现代信使中的社会工程:攻击性安全的应用

Iryna STOPOCHKINA, Mykola ILYIN, Oleksandra PONOMARENKO
{"title":"现代信使中的社会工程:攻击性安全的应用","authors":"Iryna STOPOCHKINA, Mykola ILYIN, Oleksandra PONOMARENKO","doi":"10.32782/it/2023-2-10","DOIUrl":null,"url":null,"abstract":"The work considers the problems of social engineering in modern messengers, and provides classification indicators for modern attacks. Attention is focused on the Telegram messenger, whose channel owners and visitors to these channels may suffer from the intervention of fraudsters who cannot always be identified in time. Fraudsters or malicious bots are exposed and removed as a result of certain user complaints, very often when the purpose of the malicious intervention has already been realized. This indicates the need to develop new proactive solutions. The purpose of this work is to enrich offensive security mechanisms for social messengers by using bots and artificial intelligence using specially created prompts. The novelty of the work. It is proposed to place a kind of honeypot analogues in the space of communication. The role of the decoy victim is given to a specially configured bot disguised as a user, capable of carrying out a conversation according to a given scenario. The bot’s algorithm has been developed. Methodology. Social engineering is seen as a proactive security tool aimed at identifying vulnerabilities that attackers can exploit, as well as a reverse defense by obtaining information from fraudsters that compromises them. Main results. The work successfully combined developed offensive security scenarios for real Ukrainian chats at the time of the research, with the capabilities of ChatGPT, which made it possible to implement a bot, with the ability to communicate according to the scenario specified by the security specialist. Testing of the bot and the corresponding application in the Telegram channel was carried out, with the consent of real users, which proved the workability of the solution. Conclusions. The modern level of artificial intelligence tools allows one to obtain valuable information about attackers in the information space, conduct automated security testing, and implement other offensive security scenarios. Channel administrators can use the solution as a channel subscribers filtering tool.","PeriodicalId":486523,"journal":{"name":"Information Technology Computer Science Software Engineering and Cyber Security","volume":"3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-09-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"SOCIAL ENGINEERING IN MODERN MESSENGERS: APPLICATIONS FOR OFFENSIVE SECURITY\",\"authors\":\"Iryna STOPOCHKINA, Mykola ILYIN, Oleksandra PONOMARENKO\",\"doi\":\"10.32782/it/2023-2-10\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The work considers the problems of social engineering in modern messengers, and provides classification indicators for modern attacks. Attention is focused on the Telegram messenger, whose channel owners and visitors to these channels may suffer from the intervention of fraudsters who cannot always be identified in time. Fraudsters or malicious bots are exposed and removed as a result of certain user complaints, very often when the purpose of the malicious intervention has already been realized. This indicates the need to develop new proactive solutions. The purpose of this work is to enrich offensive security mechanisms for social messengers by using bots and artificial intelligence using specially created prompts. The novelty of the work. It is proposed to place a kind of honeypot analogues in the space of communication. The role of the decoy victim is given to a specially configured bot disguised as a user, capable of carrying out a conversation according to a given scenario. The bot’s algorithm has been developed. Methodology. Social engineering is seen as a proactive security tool aimed at identifying vulnerabilities that attackers can exploit, as well as a reverse defense by obtaining information from fraudsters that compromises them. Main results. The work successfully combined developed offensive security scenarios for real Ukrainian chats at the time of the research, with the capabilities of ChatGPT, which made it possible to implement a bot, with the ability to communicate according to the scenario specified by the security specialist. Testing of the bot and the corresponding application in the Telegram channel was carried out, with the consent of real users, which proved the workability of the solution. Conclusions. The modern level of artificial intelligence tools allows one to obtain valuable information about attackers in the information space, conduct automated security testing, and implement other offensive security scenarios. Channel administrators can use the solution as a channel subscribers filtering tool.\",\"PeriodicalId\":486523,\"journal\":{\"name\":\"Information Technology Computer Science Software Engineering and Cyber Security\",\"volume\":\"3 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-09-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Information Technology Computer Science Software Engineering and Cyber Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.32782/it/2023-2-10\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Technology Computer Science Software Engineering and Cyber Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.32782/it/2023-2-10","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

这项工作考虑了现代信使中的社会工程问题,并为现代攻击提供了分类指标。注意力集中在Telegram messenger上,其频道所有者和访问这些频道的人可能会受到欺诈者的干预,这些欺诈者往往无法及时识别。由于某些用户投诉,欺诈者或恶意机器人被曝光并被删除,通常在恶意干预的目的已经实现的情况下。这表明需要开发新的主动解决方案。这项工作的目的是通过使用机器人和人工智能来丰富社交信使的攻击性安全机制,并使用专门创建的提示。工作的新奇。提出在通信空间中放置一种蜜罐类似物。诱饵受害者的角色被赋予一个伪装成用户的特殊配置的机器人,能够根据给定的场景进行对话。机器人的算法已经开发出来了。方法。社会工程被视为一种主动的安全工具,旨在识别攻击者可以利用的漏洞,以及通过从危及它们的欺诈者那里获取信息来进行反向防御。主要的结果。这项工作成功地将研究时开发的针对真实乌克兰聊天的攻击性安全场景与ChatGPT的功能结合起来,这使得实现机器人成为可能,并能够根据安全专家指定的场景进行通信。在真实用户同意的情况下,在Telegram频道中对bot和相应的应用程序进行了测试,证明了该解决方案的可行性。结论。人工智能工具的现代水平允许人们在信息空间中获取有关攻击者的有价值信息,进行自动化安全测试,并实现其他攻击性安全场景。通道管理员可以将该解决方案用作通道订阅者过滤工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
SOCIAL ENGINEERING IN MODERN MESSENGERS: APPLICATIONS FOR OFFENSIVE SECURITY
The work considers the problems of social engineering in modern messengers, and provides classification indicators for modern attacks. Attention is focused on the Telegram messenger, whose channel owners and visitors to these channels may suffer from the intervention of fraudsters who cannot always be identified in time. Fraudsters or malicious bots are exposed and removed as a result of certain user complaints, very often when the purpose of the malicious intervention has already been realized. This indicates the need to develop new proactive solutions. The purpose of this work is to enrich offensive security mechanisms for social messengers by using bots and artificial intelligence using specially created prompts. The novelty of the work. It is proposed to place a kind of honeypot analogues in the space of communication. The role of the decoy victim is given to a specially configured bot disguised as a user, capable of carrying out a conversation according to a given scenario. The bot’s algorithm has been developed. Methodology. Social engineering is seen as a proactive security tool aimed at identifying vulnerabilities that attackers can exploit, as well as a reverse defense by obtaining information from fraudsters that compromises them. Main results. The work successfully combined developed offensive security scenarios for real Ukrainian chats at the time of the research, with the capabilities of ChatGPT, which made it possible to implement a bot, with the ability to communicate according to the scenario specified by the security specialist. Testing of the bot and the corresponding application in the Telegram channel was carried out, with the consent of real users, which proved the workability of the solution. Conclusions. The modern level of artificial intelligence tools allows one to obtain valuable information about attackers in the information space, conduct automated security testing, and implement other offensive security scenarios. Channel administrators can use the solution as a channel subscribers filtering tool.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信