
It’s an industry irony that the “lower tech” the email scam, the harder it is to catch. Nevertheless, it is true.
The nature of business email compromise (BEC) scams exposes the limits of manual SOC workflows. Because BEC scams often come with nothing but a one-sentence plea for payment, the work required to determine guilt can take much more than scanning for a few malicious clues. And this can take time that many SOCs don’t have.
A quick dive into the process required to identify, catch, and stop BEC scams will prove the need for AI-driven investigation tools to be involved in the process. At least, if companies want to catch these threats at scale.
Why BEC Isn’t an Easy Catch
Social engineering attacks like phishing and business email compromise (BEC) can fly under the radar because there is often no easy-to-spot malware included. No malicious code or tell-tale technical giveaways exist to be detected by email scams or found via sandboxing.
The process for catching a BEC scam is highly sophisticated and takes a lot of expertise. If your users can’t spot it on sight, which (thanks to AI), many can’t, then your SOC is going to have to roll its sleeves up and do the dirty work.
However, handling all the components that go into a successful BEC investigation is a tall task for any security operations team. Only a well-staffed, mature team can typically complete all the necessary steps while still handling the everyday security tasks.
That is, until AI came along. See why an AI SOC is the answer to helping strapped teams spot BEC scams at scale and why only AI can do so.
What It Can Take to Catch BEC in the Real World
Below is a practical approach to identifying and stopping a BEC attack in the wild. Remember the time it takes for each step, the resources required, and the opportunity cost of being unable to focus on other security imperatives during the process.
- The Tip-Off: According to Prophet Security, SOCs will be alerted to a potential BEC scam when an employee notices one of the following:
- A message without context, like “Are you free now?”
- A request for financial action that deviates from standard policy.
Remember, there is nothing here for technology to “catch” regarding malicious code, harmful behaviors, and so on. Newer AI-driven email security tools are beginning to include context and semantic analysis, however.
- The Metadata: SOCs can’t rely on forwarded emails because those typically leave out key pieces of metadata, like:
- Encoding schemes and MIME boundaries.
- X-Headers, which give insight into the sending structure.
- DMARC verdicts and other authentication results (SPF, DKIM)
To avoid these crucial data points being lost, SOCs need to open suspicious emails directly from the user’s inbox using things like eDiscovery tools, so the message artifacts remain intact.
- The Origin: SOCs need to take the original email and determine where it came from. This means taking the time to check for:
- Atypical patterns in geography, send time, and device.
- Spoofed domains. These can evade human detection but are caught by DMARC and other forms of authentication.
- Lookalike domains. Check for typosquatting and character substitutions (microsoft.c0m, for instance).
- The Bad Behavior. Now, SOCs must consult logs for signs of irregular behavioral telemetry. They can sift through SIEMs, audit trails, and access logs from IAM tools like Okta and Azure. This takes time, but it must be done to confirm the malicious activity that typically follows a BEC breach. Tell-tale signs include:
- Modifying inbox rules
- Exporting mailbox data
- Granting third parties mailbox access
And more.
- The Bad Business Processes. At this point, the SOC’s work still isn’t done. They must investigate whether the request in the message aligned with a properly established business workflow, or whether it attempted to evade those processes. For example, was an employee asked to pay a new vendor that hadn’t been approved by Accounts Payables?
Too Much for SOCs to Handle on a Good Day?
The purpose of detailing the BEC investigation process is to highlight the fact that it is hard. It is tedious, time-consuming, and takes a significant amount of BEC understanding and threat-catching know-how.
Not all startups, newly digitized companies, or small businesses have those skills. And not all large companies want to devote the time to using them, every single time a suspicious email comes up.
Even if small and large enterprises alike could perform this process, over and over, the resources it would take would be counterproductive and distract from the myriad other security duties a SOC has to perform.
So, how do companies at all security maturity levels keep up with BEC on a scale? The answer is AI.
Adding AI SOCs Into the Mix
Part of the reason keeping pace with malicious emails is such a challenge today is that AI is helping threat actors churn out sophisticated, well-researched, and well-written BEC and phishing scams at an incredible rate.
AI accounts for the creation of 40% of BEC scams today. This means attackers are launching BEC attacks faster and better than before, leaving SOCs (that still use manual investigation techniques like those outlined above) struggling to keep up.
With an AI SOC, those investigative methodologies remain the same. AI performs those processes at lightning speed, consulting the right tools and orchestrating the right workflows to pull data faster and more efficiently.
The right AI SOC can completely take care of Tier 1 and Tier 2 investigative measures, giving analysts a considerable head start when performing their investigations. This allows human SOCs to keep up with the inhuman influx of BEC emails.
This allows businesses to fight BEC at scale. For a list of the top AI SOCs out there, IT Wire does a great rundown.
About the author:
An ardent believer in personal data privacy and the technology behind it, Katrina Thompson is a freelance writer leaning into encryption, data privacy legislation, and the intersection of information technology and human rights. She has written for Bora, Venafi, Tripwire, and many other sites.
http://itwire.com/security/why-business-email-compromise-is-the-ultimate-test-of-soc-maturity.html
