Site navigation

GenAI in Cyber: The Good, the Bad, and the Ugly

Elizabeth Greenberg

,

genAI cybersecurity
At the second annual Scot-Secure West summit held in Glasgow, Elliot Went, senior systems analyst at SentinelOne, dissected the impact genAI is having on the cyber-threat landscape, and how vendors and defenders can take advantage of the emerging technology to compete with adversaries. 

The cyber-threat landscape is continually transforming with new technologies, shifting geopolitical threats, and undulating economic tides.

The advent of generative AI has exacerbated this transformation – it can do everything faster, more efficiently, and on a greater scale, whether this is creating cyber-threats or detecting and mitigating against them.

It’s impossible to talk about any facet of technology, especially cybersecurity, without talking about how AI has already affected the industry, with regards to its current capabilities, and the threats it’s giving rise to.

With this in mind, Elliot Went, senior systems analyst at SentinelOne took us through the good, the bad, and the ugly of AI in cybersecurity.

The Ugly

Went introduced three menacing threat forms that utilise generative AI technologies, which not only exploit the technology’s advanced efficiency, but more of its innovative and creative capabilities.

Frist, Deep Locker, which uses a generative AI neural network to contextually understand its environment to guide its execution. It is location aware, and can be deployed to multiple environments to then decide how it will penetrate and execute an attack. It can use webcams, facial and voice recognition, generating ‘aware’ malware quietly to avoid detection.

Next, Went explained the tech behind Black Mamba, a polymorphic malware driven by generative AI. The description alone sounds straight out of a horror film, with the artificial intelligence able to ‘slither’ around its environment, “dynamically evolving code on the fly” by feeding the data it collects to generative AI.

It’s capable of picking up on threat detectors, meaning it can circumvent these “static controls” by generating novel workarounds.

MalGAN, which stands for generative adversarial malware, denotes a method of model training using a generator and a discriminator to train an AI model.

A discriminator has access to the target output, let’s say, a picture of a dog, or, alternatively, a line of malware code that is impervious to current detectors.

A generator will start creating pictures of what it thinks a dog will look like, and send it to the discriminator, which will then give it a percentage match, until the generator’s output is as close to a 100% match to the target outcome as possible.

“Applied in a malicious sense,” Went said, “a discriminator is using ML [machine learning] detection rules to create a bunch of code, until that code is not protected by any current ML detection. Essentially, generating content to circumnavigate AI detection.”

This pernicious parade of genAI applications seem straight out of a cybersecurity specialists’ nightmares, and in actuality, that’s where they currently reside.

“They’re not actually affecting the real world right now,” Went assured the audience. “The models were built as proof of concept by research and development organisations.”

The ‘ugly’ side of AI is labelled so because right now, it is just that. These malicious use cases of AI have yet to be employed on the big stage, though Went said that the models and their variations were in development in lots of nation states, “until it eventually seeps out.”

Investigating and inventing the ugliest side of AI is key, however, in defending against it.

Now, however, AI is already being used for the bad.

The Bad

If you’ve paid attention to the current threat landscape (which you can catch up with here), then you know AI has almost instantly been snapped up and used by threat actors and adversaries since it was released into the mainstream.

Advents of AI chatbots, and the seminal release of ChatGPT, put the fast efficiency of AI in the hands of the specialists, the public, and threat actors alike.

But, as Went points it out, the use cases of genAI tend to follow a typical pattern, whether it is used by experts in their field, by the public making searchers, or by adversaries trying to launch a cyber-attack.

“It’s a tool, we use it as a tool,” he said. “We point it at what we want to achieve, and it helps us be more efficient and more effective.”

Common use cases for AI by adversaries is to improve their phishing and social engineering attacks, with high fidelity and increased sophistication that has been noted by many a cyber-threat landscape review.

But AI can also be used in brute force credential attacks, and enlarge distributed denial of service (DDoS) attacks at scale.

AI can be used to poison data, sifting through vast sets to find and exploit vulnerabilities.

“Threat actors are just leveraging AI to do the same stuff,” Went said, but with devastating results.

Phishing attacks are more difficult to detect by humans, and AI is struggling to identify its own AI-generated social engineering tactics.

Further, the scale at which AI can carry out attacks will only increase their success rate, and the ease with which these tools can be employed has lowered the skills threshold dramatically, opening up cyber-attacks to an entirely new platform of would-be attackers.

Went did mention that we are catching up, at least in terms of classifying the ways AI is being used by threat actors.

The MITRE ATT&CK (adversarial tactics, techniques, and common knowledge) framework has “further built our taxonomy on AI-based threats,” Went said, which cybersecurity defenders can study to aid them in dealing with or detecting those AI-driven attacks.

So, we’ve discussed the ugly of AI haunting cyber specialists’ nightmares (and potentially, our futures) and the very real, very active bad side of AI in cyber. But will Went give us a glimmer of AI’s promised good side?


Recommended reading


The Good

Just as it can be used as an attack vector, AI can be used in defence – in fact, it has been for years.

“I’m sure you’ve seen just about every security vendor saying they’ve used AI for years,” Went commented.

And they are pretty much right – cybersecurity techniques often employ different forms of AI in their defence and detection capabilities, mainly in the form of machine learning models.

Went says these are front end models, capable of detecting threats and vulnerabilities out of myriad data points.

“In this arena, generative AI is kind of irrelevant,” Went said. Sure, genAI can be used to advance the efficiency of these ML models, but the data landscape is much more complex than that typically dealt with by most mainstream genAI models.

“When we think about all the really sophisticated outputs of things like ChatGPT, they are dealing with mainly three inputs of data – text, images, videos – and its because we have an internet worth of data in a standardised format.

“If you think about what we’re trying to detect across – we’re trying to detect across telemetry, logs, deep sets of data, and data that is probably in the production formats across different vendors,” Went explained.

So training a model on these various data sets and forms is not necessarily where genAI is going to make its mark.

“But really what we’re going to be seeing again is using Ai as a tool, as existing as a format today, to instil AI in every function of security tooling that you do today,” Went said.

Essentially, AI will do the same thing it’s done for threat actors – make everything more effective and efficient.

“It’s going to help do threat hunting, it’s going to help translate data sets, help build configurations, understand tools with a quicker time to get value,” Went said.

Generating value from data sets, which Went has demonstrated are incredibly complex and vast, has been a huge barrier “typically requiring deceased worth of skills,” Went said.

Getting the data into a format AI can understand can be a worthwhile pursuit, also aided by AI, to streamline and clean the data pipeline.

Ensuring that AI can understand the data means that analysis, investigations, and vulnerabilities can be done and detected in a much more efficient manner, leaving experts more time for less monotonous tasks.

Building queries on what to look out for across a system, as far as threats of vulnerabilities, can also be aided by AI.

“That’s real low hanging fruit for AI to translate plain, natural language questions into really complex queries,” that existing systems can then act upon, Went explained.

Through the integration of effective data analysis and query building, AI can be used to find the needle in the haystack, as Went puts it, a lot faster.

Standardising a data set, with AI and for AI to understand, can not only help with cyber-defence but can help with the entire stack’s configuration.

“Having an AI engine that can just tell you that you are starting to drift into a really risky area with your configuration,” can be incredibly useful to avoid problems and keep track of your stack and defence posture, Went explained.

Just as with other work, using AI to filter investigations can “really alleviate the manual overhead” that typically falls on advanced security operatives that can spend their time and expertise on higher level tasks.

Using AI in security is a complicated but essential affair. It is not simply “purchasing a commercial chatbot that sits on top technology,” Went said.

“We’re trying to make this a strategic capability.”

Using AI across cyber-investigations, to improve analysts experiences and summarise and take action quicker, are all part of an AI “roadmap” already being used by many cybersecurity vendors as they try to keep up with emerging AI threats.

“Without leveraging AI, despite all the pushback everyone’s going to get about how we adopt that effectively and how we govern that, if we are not doing AI on the defensive side, we do not stand a chance,” Went said.

“There’s no way we’re going to be able to keep up with the challenge.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data