论文标题
AI会制作网络剑或盾牌:一些技术进步的数学模型
Will AI Make Cyber Swords or Shields: A few mathematical models of technological progress
论文作者
论文摘要
我们旨在通过考虑网络钓鱼,脆弱性发现以及修补和剥削之间的动态来证明数学模型对网络安全技术进步的政策辩论的价值。然后,我们将输入调整为那些数学模型,以匹配其基础技术的一些可能进步。我们发现AI对网络钓鱼的影响可能被高估,但可能会导致更多攻击未被发现。脆弱性发现的进步有可能帮助攻击者比防守者更多。与编写补丁程序的自动化相比,编写利用的自动化对攻击者更有用,尽管有助于更快地部署补丁的进步有可能比任何一个更具影响力。
We aim to demonstrate the value of mathematical models for policy debates about technological progress in cybersecurity by considering phishing, vulnerability discovery, and the dynamics between patching and exploitation. We then adjust the inputs to those mathematical models to match some possible advances in their underlying technology. We find that AI's impact on phishing may be overestimated but could lead to more attacks going undetected. Advances in vulnerability discovery have the potential to help attackers more than defenders. And automation that writes exploits is more useful to attackers than automation that writes patches, although advances that help deploy patches faster have the potential to be more impactful than either.