AI-armed cyber strikes : Fighting fire with fire
IT professionals believe a cyberattack credited to ChatGPT is less than a year away
ChatGPT has answers for almost everything, but there is one answer we may not know for a while: will this tool turn out to be the genie its creators regret taking out of the bottle over unintended consequences in cybersecurity? BlackBerry surveyed 1,500 IT decision-makers across North America, the United Kingdom and Australia, and 51 per cent of respondents predicted we are less than a year away from a cyberattack credited to ChatGPT. Three-quarters of respondents believe foreign states are already using ChatGPT for malicious purposes against other nations.
Artificial Intelligence (AI) is proving a double-edged sword. The emergence of chatbots and AI-powered tools presents new challenges in cybersecurity, especially when this technology ends up in the wrong hands. Rather than outright banning its use, the Ministry of Education of Singapore (MOE) takes an interesting approach, providing teachers with guidance and resources to effectively utilise ChatGPT to enhance learning. Students are taught digital literacy skills and cyber wellness competencies to use technology effectively in their learning.
There are plenty of benefits to using this kind of advanced technology and we are just scratching the surface, but we also cannot ignore the risks. As the platform matures and hackers become more experienced, it will become more difficult to defend without also using AI to level the playing field.
AI-armed cyber threats close the gap in human weaknesses
Today, cyber threats are moving at pace and cybersecurity professionals have a hard time keeping up. In its latest global threat intelligence report, BlackBerry’s Threat Research and Intelligence team identified Singapore as one of the top ten countries experiencing the most cyber attacks. In the 90 days between September 1 and November 30, 2022, the company’s AI cybersecurity software stopped 1,757,248 malware-based cyberattacks, including about 10,300 attacks in Singapore in that period. That comes to around 113 attacks a day, and nearly five attacks an hour.
AI, machine learning, deep learning and generative AI is fast-tracking practical knowledge mining, but the same is true for malware coders, with the ever-evolving cybersecurity industry often likened to a whack-a-mole game where the bad guys just keep popping up. In the past, these bad actors would rely on their own experience, forums, and security researcher blog posts to understand different malicious techniques, and then convert them into code, but programs like ChatGPT have given them another arrow in their quiver to wreak digital havoc.
ChatGPT can respond to a wide range of queries and can even create complex mutable malware targeting open vulnerabilities in the customer’s environment. Generative AI technology leverages vast amounts of telemetry which can be used by hackers to train for a targeted environment and identify patterns and gaps for complex exploitation to create zero-day attacks.
AI can also be used to create convincing phishing emails, text messages, and social media posts to trick people into providing sensitive information or installing malware. Poor language skills have always been a weakness of hackers and ChatGPT can now be used to help bridge this gap and provide more authentic and effective communication. AI-generated deepfake videos can be used to impersonate officials or organisations in phishing attacks. It can be used to launch distributed denial of service (DDoS) attacks, which involve overwhelming an organisation’s systems with traffic to disrupt operations, or be used to gain control over critical infrastructure, causing real world damage.
Fighting fire with fire
BlackBerry’s research reveals that the majority (82 per cent) of IT decision makers plan to invest in AI-driven cybersecurity in the next two years, and almost half (48 per cent) plan to invest before the end of 2023. This reflects the growing concern that signature-based protection solutions are no longer effective in providing cyber protection against an increasingly sophisticated threat. IT decision makers are positive ChatGPT will enhance cybersecurity for business, but our survey also shows 85 per cent of respondents believe governments have a moderate-to-high responsibility to regulate advanced technologies.
The growing use of AI in developing threats makes it even more critical to stay one step ahead by also using AI to proactively fight threats. Organisations need to continue to focus on improving prevention and detection and look at how to include more AI in different threat classification processes and cybersecurity strategies.
One of the key advantages of using AI in cybersecurity is the ability to analyse vast amounts of data in real time. The sheer volume of data generated by modern networks makes it impossible for humans to keep up. AI can process data much faster, making it more efficient at identifying threats.
As cyberattacks become more severe and sophisticated, and threat actors evolve their tactics, techniques, and procedures (TTP), traditional security measures become obsolete. AI can learn from previous attacks and adapt defence techniques, making it more resilient against future threats.
AI can also be used to mitigate highly targeted and often difficult-to-detect ATP (advanced threat protection) and Zero threats before they cause significant damage. Using AI to automate repetitive tasks when it comes to security management also allows cybersecurity professionals to focus more on strategic tasks, such as threat hunting and incident response.
The future of cybersecurity
AI matters more than ever in security now that cybercriminals are using it to up their game. It is becoming increasingly critical that organisations – particularly those supporting critical infrastructure – are equipped to fight AI with AI. However, cybersecurity managers should be alert to many security providers’ claims to use AI or ML, when the application is limited to optimising and automating some aspects of their signature-generation processes as plugins or add-ons. This ultimately falls short of the full promise of AI – especially in this new era of AI-powered cyberattacks.
Both cyber professionals and hackers will continue to investigate how they can best use this technology, and only time will tell who becomes more effective. That is why Singapore’s MOE approach to ChatGPT is commendable – instead of shying away from AI, it is encouraging academia to lean in and nurture today’s young minds to help them get ahead of the technology curve, aiming to arm them with the skills and cyber technology tools to help fight fire with fire.
Shishir Singh is executive vice president and chief technology officer, cybersecurity, at BlackBerry
TRENDING NOW
Fed hike throws Singapore banks a margin lifeline; UOB most likely to feel impact
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
Real-estate veteran Desmond Sim quits from CEO roles at Realion, ETC
Chagee, Mixue and Luckin won the market. Sustaining their edge is the harder part