Poetry4Shellz – Avoiding Limerick Based Exploitation and Safely Using AI in Your Apps

QCon London 2024

Session

Poetry4Shellz – Avoiding Limerick Based Exploitation and Safely Using AI in Your Apps

Wednesday Apr 10 / 02:45PM BST, Mountbatten (6th Fl.)

Abstract

LLM based AI has introduced huge shifts in the technology landscape in a very short amount of time, a consequence of which has been the immense pressure on organizations of all types to adopt and/or develop any and all things AI. This pressure has resulted in widespread usage of fledging technologies often with surprising capabilities that are not well understood in terms of their security implications or interactions with other data and APIs. You yourself might be under that very pressure now!

This talk will provide a case study of a real world LLM based app that is vulnerable to a variety of attack vectors that illustrate the challenges to account for when integrating today's LLM technologies into web application stacks as well as how to protect against them. We will walk through a full attack pathway that culminates in the combination of the LLM with SaaS API's in order to gain full control. 

Things then get weird as we explore the ways in which attack payloads can be obfuscated for delivery and how we will need to adjust some of our traditional security approaches in response.

No deep AI or LLM knowledge is required for the talk, an overview of LLMs and the general attacks against them will be provided. Basic knowledge of limericks is advised.

76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2024 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Wednesday 10 April

10:35 Mountbatten (6th Fl.) Session zero trust A Zero Trust Future for Applications: Practical Implementation and Pitfalls Ashish Rajan CISO @Kaizenteq Ltd, Host of "Cloud Security Podcast", and SANS Trainer for Cloud Security, 13+ Years Experience in the CyberSecurity Industry 11:45 Windsor (5th Fl.) Session Ethical AI Trends in InfoSec: Data Minimisation, Autoclassification, and Ethical AI Rachael Greaves CEO & Co-Founder @Castlepoint Systems, Australia's Most Outstanding Woman in IT Security, RegTech Female Entrepreneur of the Year, Women in Fintech Powerlist, Top 100 Innovator, CISM, CISA, CDPSE, & CIP 13:35 Mountbatten (6th Fl.) Session Beyond the Breach: Proactive Defense in the Age of Advanced Threats Michael Brunton-Spall Deputy Director Cyber Policy and Solutions @Cabinet Office 14:45 Mountbatten (6th Fl.) Session Poetry4Shellz – Avoiding Limerick Based Exploitation and Safely Using AI in Your Apps Rich Smith 15:55 Mountbatten (6th Fl.) Session From Anti-Patterns to Best Practices: A Practical Guide to DevSecOps Automation and Security Spyros Gasteratos Founder @smithy.security