Analysis and Prevention of AI-Based Phishing Email Attacks

被引:0
|
作者
Eze, Chibuike Samuel [1 ]
Shamir, Lior [1 ]
机构
[1] Kansas State Univ, Dept Comp Sci, Manhattan, KS 66506 USA
关键词
phishing; cybersecurity; SPAM;
D O I
10.3390/electronics13101839
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing email attacks are among the most common and most harmful cybersecurity attacks. With the emergence of generative AI, phishing attacks can be based on emails generated automatically, making it more difficult to detect them. That is, instead of a single email format sent to a large number of recipients, generative AI can be used to send each potential victim a different email, making it more difficult for cybersecurity systems to identify the scam email before it reaches the recipient. Here, we describe a corpus of AI-generated phishing emails. We also use different machine learning tools to test the ability of automatic text analysis to identify AI-generated phishing emails. The results are encouraging, and show that machine learning tools can identify an AI-generated phishing email with high accuracy compared to regular emails or human-generated scam emails. By applying descriptive analytics, the specific differences between AI-generated emails and manually crafted scam emails are profiled and show that AI-generated emails are different in their style from human-generated phishing email scams. Therefore, automatic identification tools can be used as a warning for the user. The paper also describes the corpus of AI-generated phishing emails that are made open to the public and can be used for consequent studies. While the ability of machine learning to detect AI-generated phishing emails is encouraging, AI-generated phishing emails are different from regular phishing emails, and therefore, it is important to train machine learning systems also with AI-generated emails in order to repel future phishing attacks that are powered by generative AI.
引用
下载
收藏
页数:13
相关论文
共 50 条
  • [1] How to prepare for the onslaught of phishing email attacks
    Burke, Stephen
    Computer Fraud and Security, 2021, 2021 (05): : 12 - 14
  • [2] Digitally-Signed Video/Audio Streams as Prevention of AI-Based Attacks
    Galiautdinov, Rinat
    INTERNATIONAL JOURNAL OF SOFTWARE SCIENCE AND COMPUTATIONAL INTELLIGENCE-IJSSCI, 2021, 13 (04): : 54 - 63
  • [3] Analysis and Prevention of Phishing Attacks in Cyber Space
    Mishra, Alekh Kumar
    Tripathy, Asis Kumar
    Swain, Satyabrata
    2018 FIRST INTERNATIONAL CONFERENCE ON SECURE CYBER COMPUTING AND COMMUNICATIONS (ICSCCC 2018), 2018, : 430 - 434
  • [4] Attribute-based Prevention of Phishing Attacks
    Atighetchi, Michael
    Pal, Partha
    2009 8TH IEEE INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS, 2009, : 266 - 269
  • [5] A framework to assist email users in the identification of phishing attacks
    Loetter, Andre
    Futcher, Lynn
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (04) : 370 - 381
  • [6] A FRAMEWORK FOR SECURING EMAIL ENTRANCES AND MITIGATING PHISHING IMPERSONATION ATTACKS
    Nmachi, Wosah Peace
    arXiv, 2023,
  • [7] AI-based microbiome analysis
    Song, J. S.
    CLINICA CHIMICA ACTA, 2022, 530 : S4 - S4
  • [8] Novel interpretable and robust web-based AI platform for phishing email detection
    Al-Subaiey, Abdulla
    Al-Thani, Mohammed
    Alam, Naser Abdullah
    Antora, Kaniz Fatema
    Khandakar, Amith
    Zaman, S. M. Ashfaq Uz
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 120
  • [9] Online detection and prevention of phishing attacks
    Institute of Communications Engineering, PLA Univ. of Sci. and Tech., Nanjing 210007, China
    Jiefangjun Ligong Daxue Xuebao, 2007, 2 (133-138): : 133 - 138
  • [10] The (Relative) Impact of Email Cues on the Perceived Threat of Phishing Attacks: A User Perspective on Phishing Deceptiveness
    Burda, Pavlo
    Kokkini, Maria Eleni
    Allodi, Luca
    Zannone, Nicola
    9TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS, EUROS&PW 2024, 2024, : 67 - 84