offensive cyber capabilities of AI It’ll enable you do precisely this. That is essentially the most complete analysis of its sort thus far. It covers each stage of the cyber assault chain, addresses a variety of risk sorts, and is predicated on real-world knowledge.
Our framework allows cybersecurity professionals to determine needed defenses and prioritize them earlier than malicious actors exploit AI to hold out refined cyberattacks.
Constructing a complete benchmark
Our trendy Frontier Security Framework acknowledges that superior AI fashions have the potential to automate and speed up cyberattacks, decreasing prices for attackers. This will increase the danger of bigger assaults being carried out.
To remain forward of the rising risk of AI-powered cyberattacks, we have now adopted a confirmed cybersecurity evaluation framework: Miter attack & CK. These frameworks have made it attainable to evaluate threats throughout the whole end-to-end cyber assault chain, from reconnaissance to focus on motion, and throughout quite a lot of attainable assault situations. Nonetheless, these established frameworks weren’t designed with attackers utilizing AI to infiltrate techniques. Our strategy bridges this hole by proactively figuring out the place AI could make assaults quicker, cheaper, and simpler. For instance, by enabling absolutely automated cyberattacks.
We analyzed over 12,000 real-world makes an attempt to make use of AI in cyberattacks throughout 20 international locations utilizing knowledge from: Google’s Threat Intelligence Group. This helped determine frequent patterns through which these assaults unfold. From these, we have now curated a listing of seven typical assault classes, together with phishing, malware, and denial of service assaults, and recognized key bottleneck steps alongside the cyber assault chain the place AI can considerably disrupt conventional assault prices. By specializing in and assessing these bottlenecks, defenders can extra successfully prioritize safety sources.

