Cyber IT Supervisory Forum eBook

Internal Use Only

Risks From AI-Augmented Cyber Attacks  How can AI be used to help cyber criminals/nation states? ‒ Vulnerability discovery

‒ Social engineering ‒ Malware creation

 AI impact on current cyber risks is low-moderate ‒ Bad guys may be more efficient but overall approach is similar [3] [4] ‒ AI’s impact may increase over time but unlikely to fundamentally alter the offense defense dynamic (probably…)

9

© 2024 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-01698-01.

Internal Use Only

AI Use for Cyber Defense—A Game Changer?

 AI/ML is commonly used in cyber products/services [5] ‒ Rule-based AI has been used for cybersecurity since the 1980s ‒ More recently, ML and generative AI have played a larger role:

 Synthesizing data into actionable recommendations.  Creating human-readable reports and presentations.  Answering questions about an incident or vulnerability.

 Does it help? Yes, but with limitations [6] ‒ Lack of contextual awareness ‒ Complexity and limited transparency ‒ Vulnerability to adversary attacks

10

© 2024 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-01698-01.

Made with FlippingBook Digital Publishing Software