
Potential Abuse of Resources by High Token Count and Large Response Sizes
Elastic Detection Rules
View SourceSummary
This detection rule is designed to identify potential misuse of resources within AWS Bedrock, a managed service for building large AI applications. The rule looks for users generating extraordinarily high input token counts alongside many requests and large response sizes, which might indicate attempts to overload the service or illicit data extraction. Such behavior can signify a significant risk of data breaches or service disruptions. The rule operates on logs from AWS Bedrock's invocation, focusing on user interactions that exceed specified thresholds, thus allowing organizations to flag and investigate suspicious activities. Additionally, it offers detailed triage and response guidance, helping security teams to effectively handle potential incidents involving resource abuse.
Categories
- Cloud
- AWS
- Infrastructure
Data Sources
- Cloud Service
- Network Traffic
- Application Log
ATT&CK Techniques
- T0051
Created: 2024-05-04