24 Jul 2006
Artificial intelligence (AI) software is now being widely used by hackers to find formerly undiscovered application vulnerabilities, security experts have warned.
Researchers at Secure Computing said that cyber-criminals are exploiting the ability of AI tools to use a methodology referred to as 'fuzzing' to test applications for bugs.
During this process the AI tools check allowed input for a given application and try to force abnormal responses to see whether unexpected results can be generated.
Once a bug is found, further research can determine whether the bug can be exploited as a vulnerability and then packaged as an exploit.
Secure Computing found that hackers are sharing fuzzing results in a collaborative effort in IRC chatrooms and news groups to rapidly develop new threats.
The large increase in application vulnerabilities reported recently is thought to be a direct result of the use of fuzzing tools, the company added.
"Fuzzing will clearly accelerate the ability for hackers to discover new vulnerabilities in software applications," said Paul Henry, vice president of strategic accounts at Secure Computing.
"Software vendors were already struggling to keep up with patches for software bugs. The use of fuzzing tools by hackers and the flood of newly discovered vulnerabilities may overwhelm software vendors' ability to respond with patches."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Java / Oracle Coherence Technical / Solution Architect...
ASP.Net/C#/Web Development/Desktop Development/Winforms...
My Major client urgently requires an experienced contract...
Decision Systems Analyst West Midlands £19-24,000 Are...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
WHAT??
Fuzzing and AI dude there seems to be a disconnect in that statement!
Posted by: cryptobit 28 Jul 2006
LOL
Fuzzing has nothing to do with AI, I think this guy is confusing it with "Fuzzy Logic". Fuzzing has been around forever and is nothing new.
Posted by: JK 25 Jul 2006