{"id":2921,"date":"2024-04-04T07:41:46","date_gmt":"2024-04-04T12:41:46","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-analytics\/ai-dual-role-smb-brand-spoofing"},"modified":"2024-04-04T07:41:46","modified_gmt":"2024-04-04T12:41:46","slug":"ais-dual-role-on-smb-brand-spoofing","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/04\/ais-dual-role-on-smb-brand-spoofing\/","title":{"rendered":"AI&#8217;s Dual Role on SMB Brand Spoofing"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt6f069d6b20c23bc5\/64f1769cc7f4a407caa043bd\/fakeface-Bulat_Silvia-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AI is simultaneously making it easier for adversaries to pull off brand spoofing and easier for organizations to block spoofing and other threats. Both usages have significant implications for small to midsize businesses (SMBs).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Brand impersonation is typically <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/facebook-and-microsoft-are-the-most-impersonated-brands-in-phishing-attacks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">associated with brand names<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but it&#8217;s arguably easier and more effective for hackers to impersonate their local bank than Bank of America. That&#8217;s especially true as of late, thanks to the ease of collecting and generating fake content with AI.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some security architects are fighting back by designing systems that use AI to instead detect and block impersonation attacks, especially in cases where businesses can&#8217;t afford to do so themselves.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Impersonating SMBs Online\">Impersonating SMBs Online<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to data provided to Dark Reading by Check Point, businesses with 100 or fewer employees have faced an average of 255 cyberattacks per week in 2024.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among those, brand spoofing is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/why-cisos-should-care-about-brand-impersonation-scam-sites\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">one of the most pernicious<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. While a spoofing campaign against Bank of America won&#8217;t even dent its books, the same attack against smaller organizations can cause serious, lasting damage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There&#8217;s the potential degradation of trust and reputation, as consumers may feel the brand isn&#8217;t reliable or safe,&#8221; explains Jeremy Fuchs, Harmony email analyst. &#8220;There&#8217;s also the potential loss of funds. Take a small clothing company. If someone wants to buy a t-shirt, but instead &#8216;buys it&#8217; from a spoof, the business is losing out on money. Finally, when a brand is spoofed, it can lead to email providers like Google or Yahoo blocking legitimate messages, such as for email marketing.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is especially worrying because &#8220;A smaller brand\u2014whether it&#8217;s a local bank, doctor, law firm, it doesn&#8217;t really matter\u2014is actually easier for hackers to spoof than a larger one,&#8221; Fuchs explains. Not only do they lack time, money, and personnel to invest in cybersecurity, but &#8220;Oftentimes, small businesses just aren&#8217;t expecting it. They assume that it&#8217;s going to be Bank of America that&#8217;s targeted.&#8221; Customers also tend to make that assumption (if they&#8217;re aware of the threat at all).&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Historically, SMBs have had one thing going for them: phishing campaigns took time and effort to craft so, from an attacker&#8217;s perspective, it might have felt like bang for their buck to target larger organizations with wider audiences.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is no longer the case, however, thanks to generative AI. Hackers can now use chatbots to whip up <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/phishing-malicious-implants-ai-cyberattacks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">convincing emails mimicking any business<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in minutes flat.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Preventing Brand Spoofing\">Preventing Brand Spoofing<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It took no time or effort for hackers to start using AI to improve the quality and efficiency of impersonation attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security engineers, meanwhile, have faced a far greater challenge in utilizing the same technology for their goals.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Imagine, for example, that you want to use AI to detect spoofing attacks against Microsoft. You&#8217;d need to train an algorithm to distinguish legitimate and faked URLs, iconography, content, and more, associated not just with the company as a whole but also all of its various products, subsidiaries, the public figures behind them, and so on.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And Microsoft is an easy example.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The real challenge is how to identify small businesses,&#8221; explains Dan Karpati, CTO of generative AI and cybersecurity at Check Point. &#8220;Everyone&#8217;s familiar with the big ones\u2013the top sites in the US and other major countries\u2013but how do we know about a store in a small village in Spain, or Lisbon?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft researchers made early inroads into the problem back in 2021, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/researchers-create-new-approach-to-detect-brand-impersonation\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">training a neural network on 1,000 brand impersonation attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and generating mathematical representations of brand identities based on nearest neighbor classifications.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The system Karpati designed works in a similar fashion, first by automatically gathering data from a URL and the content of a legitimate web page. &#8220;It can be the URL, favicon, [data] inside of the HTML, copyrights, links in the sites, pictures\u2013a lot of features. Each time that we collect telemetry about a site, we open a new cluster. And if you mark it as benign, okay, now we have some sense of how benign looks for this brand,&#8221; he explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Then, he continues, &#8220;Every time that we observe new access to a site, we extract its features and we ask\u2013automatically\u2014&#8217;Is this access with these features that we extracted from the browser, or on the network, aligned with what we recorded about the cluster?'&#8221; In other words, with a model for what a brand&#8217;s domain structure, iconography, and content should look like, new sites that pop up with largely similar but slightly different features can be flagged as spoofs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Because the system is cloud-based and AI-driven, it can apply this same process across just about any company with an online presence. According to Check Point, this system protects <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/blog.checkpoint.com\/security\/brand-spoofing-prevention-check-point-software-technologies-ai-powered-pre-emptive-zero-phishing-prevents-local-and-global-brand-impersonation-attacks\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">thousands of organizations in hundreds of countries<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> every month.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Lower-Tech Solutions\">Lower-Tech Solutions<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides advanced AI, there are other solutions companies can implement to make the job of impersonating them more difficult, and less profitable for hackers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For one thing there&#8217;s Domain-based Message Authentication, Reporting &amp; Conformance (DMARC), the email verification protocol often <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/google-yahoo-push-dmarc-forcing-companies-to-catch-up\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">required of larger organizations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but which <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/nonprofit-domains-basic-dmarc-impersonation-protections\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">smaller ones tend to overlook<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Ironically, it&#8217;s far easier for a small business to be DMARC-compliant than a larger one.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;You have to be able to track all your domains, and for some companies that have hundreds, it can be difficult. If you have one domain, it takes like 20 minutes,&#8221; Fuchs points out. &#8220;DMARC can be a huge undertaking depending on how many domains you have, but it is a worthwhile project. It&#8217;s a huge step in making sure that when somebody gets an email from you, it&#8217;s coming from you, or not from somebody who appears just like you.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And simply communicating with customers and vendors always helps, whether it be through helpful cyber hygiene tips and resources, or regular notices\u2013&#8221;We&#8217;ll never ask you for this code,&#8221; &#8220;We&#8217;ll never send you an email like this,&#8221; and the like.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Having both of those measures, and having that kind of open and honest culture\u2013like, &#8216;This is a problem, we&#8217;re trying to fix it, here&#8217;s how we&#8217;re doing it, and here&#8217;s how you can help us&#8217;\u2013makes you a candidate for better outcomes,&#8221; Fuchs says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/ai-dual-role-smb-brand-spoofing\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI is simultaneously making it easier for adversaries to pull<\/p>\n","protected":false},"author":12,"featured_media":2922,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2921","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=1200%2C800&ssl=1",1200,800,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=1200%2C800&ssl=1",1200,800,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=1200%2C800&ssl=1",1200,800,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/ais-dual-role-on-smb-brand-spoofing.jpg?fit=1200%2C800&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2921"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2921\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2922"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}