Business Email Compromise Detection Challenges with IRONSCALES’ Eyal Benishti
IRONSCALES CEO Eyal Benishti explains how generative artificial intelligence (AI) is going to make business email compromise (BEC) much more challenging to detect.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with the Al Bei, who is CEO for iron scales, and we're talking about the impact that AI is about to have on business email compromise, which is already a major problem and might be getting worse before it gets any better.
Yeah, welcome to the show. Thank you. Happy to be here.
What should we be on the lookout for? It seems like these types of attacks are getting more sophisticated and harder to detect, but to what degree? So we see a huge increase in the volume and sophistication of this type of attack.
As you probably know, business email compromise, uh, the type of phishing emails that are most social engineer that were geared toward, kind of lewing someone to do something that is not supposed to to do. So it's highly intentional, um, focused unlike, you know, what we call the bulk phishing or the low level phishing. Well, threat actors, traditionally were trying to use to trying, we're trying to lose someone to click on a link or, um, open an at attachments and try to install something on his endpoint or stealing credentials with business similar compromise.
You'll see more attempts to kind of, um, make someone pay, uh, a fake invoice or, um, make a wire request that he's not supposed to do or change a database records, uh, with bank account details and, and stuff like that. So these attacks are highly targeted, highly contextualized, and are more skilled and, and and focused on hack hacking the business process. Like we, we like to call it, like, you know, let's, let's try and make someone do something that is not supposed to do without his selling anything on his, on his endpoint.
Just, just drive this type of action that can be, um, helpful for the organization. It also seems like even before AI, that these folks were lurking longer inside the process and kind of making themselves feel like a more natural part of it before they strike. Yes.
So there are, there are two main kind of methods, um, that these guys are using. One of them is, like you, you mentioned, they're lurking. They're already inside the account and they're waiting for the, um, for the best time to kind of, you know, jump in and, um, basically, uh, do whatever they're trying to do.
Um, so they're jumping on existing threads. The second one is more like, you know, it's, it's still a more planned play type of attack. Like they know that if, for example, if they impersonate or spoof the sea of the company and send someone inside the company, um, an email asking them to do something, there is a big chance that this person will go, um, and do that.
So, so even when you think about basically there are different levels, uh, and different types of business, semi compromised, um, attacks as we see them, uh, today On the AI front, what types of tools are these folks using? I mean, theoretically there are, uh, guardrails that prevent generative AI platforms from being abused, at least the public ones or cyber criminals creating their own, or are they getting around those guardrails First? There are ways to kind of walk around those guardrails and full, um, you know, the, the commercial tools into, at the end of the day generating the, the phishing emails that you want them to, to generate.
5. And generally this is all they need these days in order to be able to generate, to generate high, highly sophisticated BC emails on, on a high volume, Our email gateway is gonna be able to detect these threats, or do we need to revamp them as well? So we have AI to fight AI because it doesn't sound like the average employee's gonna be able to detect the proverbial Nigerian print scam because of misspellings.
We, we will definitely need ai, excuse me, not just that we need ai, we need ai, like AI is a tool, okay. And we're using AI and NLP in this specific case and anomaly detection in order to, to detect BC um, attacks. But I think what is very important, especially in the context of business similar compromise, is what data are we feeding into the ai?
Because the AI is just as good as the data is as as we feed, uh, into it and we train, um, the AI on. So if you think about it from a gateway level perspective, you know, they mostly see the in inbound and outbound traffic into the organization, but they have nothing, um, about what's happening internally and how users are behaving and acting and communicating internally. So this is a huge blind spot for gateway level or perimeter based, um, solution.
When you look at the more modern kind of solutions, they're looking at everything and collecting more data points and more references in order to build a more comprehensive behavioral kind of model of the organization, which helps to flag out and, and stop, uh, business similar compromise and everything that is basically deviating for what we consider to be normal or trusted inside, uh, the organization. So it might be confusing 'cause SEC sectors can use AI as well, but at, at the end of the day, it's all about what kind of data do you see, what kind of behavior you can, uh, you can profile that can get you to the point that you can leverage on this super powerful tool in order to stop, uh, pc. And yes, at the end of the day, especially with the volumes that are increasing every, every day now, it'll be an AI versus ai, um, kind of, um, wall.
Uh, but, and it's, it's, it's a very important, uh, important one. Even when it comes to ai. We will not be able to detect 100% of the PCs and other stuff that they're towing at us because like I mentioned, we only know to detect bad intent that we've seen in the past.
If they try to lure you to pay a invoice or they're trying to lu you to wire money or buy cards or run, run a task on a, on an end, these types of bad intents we already turned the machine to, to recognize. But we, we know that, you know, based on everything that we've seen in the history of cybersecurity, that is a cat and a mouse type of, uh, game. And they will come with new scams and new kind of bad intents and ways, um, you know, to, you know, at the end of the day, and if you look at the cyber cyber criminals world, it's obviously monetization and making money.
So they will find new ways, uh, to do that and even, um, bypass AI based detection. I think that creating, having a super strong AI on your side to be able to filter out 99% of this bad stuff, but create a culture inside the organization that is very cybersecurity focused and make make sure that people understand that hey, we're putting the best tools that we can, that we can and we're deploying the best technology, AI powered, but you still need to stay vigilant. You still need to be able to kind of, you know, um, let us know and raise your hand when you see something that, uh, is suspicious.
And, and in this case, there is a huge opportunity to take AI and change the end user experience as well and augment user experience because we could not expect them, uh, to look into every single, uh, tiny details. So by using AI in order to augment and, and improve their, uh, their experience, we can help them and we can guide them to things that they maybe need to take, uh, a second look or look deeper and potentially report to their, uh, security team. So the combination of AI as a detection tool that we're using in order to detect PC and AI generated pc uh, solution, and people that are highly aware and understand like, you know, even the limitations of AI and what AI can do for them and are now empowered with a an augmented end user experience to be part of this detection, to be part of the security organization, this is the opportunity that currently organizations have in order to basically equip their security teams and their end users with a better way to fight BC attacks.
You mentioned increasingly sophisticated, and we hear the phrase deep fake all the time. Is this gonna be more than just text driven? It's gonna be audio and video and just how complicated or, um, a challenge are we looking at?
Absolutely. Um, we already started to think about how ong the text, um, will look like, like imagine, um, get getting a fake email from someone that you supposedly know and then, uh, a follow up by a text message, and then they will leave you a, a fake voicemail, um, on your mobile because it's very, very easy to deepfake their voice and the next generation. And we already see some first signs for that.
They might even call you on Zoom and you will see this person kind of talking with you and interacting with you and everything will just make sense because it's all fully correlated between the email, the text, the voicemail and, and the video conference on the video chat that you are just, uh, doing. And most of us, we will, we will never know that we are not speaking with a real person and this well coordinated type of, uh, text using deep fake absolutely something that we need to start think about. And again, it has to do with the type of technical controls that we can put in place and the awareness that we need to provide to our users.
So they know that these things are possible these days. So if someone is calling you and or leaving a voicemail, it sounds exactly like your boss or your peer or, or whoever, uh, it, it might not be them. So you need to be very, very, um, careful and, and, and validate every, every communication that is inbound that is coming your way that you has ha haven't initiated, uh, originally.
So is this gonna become much like the way we use the phone today? If I don't know who you are, I don't answer it. So, uh, if I have an email, I'm not gonna open it.
'cause I don't know who you are. So I mean, how's, how will this change our behavior and what's the impact on the way we do business today? Well, it doesn't, that heel is not a secure channel.
It was not designed to be, uh, with security in mind. We need to be, we need to stay suspicious. And I believe that as things will move forward, we'll find more secured way to, to communicate with each other.
We know that even, even more secured kind of communication channels like Microsoft Teams and Slack are now being used by, uh, by the bad guys, uh, because they know that we, we tend to trust more things that are being communicated using, uh, collaboration tools. But I see a shift, I see a world that is evolving into understanding that there are some mediums that are less trusted. We need to be very suspicious and gradually move our passive communication, um, to different platform.
All right. So it's gonna be 2024. Um, what's your best advice to the cybersecurity folks?
How do I have this conversation with folks without them looking at me like I'm running around saying the sky has fallen? I think it's important to make sure that they understand that PC and fishing is, is is not just a, it's not gonna be be just a pure businesses in terms of what, um, what people might do if they're receiving a BC email. I think it's important to understand that it's gonna be an operational kind of challenge for them, because what we see and what we think will happen is that they will experience BC and phishing at the same levels and volumes that we've experienced spam in the past because these kind of things can be generated automatically now with all models and generative ai, the volumes, uh, will increase.
So having an AI and N-L-P-L-L-M power kind of AI on your side, it's gonna be not a nice drive. It's gonna be a must have. Otherwise, again, if you're still the more traditional ways to filter out bad emails, um, it'll be a problem, both risk and operational problem, uh, for organization.
And at the same time, keep, keep investing in, in, in your employees and your users. Increase awareness, educate them, and make sure they understand, uh, the technology and understand the risk. Do you think as we kinda look at all of this and there needs to be a more, shall we say, uh, adult conversation between the security teams and the rest of the business folks, do they get it?
Because I think maybe a lot of them are making some assumptions about how to use AI and the technologies without maybe considering what the bad guys are up to. So I'm have, it's a good question. I'm having a lot of conversations with CSOs and other security professional, uh, these days, and I can tell you for sure that generative AI and the potential risk are now things that are being discussed at the board level.
I think that, um, many, many organizations and many boardrooms now understand that it's, it's a, it's a real risk that it's something that we need to start, um, addressing now and not wait until it's become, um, more than that, uh, or think something bad, um, happens. So I think it's, it's our job and it's our, uh, you know, security partners job to keep educating, keep educating everyone, educate your employees, educate your, um, your board and your management and senior leadership about what, what this technology is, what are the potential risk and start planning now, um, and implementing now things that can help keep the organization more secured. Phishing email is just one threats that generative ai, um, is introducing, um, to the business world.
We already know that this type of technologies could even generate, uh, malware malicious, uh, software and change existing malware, uh, to be, um, undetected and some other new challenges, not to mention data leak prevention and, and stuff like that. So it's a, it's a big, it's a big thing and it's now being seriously discussed, like it should. All right folks, you're to hear it.
If you thought fraud and business email compromise was challenging now you ain't seen nothing yet, it's gonna be much more so as we go forward and we'll see how we all respond. Hey Al, thanks for being on the show. Thank you very much.
It was a pleasure. Alright, And back to you guys in the.