AWS guardduty: Document AI workload attack sequence detection via AI Protection
Summary
Adds a section explaining that enabling AI Protection lets Extended Threat Detection detect attack sequences involving AI workloads (anomalous model invocations, cost harvesting, direct prompt injection) and correlate them into AttackSequence:IAM/CompromisedCredentials findings.
Security assessment
Documents a detection capability for AI workload threats and how to enable it. It is security best-practice/feature documentation, not remediation of a specific vulnerability.
Evidence
+Enable [AI Protection](./ai-protection.html) to help GuardDuty detect attack sequences that threaten the AI workloads in your account. AI Protection analyzes AWS CloudTrail data events from Amazon Bedrock and Amazon SageMaker AI. It can detect activities such as anomalous model invocations, cost harvesting attacks, and direct prompt injection attempts.
Diff
diff --git a/guardduty/latest/ug/guardduty-extended-threat-detection.md b/guardduty/latest/ug/guardduty-extended-threat-detection.md index 1190cd6f5..f781534f2 100644 --- a//guardduty/latest/ug/guardduty-extended-threat-detection.md +++ b//guardduty/latest/ug/guardduty-extended-threat-detection.md @@ -87,0 +88,2 @@ Extended Threat Detection is enabled automatically for all GuardDuty accounts, e + * Detecting attack sequences involving AI workloads + @@ -173,0 +176,19 @@ To enhance Extended Threat Detection for EC2 detection capabilities, enable Runt +### Detecting attack sequences involving AI workloads + +Enable [AI Protection](./ai-protection.html) to help GuardDuty detect attack sequences that threaten the AI workloads in your account. AI Protection analyzes AWS CloudTrail data events from Amazon Bedrock and Amazon SageMaker AI. It can detect activities such as anomalous model invocations, cost harvesting attacks, and direct prompt injection attempts. + +To add signals from your AI workloads to [AttackSequence:IAM/CompromisedCredentials](./guardduty-attack-sequence-finding-types.html#attack-sequence-iam-compromised-credentials) attack sequences, you must enable AI Protection. GuardDuty can then use the following finding types as correlation signals: + + * [Impact:IAMUser/AnomalousModelInvocation](./findings-ai-protection.html#ai-protection-anomalousmodelinvocation) + + * [Impact:IAMUser/CostHarvesting](./findings-ai-protection.html#ai-protection-costharvesting) + + * [Impact:IAMUser/PromptInjection.Direct](./findings-ai-protection.html#ai-protection-promptinjection-direct) + + + + +For example, a threat actor might use the same potentially compromised AWS credentials to make an anomalous Amazon Bedrock or Amazon SageMaker AI model invocation. GuardDuty can correlate that invocation with other suspicious actions taken with those credentials. It then represents them as a single [AttackSequence:IAM/CompromisedCredentials](./guardduty-attack-sequence-finding-types.html#attack-sequence-iam-compromised-credentials) attack sequence finding. On their own, AI Protection findings do not generate an attack sequence. + +If AI Protection is not enabled, GuardDuty cannot generate individual [AI Protection finding types](./findings-ai-protection.html). As a result, GuardDuty cannot detect multi-stage attack sequences that involve these findings. For more information about enabling this protection plan, see [AI Protection](./ai-protection.html). +