Deceptive Intelligence: Ai, Social Engineering, and Securing the Human Element
暫譯: 欺騙性智慧:AI、社會工程與保護人類元素

Oriyano, Sean

  • 出版商: Apress
  • 出版日期: 2026-05-29
  • 售價: $1,560
  • 貴賓價: 9.8$1,528
  • 語言: 英文
  • 頁數: 751
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9798868821769
  • ISBN-13: 9798868821769
  • 相關分類: Penetration-test
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

This book explores the transformative impact of artificial intelligence on social engineering and testing, offering a timely and necessary guide for navigating one of the most pressing challenges in modern cybersecurity. AI is not only revolutionizing how attackers exploit vulnerabilities but also how defenders test and strengthen their systems. With over 80% of data breaches attributed to human error or social engineering, and phishing responsible for 36% of successful cyberattacks, the stakes for organizations are higher than ever. The rise of AI tools capable of automating these attacks has introduced new complexities, making it critical for organizations to adopt advanced strategies to test their resilience.

The book's core mission is to equip cybersecurity professionals with the tools, knowledge, and frameworks to counter these AI-driven threats ethically and effectively. Readers will discover how to simulate sophisticated AI-enabled attacks, from deepfake impersonations to multi-channel phishing campaigns, all while respecting ethical boundaries. Practical applications are emphasized, such as leveraging open-source tools to mimic real-world attack scenarios and using AI to analyze human vulnerabilities. It also provides actionable guidance on building defenses and training programs that reflect the rapidly evolving threat landscape.

As AI tools like ChatGPT, deepfake generators, and voice synthesis platforms become increasingly accessible, their misuse in crafting malicious campaigns is accelerating. Research shows that 83% of organizations experienced a successful phishing attack in 2022, while incidents involving deepfakes rose 300% compared to the previous year. Meanwhile, the widespread availability of personal information on social media has created fertile ground for AI-driven reconnaissance, making targeted social engineering easier and more effective than ever. This book directly addresses these challenges, showing how to test against these threats before attackers can exploit them.

What makes this book essential is its focus on preparing organizations for the future of security testing. It goes beyond describing threats by offering a blueprint for integrating AI into their existing workflows, enabling defenders to think like attackers and stay one step ahead. From actionable case studies to ethical frameworks, it provides a comprehensive resource for testing and improving defenses in environments where the line between human and machine deception grows increasingly blurred. This is not just a book about threats--it's a call to action for organizations to evolve their approach to security and embrace AI's potential to strengthen their defenses.

What You Will learn:

  • How AI reshapes social engineering and testing, acquiring the knowledge to simulate advanced threats such as AI-generated phishing, deepfakes, and automated reconnaissance.
  • How to develop skills to implement open-source AI tools for crafting ethical attack simulations, testing human and organizational vulnerabilities, and strengthening defenses.
  • How to prepare to navigate future challenges in AI-enabled security testing, ensuring readers remain adaptable as social engineering threats evolve.

Who This Book is for:

The primary audience includes technical positions, penetration testers, and security professionals (mid- to senior-level cybersecurity professionals, including penetration testers, red teamers, and SOC analysts, with 3-10 years of experience in technical roles); the secondary audience is managers, technical managers, strategists, and influencers, legal (5+ years in management or leadership roles, overseeing technical teams or developing security strategies); and the tertiary audience is beginners (Entry- to mid-level technical professionals exploring advanced cybersecurity techniques or AI applications).

商品描述(中文翻譯)

這本書探討人工智慧對社會工程和測試的變革性影響,提供了一個及時且必要的指南,以應對現代網路安全中最迫切的挑戰之一。人工智慧不僅徹底改變了攻擊者利用漏洞的方式,也改變了防禦者測試和加強其系統的方式。超過80%的資料洩漏歸因於人為錯誤或社會工程,而網路釣魚攻擊則佔成功網路攻擊的36%,這使得組織面臨的風險比以往任何時候都要高。能夠自動化這些攻擊的人工智慧工具的興起,帶來了新的複雜性,使得組織必須採取先進的策略來測試其韌性。

本書的核心使命是為網路安全專業人士提供工具、知識和框架,以道德且有效地對抗這些由人工智慧驅動的威脅。讀者將學會如何模擬複雜的人工智慧驅動攻擊,從深偽(deepfake)冒充到多通道的網路釣魚活動,同時尊重道德界限。書中強調實用應用,例如利用開源工具模擬現實世界的攻擊場景,以及使用人工智慧分析人類的脆弱性。它還提供了可行的指導,幫助建立反制措施和培訓計劃,以反映快速演變的威脅環境。

隨著像 ChatGPT、深偽生成器和語音合成平台等人工智慧工具變得越來越可及,其在製作惡意活動中的濫用也在加速。研究顯示,83%的組織在2022年經歷了成功的網路釣魚攻擊,而涉及深偽的事件較前一年上升了300%。同時,社交媒體上個人資訊的廣泛可用性為人工智慧驅動的偵查創造了肥沃的土壤,使得針對性的社會工程變得比以往更容易且更有效。本書直接針對這些挑戰,展示如何在攻擊者利用這些威脅之前進行測試。

本書之所以必不可少,是因為它專注於為組織未來的安全測試做好準備。它不僅僅是描述威脅,而是提供了一個將人工智慧整合到現有工作流程中的藍圖,使防禦者能夠像攻擊者一樣思考,並保持領先一步。從可行的案例研究到道德框架,它提供了一個全面的資源,用於在人工與機器欺騙的界線日益模糊的環境中測試和改善防禦。這不僅僅是一本關於威脅的書——它是對組織的行動呼籲,促使他們改變安全方法,並擁抱人工智慧加強其防禦的潛力。

你將學到的內容:
- 人工智慧如何重塑社會工程和測試,獲得模擬先進威脅(如人工智慧生成的網路釣魚、深偽和自動化偵查)的知識。
- 如何發展技能,實施開源人工智慧工具以製作道德的攻擊模擬,測試人類和組織的脆弱性,並加強防禦。
- 如何準備應對未來的人工智慧驅動安全測試挑戰,確保讀者在社會工程威脅演變時保持適應性。

本書的讀者對象:
主要讀者包括技術職位、滲透測試員和安全專業人士(中高級網路安全專業人士,包括滲透測試員、紅隊成員和安全運營中心分析師,擁有3-10年的技術角色經驗);次要讀者是經理、技術經理、策略家和影響者,法律(在管理或領導角色中擁有5年以上經驗,負責技術團隊或制定安全策略);第三讀者是初學者(入門至中級技術專業人士,探索先進的網路安全技術或人工智慧應用)。

作者簡介

Sean-Philip Oriyano has been actively working in the IT field since 1990. Throughout his career, he has held positions such as support specialist to consultants and senior instructor. Currently he is an IT instructor who specializes in infrastructure and security topics for various public and private entities. Sean has instructed for the US Air Force, Navy, and Army at locations both in North America and internationally. Sean is certified as a CISSP, CHFI, CEH, CEI, CNDA, SCNP, SCPI, MCT, MCSE, and MCITP, and he is a member of EC-Council, ISSA, Elearning Guild, and Infragard.

作者簡介(中文翻譯)

Sean-Philip Oriyano 自1990年以來一直活躍於資訊科技領域。在他的職業生涯中,他擔任過支援專家、顧問和高級講師等職位。目前,他是一名資訊科技講師,專注於基礎設施和安全主題,為各種公私機構提供教學。Sean 曾在北美及國際地區為美國空軍、海軍和陸軍授課。Sean 擁有 CISSP、CHFI、CEH、CEI、CNDA、SCNP、SCPI、MCT、MCSE 和 MCITP 認證,並且是 EC-Council、ISSA、Elearning Guild 和 Infragard 的成員。