arXiv:2508.15808cs.CRcs.AI2025-08被引 2

AI让攻击者更容易,落后企业更危险,必须加快修复速度。

Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations

  • AI降低攻击门槛,使更多攻击者瞄准防御薄弱企业
  • 攻击者能更快发现漏洞,企业需比现在快得多修复
  • 适合资源有限的中小企业和政策制定者参考

人工智能的进步正在重塑网络安全攻防平衡。对于多数缺乏资源的‘落后企业’——依赖老旧系统、安全人力不足、难以及时打补丁——以往因攻击者缺乏经济动机而维持的低防御策略将不再可行。随着AI能力提升,攻击成本下降,攻击频率和覆盖面显著增加;同时,攻击者可更早发现并利用漏洞。这意味着落后企业不能仅追求与当前领先者持平,而必须实现更快的漏洞修复速度和更强的系统韧性。未来攻击数量将急剧上升。本文提出一系列组织与政府层面的应对方案,以增强这类企业的整体防御能力。

原文摘要 · Abstract (English)

Advances in AI are widely understood to have implications for cybersecurity. Articles have emphasized the effect of AI on the cyber offense-defense balance, and commentators can be found arguing either that cyber will privilege attackers or defenders. For defenders, arguments are often made that AI will enable solutions like formal verification of all software--and for some well-equipped companies, this may be true. This conversation, however, does not match the reality for most companies. "Trailing-edge organizations," as we term them, rely heavily on legacy software, poorly staff security roles, and struggle to implement best practices like rapid deployment of security patches. These decisions may be the result of corporate inertia, but may also be the result of a seemingly-rational calculation that attackers may not bother targeting a firm due to lack of economic incentives, and as a result, underinvestment in defense will not be punished. This approach to security may have been sufficient prior to the development of AI systems, but it is unlikely to remain viable in the near future. We argue that continuing improvements in AI's capabilities poses additional risks on two fronts: First, increased usage of AI will alter the economics of the marginal cyberattack and expose these trailing-edge organizations to more attackers, more frequently. Second, AI's advances will enable attackers to develop exploits and launch attacks earlier than they can today--meaning that it is insufficient for these companies to attain parity with today's leading defenders, but must instead aim for faster remediation timelines and more resilient software. The situation today portends a dramatically increased number of attacks in the near future. Moving forward, we offer a range of solutions for both organizations and governments to improve the defensive posture of firms which lag behind their peers today.

网络安全AI攻击企业防御漏洞修复

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。