Goto

Collaborating Authors

 simulating malicious ai


DeepPhish : Simulating Malicious AI - Semantic Scholar

#artificialintelligence

In this work we describe how threat actors may use AI algorithms to bypass AI phishing detection systems. We analyzed more than a million phishing URLs to understand the different strategies that threat actors use to create phishing URLs. Assuming the role of an attacker, we simulate how different threat actors may leverage Deep Neural Networks to enhance their effectiveness rate.


DeepPhish: Simulating Malicious AI to Act Like an Adversary

#artificialintelligence

An idea applies in physical space and cyberspace: When you're plotting against an adversary, you want all the intel you can get on which weapons they're using and how they're using them. The same idea drove researchers at Cyxtera Technologies to explore the weaponization of artificial intelligence (AI) in phishing attacks, which continue to evolve as cybercriminals employ more sophisticated techniques. Encryption and Web certificates, for example, have become go-to phishing tactics as attackers alter their threats to evade security defenses. Web certificates provide a low-cost means for attackers to convince victims their malicious sites are legitimate, explains Alejandro Correa, vice president of research at Cyxtera. It doesn't take much to get a browser to display a "secure" icon – and that little green lock can make a big difference in whether a phishing scam is successful, he says.