Content-Based Attacks: SAP System's Blind Spot
Show notes
TAKEAWAYS
- Understand why endpoint and EDR tools have no visibility into SAP file uploads
- Learn how content based attacks differ from classic malware and why they are worse
- Discover which everyday file formats can carry executable content into your landscape
- See where SAP's responsibility ends and yours begins in cloud deployments
- Recognise how retrieval pipelines turn ordinary documents into prompt injection vectors
HOST & GUEST: Host: Waseem Ajrab – Managing Director, NO MONKEY Guest: Joerg Schneider-Simon – Chief Technology Officer & Co-Founder, bowbridge
CHAPTERS 01:22 Joerg's journey in cybersecurity and focus on file security 02:26 How SAP security has evolved over the years 03:21 The shift from perimeter security to external integrations 04:17 The changing cybersecurity landscape for SAP 05:55 Limitations of traditional antivirus in SAP environments 09:34 SAP's API for content security and its evolution 13:55 Security misconceptions in cloud SAP deployments 17:19 Content security challenges in cloud and Rise environments 20:33 Impact of interconnected systems and attack surfaces 22:27 The role of AI and large language models in security risks 25:03 Understanding content-based attacks and their risks 30:24 Content types that introduce security risks 34:41 How AI and LLMs expand attack surfaces 37:18 Prompt injections and vulnerabilities in AI applications 41:10 Risks of retrieval augmented generation (RAG) in enterprise AI 43:00 Strategies for modern enterprise content security 49:10 Key message: Question your security assumptions
New episodes drop regularly, featuring conversations with cybersecurity experts, SAP practitioners, and industry leaders who've been in the trenches. No vendor pitches. No fluff. Just actionable insights you can apply today.
Because curiosity is free – but recovery isn't.
Show transcript
00:00:00: because many people think that viruses or traditional malware are actually the most predominant threat for SAP applications, or enterprise applications in general.
00:00:10: Now funny enough... That's not really the case!
00:00:13: With content-based attacks that aren't malware things are very different Because these types of attacks have potential to compromise and attack the application itself.
00:00:32: Jörg it is great having you on this show with us And definitely looking forward Finally, having you again in our new format now with how we tackle SAP security.
00:00:43: Where are going to dig into how organizations can protect business critical content and older environments?
00:00:49: Modern environments... And definitely without a topic without AI nowadays just gets unrecognized right so futuristic I always call it environments on how he can do that.
00:00:59: but before we dig into the four hour listeners who might not know your journey that led you to specialize in enterprise file security.
00:01:09: Tell us about yourself?
00:01:10: Yeah, well hi Wazim thankyou for having me on the show.
00:01:14: it's a great pleasure.
00:01:17: I wanted to do this for long time but somehow we never found the time.
00:01:20: But i'm great We were able to schedule it now.
00:01:24: So who is Jörg?
00:01:26: Well Jörgen has been in the cybersecurity space For almost thirty years.
00:01:30: Now started off when Cybersecurity was still called Internet Security.
00:01:34: Those were the early days of internet firewalls.
00:01:38: And my journey has led me through stages in preset support, then moving into product marketing and product management until I co-founded my current company, Bowbridge back in two thousand five.
00:01:51: so we've been around for over twenty years already And the focus of this company is, as you may already have hinted at file security or content security for mission-critical enterprise applications SAP.
00:02:02: But since recently we also expanded into the Salesforce area acknowledging that Salesforce is playing an increasingly critical role in the Enterprise Security Market Also.
00:02:13: but today it's all about SAP
00:02:16: Nice.
00:02:17: So, over the years you've watched how enterprise security evolved.
00:02:22: looking back at this what has fundamentally let's say changed in our organizations need to protect business applications or as we are talking about it SAP?
00:02:32: Yes so obviously all of those last year plus decade and a half The way enterprise application specifically SAP applications are deployed in large organizations have change dramatically.
00:02:44: When we started with Bowbridge, most of the SAP implementations were really way in the back of The Enterprise Network.
00:02:51: We had a secure perimeter back then and layers of firewalls And the SAP application was really In-the-back, well protected only accessible from inside.
00:03:04: Now that obviously has changed because the value of SAP Application increases once the interaction with external parties comes into play.
00:03:15: If you can hook up your SAP applications, With Your Suppliers ,With Your Partners if You Can Automate Processes Around Your Business By Integrating External Applications That's Where SAP Really Shines.
00:03:28: Now The Flipside of that Metal Is Obviously When You Expose Those Applications To Integrations You Also Exposed Them to External Threats.
00:03:38: In my opinion, that's when the SAP cybersecurity space really came to be.
00:03:43: Before that everybody was talking about SAP security and was referring to roles and permissions in SOD maybe GRC but customers or potential customers were not looking at SAP security from a cyber angle.
00:03:59: That has changed a lot.
00:04:01: I remember anecdotes from our first customers meeting when we came into the room and the customer invited not just the SAP people, but also the cybersecurity people.
00:04:10: And they started by introducing themselves to each other although they weren't in same company.
00:04:16: that is no longer the case so those teams are now well integrated.
00:04:20: it has become common knowledge that securing those mission critical enterprise applications is really something that needs to be taken seriously.
00:04:29: I can see it, i mean...i could definitely argue with how ive seen other customers who are still approaching in a completely different mindset Which brought me, well I wanted to ask you that question.
00:04:42: Like this kind of mindset That belongs in a different era.
00:04:47: You're just saying now it has completely changed?
00:04:50: I do see the change during this year.
00:04:51: To be honest with you It's happened enormously...I don't know what happened.
00:04:55: This is completely Now changing towards that fact.
00:04:58: So maybe If gives us hook into looking Back at little bit Looking specifically on our topic Why this kind of traditional antivirus struggles in SAP.
00:05:11: From your perspective, you've been in this for so many years.
00:05:16: Traditional anti-virus and endpoint protection has always been protecting enterprise other enterprise applications or operating systems or networks.
00:05:26: whatever four decades what assumptions were those technologies originally built around?
00:05:32: when an organization talks about implementing technologies to SAP specifically.
00:05:38: Yeah, well I'm glad you managed to just flip around your question when you started about those applications protecting applications because a matter of the fact is They used to be called endpoint security and now they're called DDR or XDR, whatever you wanna call them.
00:05:55: They are not designed to protect applications.
00:05:58: those our infrastructure security components meant to secure the infrastructure layer.
00:06:04: that is the end point whether it's a desktop Or laptop or server but they have no visibility into the application itself which In many cases really has led to some confusion, to some mis-preconceptions with customers who were assuming that those solutions did in fact protect the applications running on top of those server operating systems or desktop operating systems when in fact is not the case.
00:06:32: Even though these solutions have changed over years and they've very much evolved from being a purely file based security solution.
00:06:41: so an antivirus Traditional, like the quote-unquote simple antivirus would simply just monitor file system access.
00:06:50: So whenever a file is being written to a local or remote filesystem on that server and endpoint That's when it will be scanned And also On Access which means When The File Is Being Read.
00:07:02: Thats Also When It's Scanned.
00:07:04: Now If One Understands How Enterprise Applications Like SAP Handle File Transfers attachments to some business processes you do in a Fiori application, then.
00:07:16: You understand that this file is attached to the business transaction never actually written into the filesystem of the server so it completely flies over the antivirus or XDR solution's head.
00:07:30: It never sees because its not ever written to disk.
00:07:33: Now I had mentioned those solutions have evolved for years and thats certainly true.
00:07:37: we are seeing more advanced types of malware, like file-less malware that comes flying into your application via web applications or any other type of sources.
00:07:49: That never actually persists files on disk but in order to catch those and the current tools do a pretty good job at doing that, that malware needs be executed right?
00:07:58: It need run absolutely then the XDR solution would catch them when it runs.
00:08:03: now again if we look from an SAP's application perspective the malware that is included in a document, I don't know.
00:08:12: A supplier?
00:08:13: A vendor or partner an external applicant for job attaches to their business transaction.
00:08:19: not only it's never written on disk so you can catch with file system monitoring nor has ever executed.
00:08:26: So no way of actually catching other than filtering files and documents and data being ingested at the point of ingestion
00:08:38: With SAP currently, just on a very high level.
00:08:41: brief for our audience.
00:08:43: How is this currently done?
00:08:44: For many years now, SAP has been including a proprietary application program and interface an API into all of SAP's kernels whether it's the SAP Application Server ABAP, the Application Server Java in business objects even in the HANA database.
00:09:02: This API called VSI, the Virus Scan Interface.
00:09:06: that API allows applications to pass documents, files any types of data.
00:09:12: To an externally attached virus scanner or malware scanner.
00:09:17: that would then perform scans according to some configurations are set in the SAP customizing and That is exactly The API that our product has been connecting too.
00:09:26: for many years.
00:09:28: that API also has evolved over the years.
00:09:30: right it started off as a simple anti-virus API But that's why the name virus scan interface came from.
00:09:38: That name stuck, although the scope of API has changed dramatically.
00:09:42: It's really evolved into becoming something more like a content security interface that is able to detect and specify very granularly what type of content customers are supposed to allow in two applications which types of contents they're not supposed to be allowed
00:10:00: with this virus interface because I mean, going through different advisory engagements and so on.
00:10:06: what we see is that it's something That Is definitely not existing to some in some extent but of course based On your customers.
00:10:15: there is a lot.
00:10:16: That are utilizing this And one Of the main or One of The excuses of Not Utilizing This is that i have x whatever on my operating system?
00:10:28: I know you have explained it exactly, but can this virus scan interface be properly configured to instance as you guys are doing for many years.
00:10:42: A non-specialized antivirus content security whatever you want call and why?
00:10:49: It cannot.
00:10:50: so the virus can interface really is a proprietary API For the techies among audience, it's a C API that sits in the ABAP kernel and Java kernel.
00:11:04: And is invoked by ABAP function modules.
00:11:08: specifically It passes on content along with some metadata information to VSI client To parts connected to the API That performs this scan.
00:11:22: This connection is proprietary.
00:11:24: So a standard off-the-shelf antivirus or XDR solution simply doesn't have the plug that goes into that socket, so it cannot connect to that proprietary API in order to really implement any type of content scanning at the SAP layer you need.
00:11:44: Now
00:11:53: this is coming from our like older ECCs, right?
00:11:57: Your ECC systems even as for it.
00:11:58: But now always a question that will come into place Is now everybody moving to the cloud?
00:12:06: They're exploring that kind of Cloud adoption.
00:12:09: So before I dig on how The differences many organizations assume That when they are in This holy cloud i call It off SAP.
00:12:18: that automatically makes them more secure.
00:12:21: First question is how accurate is that assumption?
00:12:25: And then the second question, I would like to touch base on the content security when it comes to rice but we'll come through.
00:12:31: Yeah
00:12:31: well those are obviously...I would always call them loaded questions.
00:12:36: Okay
00:12:38: i think there is another misconception in that area or at least they used to be from any customers who were for some reason led.
00:12:48: moving their applications into the cloud would automatically make them more secure.
00:12:53: That's very obviously not the case, The thing that is more secure arguably Is the operating system layer.
00:13:00: if you look at solutions or offerings like rise with SAP which has recently been renamed to I don't even know what everybody still calls it rise.
00:13:09: so do i basis?
00:13:11: So they got the SAP standard layout.
00:13:13: this is pretty standardized and pretty hardened.
00:13:16: However when it comes to securing the data that is processed by these applications, then very clearly falls into customers' responsibilities.
00:13:27: SAP has published and updated quite a few times their so-called shared security responsibility matrix.
00:13:35: I think it's pretty well crafted document That really lines out where SAPs responsibility in terms of security ends And with the customer's responsibility starts.
00:13:48: That line is not always intuitive to the customer, but it's fairly well documented and securing data that is processed by the application.
00:13:58: this very clearly something in the realm of customers responsibility.
00:14:05: Maybe before I go to content security, with this shared responsibility model as you have discussed where do you see the biggest misunderstandings?
00:14:17: I wouldn't necessarily call them misunderstanding.
00:14:20: I would rather say it's misperceptions or wrong assumptions.
00:14:25: Customers are assuming certain things and then those things turn out not to be the case.
00:14:30: just like in the past they used to assume that their OS layer antivirus will protect applications very similar here.
00:14:37: They assume that SAP or whoever their cloud provider is, has it covered when in fact they don't because its not the responsibility.
00:14:46: Okay
00:14:46: make sense.
00:14:47: and now going a little bit towards this content security.
00:14:52: how can we look at from perspective where SAP manages infrastructure, OS whatever kind of layers?
00:14:59: And as you said, customers still remain need to manage their applications.
00:15:03: Their data is say the application layer.
00:15:06: how does content security change in that perspective?
00:15:09: Technically it doesn't really change a lot from point of view.
00:15:13: what's required?
00:15:14: You're still require an enterprise grade anti-malware engine and some other detection capabilities for things dangerous but not classic malware we might get into later.
00:15:26: The challenge really comes from the fact that now in scenarios like in Rise, customers only own and can see or manage very upper layers of that stack.
00:15:40: So trying to secure your upper layer with a security tool that runs on lower layers is going be difficult because customers no longer have access to those lower layers.
00:15:56: Running a SAP application on RISE, I do not have access to the OS layer of the software that runs my...I'm sorry.
00:16:05: ...I don't have access for the OS layers in this server that run my applications.
00:16:13: So if customers use a solution that requires some configuration changes to be performed at the OS Layer.
00:16:21: they have no way to do those changes themselves.
00:16:24: They need to call up SAP make an appointment with their TSM and then flip a switch for one parameter to flip from zero two, which is obviously going to cost time.
00:16:35: And ultimately also go into cost money.
00:16:37: so deploying security solutions in those types of environments really require solutions that are designed With this type of infrastructure in mind capabilities for customers to retain full control of all the security settings, even though they don't have access to the OS layer.
00:16:57: Needless to say our solution does that but this is not something specific to our product or even to this area in general.
00:17:06: This a challenge always comes up when When customers try to use solutions that were built for an on-premise world in a cloud application world, there's a disconnect here simply because those solutions weren't meant to be used.
00:17:23: No definitely and with the Cloud adoption then becomes this kind of different entry points Interconnected systems, you have non SAP systems.
00:17:35: BTP which is the business technology platform.
00:17:37: all of these does it still change?
00:17:40: The way we need to think off content security?
00:17:44: well in my mind It drastically increases the attack surface because that system is with every integration That you perform on a system view you eventually increase the attack surface.
00:17:56: So, we want to make sure that all those interfaces and interconnections are very well secured.
00:18:03: You were speaking of systems that integrate with non SAP applications using things like web services or BTP or whatever integration platform you're using Now.
00:18:12: obviously when data flows from one application into another it usually crosses a trust a trust zone and that's where you want to scan it.
00:18:22: So, It increases the attack surface And it also increases The number of checkpoints That You have...and that you can use To actually secure the data flow into your applications.
00:18:32: Question is Are customers doing it?
00:18:35: Some are.
00:18:36: We've had some customers who were very well educated Very well set up and very aware Of security risks coming from those integrations.
00:18:44: Others still a way to go, which I think is normal.
00:18:48: You always have customers anywhere along the spectrum of being not just fully on-prem too full cloud but also from being you know Anywhere along that security maturity journey?
00:18:59: Yeah whether or also i mean this Is like The hybrid model where they're off different attack surfaces coming into place.
00:19:07: i do see it however That i think right now i don't want to Go Into the ai topic Right Now.
00:19:12: i want To keep It for later.
00:19:13: But With the increase use of AI, do you see it that and I think this is more towards at the attack surface on questioning here.
00:19:24: Isn't it faster now to develop some sort off malware or some sort of exploit against all different interconnected systems or hybrid system that enables the customer to not be as relaxed, they should have in the past.
00:19:42: I don't know if it was a relaxed moment but for some extent makes them... research behind is faster nowadays.
00:19:53: Any thoughts on this?
00:19:54: It's absolutely true.
00:19:56: We see that many areas where we see exploits being created much, much faster.
00:20:02: Where we see vulnerabilities being discovered much faster especially in environments where source code is accessible.
00:20:10: for those who understand SAP you understand that most of the SAP standard is available in source so You can actually look into That and a well-trained AI system Is able to find vulnerability that previous vulnerability scanners code scanning tools may have missed?
00:20:29: then there are many dependencies that you don't necessarily immediately see as an application owner.
00:20:35: So your application might depend on something, a couple of years old upstream and if the vulnerability is discovered in that component or library package it can actually trickle down to make your application vulnerable.
00:20:59: packaging and compression libraries.
00:21:02: So it's not a new topic, but is something that is very clearly accelerating dramatically?
00:21:07: Yes
00:21:08: I do agree on this.
00:21:09: I mean tools took you few months to build.
00:21:14: now takes less than the time by enormous.
00:21:18: Now we did speak about content security And i want touch based on content-based attacks.
00:21:24: Before we dig into, I would like to know from... You live and breathe this kind of content-based attacks.
00:21:31: Can you give us an explanation?
00:21:34: Sure!
00:21:35: It's a great question actually because many people think that viruses or traditional malware are the most predominant threat for SAP applications in general.
00:21:47: Funny enough, that's not really the case.
00:21:50: A malware that is ingested into an SAP application and that is stored somewhere in your data storage whether it's a database or document management system doesn't affect the application itself.
00:22:02: It might hit next user who opens and executes this file but has no impact to its application.
00:22:10: With content-based attacks which are not malware things are very different because these type of attacks have the potential to compromise or attack the application itself.
00:22:20: Let me give you a very simple example, You have a business workflow with let's say a supplier where...you know.. you've got an automated process and ordering some supplies for your organization to create something And that supplier sends you invoices so they upload those invoises into a Fiori application that was built specifically for that purpose.
00:22:48: Now, few people understand.
00:22:50: in those files are uploaded attackers may embed content That will run and be executed as soon as this document is viewed.
00:23:01: So it doesn't have to an executable type of file.
00:23:04: It does not need to be an exe or EXE file a script.
00:23:10: it doesn't have to be screen saver.
00:23:12: It can be PDF document, an image or different types of files.
00:23:18: and one analogy that most people understand is macros in office documents.
00:23:24: I think by now many people understand if you open word document from untrusted source Because call ITE don't click on.
00:23:36: yes, because that will cause the macro to run.
00:23:38: Now many file formats.
00:23:39: I've mentioned PDF but it's also true for other file format.
00:23:42: they have an option to embed such active content in those documents which means as soon as the accountant opens the invoice to view It That Content Will Be Executed In The Browser.
00:23:55: The tricky part about this is...because that document has been downloaded from SAP application your browser treats it like a part of the SAP application.
00:24:06: The consequence is that any type of active content embedded in this document has full access to the application with same level as the user who downloaded the file had.
00:24:18: So if an administrator opens that PDF document or that support case, and it has an attachment to open that attachment.
00:24:26: That attachment run some code that's embedded in there... ...that code can actually piggyback on the connection that came over And perform operations of application from.
00:24:37: It is a very fundamental problem In basically any type of web application.
00:24:41: This isn't something specific for SAP from an attacker's perspective, it works just the way in Salesforce.
00:24:48: It works just a way another web-facing applications but is something that is beyond the scope of traditional anti malware.
00:24:56: so having and embedded JavaScript in PDF document Is not something your virus scanner would detect because its legitimate capability Unless that embedded payload is something known to be malicious, some metasploit or whatever.
00:25:16: Then the virus scanner would detect it.
00:25:17: but if its a simple javascript that tries create user just takes his chance right?
00:25:24: Just try connect to zero one and try to create a user.
00:25:27: That's something that the Virus Scanner wouldn't pick up on.
00:25:33: additional scanning capabilities that have been purpose developed to secure those applications above and beyond virus-scanning.
00:25:41: So when you talk about this kind of content, as with SAP it processes a lot of structured end actually unstructured content.
00:25:52: what are these kinds to an enterprise?
00:25:58: Well,
00:25:58: from a interactive perspective it's really first and foremost document types.
00:26:02: So we have content security threats.
00:26:05: in PDF documents that I've mentioned you have anything that is web format related HTML, MHTML emails.
00:26:14: You have Anything that is office documents That may not just include macros but Office Documents Technically being zip files are also a great way to smuggle Java classes, by the way.
00:26:26: So those types of document that I very commonly exchanged when a
00:26:32: user
00:26:33: usually human uploads something into an application but there some they're a bit more esoteric.
00:26:38: so you could embed scripting languages in some graphic type like SVG which is a scalable vector graphics.
00:26:44: it's XML based Vector Graphics format.
00:26:47: You Could Embed content in metadata of files, and I'm going to come back to metadata later on.
00:26:54: But one attack vector for instance is to include PHP or Perl in PDF meta data.
00:27:01: so those are things that like i said the virus scanner would not pick up And this is something that will be included into file.
00:27:08: Now when it comes to structured content obviously there's a lot going between SAP systems or applications general based on XML.
00:27:16: XML by itself can also embed scripts.
00:27:19: It doesn't execute it automatically, but it can embed and depending on how is processed that script language run.
00:27:27: Then there are some more advanced multi-steps attack including things like SSLTEs so XSL templates that can be used to rewrite any arbitrary XML into HTML plus JavaScript which the browser then renders executes the JavaScript again.
00:27:46: you have sort of structure stored cross-site scripting attack, basically.
00:27:52: That's what it ultimately comes down to having a document that is stored in an application and when accessed the content in that document
00:28:12: from other than the content.
00:28:13: but also where you said that do not treat these kind of content attacks as basically based on traditional malware detection because this is a very important point, I don't know if it's outside of SAP who are not ingrained.
00:28:29: But i think in web-based applications... You've said it!
00:28:34: It's all good.
00:28:35: let me know when we can continue.
00:28:37: okay
00:28:37: go ahead sorry
00:28:39: no problem.
00:28:39: so You discussed why malware or these kinds of content attacks shouldn't be thought off as your traditional malware detection.
00:28:49: And that's a very important point where organizations need to think about this kind of content-based attack, what you said is web application attacks and it does affect SAP.
00:29:02: So I'd like then jump directly into discussing how fundamentally change when we're introducing AI into the mix.
00:29:13: And I know that because now attacks, you can hide anything behind those PDFs and i would like to explain First of all, as we did it this attack surface.
00:29:25: first of all I'd like to discuss the attack service.
00:29:27: How does it change?
00:29:29: when now?
00:29:29: We're introducing assistance like Jule so SAP Jule for people who don't know it co-pilot and any kind of enterprise AI platforms.
00:29:37: how Does that attack surface changed?
00:29:39: first of All The short answer is It grows.
00:29:42: the attack surface grows.
00:29:43: it grows pretty dramatically because the introduction of AI or actually more specifically, The Introduction Of LLM-Powered Applications really grows the attack surface from things that are possible within the scope and functionality of applications to anything that can be described with words.
00:30:08: When comparing a content based attack with PDF let's stick to this example.
00:30:14: I have two I have to adhere to the principles of PDF as an attacker and i have to embed my malware or attack code in a certain way that is very specific to SAP.
00:30:28: Very specific to pdf, I apologize with LLM-based applications My Attack Code quote on quote attack code Is not really code!
00:30:37: My attack code is language.
00:30:40: it's human language.
00:30:42: And The really big The change here is that now anything embedded in a document, even things that may be readable by humans but doesn't have to be potentially code or are potentially instructions the large language model might decide to act upon.
00:31:05: Which we're not using those exploits with Perl and Java.
00:31:14: Basically, what you're trying to say is simple human words that tell this large language model.
00:31:22: What to do but hidden somewhere?
00:31:24: Exactly
00:31:24: exactly.
00:31:25: I think by now everybody should be familiar more or less with the concept of prompt injections and i think most people have tried it in their chatbot application.
00:31:35: there were many vulnerable chatbots on the internet And I think some of them have gone viral where I don't know, instruct the chatbot of a fast food restaurant chain to help you with your coding exercises where you had a chat bot of a car dealer that was basically selling new cars for virtually zero dollars.
00:31:59: So there have been incidents that go above and beyond the well-known.
00:32:04: ignore all previous instructions.
00:32:11: Business consequences, so the case of that car dealership where the chatbot actually closed a legally binding contract to sell a car for much less than it was worth.
00:32:23: Those are really just tip-of-the icebergs on what happens when those LNM based applications and chatbots or really generation one of these applications?
00:32:34: When we think about agentic application Like the name suggests, the agency to perform certain operations possibly in a chain.
00:32:46: So one agent delegates tasks to another agent-toanother agent when we have those chains and we have vulnerabilities like prompt injections which are intrinsic to LLM based applications.
00:32:59: it's not something you can get rid of by any technical means.
00:33:02: then you have an attack surface that grows pretty much exponentially.
00:33:06: How does it relate to what we spoke about earlier?
00:33:09: Well, in generation one AI applications or LLM-based applications... It was really a human talking through an LLm through a chat interface.
00:33:20: Those applications were limited to what the LM had been trained on.
00:33:24: So if asked for information that wasn't known at time of its training If we're basically to tell you, I don't know.
00:33:33: So the AI labs came up with a concept called reg retrieval augmented generation which means they now give The large language model option to retrieve information and traditionally it was the internet.
00:33:47: if Basically tells me that the assistant or chatbot your helpful assistant You cannot answer the question based on knowledge.
00:33:56: go out of the Internet And find in business scenario in an enterprise application, that RAG pipeline as it's called is actually ingesting business information.
00:34:08: It is ingesting information from tables and it may very well depending on the application ingest information that sits in unstructured content in files.
00:34:18: And thats where we're closing a little loop to our PDFs As a weapon.
00:34:24: I don't have know about the inner workings of pdf to use that PDF, to trick the LLM into doing something it is not supposed to do.
00:34:33: It's sufficient for me to include the instructions in that PDF because what happens technically in RAG is LLMs have a context and all of this information retrieved by that Retrieval Augmented Generation Pipeline is inserted into very same contexts.
00:34:53: so the Llm really does NOT have capability to distinguish between what is legitimate instructions and what data I'm supposed work on.
00:35:03: So if it now finds instruction in the data, It may act upon those instructions and ignore ones that were real
00:35:13: instructions.".
00:35:20: SAP systems and business processes, what would be from your opinion before we talk about protection mechanisms?
00:35:29: What will be in your opinion those risks?
00:35:31: high risks that organizations should look into or at least start to look into when it comes to SAP landscape.
00:35:39: SAP environments where they're connecting their large language models When they have the rag when they have all of these different assistance in place One are now making business, what do you call it?
00:35:51: Business?
00:35:53: not just recommendations but decisions.
00:35:55: Business Decisions that's one.
00:35:57: and then the other part is really how to... Do You protect That?
00:36:02: so The first Parts Is the Risks And Then How To Can We Protect It?
00:36:06: Yeah So the the risks.
00:36:08: Really I think i Think I Spoke to That.
00:36:10: yeah at
00:36:11: Length Is to Trick an LLM Into Doing Something Its Not Supposed to do.
00:36:16: If we think of that in the context of an agentic application, or even swarms of agents interact automatically with each other then this is something very critical because it will become also very difficult to track and trace what actually happened.
00:36:38: have visibility today into the decision-making process of an LLM.
00:36:44: And if you want to call it, Decision Making Process because don't flame me on that I know is not a decision making process but That's what It looks like To The Outsider right?
00:36:53: So having that observability and being able to really trace where does that quote unquote decision come from Is something thats going to be very difficult for most organizations to implement.
00:37:04: If I look maybe two years into the future, we're seeing first implementations of that but not really in production environments yet.
00:37:12: But people will get there.
00:37:15: if you think up those agentic applications where you have a couple of specialized agents and one agent gets larger tasks dissects it into smaller sub-task delegates to other agents And then those may delegate the task to another agent.
00:37:31: There is no way We can have human in loop type control because you would have to have a human at every layer of that multi-layer, agentic framework which is not something that's feasible.
00:37:42: So the protection strategies and it takes me into second part if your question in my mind really just two fold.
00:37:50: one part of the protection is something we always said as security community has always said is sanitation data sanitation.
00:38:00: sanitize your inputs make sure that whatever you ingest is safe.
00:38:05: Now, it's much easier to do with things like XMLs and documents that follow a certain format because if you understand the data format then know where to look for indicators of attack but not indicators of compromise.
00:38:20: If we try doing this in natural language It will be more tricky Still... That's how companies go.
00:38:28: Companies need to sanitize their input not just from a structured perspective, but also from a linguistic perspective.
00:38:36: And the second thing that I think is going to be critical for most organizations Is make sure That organizations can detect The effects of those breach.
00:38:48: So we've seen the concept Of IOCs or indicators of compromise in threat hunting.
00:38:54: Now there's a concept is related to that, there's called indicators of prompt compromise.
00:39:02: Develop some mechanisms and technologies... Some ways really detect the prompt ingested by your agent or any other agents may have something aimed at tricking an agent into doing something it isn't supposed to do.
00:39:20: Absolutely!
00:39:21: To wrap up with our specific topic I think you answered most of it.
00:39:27: What would a modern, we spoke about older modern futuristic enterprises.
00:39:34: and when it comes to SAP what does in Modern Enterprise content security strategy look like from that perspective?
00:39:41: Well
00:39:41: It needs to grow right...it's definitely not something that can stay static.
00:39:46: yeah Something that protected you yesterday is Not going to be as powerful And as protective tomorrow simply because the threat landscape is under constant change, Because the threat vectors are constantly changing and especially with tools like AI.
00:40:05: And the adoption of AI tools having in mind that those new vectors actually have the potential to compromise your brand-new shiny agentic applications companies need to have on the radar.
00:40:19: And again, we're going full circle here because there is... Again, the misconception that it is within the responsibility of AI platform provider to secure those applications when in fact it's not?
00:40:35: It is within a responsibility for customers who use this application To make sure these applications are secured.
00:40:42: Not a platform question but an application.
00:40:46: Definitely agree with it.
00:40:48: It's an application question.
00:40:49: when it comes to fulfilling that circle we just talked about and I do want to stop here, but before i stopped... ...I'd like to ask you one question.
00:40:59: if listeners today listen to our podcast.. ..and remember one message from Todays Conversation what would you wanted to be?
00:41:06: Well
00:41:07: the One Message really is Question your Assumptions When it Comes To the security of data you ingest in your SAP applications.
00:41:19: Don't assume anything, think... Assume a zero-trust thought-of-mind set and question any thing related to security when it comes to documents or data that you ingested into those applications.
00:41:32: I
00:41:32: think is very well put.
00:41:34: We can speak about this topic for next few hours but I'd like thank you for joining us.
00:41:41: We definitely want to see you again with all the new work that your also doing at Bowbridge.
00:41:46: Jörg, thank you and
00:41:47: it's been a pleasure.
00:41:49: Pleasure is mine!
00:41:50: Thank You!
New comment