{"id":41338,"date":"2023-09-14T13:32:30","date_gmt":"2023-09-14T17:32:30","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=546786"},"modified":"2023-09-14T13:32:30","modified_gmt":"2023-09-14T17:32:30","slug":"how-to-defend-your-organization-against-deepfake-content","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/how-to-defend-your-organization-against-deepfake-content\/","title":{"rendered":"How to defend your organization against deepfake content"},"content":{"rendered":"<p>IT departments should implement real-time audio and video verification capabilities, passive detection techniques, and better protection of high-priority officers and their communications to defend against AI-generated deepfake messaging, say American cyber intelligence agencies.<\/p>\n<p>\u201cThe tools and techniques for manipulating authentic multimedia are not new, but the ease and scale with which cyber actors are using these techniques are. This creates a new set of challenges to national security,\u201d said Candice Rockell Gerstner, a specialist in multimedia forensics at the U.S. National Security Agency (NSA). \u201cOrganizations and their employees need to learn to recognize deepfake tradecraft and techniques and have a plan in place to respond and minimize impact if they come under attack.\u201d<\/p>\n<p><a href=\"https:\/\/media.defense.gov\/2023\/Sep\/12\/2003298925\/-1\/-1\/0\/CSI-DEEPFAKE-THREATS.PDF\"  rel=\"noopener\">In a report<\/a> issued Tuesday by the NSA, the FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) say there are currently limited indications of significant use of synthetic media techniques by malicious state-sponsored actors. However, they warn the increasing availability and efficiency of synthetic media techniques available to less capable malicious cyber actors means deepfake content will likely increase in frequency and sophistication.<\/p>\n<p>The term \u201cdeepfake\u201d refers to multimedia that has either been synthetically created or manipulated using some form of machine or deep learning (artificial intelligence) technology.<\/p>\n<p><a href=\"https:\/\/www.itworldcanada.com\/article\/the-future-of-cybersecurity-is-ai-deep-fakes-and-ransomware-maplesec-conference-told\/459781\"  rel=\"noopener\"><strong>Related content: The future of cybersecurity is AI and deepfakes<\/strong><\/a><\/p>\n<p>Employees may be vulnerable to deepfake tradecraft and techniques, which may include fake online accounts used in social engineering attempts, fraudulent text and voice messages used to avoid technical defenses, faked videos used to spread disinformation, and other techniques, the report says.<\/p>\n<p>Malicious actors may use deepfakes with manipulated audio and video to try to impersonate an organization\u2019s executive officers and other high-ranking personnel for, among other things, convincing employees to shift funds to bank accounts controlled by crooks. Or to disrupt an organization&#8217;s reputation or share price.<\/p>\n<p><a href=\"https:\/\/www.itworldcanada.com\/article\/deepfakes-fueling-the-online-anarchy-researchers-weigh-in-on-the-complexities-of-regulation\/543830\"  rel=\"noopener\"><strong>Related content: Deepfakes fueling online anarchy<\/strong><\/a><\/p>\n<p>There was a huge increase in deepfake images for LinkedIn profile pictures last year, the report notes. In 2019, deepfake audio was used to steal the equivalent of US$243,000 from a U.K. company. And in May an AI-generated scene depicting an explosion near the Pentagon caused &#8220;general confusion and turmoil on the stock market,&#8221; the report adds.<\/p>\n<p>The report says organizations should<br \/>\n&#8212; implement identity verification capable of operating during real-time communications. This can include testing to prove an image is live, mandatory multi-factor authentication using a unique or one-time generated password or PIN for logging into video calls, and using known personal details, or biometrics, to ensure those entering sensitive communication channels or activities are able to prove their identity;<\/p>\n<p>&#8212; use tools that look for compression artifacts, as well as those that can verify reflections and shadows, in video communications;<\/p>\n<p>&#8212; consider using open source tools found on <a href=\"https:\/\/github.com\/NVlabs\/stylegan3-detector\"  rel=\"noopener\">GitHub, like Nvidia&#8217;s StyleGAN3 Synthetic Image Detection<\/a>;<\/p>\n<p>&#8212; look for physical properties in videos that would not be possible, such as feet not<br \/>\ntouching the ground;<\/p>\n<p>&#8212; protect company-created media like promotional or training videos from being copied using tools like watermarks. Organizations should also partner with media, social media, career networking, and similar companies in order to learn more how these companies are preserving the provenance of online content;<\/p>\n<p>&#8212; train employees how to spot deepfake audio and video content. Training resources specific to deepfakes include the SANS Institute&#8217;s blog \u201c<a href=\"https:\/\/www.sans.org\/newsletters\/ouch\/learn-a-new-survival-skill-spotting-deepfakes\/\"  rel=\"noopener\">Learn a New Survival Skill: Spotting Deepfakes;\u201d<\/a> and MIT Media Lab&#8217;s blog <a href=\"https:\/\/www.media.mit.edu\/projects\/detect-fakes\/overview\/\"  rel=\"noopener\">\u201cDetect DeepFakes: How to counteract information<\/a><br \/>\n<a href=\"https:\/\/www.media.mit.edu\/projects\/detect-fakes\/overview\/\"  rel=\"noopener\">created by AI\u201d.<\/a><\/p>\n<p>The post <a href=\"https:\/\/www.itworldcanada.com\/article\/how-to-defend-your-organization-against-deepfake-content\/546786\">How to defend your organization against deepfake content<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Advice from the FBI, NSA and CISA on spotting and preventing your firm from being victimized by deepfake audio<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[21,16],"tags":[391,396,393,275],"class_list":["post-41338","post","type-post","status-publish","format-standard","hentry","category-emerging-tech","category-security","tag-di","tag-postmedia","tag-security-strategies","tag-top-story"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/41338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=41338"}],"version-history":[{"count":1,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/41338\/revisions"}],"predecessor-version":[{"id":41339,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/41338\/revisions\/41339"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=41338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=41338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=41338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}