Website Security & Threat Management
Dispelling the Generative AI fear: how Cloudflare secures inboxes against AI-enhanced phishing

Dispelling the Generative AI fear: how Cloudflare secures inboxes against AI-enhanced phishing

3/4/2024 · Ayush Kumar, Bryan Allen

What this post added

This post details how Cloudflare's email security models are being enhanced to defend against AI-generated phishing and Business Email Compromise (BEC) attacks. It explains how LLMs can be used by attackers to create more convincing emails, but also highlights the inherent limitations and trade-offs. Cloudflare's existing machine learning systems, trained on billions of messages, are already equipped to detect these AI-enhanced threats by analyzing multiple signals beyond just text, including sender reputation, domain authenticity, communication patterns, and metadata. The post provides examples of how these signals are used to identify malicious emails, such as domain mismatches and recently registered domains, and discusses the importance of opportunity and data availability as bottlenecks for AI-driven attacks. It also reiterates the effectiveness of Cloudflare's existing email security products in protecting customers.

Read the original post ↗