AI-Powered Attack Surface Discovery: Analyzing SSL Pinning Bypass Capabilities with an LLM-Based Model
4th Cognitive Models and Artificial Intelligence Conference, AICCONF 2026, Prague, Çek Cumhuriyeti, 24 - 25 Nisan 2026, (Tam Metin Bildiri)
- Yayın Türü: Bildiri / Tam Metin Bildiri
- Doi Numarası: 10.1109/aicconf69182.2026.11600698
- Basıldığı Şehir: Prague
- Basıldığı Ülke: Çek Cumhuriyeti
- Anahtar Kelimeler: Artificial Intelligence, Context Manipulation, Cybersecurity, Large Language Models, SSL Pinning
- İnönü Üniversitesi Adresli: Evet
Özet
With the advancement of artificial intelligence technologies, new challenges have emerged across various domains where technology is employed, and novel solution approaches have been developed to address these challenges. In the context of cybersecurity, this transformation manifests itself through both the expansion and the increasing complexity of attack surfaces. Alongside the development of artificial intelligence, intelligent solutions integrated into defensive security technologies have become more prominent; however, the growing extent to which malicious actors exploit artificial intelligence has also introduced new threat vectors, including the malicious use of static and dynamic analysis techniques. One of the critical issues in the field of cybersecurity is the identification of attack surfaces, as this process can provide information about the core assets of systems and thereby lead to a reduction in overall security levels. A commonly used approach in attack surface discovery involves analyzing network traffic to determine which systems endpoint devices communicate with, as well as the protocols and endpoints used for data exchange. To prevent such analyses, various security measures are implemented in applications running on endpoint devices. One such measure is the SSL pinning mechanism, which aims to prevent the conversion of encrypted HTTPS traffic into plaintext HTTP traffic. However, several classical techniques exist for bypassing this mechanism. In this study, the capabilities of ChatGPT, an LLM-based model, in relation to SSL pinning bypass on the LinkedIn mobile application are analyzed, and the potential of artificial intelligence technologies to be applied to current challenges in the cybersecurity domain is examined. The results of the analyses indicate that ChatGPT possesses the capability to generate code via the Frida tool that can bypass SSL pinning mechanisms and, in this context, can produce effective outcomes in attack surface discovery processes.