ChatGPT Security Risks: A Guide for Cyber Security Professionals

C H AT G P T S E C U R I T Y R I S K S : A G U I D E F O R C Y B E R S E C U R I T Y P R O F E S S I O N A L S How previously unknown chatbot risks could affect your business
Table of Contents Introduction ...................................................................................................................3
4 Areas of Risk .............................................................................................................4 People ....................................................................................................................5 Data Privacy ........................................................................................................7 Malware .................................................................................................................9 Breaches ............................................................................................................11
Conclusion ...................................................................................................................13
ChatGPT Security Risks
2
ChatGPT Security Risks
3
Introduction The advancement of language models, like ChatGPT, heralds the beginning of a new era in human-machine collaboration. ChatGPT can offer human-like responses based on a vast knowledge base, and due to the machine learning model on which it was built, the technology will continually improve over time.
and some are exceptionally enthusiastic about what AI-based tools, like ChatGPT, can accomplish.
Presently, employees can use ChatGPT on a per-instance basis, or businesses can integrate ChatGPT into their own applications or platforms, such as a website or mobile app, to provide automated support or AI-powered features. API integrations are available through OpenAI (ChatGPT’s parent company) and through third-parties.
Because third-party entities also offer pre-built chatbot-powered solutions, businesses can customize the tool in ways that integrate
software-as-a-service products.
of technology and we’re only
ChatGPT Security Risks
4
Regardless of how ChatGPT is integrated and applied in the business setting, the technology can provide
and offer new insights.
The challenge is how to overcome security obstacles.
As the use of ChatGPT and similar technologies expand, so do cyber security risks.
The four substantial areas of risk include:
Continue reading to understand how these risks could affect your business.
People Data Privacy Malware Data Breaches
ChatGPT Security Risks
5
People
threat vectors and attack surfaces. In other words, people are error-prone and no ready-made solution exists to solve that issue.
ChatGPT Security Risks
6
By and large, employees have the best of intentions, and want to engage with ChatGPT in a way that’s
may not inherently know what is or isn’t acceptable in the way of chatbot use. Chances are that they haven’t given it much thought—they just know that a chatbot can help provide results.
The “newness” of the technology may not ‘mesh’ with employees’ pattern-recognition modalities. Employees may not realize that this ‘shiny new thing’ is still, in essence, a third-party website for which regular cyber security rules apply.
information for clients, asking the technology to build out a report for them. In turn, corporate data may end up on non-enterprise servers. On said servers, the data may be under-secured or secured in a way that’s not compliant with an organization’s legal mandates. The ChatGPT end-user license agreement discusses this risk.
As a leader, advocate for responsible use of ChatGPT in the workplace. In a personable way, tell employees about what information can be and should not be shared with chatbots. Explain the reasoning and ensure that you can point to evidence that supports your decisions. Be sure to thank everyone for their cooperation with these new guidelines that are evolving in parallel with the technology itself.
Earlier this year, Amazon issued a company-wide warning pertaining to sharing information with OpenAI’s chatbot. ‘We wouldn’t want its output to include or resemble our confidential information
(and I’ve already seen instances where its output closely matches existing material)’ read the warning.
1 JPMorgan restricts ChatGPT usage…, Paul Farrel, Daily Mail, 22 February 2023
ChatGPT Security Risks
7
Data Privacy According to ChatGPT itself, “Chatbots that use ChatGPT may collect and store sensitive
information, or health data. This information could potentially be accessed or stolen by unauthorized individuals, putting the privacy and security of individuals at risk.”
ChatGPT Security Risks
8
To ensure maximal data privacy, leverage the following insights:
• Implement access controls in order to limit internal access to sensitive data. Apply user controls and authentication mechanisms. Encrypt sensitive data.
• AI-based applications that use ChatGPT and ChatGPT itself should be hosted on secure servers and storage systems. Make sure that your hosting and storage providers apply appropriate cyber security measures; from access controls, to encryption, to intrusion detection systems.
• Routinely update cyber security measures to ensure that they remain capable of fending off waves of advanced cyber threats. In so doing, organizations may wish to consider vulnerability assessments, penetration testing, and regular updates to security policies and procedures.
• When leveraging ChatGPT, businesses should be sure to pursue appropriate measures to protect sensitive data that may be collected by chatbots and other AI-based applications.
•
Collection and storage of sensitive information: Chatbots that use ChatGPT may collect and store sensitive information such as personal data, financial information, or health data.
This information could potentially be accessed or stolen by unauthorized individuals, putting the privacy and security of individuals at risk.
ChatGPT Security Risks
9
Malware At this point, ChatGPT’s capacity to produce malicious software code is limited, although extant. Cyber criminals can use chatbots to help them execute on malicious activities and in so doing, have been observed bypassing the chatbot’s safeguards.
ChatGPT Security Risks
10
Check Point researchers have monitored dark web forums and found instances where cyber criminals were exchanging information about the use of the chatbot to “improve” malware code.
Reddit users are having discussions about “jailbreaks” (certain language prompts that successfully override the chatbot’s defenses), which cyber criminals have made use of.
leverage the code in order to fast-track ransomware projects. While the chatbot will not write a complete ransomware script, the short-form sample material produced could still prove dangerous.
Cyber security researchers have also observed that asking ChatGPT for new pieces of code continuously can enable users to create highly evasive polymorphic malware. While this is not a new capability for cyber attackers, ChatGPT’s ability to manufacture code may enable low-skilled wanna-be cyber criminals to execute sophisticated attacks.
and with that, they can scale-up malware deployment.
manager at Check Point, organizations should take corresponding precautions. To quickly stem the volume of
can help your business respond to and stop potential breaches. Fight AI threats with AI-powered tools.
Check Point
How hackers can abuse ChatGPT to create malware, Alexis Zacharakos, TechTarget, 22 February 2023
ChatGPT Security Risks
11
Data Breaches ChatGPT and similar technologies introduce new data breach-related risks. In the event that a business’s ChatGPT instance were compromised, sensitive information could be exposed to hackers.
ChatGPT Security Risks
12
According to OpenAI’s privacy policy, the company collects individual IP addresses, browser types, settings and data on user interactions with the chatbot site. Other collected data may include the type of content that users engage with, features that users utilize, and actions that users take.
It also aggregates data about users’ browsing activities over time and across divergent websites. OpenAI’s
in order for the company to accomplish business objectives.
To mitigate the risk of data compromise that comes with chatbot use, businesses need to pursue appropriate security measures. These may include implementing encryption to protect sensitive data, limiting access to systems, and regularly monitoring systems for suspicious activity.
Address system weaknesses quickly and broadly take a proactive approach to security. When implementing
related risks.
ChatGPT Security Risks
13
Conclusion ChatGPT and similarly powerful tools are now an inescapable element to consider in developing a strong, resilient cyber security framework.
"It's a great technology—but, as always with new technology, there are risks and it's important to discuss
As technology continues to advance, cyber security and IT leaders need to stay informed and to stay ahead of potential cyber security threats.
By learning about the risks associated with ChatGPT and similar technologies, and by taking precautions, we can ensure that powerful AI-based tools are used in the most secure ways possible. Protect your world.
For more executive-level insights into ChatGPT, please visit checkpoint.com.
Did you know? New chatbots also offer a certain advantage to cyber security professionals.
These chatbots are particularly good at understanding code, and as a result, defenders may be able to use them to better understand malware.
ChatGPT and more: What AI chatbots mean for the future of cybersecurity, Danny Palmer, ZDNet, Feb 14 2023
© 2024 Check Point Software Technologies Ltd. All rights reserved.