Potential denial of wallet abusing AI services
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud AI Infrastructure Analytics
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Endpoint Denial of Service: Application Exhaustion Flood (T1499.003), Resource Hijacking (T1496)
Severity
Low
Description
An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption.
Attacker's Goals
Disrupting or shutting down an ML service.
Investigative actions
Investigate the impact on the ML service.
Variations
PreviousPotential DCSync by an unusual user
NextPotential extraction of NAA Account Credentials in Microsoft Configuration Manager
Was this helpful?
