https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Getty Images

Sponsor Content

what MSPs should know about ChatGPT

What MSPs Should Know about ChatGPT

  • Written by Barracuda MSP Guest Blogger
  • February 24, 2023
Cybercriminals are already trying to leverage AI-based tools in their attacks, so security professionals need to be prepared.

The AI-based natural language processing tool ChatGPT has been a hot topic online and in the press, and it has inspired numerous debates about its potential uses —and abuses. For example, it can help streamline computer code writing and generate legitimate-sounding term papers and marketing copy. This poses ethical dilemmas (will students use it to cheat?) and is causing panic among copywriters across various industries who fear being replaced by an AI algorithm.

But a more immediate ChatGPT-related threat will likely come from cybercriminals. Anyone familiar with common cyberattacks would immediately recognize the utility of a convincing copy generator for creating credible phishing emails and other content that could make it easier to launch business email compromise (BEC) and other attacks.

Efficient, Yet Dangerous in the Wrong Hands

While ChatGPT does include internal guardrails to keep criminals from directly using it to create scam emails (and other types of objectionable content), several companies and researchers have found ways to rephrase their requests to create such emails. This capability will make experienced hackers more efficient and lower the entry threshold for newbies who could create more effective phishing campaigns using the platform. (A writer at Forbes even got ChatGPT to explain its cybersecurity risks.)

Additionally, an AI tool in the wrong hands could even be used to enable realistic-sounding online conversations via email or messenger. For instance, the algorithm could be trained to mimic a typical exchange or even be trained to create responses that look like those issued by specific people (for example, a company executive or finance officer). AI could also be used as malicious customer service chatbots that trick users into giving up personal or financial information.

If an attacker had already gained access to an email account, they could use the text from the compromised account to train a model to write emails in the style of a specific user. In these scenarios, even if the potential victim of a scam asks a question, ChatGPT can provide plausible answers and conduct an entire conversation professionally. For example, a bot could be created to mimic the CEO of a company to trick the CFO into making a financial transfer. In that case, there would not be any way (outside of a confirmation phone call) to verify their identity.

One of the most prominent commercial use cases for such tools is generating marketing content since that type of content usually follows simple templates and is not very novel. And phishing emails are, essentially, marketing messages from criminals. ChatGPT could craft thousands of variations of the same phishing email to avoid detection — in any language. Security tools that rely on natural language processing (like traditional spam filters) would be vulnerable to this type of manipulation.

It could also replicate an existing, legitimate website or login page.

Malicious Coding Made Easy

There are other ways criminals can leverage the technology. For example, hackers could use ChatGPT or a similar tool to generate malicious code. There are already malware-as-a-service offerings on the internet; with an AI-based tool, even relatively inexperienced hackers could generate complex code. In addition, there is already evidence of some bad actors using ChatGPT to create malicious Java scripts and Python-based malware.

More importantly, the underlying technology could be pulled into an open-source environment, allowing criminals to create a custom-built guardrail-free version of the AI tool for cyberattacks.

It is not a question of if but when cybercriminals begin leveraging these AI-based capabilities in their attacks. Therefore, security professionals must be prepared to train users to spot more convincing phishing emails and deploy AI-based security solutions to help identify and mitigate these attacks faster.

The good news is that ChatGPT’s ability to write malicious code is marred by the same glitches in its ability to generate other types of content: It is often close but flawed in ways that a careful reader can quickly spot. Some requests for written content, for example, can result in “sort-of correct” results but occasionally descend into a word salad. In addition, the malicious code researchers have been able to coax out of the program is often so obviously malicious that it would be easily detected by security software.

But AI-based platforms evolve, and the platform could conceivably learn to create more effective code or more convincing phishing emails over time. Therefore, security teams must be ready with their own advanced AI-based security tools (to help spot cleverly crafted attacks) and double down on end user education to help spot AI-generated phishing scams. In addition, security protocols should be put in place for operations like financial transfers that require phone confirmations, in-person interactions or multiple signoffs.

ChatGPT and similar tools are going to help cybercriminals be more effective. As a result, security approaches must evolve to meet this challenge and incorporate technology and human intervention to counteract these increasingly sophisticated attacks.

 

 Asaf Cidon is an assistant professor of electrical engineering and computer science at Columbia University and a Barracuda adviser.

 

This guest blog is part of a Channel Futures sponsorship.

Tags: MSPs Artificial Intelligence From the Industry Intelligence Security Technologies Barracuda MSP Sponsor Content

Most Recent


  • Making Waves
    8 Channel People Making Waves This Week at Lumen, Accenture, Amazon, Canalys, More
    Cisco led a “crowded” secure access service edge (SASE) market in terms of revenue in 2022, experts said.
  • network in the cloud
    Fortinet, Huawei, Palo Alto, VMware Lauded in Gartner Peer Insights SD-WAN Study
    Thousands of customers have weighed in on how their SD-WAN vendors have performed.
  • Do AWS, Azure, Google, Oracle, Others, Have Too Much Market Power?
    The FTC, concerned about cloud vendors’ sway over customers, is seeking public comment.
  • Unemployed, layoffs
    Veeam Layoffs Impact 200 Workers, Company Remains 'Strong, Profitable'
    Veeam continues to hire for roles in R&D.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • How Hybrid Work Poses Major Cybersecurity Risks
    How Hybrid Work Poses Major Cybersecurity Risks
  • customer lifetime value
    How Well Do You Know Your Customer?
  • cyber insurance
    Cyber Insurance: 5 Things It Does Not Cover
  • Think outside the rack enclosure box
    Think ‘Outside’ the Rack Enclosure Box

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

8 Channel People Making Waves This Week at Lumen, Accenture, Amazon, Canalys, More

March 24, 2023

National Women’s History Month: Channel Women Have Stories to Tell

March 24, 2023

VEC Attack Tries to Steal $36 Million, Ferrari, Dole Hit with Ransomware Attacks

March 23, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

Channel people making waves include: @jmcbain, @NetworkMoe, @ajassy, @JulieSweet, @Elvia_Valdes_M, @GovITDave… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

We delve into AI impacting the channel, this week featuring @nvidia, @GoTo, @twilio and more.… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

[email protected]_Inc's Peer Insights are a treasure trove for partners looking to sell #SDWAN. dlvr.it/SlRDmk https://t.co/oElLXzOIbb

March 24, 2023
ChannelFutures

#CPExpo preview: @GlobalIndirect of @AryakaChannel with a preview of the next phase of the company's channel progra… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

U.S. competition regulators want to know if @AWSCloud, @Azure, @GoogleCloud, @OracleCloud hold too much market powe… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

📣 Join us on April 13th to hear from the 2023 Channel Influencers and get their insights on the state of the channe… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

#CPExpo preview: Learn about why @USWired accepted an #acquisition deal and what partners should look for in an M&A… twitter.com/i/web/status/1…

March 24, 2023
ChannelFutures

.@Veeam lays off 200 workers to increase efficiency. #backupandrecovery dlvr.it/SlQWZW https://t.co/QTJx1NX69q

March 24, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X