A few hours ago I have read a masterpiece about the current state of "Cybersecurity and AI", written by an extremely competent person (Marcus Hutchins, the guy that stopped WannaCry). It is a relatively long essay but I really encourage everyone with some interest in these topics to read it. Not only for the credibility of Hutchins, the breadth and the strength of his arguments, but also for the clarity and sharpness of his writing.
The time spent for reading this essay is an excellent investment. I will make it mandatory reading for the students of my Cybersecurity course.
- Full essay: Machine speed is a lie: stop fighting AI with AI.
- A few paragraphs that I extracted: Working Notes: Cybersecurity and AI.
I must add that I am happy to see that Hutchins makes several points that I emphasize a lot in my course, including: the practical inevitability of initial access and the need to take an "assume breach" standpoint; the necessity of detection and of structural defensive mechanisms such as, e.g., the blocking of wks-wks communication; the importance of the economic perspective for understanding attackers. But I also learned a lot, from his analysis on the basic maths of SOC response times for example.
BTW: the Working Notes website is my new way for organizing material that I find important. It helps me to distill and remember; it allows me to also disseminate at almost no cost.
The page about Cybersecurity and AI contains two further references that summarize what I have been thinking about for the past few months but never found the time to write down. Those references corroborate their claims with real data, though.
Two pages, in particular, could be of general interest:
- LLM Performance: facts about the real performance of LLMs, including a fantastic analysis by Roberto Pieraccini.
- LLM and coding: the need for competent programmers is not going to disappear.
Commenti