Active Social Engineering Defense Using Large Language Models
摘要
Digital social engineering attacks are typically characterized as having a low probability of success with success rates increasing only after bidirectional contact with the victim has been established [31]. Thus, the attackers business model has to value the time investment accordingly. In this paper a concept to utilize the surge in quality of Large Language Models (LLM) to automatically generate responses to social engineering messages is proposed. This forces the attacker to incur additional manual effort reading and replying to these responses. From the attackers point of view this increases the time expenditure in some stages of an attack without increasing their success probability for the individual victim. The proposed concept is a multi-step process and designed to be agnostic to the LLM and the digital communication medium. At its core, the concept creates a believable fictitious identity including personality traits to make the output of the LLM more realistic and thus decrease the likelihood of detection on the attacker side. The proposed concept is analyzed on challenges arising in real-world application and implemented as a proof-of-concept demonstrating the general feasibility of the approach. It was possible to show that given some assumptions a significant asymmetry in costs-incurred between the attacker and defender exists that heavily favor the defenders side. This indicates the necessity of further research into the viability and effectiveness of the approach in a real-world deployment. Given that this evaluation has not yet been conducted it is not possible to evaluate the effectiveness and scalability of the concept in regards to the social engineering landscape.