Library Header Image Library Header Image

The Clean Attack Problem: When Nothing Looks Wrong but Everything is Compromised


Posted on by Harsh Verma

For decades, cybersecurity has operated on a stable premise: attacks reveal themselves through abnormality. In recent times, humans and organizations have gotten comfortable. Cybersecurity has always relied on assumptions built on sound foundations: attacks will always look abnormal. Suspicious traffic, unusual login behavior, unauthorized privileges, or clear deviations from the normal state of daily business. The world today is slowly dismantling that assumption.

Cyberattacks are no longer carried out by humans who ring all the alarm bells. According to Microsoft, in what they call the operational reality, AI agents change how cyberattacks work because they can work inside actual processes, imitate ‌expected behavior patterns, and work according to valid actions in ways that look normal at every step.

This has changed the landscape of future enterprise environments. because nothing looks wrong when every step is monitored individually, the most dangerous attacks may not trigger any alarms.

How sequence-based attacks change cybersecurity

Traditional cyberattacks often followed the same triggers, so they raised alarms. These include: malware signatures, suspicious orders, abnormal traffic patterns, and unauthorized access attempts.

Gaphic 1 clean attack 8.11.26 blog

AI-assisted attacks are known to avoid these signals. Instead of looking suspicious all the way, attackers work according to a sequence of legitimate actions. They use: valid credentials, approved API interactions, trusted workflows, real communications and authorized system access.

This “perfectly normal” system is where the danger lies, not in any single activity. Because the process looks normal, a malicious agent operating inside an enterprise environment can:

1. Collect internal documents

2. Create support requests that look real

3. Request and escalate permissions through approved processes

4. Move comfortably through trusted integrations

This unobstructed movement is what security researchers are calling a “clean attack surface”. An attack type that blends almost seamlessly into ordinary business operations instead of differently. The Clean Attack Problem emerges precisely in this gap.

Why anomaly detection Model breaks down

Traditional anomaly detection was built around different checkpoints. The model is straightforward; Malicious behavior appears unlike normal activity → Systems detect the deviations → Alerts go off and →> Investigation begins.

According to MITRE ATLAS framework, AI systems complicate this process because these agents can imitate real human behavior, adapt to different operational contexts, learn workflow patterns, and optimize processes around controls.

These capabilities make traditional anomaly-based detection less effective for AI-generated attacks. The problem is that the processes look valid, not that the AI attacks are invisible. This leads to a breakdown of;

1. Signature-based selection

2. Static rule systems

3. Threshold trigger alerts

4. Behavioral assumptions that determine critical responses

In short, security systems are being bypassed not through evasion but through perfect compliance.

Empirical Signal: The MGM Resorts Breach case study

In 2023, MGM Resorts suffered a major cyberattack after its attackers used social engineering to convince the company's help desk to reset credentials. Once they got inside, they moved quickly through systems using legitimate accounts and mechanisms that had approved access.

What makes this attack significant is that the activity in itself did not appear malicious. The attackers used valid credentials, authorized tools, and legitimate workflows. Any security team looking for obvious anomalies would have struggled to identify a single action as clearly malicious.

The compromise rose from a sequence of actions that looked normal but collectively resulted in widespread disruption across MGM's operations.

Toward the Rise of Intent-Based Security: A Proposed Framework

My view is that the future SOC may not look like a monitoring dashboard. It will be a behavioral intelligence engine continuously interpreting machine intent in real time. This will force cybersecurity towards a major shift.

Gaphic 2 clean attack 8.11.26 blol

Security systems will no longer focus only on who performed an action, if the action was authorized, or whether the behavior matched historical patterns. Instead, it will be on “why”. Why are these actions occurring?

What intent-based security actually evaluates.

  • Behavioral sequencing: It watches a chain of actions to ensure the steps lead logically toward the goal
  • Operational context: It looks at the environment and the situation
  • Workflow legitimacy: It checks if the overall task aligns with the user's original request
  • Runtime decision patterns: Monitors decisions made by autonomous agents in real-time ensuring that they haven't drifted off-course in the middle of a task

This model reframes security from static enforcement to dynamic reasoning.

Cybersecurity used to focus on detecting abnormal behavior. AI systems are disrupting that model because attacks may now be carried out inside trusted workflows, with legitimate permissions, and normal operational patterns.

The implication is profound: valid actions can produce malicious outcomes.

Things are now moving from anomaly-centric security toward behavior-centric security. Enterprises know now that any activity that looks valid does not mean it is safe. In AI-driven environments, malicious intent can hide inside perfectly legitimate behavior sequences. In the next article, we go deeper into adaptive behavior and why AI agents do not simply break rules anymore. They redefine them.

Contributors
Harsh Verma

Principal Software Engineer - AI, Palo Alto Networks Inc

Blogs posted to the RSAConference.com website are intended for educational purposes only and do not replace independent professional judgment. Statements of fact and opinions expressed are those of the blog author individually and, unless expressly stated to the contrary, are not the opinion or position of RSAC™ Conference, or any other co-sponsors. RSAC Conference does not endorse or approve, and assumes no responsibility for, the content, accuracy or completeness of the information presented in this blog.


Share With Your Community

Related Blogs