SERVICE
AI Penetration Testing & AI Security Assessment
บริการต้นทางรองรับ LLM, Chatbot, RAG, Agentic AI, Tool Calling, API/Database, Multi-Agent และ Private/Enterprise AI Platform
ABOUT SERVICE
ทดสอบความปลอดภัยของ AI ก่อนที่ AI จะกลายเป็นช่องทางเข้าสู่ระบบขององค์กร
AI Attack Surface ไม่ได้จบอยู่ที่ Model
เมื่อ AI เชื่อมต่อ Application, RAG, Agent, Tool, API และข้อมูลภายในองค์กร ความเสี่ยงจึงต้องถูกประเมินตลอดทั้งเส้นทาง ไม่ใช่ดูเฉพาะว่า Model สามารถถูก Jailbreak ได้หรือไม่
ทำไม Traditional Penetration Testing อย่างเดียวจึงไม่เพียงพอ
Traditional Penetration Testing ยังจำเป็นสำหรับ Application และ API แต่ระบบ AI เพิ่ม Attack Surface รูปแบบใหม่ เช่น Prompt Injection, Indirect Prompt Injection, Model Behavior Manipulation, RAG Access Control, Agent Authorization และ Tool Calling ซึ่งต้องใช้การทดสอบที่ครอบคลุมพฤติกรรมและการเชื่อมต่อของ AI เพิ่มเติม
รองรับระบบ AI หลากหลายรูปแบบ
LLM Application
Generative AI / Large Language Model Application
AI Chatbot / Copilot
AI Chatbot, AI Assistant และ AI Copilot
RAG
Retrieval-Augmented Generation และ Enterprise Knowledge Assistant
Agentic AI
AI Agent, Multi-Agent System และระบบที่มี Tool / Function Calling
AI + API / Database
AI ที่เชื่อมต่อ API, Database หรือระบบภายในองค์กร
Private / Custom AI
AI Gateway, AI API, Custom AI, Private LLM และ Enterprise AI Platform
AI Security Testing Capability
| Testing Area | ตัวอย่างความเสี่ยงที่ตรวจสอบ |
|---|---|
| LLM & Generative AI Security | Prompt Injection, Indirect Prompt Injection, Jailbreak & Guardrail Bypass, System Prompt Leakage, Sensitive Information Disclosure, Insecure Output Handling, Improper Input / Output Validation, Excessive Data Exposure, Model Behavior Manipulation, Denial of Service / Resource Abuse และ Unauthorized Access to AI Functions |
| RAG Security | Sensitive Data Leakage, Unauthorized Document Retrieval, Cross-user / Cross-tenant Data Exposure, RAG Access Control Bypass, Knowledge Base Poisoning, Malicious Document Injection, Retrieval Manipulation, Vector Database Security และ Data Segregation / Permission Validation |
| Agentic AI Security | Agent Goal Manipulation, Unauthorized Tool Execution, Excessive Agency, Tool / Function Calling Abuse, Agent Authorization Bypass, Privilege Escalation, Memory Manipulation, Agent Workflow Manipulation, Unsafe Autonomous Actions, Agent-to-Agent Security, Multi-step Attack Chain และ Human-in-the-loop Bypass |
| Application & API Security | Authentication, Authorization, Broken Access Control, Business Logic, Session Management, API Security, Input Validation, Sensitive Data Exposure, Server-side Vulnerabilities, Security Misconfiguration และ Integration Security |
เมื่อ Prompt หนึ่งข้อความ กลายเป็น Multi-step Attack Chain
AI Red Teaming จำลองสถานการณ์จากมุมมองของผู้โจมตี เพื่อดูว่าการควบคุม AI หนึ่งขั้นสามารถพาไปสู่ข้อมูลหรือระบบอื่นได้ไกลเพียงใด
Prompt Injection → Sensitive Data
Malicious Document → Agent Action
แนวทางและมาตรฐานอ้างอิง
ระบบแบบไหนควรได้รับการประเมิน
Enterprise AI Chatbot
Internal AI Assistant
Customer Service Chatbot
AI Copilot
RAG / Knowledge Assistant
AI Agent
Workflow Automation with AI
Private LLM / Cloud AI Platform
เมื่อไหร่ควรทำ AI Security Assessment?
แนวทางต่อไปนี้ช่วยให้องค์กรเลือกจังหวะการประเมินที่เหมาะสมตามการเปลี่ยนแปลงของระบบ AI และการเชื่อมต่อกับระบบภายใน
