Weaponizing AI in Cyberattacks A Comparative Study of AI powered Tools for Offensive Security

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Offensive security, a critical aspect of modern cybersecurity, involves simulating cyberattacks to proactively identify and address vulnerabilities before they can be exploited. However, many tasks, such as network scanning and subdomain enumeration, are time-consuming and inefficient without automation, especially as cyberattacks grow increasingly sophisticated. Recent incidents, such as attacks targeting legacy communication systems like pagers and walkie-talkies, further underscore the urgency to automate offensive security operations. This paper presents a comparative study of automated tools, specifically WebCopilot and Sublist3r for subdomain enumeration, and RustScan combined with Nmap compared to Nmap alone for network scanning. The results demonstrate that automation significantly reduces the time required for these tasks, enhancing both efficiency and effectiveness in offensive security practices. Additionally, this study explores the potential of artificial intelligence (AI) to further transform offensive security by automating more complex tasks, such as simulating attack scenarios and adapting dynamically to defenses. Positioned as a proposal, this research advocates for the integration of AI into the attack life cycle, highlighting the future potential of fully automating offensive security processes to create more intelligent, adaptive, and effective tools.

Original languageEnglish
Title of host publicationProceedings of 2024 the 8th International Conference on Future Networks and Distributed Systems, ICFNDS 2024
PublisherAssociation for Computing Machinery
Pages283-290
Number of pages8
ISBN (Electronic)9798400711701
DOIs
StatePublished - 2 Jul 2025
Externally publishedYes
Event8th International Conference on Future Networks and Distributed Systems, ICFNDS 2024 - Marrakech, Morocco
Duration: 11 Dec 202412 Dec 2024

Publication series

NameACM International Conference Proceeding Series

Conference

Conference8th International Conference on Future Networks and Distributed Systems, ICFNDS 2024
Country/TerritoryMorocco
CityMarrakech
Period11/12/2412/12/24

Bibliographical note

Publisher Copyright:
© 2024 Copyright held by the owner/author(s)

Keywords

  • automated attacks
  • automation
  • offensive security

ASJC Scopus subject areas

  • Human-Computer Interaction
  • Computer Networks and Communications
  • Computer Vision and Pattern Recognition
  • Software

Fingerprint

Dive into the research topics of 'Weaponizing AI in Cyberattacks A Comparative Study of AI powered Tools for Offensive Security'. Together they form a unique fingerprint.

Cite this