Opens in a new tab
vmblog logo 2024 wht (updated)

Using LLMs to counter the new cybersecurity arms race

Share: 

David Marshall | Published: September 13, 2023

By Rodrigo Brito, Head of Business Line, Cybersecurity at Nokia

OpenAI’s ChatGPT has wowed much of the world with its ability to process a massive amount of text and data from the internet and rapidly churn out everything from essays and song lyrics to software code – all at an industrial scale.

But the Large Language Model (LLM) that powers ChatGPT has also set off alarm bells in the security world over how this technology can enable cybercriminals.

For example, LLMs can greatly expand the attack surface, giving cybercriminals the ability to autogenerate malware code and launch multi-stage attacks. Rudimentary cyberattacks, such as phishing or dictionary attacks, can be deployed with little effort.

Using LLMs as their fuel, a set of bad actors, with some technical skill, can more easily guess passwords or write a targeted phishing email by simply scanning social media posts on a mass scale. Or, such actors, with even more technical skill, can train LLMs to infiltrate and exploit intricate layers of critical infrastructures with the knowledge they gather from the internet.

Yet, as unnerving as such scenarios are, LLMs – as with so many technologies – can be harnessed in beneficial ways to counter the very threats that they give rise to; and doing so responsibly, with ethical considerations and data privacy in mind.

For example, LLMs can augment how Security Operations Center (SOC) analysts operate. While LLMs cannot replace human analysts, the AI model filters out the noise and presents contextual and meaningful information to help analysts make logical decisions much faster than preexisting technologies. However, security experts remain cautious and vigilant of the dark side that LLMs can unleash.

A big advantage LLMs bring to cybersecurity and many other industries is efficiency. With impressive capabilities to process all kinds of data (from security standards and architectural specifications to informal conversations on the internet), and with proper training, an LLM can accelerate threat detection and reduce response times. In addition, it can spot things like zero-day attacks (in which a vulnerability unknown to developers can be exploited by threat actors); create new mitigation workflows; and support cybersecurity forensics.

Employing LLMs for the greater good

In the right hands, LLMs can assist with cybersecurity operations, but security vendors cannot simply plug it into legacy tools and expect cyber peace. Cybersecurity researchers are carefully developing and testing the foundational model while they continue to advance new and existing security. By combining real-world attack scenarios and threat intelligence with AI technology, LLMs are being trained to detect network data breaches, uncover hidden connections and eventually recognize vulnerabilities in advance of a cyberattack.

Tapping LLMs’ ability to process vast datasets in milliseconds, security operators can rapidly identify incoming threats and mitigate vulnerabilities; improve response times and accuracy; perform diverse audits; and aid with regulatory and reporting requirements.

Who reaps the benefits?

Communication service providers and enterprises are constantly striving to optimize day-to-day security operations and uphold the security posture for their customers. By integrating LLM technology into security products, SOC analysts and threat-hunting teams are the first wave of users to reap the benefits of a reliable AI assistant.

Traditional methods of sifting through data to mitigate threats are resource-intensive and time-consuming. LLMs, powered by their capacity to comprehend diverse, unstructured data, offer a practical alternative. By asking natural-language questions, an LLM AI assistant can help navigate complex challenges, supply valuable data, put an incident into context and empower analysts to make informed, data-driven decisions during high-pressure situations.

Other users that will benefit from harnessing LLMs include CISOs, auditors, regulatory compliance officers and executives who must measure security reports against a diverse set of requirements, often in time-sensitive situations.

Interacting with an LLM-powered cybersecurity assistant can go something like this:

  • Prepare. Begin by asking the LLM to pinpoint the latest high-priority incidents. Keep in mind that you can consciously trigger hallucinations to filter out irrelevant or nonsense data to better understand how an incident relates to any other reported ones, and whether anyone has worked on similar incidents.
  • Understand. Seek to understand which critical services are affected by requesting the alert history and MITRE mapping reports. From there, uncover perimeter defenses (firewalls), internal users involved and whether there’s a data exfiltration concern, before eliciting suggested responses.
  • Respond. Ask for the success rate of a particular response. Request the workflow for that response, whether approvals are needed and if downtime is necessary.
  • Resolve. Execute the response. If the response fails or approvals are denied, ask for the reason.
  • Report. Lastly, automatically generate an incident report and email it to a supervisor with comments on resolving the incident.

Are cybersecurity AI assistants the future?

The answer is yes. Hackers will further exploit capabilities for malicious gain as LLM technology matures and as bad actors refine how they can nefariously use the technology to their advantage. Security vendors must accelerate the capabilities of their products and prepare for the emerging influx of threats.

Pairing LLMs with human security expertise can level the playing field. LLMs can be employed to strengthen code quality and consistency, speed of delivery and rapidly adapt to the ever-advancing threat landscape. In time, the foundational model will become more sophisticated, and with proper training, it has the potential to self-learn, extrapolate emerging trends and forecast behavior.

##

ABOUT THE AUTHOR

Rodrigo Brito – Head of Business Line, Cybersecurity at Nokia

Rodrigo-Brito 

As Head of the Cybersecurity Business at Nokia, Rodrigo builds breakthrough products that stay ahead of emerging security threats and safeguards Communication Service Provider networks, making 5G ecosystems safer places to operate.