版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)
文檔簡介
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
Thenear-termimpactofAIonthecyberthreat
AnNCSCassessmentfocusingonhowAIwillimpacttheefficacyofcyber
operationsandtheimplicationsforthecyberthreatoverthenexttwoyears.
UKCyberPolicycomment
DuringtheBletchleyAISafetySummitinNovember2023,internationalleaderscame
togethertodiscussthevastpotentialofAImodelsinpromotingeconomicgrowth,
propellingscientificadvances,andprovidingawiderangeofpublicbenefits.TheyalsounderscoredthesecurityrisksthatcouldarisefromtheirresponsibledevelopmentanduseofAItechnologies.TheUKgovernmentisevaluatingandaddressingthepotentialthreatsandrisksassociatedwithAI.
WhileitisessentialtofocusontherisksposedbyAI,wemustalsoseizethesubstantialopportunitiesitpresentstocyberdefenders.Forexample,AIcanimprovethedetectionandtriageofcyberattacksandidentifymaliciousemailsandphishingcampaigns,
ultimatelymakingthemeasiertocounteract.
TheSummitDeclarationhighlightedtheimportanceofensuringthatAIisdesigned,
developed,deployed,andusedinamannerthatissafe,human-centric,trustworthy,andresponsibleforthebenefitofall.TheNCSCcontinuestoworkwithinternationalpartnersandindustrytoprovideguidanceonthesecuredevelopmentanduseofAI,sothatwe
canrealisethebenefitsthatAIofferstosociety,publishing
GuidelinesforSecureAI
SystemDevelopment
inNovember2023.
NCSCAssessment
NCSCAssessment(NCSC-A)istheauthoritativevoiceonthecyberthreattotheUK.Wefuseall-sourceinformation–classifiedintelligence,industryknowledge,academicmaterialandopensource–toprovideindependentkeyjudgementsthatinformpolicydecisionmakingandimproveUKcybersecurity.Wework
closelywithgovernment,industryandinternationalpartnersforexpertinputintoourassessments.
.uk/report/impact-of-ai-on-cyber-threat
1/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
NCSC-AispartoftheProfessionalHeadsofIntelligenceAssessment(PHIA).PHIA
leadsthedevelopmentoftheprofessionthroughanalyticaltradecraft,professionalstandards,andbuildingandsustainingacross-governmentcommunity.
Thisreportusesformalprobabilisticlanguage(seeyardstick)fromNCSC-A
producttoinformreadersaboutthenear-termimpactonthecyberthreatfromAI.TolearnmoreaboutNCSC-A,pleasecontact
enquiries@.uk
.
Howlikelyisa'realisticpossibility'?
ProfessionalHeadofIntelligenceAssessment(PHIA)probabilityyardstick
NCSCAssessmentusesthePHIAprobabilityyardstickeverytimewemakeanassessment,judgement,orprediction.Thetermsusedcorrespondtothe
likelihoodrangesbelow:
Keyjudgements
·Artificialintelligence(AI)willalmostcertainlyincreasethevolumeandheightentheimpactofcyberattacksoverthenexttwoyears.However,theimpactonthecyberthreatwillbeuneven(
seetable1
).
.uk/report/impact-of-ai-on-cyber-threat
2/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
·Thethreatto2025comesfromevolutionandenhancementofexistingtactics,techniquesandprocedures(TTPs).
·Alltypesofcyberthreatactor–stateandnon-state,skilledandlessskilled
–arealreadyusingAI,tovaryingdegrees.
·AIprovidescapabilityupliftinreconnaissanceandsocialengineering,
almostcertainlymakingbothmoreeffective,efficient,andhardertodetect.
·MoresophisticatedusesofAIincyberoperationsarehighlylikelytobe
restrictedtothreatactorswithaccesstoqualitytrainingdata,significantexpertise(inbothAIandcyber),andresources.Moreadvancedusesareunlikelytoberealisedbefore2025.
·AIwillalmostcertainlymakecyberattacksagainsttheUKmoreimpactful
becausethreatactorswillbeabletoanalyseexfiltrateddatafasterandmoreeffectively,anduseittotrainAImodels.
·AIlowersthebarrierfornovicecybercriminals,hackers-for-hireand
hacktiviststocarryouteffectiveaccessandinformationgathering
operations.Thisenhancedaccesswilllikelycontributetotheglobalransomwarethreatoverthenexttwoyears.
·Movingtowards2025andbeyond,commoditisationofAI-enabledcapabilityincriminalandcommercialmarketswillalmostcertainlymakeimproved
capabilityavailabletocybercrimeandstateactors.
Context
ThisassessmentfocusesonhowAIwillimpacttheeffectivenessofcyber
operationsandtheimplicationsforthecyberthreatoverthenexttwoyears.It
doesnotaddressthecybersecuritythreattoAItools,northecybersecurityrisksofincorporatingthemintosystemarchitecture.
TheassessmentassumesnosignificantbreakthroughintransformativeAIinthistimeperiod.Thisassumptionshouldbekeptunderreview,asanybreakthrough
couldhavesignificantimplicationsformalwareandzero-dayexploitdevelopmentandthereforethecyberthreat.
.uk/report/impact-of-ai-on-cyber-threat
3/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
TheimpactofAIonthecyberthreatwillbeoffsetbytheuseofAItoenhance
cybersecurityresiliencethroughdetectionandimprovedsecuritybydesign.
MoreworkisrequiredtounderstandtheextenttowhichAIdevelopmentsincybersecuritywilllimitthethreatimpact.
Assessment
1.TheimpactofAIonthecyberthreatisuneven;bothintermsofitsusebycyberthreatactorsandintermsofupliftincapability.
2.Table1:ExtentofcapabilityupliftcausedbyAIovernexttwoyears.
.uk/report/impact-of-ai-on-cyber-threat
4/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
Highlycapable
statethreatactors
Capablestateactors,commercialcompaniessellingtostates,
organisedcybercrime
groups
Less-skilledhackers-for-hire,opportunisticcybercriminals,
hacktivists
Intent
High
High
Opportunistic
Capability
HighlyskilledinAIandcyber,wellresourced
Skilledincyber,someresourceconstraints
Novicecyberskills,limitedresource
Reconnaissance
Moderateuplift
Moderateuplift
Uplift
Social
engineering,phishing,
passwords
Uplift
Uplift
Significantuplift(fromlowbase)
Tools(malware,exploits)
Realisticpossibilityofuplift
Minimaluplift
Moderateuplift(fromlowbase)
Lateralmovement
Minimaluplift
Minimaluplift
Nouplift
Exfiltration
Uplift
Uplift
Uplift
Implications
Bestplacedto
harnessAI'spotentialinadvancedcyber
operationsagainst
networks,forexampleuseinadvanced
malwaregeneration.
Mostcapabilityupliftinreconnaissance,socialengineeringand
exfiltration.WillproliferateAI-enabledtoolstonovicecyberactors.
Lowerbarriertoentrytoeffectiveandscalableaccessoperations-
increasingvolumeof
successfulcompromise
ofdevicesandaccounts.
KEY:MINIMALUPLIFT囚MODERATEUPLIFT囚UPLIFT囚SIGNIFICANTUPLIFT
3.AIwillprimarilyofferthreatactorscapabilityupliftinsocialengineering.
GenerativeAI(GenAI)canalreadybeusedtoenableconvincinginteractionwithvictims,includingthecreationofluredocuments,withoutthe
translation,spellingandgrammaticalmistakesthatoftenrevealphishing.Thiswillhighlylikelyincreaseoverthenexttwoyearsasmodelsevolveanduptakeincreases.
.uk/report/impact-of-ai-on-cyber-threat
5/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
4.AI’sabilitytosummarisedataatpacewillalsohighlylikelyenablethreatactorstoidentifyhigh-valueassetsforexaminationandexfiltration,
enhancingthevalueandimpactofcyberattacksoverthenexttwoyears.
5.Threatactors,includingransomwareactors,arealreadyusingAItoincreasetheefficiencyandeffectivenessofaspectsofcyberoperations,suchas
reconnaissance,phishingandcoding.Thistrendwillalmostcertainly
continueto2025andbeyond.Phishing,typicallyaimedeitheratdelivering
malwareorstealingpasswordinformation,playsanimportantrolein
providingtheinitialnetworkaccessesthatcybercriminalsneedtocarryoutransomwareattacksorothercybercrime.Itisthereforelikelythatcyber
criminaluseofavailableAImodelstoimproveaccesswillcontributetotheglobalransomwarethreatinthenearterm.
6.AIislikelytoassistwithmalwareandexploitdevelopment,vulnerability
researchandlateralmovementbymakingexistingtechniquesmore
efficient.However,inthenearterm,theseareaswillcontinuetorelyon
humanexpertise,meaningthatanylimitedupliftwillhighlylikelyberestrictedtoexistingthreatactorsthatarealreadycapable.AIhasthepotentialto
generatemalwarethatcouldevadedetectionbycurrentsecurityfilters,butonlyifitistrainedonqualityexploitdata.Thereisarealisticpossibilitythat
highlycapablestateshaverepositoriesofmalwarethatarelargeenoughtoeffectivelytrainanAImodelforthispurpose.
7.Cyberresiliencechallengeswillbecomemoreacuteasthetechnology
develops.To2025,GenAIandlargelanguagemodels(LLMs)willmakeit
difficultforeveryone,regardlessoftheirlevelofcybersecurity
understanding,toassesswhetheranemailorpasswordresetrequestis
genuine,ortoidentifyphishing,spoofingorsocialengineeringattempts.Thetimebetweenreleaseofsecurityupdatestofixnewlyidentified
vulnerabilitiesandthreatactorsexploitingunpatchedsoftwareisalreadyreducing.Thishasexacerbatedthechallengefornetworkmanagersto
patchknownvulnerabilitiesbeforetheycanbeexploited.AIishighlylikelytoacceleratethischallengeasreconnaissancetoidentifyvulnerabledevicesbecomesquickerandmoreprecise.
8.Expertise,equipment,timeandfinancialresourcingarecurrentlycrucialtoharnessmoreadvancedusesofAIincyberoperations.Onlythosewho
.uk/report/impact-of-ai-on-cyber-threat
6/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
investinAI,havetheresourcesandexpertise,andhaveaccesstoqualitydatawillbenefitfromitsuseinsophisticatedcyberattacksto2025.Highlycapablestateactorsarealmostcertainlybestplacedamongstcyber
threatactorstoharnessthepotentialofAIinadvancedcyberoperations.Otherstateactorsandmostcommercialcompaniesthatoffercapabilitytostatesworldwidewillgainmoderatecapabilityupliftoverthenext
eighteenmonthsinsocialengineering,reconnaissanceandexfiltration.Capableandestablishedcriminalgroupsarealsolikelytohaveenoughtrainingdataandresourcetogainsomeuplift.
9.However,itisarealisticpossibilitythatthesefactorsmaybecomeless
importantovertime,asmoresophisticatedAImodelsproliferateand
uptakeincreases.PubliclyavailableAImodelsalreadylargelyremovethe
needforactorstocreatetheirownreplicatechnologies,especiallyinlow-sophisticationoperationssuchasspear-phishing.Less-skilledcyberactorswillalmostcertainlybenefitfromsignificantcapabilityupliftsinthistypeofoperationto2025.Commoditisationofcybercrimecapability,forexample‘a(chǎn)s-a-service’businessmodels,makesitalmostcertainthatcapable
groupswillmonetiseAI-enabledcybertools,makingimprovedcapabilityavailabletoanyonewillingtopay.
10.To2025,trainingAIonqualitydatawillremaincrucialforitseffectiveuseincyberoperations.Thescalingbarriersforautomatedreconnaissanceof
targets,socialengineeringandmalwareareallprimarilyrelatedtodata.Butto2025andbeyond,assuccessfulexfiltrationsoccur,thedatafeedingAIwillalmostcertainlyimprove,enablingfaster,moreprecisecyberoperations.
11.Increasesinthevolumeandheightenedcomplexityandimpactofcyber
operationswillindicatethatthreatactorshavebeenabletoeffectively
harnessAI.ThiswillhighlylikelyintensifyUKcyberresiliencechallengesintheneartermforUKgovernmentandtheprivatesector.
Glossary
Artificialintelligence
.uk/report/impact-of-ai-on-cyber-threat
7/8
3/4/24,11:35AMThenear-termimpactofAIonthecyberthreat-NCSC.GOV.UK
Computersystemswhichcanperformtasksusuallyrequiringhumanintelligence.Thiscouldin
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 2024-2030年中國孕婦裝市場競爭狀況及投資趨勢分析報告
- 2024-2030年中國多腔高速半自動吹瓶機資金申請報告
- 2024-2030年中國啤酒行業(yè)發(fā)展規(guī)模及前景趨勢分析報告
- 2024-2030年中國廂式貨車行業(yè)市場發(fā)展格局及未來投資潛力分析報告
- 2024-2030年中國卸妝產(chǎn)品市場營銷模式及發(fā)展競爭力分析報告版
- 2024年版摩托車銷售合同3篇
- 2024年度環(huán)保型砂石生產(chǎn)設(shè)備采購合同協(xié)議2篇
- 2021-2022學(xué)年河南省澠池高級中學(xué)高一月考數(shù)學(xué)試卷
- 2025年哈爾濱貨運從業(yè)資格證模擬考試0題b2b
- 2025年鶴壁道路貨運從業(yè)資格證考試
- 海洋平臺深水管道高效保溫技術(shù)
- 《新疆大學(xué)版學(xué)術(shù)期刊目錄》(人文社科)
- 充電樁維保投標(biāo)方案
- 《如何寫文獻綜述》課件
- 肛瘺LIFT術(shù)式介紹
- 通過《古文觀止》選讀了解古代文學(xué)的社會功能與價值
- 語言本能:人類語言進化的奧秘
- 職業(yè)生涯規(guī)劃(圖文)課件
- 2024版國開電大??啤禘XCEL在財務(wù)中的應(yīng)用》在線形考(形考作業(yè)一至四)試題及答案
- 能源管理系統(tǒng)平臺軟件數(shù)據(jù)庫設(shè)計說明書
- 中外園林史第七章-中國近現(xiàn)代園林發(fā)展
評論
0/150
提交評論