From Text to MITRE Techniques: Exploring the Malicious Use of Large Language Models for Generating Cyber Attack Payloads
P.V. Sai Charan, Hrushikesh Chunduri, P. Mohan Anand, and Sandeep K, Shukla

TL;DR
This paper investigates how large language models like ChatGPT and Bard can be exploited to generate cyber attack payloads, highlighting both risks for malicious actors and potential uses for security testing.
Contribution
It systematically demonstrates the capability of LLMs to generate implementable code for top MITRE techniques and compares their performance, revealing security implications.
Findings
ChatGPT can accelerate targeted and sophisticated cyber attacks.
LLMs enable amateurs to develop customized attack tools.
They assist malware authors in creating advanced ransomware variants.
Abstract
This research article critically examines the potential risks and implications arising from the malicious utilization of large language models(LLM), focusing specifically on ChatGPT and Google's Bard. Although these large language models have numerous beneficial applications, the misuse of this technology by cybercriminals for creating offensive payloads and tools is a significant concern. In this study, we systematically generated implementable code for the top-10 MITRE Techniques prevalent in 2022, utilizing ChatGPT, and conduct a comparative analysis of its performance with Google's Bard. Our experimentation reveals that ChatGPT has the potential to enable attackers to accelerate the operation of more targeted and sophisticated attacks. Additionally, the technology provides amateur attackers with more capabilities to perform a wide range of attacks and empowers script kiddies to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Hate Speech and Cyberbullying Detection · Software Engineering Research
