• bitcoinBitcoin(BTC)$83,531.000.41%
  • ethereumEthereum(ETH)$2,695.021.07%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$755.32-0.93%
  • rippleXRP(XRP)$1.501.17%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$119.240.93%
  • tronTRON(TRX)$0.335175-0.23%
  • zcashZcash(ZEC)$1,415.90-3.32%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-5.35%
  • HyperliquidHyperliquid(HYPE)$86.01-1.94%
  • dogecoinDogecoin(DOGE)$0.0941311.05%
  • chainlinkChainlink(LINK)$14.67-2.12%
  • moneroMonero(XMR)$538.69-0.12%
  • whitebitWhiteBIT Coin(WBT)$83.530.43%
  • USDSUSDS(USDS)$1.00-0.02%
  • cardanoCardano(ADA)$0.2451920.73%
  • RainRain(RAIN)$0.0127181.92%
  • leo-tokenLEO Token(LEO)$9.02-0.50%
  • stellarStellar(XLM)$0.223308-1.76%
  • nearNEAR Protocol(NEAR)$5.078.29%
  • bitcoin-cashBitcoin Cash(BCH)$308.520.86%
  • uniswapUniswap(UNI)$9.003.00%
  • litecoinLitecoin(LTC)$67.73-1.44%
  • avalanche-2Avalanche(AVAX)$11.3810.56%
  • CantonCanton(CC)$0.126455-0.76%
  • Ethena USDeEthena USDe(USDE)$1.000.01%
  • suiSui(SUI)$1.150.85%
  • hedera-hashgraphHedera(HBAR)$0.105180-16.58%
  • daiDai(DAI)$1.00-0.01%
  • USD1USD1(USD1)$1.000.00%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.53-3.83%
  • quant-networkQuant(QNT)$269.8713.82%
  • BitwayBitway(BTW)$1.3432.52%
  • BittensorBittensor(TAO)$308.562.62%
  • crypto-com-chainCronos(CRO)$0.0688521.12%
  • shiba-inuShiba Inu(SHIB)$0.0000063.17%
  • tether-goldTether Gold(XAUT)$4,172.530.90%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • Pump.funPump.fun(PUMP)$0.00591914.61%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • aaveAave(AAVE)$166.1313.49%
  • okbOKB(OKB)$120.742.46%
  • EthenaEthena(ENA)$0.250943-3.07%
  • Ripple USDRipple USD(RLUSD)$1.000.01%
  • OndoOndo(ONDO)$0.521.12%
  • MemeCoreMemeCore(M)$1.06-8.50%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.15-0.04%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Why generative AI is a double-edged sword for the cybersecurity sector

August 27, 2023
in AI & Technology
Reading Time: 5 mins read
A A
Why generative AI is a double-edged sword for the cybersecurity sector
ShareShareShareShareShare

Head over to our on-demand library to view sessions from VB Transform 2023. Register Here


Much has been made of the potential for generative AI and large language models (LLMs) to upend the security industry. On the one hand, the positive impact is hard to ignore. These new tools may be able to help write and scan code, supplement understaffed teams, analyze threats in real time, and perform a wide range of other functions to help make security teams more accurate, efficient and productive. In time, these tools may also be able to take over the mundane and repetitive tasks that today’s security analysts dread, freeing them up for the more engaging and impactful work that demands human attention and decision-making. 

YOU MAY ALSO LIKE

Xbox Just Unveiled Mythic Achievements, Which Are Basically PlayStation Platinum Trophies

OpenAI Launches dots: Always-On GPT-6 Astra Agents That Work From Their Own Cloud Computers

On the other hand, generative AI and LLMs are still in their relative infancy — which means organizations are still grappling with how to use them responsibly. On top of that, security professionals aren’t the only ones who recognize the potential of generative AI. What’s good for security professionals is often good for attackers as well, and today’s adversaries are exploring ways to use generative AI for their own nefarious purposes. What happens when something we think is helping us begins hurting us? Will we eventually reach a tipping point where the technology’s potential as a threat eclipses its potential as a resource?

Understanding the capabilities of generative AI and how to use it responsibly will be critical as the technology grows both more advanced and more commonplace. 

Using generative AI and LLMs 

It’s no overstatement to say that generative AI models like ChatGPT may fundamentally change the way we approach programming and coding. True, they are not capable of creating code completely from scratch (at least not yet). But if you have an idea for an application or program, there’s a good chance gen AI can help you execute it. It’s helpful to think of such code as a first draft. It may not be perfect, but it’s a useful starting point. And it’s a lot easier (not to mention faster) to edit existing code than to generate it from scratch. Handing these base-level tasks off to a capable AI means engineers and developers are free to engage in tasks more befitting of their experience and expertise. 

Event

VB Transform 2023 On-Demand

Did you miss a session from VB Transform 2023? Register to access the on-demand library for all of our featured sessions.

 

Register Now

That being said, gen AI and LLMs create output based on existing content, whether that comes from the open internet or the specific datasets that they have been trained on. That means they are good at iterating on what came before, which can be a boon for attackers. For example, in the same way that AI can create iterations of content using the same set of words, it can create malicious code that is similar to something that already exists, but different enough to evade detection. With this technology, bad actors will generate unique payloads or attacks designed to evade security defenses that are built around known attack signatures.

One way attackers are already doing this is by using AI to develop webshell variants, malicious code used to maintain persistence on compromised servers. Attackers can input the existing webshell into a generative AI tool and ask it to create iterations of the malicious code. These variants can then be used, often in conjunction with a remote code execution vulnerability (RCE), on a compromised server to evade detection. 

LLMs and AI give way to more zero-day vulnerabilities and sophisticated exploits 

Well-financed attackers are also good at reading and scanning source code to identify exploits, but this process is time-intensive and requires a high level of skill. LLMs and generative AI tools can help such attackers, and even those less skilled, discover and carry out sophisticated exploits by analyzing the source code of commonly used open-source projects or by reverse engineering commercial off-the-shelf software.  

In most cases, attackers have tools or plugins written to automate this process. They’re also more likely to use open-source LLMs, as these don’t have the same protection mechanisms in place to prevent this type of malicious behavior and are typically free to use. The result will be an explosion in the number of zero-day hacks and other dangerous exploits, similar to the MOVEit and Log4Shell vulnerabilities that enabled attackers to exfiltrate data from vulnerable organizations. 

Unfortunately, the average organization already has tens or even hundreds of thousands of unresolved vulnerabilities lurking in their code bases. As programmers introduce AI-generated code without scanning it for vulnerabilities, we’ll see this number rise due to poor coding practices. Naturally, nation-state attackers and other advanced groups will be ready to take advantage, and generative AI tools will make it easier for them to do so.  

Cautiously moving forward 

There are no easy solutions to this problem, but there are steps organizations can take to ensure they are using these new tools in a safe and responsible way. One way to do that is to do exactly what attackers are doing: By using AI tools to scan for potential vulnerabilities in their code bases, organizations can identify potentially exploitative aspects of their code and remediate them before attackers can strike. This is particularly important for organizations looking to use gen AI tools and LLMs to assist in code generation. If an AI pulls in open-source code from an existing repository, it’s critical to verify that it isn’t bringing known security vulnerabilities with it. 

The concerns today’s security professionals have regarding the use and proliferation of generative AI and LLMs are very real — a fact underscored by a group of tech leaders recently urging an “AI pause” due to the perceived societal risk. And while these tools have the potential to make engineers and developers significantly more productive, it is essential that today’s organizations approach their use in a carefully considered manner, implementing the necessary safeguards before letting AI off its metaphorical leash. 

Peter Klimek is the director of technology within the Office of the CTO at Imperva.

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers

Credit: Source link

ShareTweetSendSharePin

Related Posts

Xbox Just Unveiled Mythic Achievements, Which Are Basically PlayStation Platinum Trophies
AI & Technology

Xbox Just Unveiled Mythic Achievements, Which Are Basically PlayStation Platinum Trophies

September 29, 2026
OpenAI Launches dots: Always-On GPT-6 Astra Agents That Work From Their Own Cloud Computers
AI & Technology

OpenAI Launches dots: Always-On GPT-6 Astra Agents That Work From Their Own Cloud Computers

September 29, 2026
Dots Are OpenAI’s New Personal Agents And Soon You’ll Be Able To Control Several Of Them
AI & Technology

Dots Are OpenAI’s New Personal Agents And Soon You’ll Be Able To Control Several Of Them

September 29, 2026
Nebius Opens 2026 Physical AI Awards: Five 0K Compute Prizes, Nine Judges, and an October 25 Deadline
AI & Technology

Nebius Opens 2026 Physical AI Awards: Five $150K Compute Prizes, Nine Judges, and an October 25 Deadline

September 29, 2026
Next Post
NJ supermarket owners bringing The Fresh Grocer to Fulton Street Mall

NJ supermarket owners bringing The Fresh Grocer to Fulton Street Mall

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Judge lifts Trump's White House ban on CNN, MS NOW and Politico – Reuters

Judge lifts Trump's White House ban on CNN, MS NOW and Politico – Reuters

September 24, 2026
Village in Nepal hit by massive wave of water

Village in Nepal hit by massive wave of water

September 22, 2026
Meta’s Muse AI agent weighs on financial industry as investors fear competition to human advisors

Meta’s Muse AI agent weighs on financial industry as investors fear competition to human advisors

September 23, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!