Skip to main content

Can Your Security Stack Handle AI? An Empirical Assessment of Enterprise Controls Versus Generative AI Risks

Enterprise security teams face a critical dilemma. Executives want AI productivity gains, but it remains uncertain if existing security controls can handle the risks.

SANS-Can-Your-Security-Stack-Handle-AI-Blake-Roth (PDF, 0.44MB)

6 Nov 2025
ByBlake Roth
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Secure By Design: An Exploration of the Application of Generative AI in Threat Modeling Technical Design Documents

Research Paper

This paper explores the efficacy of large language models (LLMs) for creating comprehensive threat models by analyzing technical design documents, particularly when provided with additional contextual information about the product's underlying infrastructure and deployment environment.

  • 27 May 2026

Leveraging Large Language Models for Cross-Vendor Firewall Configuration Migration: A Comparative Case Study of Claude and ChatGPT

Research Paper

This paper investigates how two current-generation large language models (LLMs) perform on a single, representative firewall migration task.

  • 12 May 2026

No-Cost Detection of Endpoint Hard Drive Removal

Research Paper

This paper analyzes low-cost detection methods, using existing hard drive counters from Self-Monitoring, Analysis, and Reporting Technology (S.M.A.R.T.) and the Windows Registry, for their fidelity in detecting hard drive removal.

  • 19 Nov 2025

Automating Generative AI Guidelines: Reducing Prompt Injection Risk with 'Shift-Left' MITRE ATLAS Mitigation Testing

Research Paper

Automated testing during the build stage of the AI engineering life cycle can evaluate the effectiveness of generative AI guidelines against prompt injection attacks.

  • 7 Nov 2025

Fixing What You Broke: Can AI Be Used to Thwart AI-Generated Malware?

Research Paper

Security professionals are starting to rethink their approach to access control and monitoring for...

  • 3 Sep 2025

Trust But Verify: Evaluating the Accuracy of LLMs in Normalizing Threat Data Feeds

Research Paper

This paper examines whether Large Language Models (LLMs) can be reliably applied to the normalization of Indicators of Compromise (IOCs) into Structured Threat Information Expression (STIX) format.

  • 16 Jul 2025

Do AI Coding Assistants Make Bad Coders Worse? A Security Evaluation of GitHub Copilot

Research Paper

As AI coding assistants become increasingly integral to software development, the security of their generated outputs is under greater scrutiny.

  • 11 Jul 2025

AI-Driven Insecurity: Assessing Security Gaps in AI Generated IT Guidance

Research Paper

The increasing reliance on AI-generated technical guidance for IT system configuration introduces significant security risks. This study assesses these risks through a case study: setting up an Apache web server on a Rocky Linux system using instructions from seven AI models.

  • 13 May 2025

SIEM Detection Logic Conversion with LLMs

Research Paper

This research explores how Large Language Models (LLMs) and automation scripts can expedite the translation of detection logic between SIEMs, converting detections in minutes instead of hours.

  • 2 May 2025

Leveraging Large Language Models for Security-Focused Code Reviews

Research Paper

This study investigates the potential application of Large Language Models (LLMs) in enhancing...

  • 26 Mar 2025

MITRE ATT&CK Labeling of Cyber Threat Intelligence via LLM

Research Paper

This paper explores the effectiveness of various online and locally hosted LLMs in classifying an...

  • 7 Jan 2025

Revolutionizing Cybersecurity: Implementing Large Language Models as Dynamic SOAR Tools

Research Paper

This research explores the potential of Large Language Models (LLMs), explicitly using ChatGPT...

  • 5 Dec 2024

Leveraging Generative Artificial Intelligence for Memory Analysis

Research Paper

The increasing sophistication of malware poses significant challenges for traditional memory...

  • 5 Dec 2024

Machine Learning: Preventing Network Abnormalities

Research Paper

The Department of Defense (DoD) developed and published multiple zero trust documents describing the...

  • 30 Aug 2024

Safeguarding AI: Effectiveness of Guardrails in Controlling Malicious Output from Locally Hosted LLMs

Research Paper

This paper explores the effectiveness of open-source guardrails that can be added to LLM-based...

  • 21 Aug 2024

Shining a Light on AI: Ensuring Vendor Transparency in Data Sourcing and Delivery

Research Paper

Amidst the proliferation of AI solutions, the focus lies in evaluating transparency, undisclosed...

  • 29 Jan 2024

Shining a Light on AI: Ensuring Vendor Transparency in Data Sourcing and Delivery

Research Paper

Amidst the proliferation of AI solutions, the focus lies in evaluating transparency, undisclosed...

  • 29 Jan 2024

The Evolution of the Digital Predator: Using AI to Evade Security Controls

Research Paper

Since the advent of the computer, there has been a never-ending game of cat and mouse between those...

  • 20 Dec 2023
  • Foster Nethercott

Malware Detection in Encrypted TLS Traffic Through Machine Learning

Research Paper

The proliferation of TLS across the Internet leads to a safer environment for the end user but a...

  • 10 Mar 2021