AI正被用于模拟黑客攻击,提升攻防演练效率。
Red Teaming with Artificial Intelligence-Driven Cyberattacks: A Scoping Review
- 用系统性综述方法分析11篇论文,梳理AI攻击手段
- 发现AI可自动渗透系统、窃取密码与社交媒体数据
- 适合安全研究人员和红队人员了解前沿攻击趋势
人工智能(AI)的发展使复杂网络攻击和红队活动成为可能。这些基于AI的攻击可自动化渗透目标系统或收集敏感信息,并加速攻击执行过程。本文通过范围综述方法,分析文献以识别红队可用于模拟网络犯罪的典型攻击方法、目标与模型。从470条记录中筛选出11篇纳入分析。研究发现多种攻击方式,针对敏感数据、系统、社交媒体账号、密码及网址等目标。AI在开发多样化攻击模型方面的应用正构成日益严峻的威胁。同时,基于AI的红队技术也为应对此类风险提供了新途径。
原文摘要 · Abstract (English)
The progress of artificial intelligence (AI) has made sophisticated methods available for cyberattacks and red team activities. These AI attacks can automate the process of penetrating a target or collecting sensitive data. The new methods can also accelerate the execution of the attacks. This review article examines the use of AI technologies in cybersecurity attacks. It also tries to describe typical targets for such attacks. We employed a scoping review methodology to analyze articles and identify AI methods, targets, and models that red teams can utilize to simulate cybercrime. From the 470 records screened, 11 were included in the review. Various cyberattack methods were identified, targeting sensitive data, systems, social media profiles, passwords, and URLs. The application of AI in cybercrime to develop versatile attack models presents an increasing threat. Furthermore, AI-based techniques in red team use can provide new ways to address these issues.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。