Goto

Collaborating Authors

 spear-phishing attack


How AI can be used for Malicious Purposes - Deep Instinct

#artificialintelligence

In recent years, deep learning and machine learning have gained traction in so many areas that have a direct positive effect on our lives as well as complex tasks such as computer vision (image recognition), machine translation, and natural language processing. And with like so many other technologies that are changing our lives for good, it has the destructive potential to change it for bad, there is no reason why it won't also be used for malicious activities as well. Up until now, we haven't seen the use of AI for malicious activities in cybersecurity due to the high costs, lack of skills and the tools available. But just like any other technology, it's a matter of time before it happens in cybersecurity. Think about what would happen when attackers start using the power of deep learning and machine learning for their advantage?


Will Artificial Intelligence be the answer to BFSI cyberattacks?

#artificialintelligence

CIO Magazine reports that the BFSI sector will be the key target of cyber-criminals this year. They write, "BFSI companies were possibly the biggest target of cyber-criminals over the last couple of years. The trend is likely to continue as cyber-criminals will continue to find innovative ways to steal identity and money." Until recently, cybersecurity measures in the banking industry have been far from the latest technological advancements. Yet, increasingly creative security breaches and continuous frauds in the financial services industry have forced the BFSI to reboot their security strategies and adopt new technologies for their cyber security management.


How Will Machine Learning Address Cyber Security Problems in 2018?

#artificialintelligence

ML can help provide more comprehensive context-rich detections of the few bad actors already in your network. Compromises will continue in 2018, and machine learning will continue to grow in intelligent sifting through alert information to detect them. And in some cases, the ML can help the security team automatically or semi-automatically resolve them. Unfortunately, I think this is one area in which an adversarial actor using ML has the upper-hand: ML might be creating some of the problems here in 2018, but also, ML will be used more for detecting social media manipulation and automated phishing and spear-phishing attacks. This is one area where ML isn't required to get pretty good detection.


Multi-Defender Strategic Filtering Against Spear-Phishing Attacks

AAAI Conferences

Spear-phishing attacks pose a serious threat to sensitive computer systems, since they sidestep technical security mechanisms by exploiting the carelessness of authorized users. A common way to mitigate such attacks is to use e-mail filters which block e-mails with a maliciousness score above a chosen threshold. Optimal choice of such a threshold involves a tradeoff between the risk from delivered malicious emails and the cost of blocking benign traffic. A further complicating factor is the strategic nature of an attacker, who may selectively target users offering the best value in terms of likelihood of success and resulting access privileges. Previous work on strategic threshold-selection considered a single organization choosing thresholds for all users. In reality, many organizations are potential targets of such attacks, and their incentives need not be well aligned. We therefore consider the problem of strategic threshold-selection by a collection of independent self-interested users. We characterize both Stackelberg multi-defender equilibria, corresponding to short-term strategic dynamics, as well as Nash equilibria of the simultaneous game between all users and the attacker, modeling long-term dynamics, and exhibit a polynomial-time algorithm for computing short-term (Stackelberg) equilibria. We find that while Stackelberg multi-defender equilibrium need not exist, Nash equilibrium always exists, and remarkably, both equilibria are unique and socially optimal.


Optimal Personalized Filtering Against Spear-Phishing Attacks

AAAI Conferences

To penetrate sensitive computer networks, attackers can use spear phishing to sidestep technical security mechanisms by exploiting the privileges of careless users. In order to maximize their success probability, attackers have to target the users that constitute the weakest links of the system. The optimal selection of these target users takes into account both the damage that can be caused by a user and the probability of a malicious e-mail being delivered to and opened by a user. Since attackers select their targets in a strategic way, the optimal mitigation of these attacks requires the defender to also personalize the e-mail filters by taking into account the users' properties. In this paper, we assume that a learned classifier is given and propose strategic per-user filtering thresholds for mitigating spear-phishing attacks. We formulate the problem of filtering targeted and non-targeted malicious e-mails as a Stackelberg security game. We characterize the optimal filtering strategies and show how to compute them in practice. Finally, we evaluate our results using two real-world datasets and demonstrate that the proposed thresholds lead to lower losses than non-strategic thresholds.