By Vince Mazza, Guest columnist
Artificial Intelligence (AI) is quickly becoming mainstream in our lives, as its uses and applications continue to evolve. In the business world, AI can be used to write letters, announcements, marketing materials, and reports. It can analyze data of past performance and current economic indicators to help sales teams predict future trends. AI can assist across virtually every department of a company, with users observing that it saves them time and improves processes. Despite the many advantages to using AI, though, it’s essential for us all to approach this new technology with a degree of caution. And that in particular applies to issues of cybersecurity and AI.
You might say that AI is a double-edged sword when it comes to cybersecurity. It has the capability of offering strong defenses against outside cyber threats, while also being capable of introducing new vulnerabilities to a company’s infrastructure when in the wrong hands.
How can both be true? In this article, we’ll examine how AI functions, how it can both cause and prevent cyber attacks, and what you should know about using AI wisely.
QUICK ARTICLE LINKS
What is AI? How does it work?
How AI can be used to cause cyber attacks
Using AI to fight AI-enhanced cyber-attacks
Tips for using AI safely
Going Forward
AI is a rapidly evolving technology which simulates human intelligence by using machines, especially computer systems. AI has a wide range of cognitive functions that we associate with the human mind, from the simple to the complex. Part of how AI works is through “machine learning,” which allows systems automatically to identify features, classify information, find patterns in data, make determinations and predictions, and uncover insights. AI uses algorithms to create machine learning models that continuously train the systems to increase its accuracy.
It’s important to note that AI performs based on the data that it uses. So, if faulty or fraudulent data goes into the algorithm, then AI might reach incorrect assumptions or be used for fraudulent purposes. The concept of AI has been with us for about ten years, although it’s really the last few years that it has come into prominence. One way to think of AI is as something capable of containing all of documented humanity encapsulated in the mind of a 10-year old, who is making decisions based upon that data.
If that “ten year old” has been exposed to the good role models, the outcome will be far superior to the situation, compared to the ten year old has been exposed to bad role models, like cyber criminals.
Unfortunately, cyber criminals have the same access to AI that everyone else does. And they can use AI to build their attack strategies with a significantly higher chance of a successful breach or attack.
There are two AI models used: Traditional AI as well as Generative AI.
Traditional AI solves specific tasks with predefined rules. Generative AI focuses on creating new content and data. This is an important distinction.
Generative AI uses deep–learning models which take raw data (such as all of Wikipedia) and from it learn to generate statistically probably outputs when promoted to do so. Generative AI uses unsupervised learning, whereas Traditional AI often employs supervised learning and discriminative models. To highlight the difference, think again of the analogy of the 10-year old. For how long would you leave a 10-year old unsupervised?
Generative AI is quite dangerous in the wrong hands and can be used in cyber-attacks such as phishing, SMS, and other social engineering operations.
Imagine phishing and smishing messages with highly convincing content that can mimic the language, tone and design of legitimate emails. AI can eliminate awkward diction, misspellings, grammatical errors and sloppy graphics that had previously made it easier to detect malicious messages.
With these AI advantages, hackers can make emails look more legitimate. AI can also impersonate people, such as bosses, with a vernacular that is virtually intact. The precision capability with Generative AI is something that the world has never previously seen.
This AI technology is sophisticated enough to fool people by expanding its reach to include a person’s hobbies, other contacts or events in their lives. This technology allows the “deep fake” voice of a boss, or even references to news stations that the intended victim watches.
One of the more frightening components of all of this is how AI can be used in malware. Generative AI uses machine learning to learn the environment. Malware can adapt to security measures and even automate the extraction of valuable data from compromised systems. And the AI continues to learn during an attack. It changes to find the most effective attack.
And with all of that said, AI additionally makes these techniques more affordable to the less skilled attackers.
We’ve seen how AI can be used by cyber criminals to deploy more successful attacks. But that is not the entire story. It is important to know, also, that AI can be used to fight cyber attacks, when the technology is in the right hands.
When fighting AI-enhanced cyber threats, you don’t want to “bring a knife to a gun fight.” The best way to fight against AI is by using AI.
Here are a few ways that AI can be used to thwart the actions of cyber criminals:
Tips for using AI safely
Knowing that AI can be used by cyber criminals to advance their purposes, but also knowing that AI in the right hands can be an effective tool in thwarting attacks, it makes sense to look at a few ways that we can use AI safely.
Acknowledging that AI is an evolving technology that can be used for both good and criminal purposes, it’s important to know as much as you can about how it works. For the business owner who wants to concentrate on running his/her business, it makes sense to partner with a Managed Services Provider (MSP) and a cybersecurity company who can guide your efforts and keep your network protected. Let the experts give you that competitive advantage that your business needs.
Vince Mazza is co-founder and Chief Executive Officer of Guard Street Partners, LLC (Guard Street), a national cybersecurity company based in Wheaton, IL. His experience in property protection, data privacy and cybersecurity includes time as President and CEO of MH Equity Services LLC and VP at General Electric. He hosts the Guard Street Cybersecurity radio show/webcast and is viewed as a national leader in the field of cybersecurity.