2 min read

AI makes cyberattacks faster—and defenses must keep up

Georgia Tech researchers say AI is compressing cyberattack timelines from months to hours while also giving defenders new tools to respond.

Image: TechXplore

AI is changing cybersecurity on both sides of the fight. Researchers at Georgia Tech’s School of Cybersecurity and Privacy say the biggest shift is not entirely new kinds of attacks, but the speed and scale AI brings to tactics attackers already use.

“AI is dramatically speeding up cyberattacks,” said Brendan Saltaformaggio, associate professor in the School of Cybersecurity and Privacy and the School of Electrical and Computer Engineering. He said AI can find vulnerabilities much faster than people can, including in places humans might not think to check.

Most attacks still follow familiar stages: finding weaknesses, building exploits, getting into systems, and then stealing data or disrupting operations. According to Frank Li, associate professor in the same schools, AI is having its biggest effect early in that chain by helping attackers identify software bugs and craft social engineering lures more quickly.

Peter Swire, J.Z. Liang Chair in the school and professor of law and ethics in the Scheller College of Business, said the window between discovering a vulnerability and seeing it exploited has shrunk sharply.

Recommended reading

OpenAI says test agent escaped and hacked Hugging Face

“The average time until an exploit was detected, even a couple of years ago, was measured in months. Now it is measured in hours.”

Peter Swire

That compression is especially dangerous for organizations running legacy systems or operating with limited security resources. The researchers said health care systems, critical infrastructure providers, government agencies, and small businesses are all attractive targets, but no sector is exempt.

On defense, the same technology can help teams move faster too. Researchers said AI can be used to:

  • identify and patch vulnerabilities faster
  • spot subtle signs of intrusion across networks
  • analyze how a compromise happened
  • support targeted response after an attack

Saltaformaggio said AI can help defenders at every stage of stopping an attack. He pointed to Georgia Tech’s showing in DARPA’s Artificial Intelligence Cyber Challenge as evidence that AI systems can autonomously discover and reason about software vulnerabilities at scale. Swire also said a Georgia Tech team led by Professor Taesoo Kim won a $4 million DARPA prize for advanced AI-based cybersecurity defenses.

The researchers cautioned that AI security tools still need to be trustworthy and explainable, and that attackers may try to manipulate those systems as well. Li said organizations can no longer rely on human-paced processes alone, while Swire argued that patch management itself must be re-engineered for a world where exploits can appear within hours.

The advantage, they said, will go to organizations that adopt AI-driven defenses as quickly as attackers adopt AI-driven offense.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechXplore

// Keep reading