{"id":141013,"date":"2019-07-11T14:05:27","date_gmt":"2019-07-11T11:05:27","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/fears-of-ai-powered-hacking-are-misplaced-as-criminals-are-doing-fine-without-it\/"},"modified":"2019-07-11T14:05:27","modified_gmt":"2019-07-11T11:05:27","slug":"fears-of-ai-powered-hacking-are-misplaced-as-criminals-are-doing-fine-without-it","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/fears-of-ai-powered-hacking-are-misplaced-as-criminals-are-doing-fine-without-it\/","title":{"rendered":"Fears of AI-powered hacking are misplaced as criminals are doing fine without it"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/07\/Untitled-design-796x417.png\" \/><\/p>\n<div>\n<p><span style=\"font-weight: 400;\">Artificial intelligence is captivating tech news audiences. Unfortunately, growing expectations for AI\u2019s impact on legitimate business have spawned a distracting narrative about potential AI-powered cyberattacks. Is this really a threat that needs to be on our radar?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Based on my work examining dark web markets and the techniques cybercriminals use to collect, resell or commit fraud with stolen data, I question the usefulness of AI to run-of-the-mill cybercrime.<\/span><\/p>\n<h2><b>Most AI still falls short of \u201cintelligent\u201d<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The first problem with supposed \u201cAI hacking\u201d is that AI tools as a whole are limited in actual intelligence. When we talk about AI, we mostly mean data science \u2013 using massive data sets to train machine learning models. Training machine learning models is time consuming and takes an enormous amount of data, and the results are models still limited to binary actions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To be useful to hackers, machine learning tools need to be able to take an action, create something or change themselves based on what they encounter when deployed and how they\u2019ve been trained to react. Individual hackers may not have enough data on attacks and their outcomes to build creative or flexible, self-adjusting models.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, threat actors today use machine learning models to bypass CAPTCHA challenges. By taking CAPTCHA codes \u2013 the oddly-shaped numbers and letters you re-type to prove you\u2019re human \u2013 and splitting them into images, image-recognition models can learn to identify the images and enter the correct sequence of characters to pass the CAPTCHA test. This type of model lets the automated credential stuffing tools actors use pass as human, so attackers can gain fraudulent access to online accounts.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This technique is clever, but it\u2019s less an example of an intelligent model than effective data science. The CAPTCHA crackers are essentially matching shapes, and the fix for this CAPTCHA vulnerability is to create a more delicate test of real intelligence, like asking users to identify parts of an image containing a car or storefront.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To crack these more difficult challenges, a threat actor\u2019s model would need to be trained on a data set of categorized images to apply its \u201cknowledge\u201d of what a car, storefront, street sign or other random item <\/span><i><span style=\"font-weight: 400;\">is,<\/span><\/i><span style=\"font-weight: 400;\"> then carefully select partitioned pieces of that item as being part of the whole \u2013 which would probably require another level of training on partial images. Obviously, this display of artificial intelligence would require more data resources, data science expertise and patience than the average threat actor may have. It\u2019s easier for attackers to stick with simple CAPTCHA crackers and accept that in credential stuffing attacks, you win some and you lose some.<\/span><\/p>\n<h2>\n<b>What AI <\/b><b>can<\/b><b> hack<\/b><br \/>\n<\/h2>\n<p><span style=\"font-weight: 400;\">A 2018 report titled \u201c<\/span><a href=\"https:\/\/docs.google.com\/document\/d\/10p9L0WNoD5APVgFSLePm4E1CcdTn15p5lZMQkOoeTX0\/edit#heading=h.7nnvwugjzxd\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><span style=\"font-weight: 400;\">The Malicious Use of Artificial Intelligence<\/span><\/a><span style=\"font-weight: 400;\">,\u201d pointed out that all known examples of AI hacking used tools developed by well-funded researchers who are anticipating the weaponization of AI. Researchers from IBM created\u00a0<\/span><a href=\"https:\/\/www.reuters.com\/article\/us-cyber-conference-ai\/new-genre-of-artificial-intelligence-programs-take-computer-hacking-to-another-level-idUSKBN1KT120\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><span style=\"font-weight: 400;\">evasive hacking tools<\/span><\/a><span style=\"font-weight: 400;\"> last year, and an Israeli team of researchers used machine learning models to spoof\u00a0<\/span><a href=\"https:\/\/josephsteinberg.com\/artificial-intelligence-can-now-manipulate-medical-images-well-enough-to-kill-people\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><span style=\"font-weight: 400;\">problematic medical images<\/span><\/a><span style=\"font-weight: 400;\"> earlier this year, to name a few examples.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The report is careful to note that there is some anecdotal evidence of malicious AI, but it \u201cmay be difficult to attribute [successful attacks] to AI versus human labor or simple automation.\u201d Since we know that creating and training machine learning models for malicious use requires a lot of resources, it\u2019s unlikely there are many, if any, examples where machine learning played a major role in cybercrime.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Machine learning may be deployed by attackers in years to come, as malicious applications designed to disrupt legitimate machine learning models become available for purchase on dark web networks. (I\u2019m doubtful someone with resources to develop malicious AI would need to generate income from the type of petty cybercrime that\u2019s our biggest problem today; they\u2019ll make their money selling software).<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As the 2018 report on malicious AI noted, spear phishing attacks might be an early use case for this so-far-hypothetical breed of malicious machine learning. Attackers would name their target and let the program vacuum up public social media data, online activity and any available private information to determine an effective message, \u201csender,\u201d and attack method to accomplish the hacker\u2019s goal.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Evasive malware like what the IBM team developed last year might, in the future, be deployed against networks or used to create botnets. The malware could infect many connected devices on corporate networks, staying dormant until a critical mass was reached that would make it impossible for security pros to keep up with the infection. Similarly, AI tools might analyze system and user information from infected IoT devices to find new ways to forcibly recruit machines into a worldwide botnet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, because spear phishing and malware propagation are already both effective given a large enough attack surface, it still seems that a determined hacker would find it more cost-effective to do the work using simple automation and their own labor, rather than purchasing or creating a tool for these attacks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So, what can AI models hack today? Not much of anything. The problem is, business is booming for hackers anyway.<\/span><\/p>\n<h2><b>Why AI just isn\u2019t necessary<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Somewhere, someone has your information. They might only have an email address, or your Facebook username, or maybe an old password that you\u2019ve recently updated (you <\/span><i><span style=\"font-weight: 400;\">have<\/span><\/i><span style=\"font-weight: 400;\"> updated it, right?).<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Over time, these pieces get put together into a profile of you, your accounts, your interests and whether or not you take any security steps to prevent unauthorized account access. Then your profile gets sold off to several buyers who stick your email and password into automated tools that try your credentials on every banking, food delivery, gaming, email or other service the attacker wants to target \u2013 perhaps even software you use at work that will get them into corporate systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is how the vast majority of hacks evolve. Because internet users can\u2019t seem to beat\u00a0<\/span><a href=\"https:\/\/www.helpnetsecurity.com\/2019\/02\/19\/indicators-of-poor-password-hygiene\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><span style=\"font-weight: 400;\">bad passwords<\/span><\/a><span style=\"font-weight: 400;\">, stop clicking malicious links,\u00a0<\/span><a href=\"https:\/\/www.cnet.com\/news\/take-this-google-quiz-to-see-if-you-can-spot-phishing-emails\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><span style=\"font-weight: 400;\">recognize phishing emails<\/span><\/a><span style=\"font-weight: 400;\">, or avoid insecure websites. Machine learning is an overly complicated solution to the easily automated task of taking over accounts or duping victims into infecting their systems.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Sure, that\u2019s a little bit of victim-shaming, but it\u2019s important for the digital public to understand that before we worry about artificially-intelligent hacking tools, we need to fix the problems that let even technically-unskilled attackers make a living off of our personal information.<\/span><\/p>\n<p class=\"c-post-pubDate\">\n                                    Published July 11, 2019 \u2014 11:00 UTC\n                                <\/p>\n<\/p><\/div>\n<p><script data-src=\"http:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&amp;appId=378011798897423&amp;version=v2.6\" id=\"socialSrcFacebook\" type=\"text\/template\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/podium\/2019\/07\/11\/fears-of-ai-powered-hacking-are-misplaced-as-criminals-are-doing-fine-without-it\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Artificial intelligence is captivating tech news audiences. Unfortunately, growing expectations for AI\u2019s impact on legitimate business have spawned a distracting narrative about potential AI-powered cyberattacks. Is this really a threat that needs to be on our radar? Based on my work examining dark web markets and the techniques cybercriminals use to collect, resell or &hellip;<\/p>\n","protected":false},"author":1,"featured_media":141014,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-141013","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/141013","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=141013"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/141013\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/141014"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=141013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=141013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=141013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}