Unlocking AI to strengthen cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The paradox of cybersecurity is that to defend ourselves, we need to know how attackers operate, reproduce their techniques, and examine vulnerabilities before they are exploited.

But the same tools that help detect and correct a weakness can also be used to exploit it.

Artificial intelligence has enhanced this situation. An advanced model has the capacity to be our best ally, analyze millions of lines of code, detect anomalous patterns, and propose patches in a matter of minutes. In the hands of an attacker, it can automate target recognition, facilitate social engineering campaigns, or reduce the knowledge needed to program malware.

Open source cybersecurity initiative

In this context, the company NVIDIA has launched an open-source cybersecurity initiative, the Open Secure AI Alliance, together with dozens of tech companies, cybersecurity firms, and organizations linked to open software.

Its purpose is to develop and share models, tools, data, and techniques to strengthen and improve current software, based on artificial intelligence agents.

The initiative raises an ethical, but also technical and operational dilemma: should the most advanced cyber defense capabilities be made available to the community?

The Alliance believes so, in the conviction that those who defend us from cyber threats need open tools that can be continuously improved and run on their own infrastructures.

The advantages of open models

The recent incident suffered by Hugging Face demonstrated that the closed tools initially used to investigate the attack did not function optimally because at certain times they did not adequately distinguish between the attacker’s activity and legitimate defensive actions.

According to them, the company then resorted to an open model run on its own infrastructure to help contain the intrusion.

Open models present evident advantages: they facilitate independent auditing, reduce dependency on a single provider, allow models to be adapted to specific languages, sectors, and threats, and promote technological sovereignty.

They also allow responding to a recurring demand, by putting advanced capabilities within reach of administrations, small businesses, universities, and response teams that do not have the resources of large corporations.

But it would be naive to argue that all openness automatically produces more security.

Indeed, publishing a powerful model, a dataset, or a vulnerability discovery tool can simultaneously benefit defenders and attackers.

The issue is not to choose between openness and security as if they were incompatible concepts, but to determine what should be opened, when, for whom, and under what conditions.

‘Open’ does not mean ‘ungoverned’

The new alliance must demonstrate that, also regarding AI-based cybersecurity, “open” does not mean “ungoverned.” On the contrary, it will need evaluation procedures before releasing capabilities, coordinate vulnerability disclosures, perform agent controls, maintain activity logs, manage identities and permissions, design isolated test environments, and execute quick correction mechanisms.

The experience with Akrites, an initiative led by the Linux Foundation, can be inspiring. But it is also an opportunity to highlight and value the role of CSIRTs in the field of defensive AI, whose actions find some legal protection. As is known, these organizations start from the premise that finding a vulnerability is not enough. It must be verified, reported to the responsible party, a solution developed, and ensured that it reaches the affected systems before being exploited.

Data governance

Data governance in AI cybersecurity will be equally decisive, as part of the information used may contain personal data, trade secrets, or details about critical infrastructures. In this line, it should not be forgotten that sharing threat intelligence also requires applying principles of minimization, access control, quality, traceability, and purpose limitation in processing.

Public authorities must also avoid two mistakes already made in the past. The first would be to consider that open models are, by definition, a threat and to subject them to general restrictions that ultimately weaken defenders and concentrate technological capacity in a few companies.

The second would consist of blindly trusting in the self-regulation of an alliance largely made up of actors with significant commercial interests.

The Open Secure AI Alliance can succeed because it is based on the idea that against increasingly automated attacks, unity makes strength.

But, in essence, its success will be measured by its ability to build an ecosystem in which openness increases transparency, strengthens reaction means against cyberattacks, and accelerates the solution of vulnerabilities without weakening the defensive capabilities of organizations.

And indeed, in the realm of cybersecurity, keeping part of our defenses hidden does not alone guarantee the effectiveness of protection. But openness, by itself, neither. Security will arise from combining shared knowledge, responsibility, and rules that allow us to advance quickly in a world where AI has multiplied the impact of cyber threats.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW