Skip to content
Information Technology, Research Development

Study tests if AI can help fight cybercrime

Charles Darwin University 2 mins read

Artificial Intelligence (AI) could become a crucial asset to fight the growing global risk of cybercrime, a new study with Charles Darwin University (CDU) has found.

The study, led by researchers from CDU’s Energy and Resources Institute alongside Christ Academy Institute for Advanced Studies in India, examined if generative AI (GenAI) could be used in penetration testing, known as pentesting, which is a cybersecurity exercise aimed at identifying weak spots in a system’s defences.

Researchers used ChatGPT to run a series of pentesting activities in reconnaissance, scanning, vulnerability assessments, exploitation, and reporting activities.

Prompts included trying to anonymously log into a server and download files, inspect source codes of webpages, and find data embedded within an archive.

Co-author and CDU Senior Lecturer in Information Technology Dr Bharanidharan Shanmugam said the purpose of the study was to explore whether AI could be used to automate some pentesting activities, with the results showing ChatGPT had enormous potential.

“In the reconnaissance phase, ChatGPT can be used for gathering information about the target system, network, or organisation for the purpose of identifying potential vulnerabilities and attack vectors,” Dr Shanmugam said.

“In the scanning phase, ChatGPT can be used to aid in performing detailed scans of the target particularly their network, systems and applications to identify open ports, services, and potential vulnerabilities.

“While ChatGPT proved to be an excellent GenAI tool for pentesting for the previous phases, it shown the greatest in exploiting the vulnerabilities of the remote machine.”

Dr Shanmugam added while the technology could revolutionise pentesting, use of AI to improve cybersecurity must be strictly monitored.

“Organisations must adopt best practices and guidelines, focusing on responsible AI deployment, data security and privacy, and fostering collaboration and information sharing,” he said.

“By doing so, organisations can leverage the power of GenAI to better protect themselves against the ever-evolving threat landscape and maintain a secure digital environment for all.”

Generative AI for pentesting: the good, the bad, the ugly was published in the International Journal of Information Security.


Contact details:

Emily Bostock
Acting Research Communications Officer

T: +61 8 8946 6529
M: 0432 417 518
E: 
media@cdu.edu.au

Media

More from this category

  • Information Technology
  • 31/10/2024
  • 09:18
Data#3

Data#3 wins Customer Experience Partner of the Year for APJC at Cisco Partner Summit 2024

Hello, We are delighted to share that Data#3 has won the Customer Experience Partner of the Year for APJC award at Cisco's 2024 Partner Summit. This is one of three awards we won at the Summit, another release is to follow tomorrow for the other awards. Please see below the release for this Customer Experience award. Thank you, Erin ReganData#3 Design Lead Data#3 wins Customer Experience Partner of the Year forAPJC at Cisco Partner Summit 2024 October 31, 2024; Brisbane, Australia: Leading Australian technology services and solutions provider, Data#3, is proud to announce that it has been named Customer Experience…

  • Information Technology
  • 31/10/2024
  • 07:10
Zoom Video Communications, Inc.

Zoom to Release Financial Results for the Third Quarter of Fiscal Year 2025

SAN JOSE, Calif., Oct. 30, 2024 (GLOBE NEWSWIRE) -- Zoom Video Communications, Inc. (NASDAQ: ZM) today announced it will release its financial results for the third quarter of fiscal year 2025 on Monday, November 25, 2024, after the market closes.A live Zoom Webinar of the event can be accessed at 2:00 pm PT / 5:00 pm ET through Zoom’s investor relations website at https://investors.zoom.us. A replay will be available approximately two hours after the conclusion of the live event.About ZoomZoom’s mission is to provide an AI-first work platform for human connection. Reimagine teamwork with Zoom Workplace — Zoom’s open collaboration…

  • Aviation, Information Technology
  • 30/10/2024
  • 15:00
Juniper Networks

Thai Airways Soars to New Heights with the AI-Native Networking Platform from Juniper Networks, Fueling the Airline’s Digital Transformation and Growth

BANGKOK, 30 October, 2024 – Juniper Networks® (NYSE: JNPR), a leader in secure, AI-Native Networking, today announcedthat Thai Airways has modernized the network infrastructure…

  • Contains:

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.