Abstract
A rising digital economy implies more cybersecurity challenges. As organisations continue with their digital transformations, they need to implement pervasive cyber defense measures to comply with the corresponding severe security threats. The number of organisations and individuals falling victim to targeted attacks such as spear-phishing attacks is growing rapidly. Regardless of substantial exploration in mitigation systems, attackers today are becoming more sophisticated as they cultivate their techniques, employing advanced natural language (NL) capabilities to deceive email security systems. Game theory approaches based on cybersecurity are mostly concentrated on proposing defence algorithms against attacks. This work is comprehensively centred on the role of the attacker in spear-phishing attacks, using OpenAI text generating model Generative Pre-trained Transformer 2 (GPT-2) to generate emails with various malicious content. Attackers use those emails to attack a target and attempt to deceive the defence system. Considering the lack of theoretic analysis from the attacker's perspective, a non-cooperative zero-sum spear-phishing game model is proposed that allows an attacker to choose an optimal strategy for maximising payoff. Moreover, we calculated the Nash equilibrium (NE) in mixed strategies for the attacker-defender game and provided a reasonable scheme for an attacker to gain an advantage over the target.
| Original language | English |
|---|---|
| Title of host publication | IET Conference Proceedings |
| Publisher | Institution of Engineering and Technology |
| Pages | 178-184 |
| Number of pages | 7 |
| Volume | 2021 |
| Edition | 4 |
| ISBN (Electronic) | 9781839534300, 9781839535048, 9781839535741, 9781839535918, 9781839536045, 9781839536052, 9781839536069, 9781839536199, 9781839536366, 9781839536588, 9781839536793, 9781839536809, 9781839536816, 9781839536847, 9781839537035 |
| DOIs | |
| Publication status | Published - 2021 |
| Event | 7th Competitive Advantage in the Digital Economy, CADE 2021 - Virtual, Online Duration: 2 Jun 2021 → 3 Jun 2021 |
Conference
| Conference | 7th Competitive Advantage in the Digital Economy, CADE 2021 |
|---|---|
| City | Virtual, Online |
| Period | 2/06/21 → 3/06/21 |
Keywords
- EMAIL GENERATION
- GAME THEORY
- GPT-2
- NASH EQUILIBRIUM
- SPEAR-PHISHING ATTACKS