AI Plus Smaller Vulnerabilities Equals Bigger Threats?

It is common knowledge to prioritize cybersecurity. Whether it is for your personal computer or work for your organization, keeping your devices safe from unwelcomed parties is critical.

With that said, a new factor can bring more harm than good. As much as AI is viewed for its perks and efficiency, the problem with AI is that it can lead to smaller vulnerabilities in the system becoming a bigger threat.

The Bigger Picture

TuxCare CEO Igor Seletskiy states that AI models are beginning to identify chains involving multiple low and medium severity vulnerabilities that human researchers would rarely connect. At an individual rate, these particular flaws might not warrant urgent action. However, if they are combined, they can lead to a complete system compromise.

Seletskiy states that the future risk is not necessarily an increase in high-severity issues, but rather that Ai has the ability to create higher scale vulnerabilities.

Basically, every open flaw can be linked with another, and a chain can grow exponentially.

Interestingly, Seletskiy states that Common Vulnerabilities and Exposures (CVEs) scoring might need to become more contextual. He suggested that experts should stop measuring incoming vulnerabilities and start measuring their own exposure and remediation throughput.

What Should be Tracked?

So, what should we do instead of relying on isolated CVE scores? Seletskiy recommends that the follow metrics are tracked and recorded instead:

  1. Time frame of when the vulnerability was discovered to when it was patched– Keeping track of a time frame and how fast a particular software works can help you understand what is the best action to do
  2. Backlogging size- Understand the number of open vulnerabilities as well as how fast they can grow and cause damage.
  3. Backlogging age-See how long the flaws sit open. A chain only needs a few links already in the system to start its work
  4. Stop treating “not reachable” as “safe”– A flaw is a flaw, no matter how small it appears.

Minor Flaws That Lead to a Major Breach

No matter how small the flaw appears, postponing fixing the issue can still lead to dire consequences. The longer we put off updating our system, the more likely hackers can find an open window to sneak into the system.

Some examples of “minor” issues include low-severity info leaks, medium-impact access-control or server-side request forgery (SSRF) gaps, and memory-corruption bugs in the system.

Individually, these kinds of flaws are things that IT teams routinely postpone updates or fixing up. However, if the flaws link together, the chances of a hacker infiltrating the system increase. Just putting off a simple system update could leave an open window for hackers.

What Can We Do?

Seletskiy states that one seemingly logical solution cannot work alone. However, trying to pre-chain is a common trap, and it can tip the scales to attackers.

The most effective action to take requires rethinking how your software is built and how you maintain it. Rather than using a defensive AI, you should try predicting how a chain can play out, and reduce the number of things that can lead to a cyber threat.

Another recommendation is eliminating any vulnerabilities that can enable chaining. Removing links before they even start can prevent a threat. Software should be updated regularly, and users should rapidly eliminate any flaws that are already in the system.

For more information, you can read the full article from Tech News World.

Link: https://www.technewsworld.com/story/ai-makes-low-severity-vulnerabilities-more-dangerous-177747.html

About Advanced Network Consulting

Advanced Network Consulting is a Southern California based IT consulting company focused on the small business market. For businesses in Southern California, or a business that has an office in LA or Orange County, Advanced Network Consulting offers on-site and remote network and server support.

Hoping to improve the efficiency of your computer? Need to strengthen the cybersecurity of your device? We offer a complimentary one-hour onsite evaluation, and our network and server solutions will ensure that your business continues to be operational.

Contact us through our site: https://www.ancsite.com/

#ANC #Advanced_Network_Consulting #IT #IT_consultant #OC_small_business #computing #technology #Tech_News_World #AI #AI_issues #cybersecurity #system_security #computer_safety #vulnerabilities