21
AI Security Operations
The alert appeared at 2:47 AM on a Tuesday. The SIEM flagged unusual API activity against the company's customer service chatbot: 847 requests in 90 minutes from a single session, each containing slight variations of what looked like normal customer questions. The overnight analyst saw that all requests came from an authenticated session, noted that no data-exfiltration signature had triggered, and marked the ticket as a false positive. By morning, the attacker had extracted prompt behavior, customer account details, retrieval context, and enough workflow information to make future attacks easier.
That is the operational problem with AI systems. The attack may use legitimate access, authorized APIs, normal-looking prompts, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access