当护栏不足以应对安全威胁时:利用架构控制重塑智能体人工智能安全.pdf

编号:981911 PDF 49页 1.53MB 下载积分:VIP专享
下载报告请您先登录!

当护栏不足以应对安全威胁时:利用架构控制重塑智能体人工智能安全.pdf

1、#BHUSA BlackHatEventsWhen Guardrails Arent EnoughWhen Guardrails Arent EnoughReinventing Agentic AI Security With Architectural ControlsDavid Richards Brauchler III#BHUSA BlackHatEventsA Story:Consider An Alternate History The year is 1991,HTTP 0.9 released All web traffic accesses static pages Prim

2、ary risk:Modified site content In response,we invent the WAF As the web develops,WAF is our first(and often only)line of defenseWAF#BHUSA BlackHatEventsAnd Yet Vulnerabilities PersistedWAF#BHUSA BlackHatEventsWeve Approached AI The Same WayGuardrails#BHUSA BlackHatEventsAllow Me To Prove That To You

3、#BHUSA BlackHatEventsRemote Code ExecutionAccessing internal cloud environment#BHUSA BlackHatEventsAdmin,Root,And Default Passwords Exposed Via RAGAlmost every word in this list is too sensitive to reveal on stage.#BHUSA BlackHatEventsControlAdmin Sessions#BHUSA BlackHatEventsDavid Brauchler IIINCC

4、Group Technical Director,AI/ML Security Practice Lead Appsec Specialist,Penetration Tester Barbecue Enthusiast Armchair Theologian Obsessed Technologist Retro Gamer,Serial Arcade Hopper#BHUSA BlackHatEventsAgendaRoot Cause AnalysisWhere does risk originate in AI systems?Threat ModelingHow do we eval

5、uate the security of AI environments?Key AI RisksWhere do AI technologies contribute to attack surface?Key Mitigation StrategiesHow do we integrate zero-trust with AI?Lessons LearnedHow do we implement these techniques into real applications?#BHUSA BlackHatEventsGuardrails Are Not Security Boundarie

6、s!Reputational risk is not your greatest risk Asset Confidentiality,Integrity,and Availability reign supremeGuardrails are statistical measures that do not offer“hard”security guarantees Guardrails are defense-in-depth measures,not first-order security controls Every guardrail can and will be bypass

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(当护栏不足以应对安全威胁时:利用架构控制重塑智能体人工智能安全.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠