AIRLINK 75.25 Decreased By ▼ -0.18 (-0.24%)
BOP 5.11 Increased By ▲ 0.04 (0.79%)
CNERGY 4.60 Decreased By ▼ -0.15 (-3.16%)
DFML 32.53 Increased By ▲ 2.43 (8.07%)
DGKC 90.35 Decreased By ▼ -0.13 (-0.14%)
FCCL 22.98 Increased By ▲ 0.08 (0.35%)
FFBL 33.57 Increased By ▲ 0.62 (1.88%)
FFL 10.04 Decreased By ▼ -0.01 (-0.1%)
GGL 11.05 Decreased By ▼ -0.29 (-2.56%)
HBL 114.90 Increased By ▲ 1.41 (1.24%)
HUBC 137.34 Increased By ▲ 0.83 (0.61%)
HUMNL 9.53 Decreased By ▼ -0.37 (-3.74%)
KEL 4.66 No Change ▼ 0.00 (0%)
KOSM 4.70 Increased By ▲ 0.01 (0.21%)
MLCF 40.54 Decreased By ▼ -0.56 (-1.36%)
OGDC 139.75 Increased By ▲ 4.95 (3.67%)
PAEL 27.65 Increased By ▲ 0.04 (0.14%)
PIAA 24.40 Decreased By ▼ -1.07 (-4.2%)
PIBTL 6.92 No Change ▼ 0.00 (0%)
PPL 125.30 Increased By ▲ 0.85 (0.68%)
PRL 27.55 Increased By ▲ 0.15 (0.55%)
PTC 14.15 Decreased By ▼ -0.35 (-2.41%)
SEARL 61.85 Increased By ▲ 1.65 (2.74%)
SNGP 72.98 Increased By ▲ 2.43 (3.44%)
SSGC 10.59 Increased By ▲ 0.03 (0.28%)
TELE 8.78 Decreased By ▼ -0.11 (-1.24%)
TPLP 11.73 Decreased By ▼ -0.05 (-0.42%)
TRG 66.60 Decreased By ▼ -1.06 (-1.57%)
UNITY 25.15 Decreased By ▼ -0.02 (-0.08%)
WTL 1.44 Decreased By ▼ -0.04 (-2.7%)
BR100 7,806 Increased By 81.8 (1.06%)
BR30 25,828 Increased By 227.1 (0.89%)
KSE100 74,531 Increased By 732.1 (0.99%)
KSE30 23,954 Increased By 330.7 (1.4%)

ISLAMABAD: The federal government has issued an advisory regarding cyber security threat of ChatGPT, while saying that a breach of around 100,000 ChatGPT user accounts on the dark web through an information stealing malware (Raccoon, Vider, Redline) is reported. The advisory further stated that the report about the breach also highlights one of the major challenges of Al-driven projects (including ChatGPT); the sophistication of cyber-attacks.

The government has suggested precautionary measures and cautious use of ChatGPT (at organizational and individual level).

Globally, many organisations are integrating ChatGPT and other Al-powered APIs into their operational flows/information systems. ChatGPT accounts signify the importance of Al-powered tools along with the associated Cyber risks as it allows users to store conversations. In case of breach, access of a user account may provide insight into proprietary information, area of interest/research, internal operational/business strategies, personal communications and software code etc.

The precautionary measures for users include; (1) Do not enter sensitive data into ChatGPT. If essential, ensure to disable the chat saving feature from the platform's settings menu or manually delete those conversations as soon as possible, (2) Use a malware-free/screened system for ChatGPT. An infected system (with information stealer malware) may take snap screenshots or perform key logging, leading to a data leak, (3) ChatGPT/other Al-powered tools and APIs must not be used by users handling extremely sensitive data. Masking of critical information/ dummy data may be utilized where absolutely essential.

For organizations the precautionary measures include, through best practices, organizations can ensure that ChatGPT is used securely and the data is protected. It is also important to note that Al technology is constantly evolving. The key to protection may be that organizations must stay up-to-date with the latest security trends. Few best practices (but not limited to) are as follows:

(1) Conduct Risk Assessment: Before the use of ChatGPT, conduct a comprehensive risk assessment to identify any potential/exploitable vulnerabilities. This will help organizations to develop a plan to mitigate risks and ensure that their data is protected.

(2) Use Secure Channels: To prevent unauthorized access to ChatGPT, use secure channels to communicate with the chatbot. This includes using encrypted communication channels and secureAPIs.

(3) Mechanism to Monitor Access: It is important to monitor who has access to ChatGPT. A mechanism be ensured that access is granted only to authorize individuals. This can be achieved by implementing strong access controls and monitoring access logs.

(4) Implement Zero-Trust Security: Zero-trust security (an approach that assumes that every user and device on a network is a potential threat) be adopted. This means that access to resources should be granted only on a need-to-know basis followed by strong authentication mechanism.

(5) Train the Employees: Employees be trained on use of ChatGPT and the potential risks associated with its use. The employees do not share sensitive data with chatbot and are aware of the potential threat of social engineering attacks.

Copyright Business Recorder, 2023

Comments

Comments are closed.