DeepPhish: Simulating Malicious AI to Act Like an Adversary
An idea applies in physical space and cyberspace: When you're plotting against an adversary, you want all the intel you can get on which weapons they're using and how they're using them. The same idea drove researchers at Cyxtera Technologies to explore the weaponization of artificial intelligence (AI) in phishing attacks, which continue to evolve as cybercriminals employ more sophisticated techniques. Encryption and Web certificates, for example, have become go-to phishing tactics as attackers alter their threats to evade security defenses. Web certificates provide a low-cost means for attackers to convince victims their malicious sites are legitimate, explains Alejandro Correa, vice president of research at Cyxtera. It doesn't take much to get a browser to display a "secure" icon – and that little green lock can make a big difference in whether a phishing scam is successful, he says.
Oct-26-2018, 18:20:47 GMT