In living off the land attacks, malicious actors use legitimate tools and processes already present on a system to avoid detection. In this paper, we explore how the on-device LLMs of the future will become a security concern as threat actors integrate LLMs into their living off the land attack pipeline and ways the security community may mitigate this threat.
翻译:在“利用合法工具生存”攻击中,恶意行为者利用系统中已存在的合法工具和流程来规避检测。本文探讨了未来设备端大型语言模型如何成为安全威胁——攻击者可能将LLM整合到其“利用合法工具生存”的攻击链条中,并分析了安全社区可采取哪些措施来缓解此类威胁。