Daniel Miessler on the AI Attack/Defense Balance
文章讨论了网络安全中攻击者与防御者的优劣势变化。拥有更多上下文信息的一方将占据优势。目前攻击者利用公开信息进行攻击,而防御者需借助内部知识应对。未来3-5年内,AI和SPQA技术将使防御者获得优势。 2025-10-2 16:19:59 Author: www.schneier.com(查看原文) 阅读量:10 收藏

His conclusion:

Context wins

Basically whoever can see the most about the target, and can hold that picture in their mind the best, will be best at finding the vulnerabilities the fastest and taking advantage of them. Or, as the defender, applying patches or mitigations the fastest.

And if you’re on the inside you know what the applications do. You know what’s important and what isn’t. And you can use all that internal knowledge to fix things—hopefully before the baddies take advantage.

Summary and prediction

  1. Attackers will have the advantage for 3-5 years. For less-advanced defender teams, this will take much longer.
  2. After that point, AI/SPQA will have the additional internal context to give Defenders the advantage.

LLM tech is nowhere near ready to handle the context of an entire company right now. That’s why this will take 3-5 years for true AI-enabled Blue to become a thing.

And in the meantime, Red will be able to use publicly-available context from OSINT, Recon, etc. to power their attacks.

I agree.

By the way, this is the SPQA architecture.

Tags: , ,

Posted on October 2, 2025 at 12:19 PM1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/10/daniel-miessler-on-the-ai-attack-defense-balance.html
如有侵权请联系:admin#unsafe.sh