Defending Against Generative AI-Based Social Engineering

所在平台: Udemy

课程主页: https://www.udemy.com/course/social-engineering-genai/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:针对生成性人工智能社会工程的防御 课程概述: 本课程旨在帮助用户和企业抵御社会工程攻击,尤其是利用生成性人工智能(AI)加速的攻击。课程内容涵盖生成性AI的基本知识,包括其模型、特征和潜在滥用方式;社会工程的基本概念及其手段;生成性AI如何在社会工程中加速攻击手法,导致更复杂、更快速的大规模攻击。 课程内容包括: 1. **生成性人工智能基础**:学习模型类型、生成内容的特性以及因疏忽或恶意而导致的滥用情况。 2. **社会工程基础**:理解社会工程的概念,包括操纵个人以获取信息的技术及其促成因素。 3. **生成性AI与社会工程的结合**:探讨生成性AI如何使攻击更加复杂化、快速化和针对性。 4. **生成内容的类型与检测**:关于文本、图像、音频和视频等生成内容类型的应用与检测方法。 5. **高级钓鱼与身份冒充**:学习如何应对利用生成性AI进行的身份冒充与钓鱼攻击。 6. **情感操控与超个性化**:了解攻击者如何利用情感操控策略影响个体决策。 7. **防御措施**:课程将详细介绍机构防御的策略,包括员工培训、文本证实、行为分析及身份验证等。 8. **技术与政策防御**:学习如何利用技术工具自动识别和防御生成内容的威胁,并建立相应的政策和文化。 9. **应对与恢复**:理解对生成性AI社会工程攻击的应对策略,包括风险评估、响应与恢复流程。 通过本课程,您将掌握抵御利用生成性AI加速的社会工程攻击的技能和策略,提升自己和组织的安全防范能力。

课程评论(0条)

课程详情

DON'T GET ENGINEEREDSocial engineering, such as phishing, is one of the biggest problems for corporations - and users - in terms of security.And the advent of generative AI.has just made it worse.In the world of today, companies and individuals must be able to not only resist social engineering and phishing, but resist it when it leverages generative AI - which means faster, larger-scale, more sophisticated attacks.This course will teach you how to protect against social engineering, when social engineering is accelerated by generative AI.LET ME TELL YOU.EVERYTHING.Some people - including me - love to know what they're getting in a package.And by this, I mean, EVERYTHING that is in the package.So, here is a list of everything that this course covers:You'll learn the basics of generative AI and what it can do, including common models and families of models, the characteristics of generative content, and how it can be misused due to negligence or active malevolence (including biases, misinformation, impersonation and more);You'll learn the basics of social engineering and what it consists of (manipulating someone to access information you otherwise would not), including common approaches and the facts that enable it (social norms, weak OPSEC, etc);You'll learn the basics of social engineering with generative AI, including how it accelerates approaches (more sophisticated attacks, faster attacks, on larger scales, with micro-targeting), the major approaches that are affected (such as impersonation or more convincing pretexts), and the major defenses that are also affected (sophisticated detection mechanisms, MFA, behavioral analytics, faster IR, etc);You'll learn about an overview of the major generative content types used in social engineering attacks (text, image, audio and video), including the specific approaches that each leverage, the model training requirements and data required for attackers to train such models, and how each type can be detected;You'll learn about generative text, including the models that enable it (e.g., LLMs), the usual distribution channels (messages, emails, social media profiles), the required data to train such models (text samples, including specific ones), and how it can be detected (inconsistencies in facts, spotting specific text styles and patterns, detecting emotional manipulation patterns);You'll learn about generative image, including the models that enable it (e.g. GANs, diffuser models, VAEs), the usual distribution channels (social media or specific platforms, such as for false documents), the required data to train such models (a variety of images, possibly of specific people or documents), and how it can be detected (artifacts, elements that meld into each other, doing reverse image searches, etc);You'll learn about generative audio, including the models that enable it (e.g., TTS models, GANs), the usual distribution channels (VoIP or cellular calls, messaging apps, social media posts), the data required to train such models (audio samples, possibly of a specific individual), and how it can be detected (mismatches in speech patterns, accent, tone, or with automated detectors);You'll learn about generative video, including the models that enable it (e.g. GANs, deep learning video models, motion transfer models), the usual distribution channels (video platforms such as YouTube/Vimeo, social media such as FB/IG/TikTok, or publications/news outlets), the required data to train such a model (a variety of footage, including possibly of a specific person or situation), and how it can be detected (mismatches in gestures, facial expressions, lack of synchronization in lip movement, etc);You'll learn about the advanced impersonation approach, where fraudsters impersonate someone, such as via text, or with an audio/video deepfake, as well as how it's executed, the specific types of consequences it has and how to defend against it;You'll learn about the hyper-personalization approach, where fraudsters create messages or bait that is targeted at a person's specific tastes or preferences, as well as how it's executed, the specific types of consequences it has and how to defend against it;You'll learn about the emotional manipulation approach, where fraudsters create content made to polarize someone in terms of emotions (positive or negative), to get them to make a rash decision without using logic, as well as how it's executed, the specific types of consequences it has and how to defend against it;You'll learn about advanced pretexting, where the fraudster uses an excuse/pretext to obtain information - but a very realistic one created with generative AI - as well as how it's executed, the specific types of consequences it has and how to defend against it;You'll learn about automated/scalable attacks, where fraudsters simply overwhelm defenses by launching attacks en masse, causing disruption and straining resources, as well as how it's executed, the specific types of consequences it has and how to defend against it;You'll learn about defending your organization with awareness and training, but specifically educating employees on the specific social engineering approaches that leverage generative AI, as well as including these in training programs, and motivating employees to be skeptical and report suspicious situations without pushback;You'll learn about defending your organization with text corroboration, verifying facts and context in communications sent, either with manual search or automated retrieval of facts, as well as pointers that can be used to identify suspicious inconsistencies in generative text (in the conclusions, in the facts, in the possible lack of congruence with similar communications, etc);You'll learn about defending your organization with mannerism analysis, analyzing nuances and incongruencies in someone's speech patterns, facial expressions, and/or body language gestures and posture, identifying telltale signs of AI-generated audio and video;You'll learn about defending your organization with identify verification measures - a practice that is standard, but that is not enough anymore, as-is, in a world where fraudsters can imitate someone's likeness in a realistic manner;You'll learn about defending your organization with technological defenses that can automate some of the flagging and removal of generative content, including content analysis tools, automated deepfake detectors, and/or behavioral analysis tools that can detect anomalies in behavior;You'll learn about defending your organization with policies and culture, defining specific types of generative threats and controls for each, defining strict processes with no exceptions, and promoting a culture of reporting suspicious actions (even with high-status clients and executives!);You'll learn about what changes, in an organization's defense strategy, due to generative AI threats - what are the defense mechanisms that stay the same in this "new world", and what are the defense mechanisms that are, additionally, necessary due to new generative threats;You'll learn about an overview of the detection and triage of attacks for generative threats, including calculating risk levels for generative threats, prioritizing these threats and dealing with them, as well as the general process of detecting and integrating these threats in the organization;You'll learn about an overview of responding to, and recovering from, social engineering attacks with generative AI, including steps such as containing or mitigating these threats, doing in-depth investigations, recovering from these, and making changes to defense mechanisms based on feedback;

课程标签

0人关注该课程

主题相关的课程