Artificial intelligence might be getting ever more sophisticated, but when it comes to security, cybercriminals are using AI to exploit the most basic of flaws in enterprise infrastructure.
According to IBM’s latest X-Force Threat Intelligence Index, exploiting vulnerabilities is now the biggest route of attacks against enterprises’ IT infrastructure, accounting for around four in ten security incidents last year – and cybercriminals are using AI to help them find and take advantage of such flaws.
But AI isn’t a brave new world for cybercriminals. Rather than dreaming up new routes of attack using artificial intelligence, they’re simply using it to automate the same old tactics.
“Itโs important to acknowledge AI has not changed the fundamentals of cyberattack campaigns,” states the report. “Attackers still rely on unpatched vulnerabilities, valid credentials and misconfigurations to accomplish their goals. What AI has changed is the speed, scale and efficiency of these attacks, which serve to make rapid detection and decisive response more important than ever.”
IBM X-Force Threat Intelligence Index details
AI might not have given criminals new ways to attack systems, but it has allowed them to refine and accelerate what they’re already doing. For example, making social engineering efforts seem more realistic and therefore more likely to fool targets. Or analysing different variants of attacks to identify what makes them successful and hone future campaigns accordingly.
Of all the attacks that IBM detected last year, over 15% involved exploring incorrectly configured access control security levels, more than 12% scanned for vulnerabilities, and a further 12% saw attackers brute-forcing passwords.
Worryingly, over half of the vulnerabilities that IBM tracked didn’t require any authentication for an attacker to exploit, “highlighting the critical need for stronger access controls, rigorous patching and secure deployment practices,” the report noted.
And much as cybercriminals are using tried-and-tested techniques, companies should be relying on well-established protocols to defeat them.
The fight back
“Organizations continue to face security incidents not due to sophisticated adversary techniques, but because foundational security controls are often inconsistently implemented or poorly maintained,” the report added. In other words, preventing attacks still requires companies to take care of their security basics.
For those hoping AI might allow the enterprises to find new ways to keep one step ahead of their would-be attackers, the oncoming AI security arms race would seem to favour the cybercriminals.
After all, they aren’t bound by the same governance and accountability, protocols and guidelines that organisations are, “potentially allowing them to adopt and operationalize new capabilities faster than most enterprises”, IBM noted.
“As a result, defensive use of AI does not automatically provide an advantage. Without high-quality data, mature processes and clear integration into security operations, AI-driven defenses can struggle to keep pace with adversaries who can rapidly test, discard and refine techniques without oversight.”