Skip to content Skip to footer

SERVICE

AI Penetration Testing & AI Security Assessment

บริการต้นทางรองรับ LLM, Chatbot, RAG, Agentic AI, Tool Calling, API/Database, Multi-Agent และ Private/Enterprise AI Platform

ABOUT SERVICE

ทดสอบความปลอดภัยของ AI ก่อนที่ AI จะกลายเป็นช่องทางเข้าสู่ระบบขององค์กร

ประเมินความเสี่ยงของ Generative AI, LLM, RAG และ Agentic AI แบบ End-to-End ตั้งแต่ Model ไปจนถึง Application, API, Tools, Data และ Enterprise System
END-TO-END SECURITY

AI Attack Surface ไม่ได้จบอยู่ที่ Model

เมื่อ AI เชื่อมต่อ Application, RAG, Agent, Tool, API และข้อมูลภายในองค์กร ความเสี่ยงจึงต้องถูกประเมินตลอดทั้งเส้นทาง ไม่ใช่ดูเฉพาะว่า Model สามารถถูก Jailbreak ได้หรือไม่

USER
APPLICATION
AI / LLM
RAG
AGENT
TOOL / API
DATA
ENTERPRISE SYSTEM
WHY AI-SPECIFIC TESTING

ทำไม Traditional Penetration Testing อย่างเดียวจึงไม่เพียงพอ

Traditional Penetration Testing ยังจำเป็นสำหรับ Application และ API แต่ระบบ AI เพิ่ม Attack Surface รูปแบบใหม่ เช่น Prompt Injection, Indirect Prompt Injection, Model Behavior Manipulation, RAG Access Control, Agent Authorization และ Tool Calling ซึ่งต้องใช้การทดสอบที่ครอบคลุมพฤติกรรมและการเชื่อมต่อของ AI เพิ่มเติม

ประเด็นสำคัญ: เป้าหมายไม่ใช่เพียงพิสูจน์ว่า AI ตอบผิดได้หรือไม่ แต่ต้องประเมินว่าผู้โจมตีสามารถใช้ AI เป็นจุดเริ่มต้นเพื่อเข้าถึงข้อมูล เพิ่มสิทธิ์ หรือสั่งการระบบอื่นได้หรือไม่
SERVICE SCOPE

รองรับระบบ AI หลากหลายรูปแบบ

GENERATIVE AI

LLM Application

Generative AI / Large Language Model Application

ASSISTANT

AI Chatbot / Copilot

AI Chatbot, AI Assistant และ AI Copilot

KNOWLEDGE

RAG

Retrieval-Augmented Generation และ Enterprise Knowledge Assistant

AGENT

Agentic AI

AI Agent, Multi-Agent System และระบบที่มี Tool / Function Calling

INTEGRATION

AI + API / Database

AI ที่เชื่อมต่อ API, Database หรือระบบภายในองค์กร

ENTERPRISE AI

Private / Custom AI

AI Gateway, AI API, Custom AI, Private LLM และ Enterprise AI Platform

TESTING CAPABILITY

AI Security Testing Capability

Testing Areaตัวอย่างความเสี่ยงที่ตรวจสอบ
LLM & Generative AI SecurityPrompt Injection, Indirect Prompt Injection, Jailbreak & Guardrail Bypass, System Prompt Leakage, Sensitive Information Disclosure, Insecure Output Handling, Improper Input / Output Validation, Excessive Data Exposure, Model Behavior Manipulation, Denial of Service / Resource Abuse และ Unauthorized Access to AI Functions
RAG SecuritySensitive Data Leakage, Unauthorized Document Retrieval, Cross-user / Cross-tenant Data Exposure, RAG Access Control Bypass, Knowledge Base Poisoning, Malicious Document Injection, Retrieval Manipulation, Vector Database Security และ Data Segregation / Permission Validation
Agentic AI SecurityAgent Goal Manipulation, Unauthorized Tool Execution, Excessive Agency, Tool / Function Calling Abuse, Agent Authorization Bypass, Privilege Escalation, Memory Manipulation, Agent Workflow Manipulation, Unsafe Autonomous Actions, Agent-to-Agent Security, Multi-step Attack Chain และ Human-in-the-loop Bypass
Application & API SecurityAuthentication, Authorization, Broken Access Control, Business Logic, Session Management, API Security, Input Validation, Sensitive Data Exposure, Server-side Vulnerabilities, Security Misconfiguration และ Integration Security
AI RED TEAMING

เมื่อ Prompt หนึ่งข้อความ กลายเป็น Multi-step Attack Chain

AI Red Teaming จำลองสถานการณ์จากมุมมองของผู้โจมตี เพื่อดูว่าการควบคุม AI หนึ่งขั้นสามารถพาไปสู่ข้อมูลหรือระบบอื่นได้ไกลเพียงใด

SCENARIO 01

Prompt Injection → Sensitive Data

Prompt Injection AI Agent Tool Calling Internal API Sensitive Data
SCENARIO 02

Malicious Document → Agent Action

Malicious Document RAG Indirect Prompt Injection Agent Action
การทดสอบครอบคลุมทั้ง Single-step และ Multi-step Attack Scenario ตามสถาปัตยกรรมของระบบจริง
STANDARDS & REFERENCES

แนวทางและมาตรฐานอ้างอิง

OWASP AI Testing Guide
OWASP GenAI Red Teaming Guide
OWASP Top 10 for Large Language Model Applications
OWASP Top 10 for Agentic Applications
OWASP Agentic AI Threats and Mitigations
OWASP Securing Agentic Applications Guide
OWASP Agent Control Standard
NIST AI Risk Management Framework
NIST Adversarial Machine Learning
MITRE ATLAS
OWASP Web Security Testing Guide
OWASP API Security Top 10
WHO SHOULD ASSESS

ระบบแบบไหนควรได้รับการประเมิน

Enterprise AI Chatbot

Internal AI Assistant

Customer Service Chatbot

AI Copilot

RAG / Knowledge Assistant

AI Agent

Workflow Automation with AI

Private LLM / Cloud AI Platform

WHEN TO TEST

เมื่อไหร่ควรทำ AI Security Assessment?

แนวทางต่อไปนี้ช่วยให้องค์กรเลือกจังหวะการประเมินที่เหมาะสมตามการเปลี่ยนแปลงของระบบ AI และการเชื่อมต่อกับระบบภายใน

BEFORE PRODUCTIONก่อนนำ AI ขึ้นใช้งานจริง
BEFORE CONNECTING DATAก่อนเชื่อม RAG หรือข้อมูลภายในองค์กร
BEFORE ENABLING TOOLSก่อนเปิดให้ Agent เรียก Tool หรือ API
AFTER MAJOR CHANGEหลังเปลี่ยน Model, Architecture หรือ Integration สำคัญ
PERIODIC ASSESSMENTประเมินซ้ำเมื่อระบบและ Threat Landscape เปลี่ยนแปลง