PERSPECTIVES FROM THE CAMPUS
One of the strengths of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the colleges, universities, and other institutions of higher education throughout our state. Hence the name, “Perspectives from the Campus”, we invite experts – immersed in the pursuit of educating their students – to offer their knowledge for finding solutions in cybersecurity that benefit all Hoosiers.
In the latest installment of this series, David Dungan, who serves as the executive director at the Center for Security Services and Cyber Defense at Anderson University, discusses how a Virtual Private Network (VPN) can protect us when we’re online, especially when it comes to connecting to public (and often free) Wi-Fi networks. He also shares his perspective on the cyber risks related to “sharing our story” and why the convenience – even in a place we believe is OK – may not be worth it, without first making sure that you’ve secured your data.
By David Dungan
Phishing is a common method used by threat actors to steal personal information, install malware, and manipulate the goodwill of users across the world. Despite the rise of Cybersecurity awareness programs and phishing detection tools, Phishing campaigns and similar social engineering attacks are still some of the most common cyber threats out there. In light of these recent trends, combating new campaigns and strategies has never been more important.
The Rise of AI (Artificial Intelligence) has given new teeth to age-old cyber threats, bolstering the complexity of phishing attacks and making them harder to detect by automated tools or human analysis. Supplying curated information to AI systems allows it to compile an untold number of personalized emails and custom-built messages made for the sole purpose of getting your information. Studies have shown that over 82.6% of all Phishing emails use AI in their creation, with the prevalence showing no sign of slowing down. But how is AI actually being used and what can we look out for?
AI-Led Personalization
AI has made specializing the contents of email extremely fast and easy. By analyzing online data (such as social media accounts and public profiles), threat actors are able to use AI to create messages that seem contextually correct and “too specific” to be wrong.
AI-built Phishing campaigns are easily able to:
- Build emails that match your background and personal interests
- Create highly accurate mimicries of specific individuals or organizations
- Write messages that reference recent events
- Steal the content of legitimate messages to create word-for-word mimicries
- Correct grammar mistakes and avoid the other “common” symptoms of Phishing
Polymorphic Phishing
Polymorphic Phishing is a subset of Phishing where emails change their appearance, randomizing contents, visuals, and the subject lines. Against normal phishing attempts, modern Phishing detection tools use a strategy called “grouping” to find similarities between the emails and identify / block matching messages. Using AI, they can change just enough elements to avoid being found by automatic detection tools.
Vishing: Deepfakes & False Voices
A trend caused by AI itself is using Deepfakes, AI-generated media built to impersonate or present a specific scenario. The accuracy of these has risen to unnerving levels over the years, fooling even experts.
Threat actors can use this to do a number of malicious activities:
- Send falsified audio recordings of “official” requests
- Impersonate employees through video
- Mass-create fake accounts, complete with autogenerated blog posts, profile contents, and certificates
- Generate fake profile pictures to accompany emails
What Can We Do?
While we can’t stop threat actors from using AI-led content against us, we can still fight against it. With Phishing being one of the most common cyber-threats, staying educated on new developments in AI and the new trends with Phishing strategies is increasingly important. By adopting phishing-resistant ways to access personal information (such as Multi-Factor Authentication (MFA) or biometrics), we are able to limit threat actor’s access if they do try to compromise your account.