Перейти к содержимому

Prompt Injection Is a Data Access Problem | Sundar Krishnamurthy | EP 114

Musings from the Cyber Trench

0:00 / 0:00

Prompt Injection Is a Data Access Problem | Sundar Krishnamurthy | EP 114

25 просмотров · 4 дня назад
Musings from the Cyber Trench
21 подписчик
25 просмотров · 4 дня назад
You cannot secure AI by filtering prompts alone. Prompt injection becomes a much harder problem when an AI agent can retrieve sensitive data or execute actions without enforcing identity and authorization at the point of access. In this episode of Musings from the Cyber Trench, I sit down with Sundar Krishnamurthy, Senior Security Architect at Expedia Group, to discuss prompt injection, AI guardrails, non-human identities, and what it takes to secure AI in real enterprise environments. We examine why architecture and data-access decisions matter more than surface-level prompt checks. We also discuss how an AI agent’s identity must remain tied to the human it represents—and why testing, isolation, logging, and authorization must be designed into the system before an MVP becomes production infrastructure. Sundar shares practical insights on: Turning threat-model assumptions into automated tests that detect removed security controls Using one LLM to review code generated by another while keeping humans in the decision process Why vague requirements and prompts produce unreliable code How indirect and multilingual prompts can bypass word-based guardrails Enforcing fine-grained authorization where data is retrieved Preserving both human and non-human identity context during agent-driven actions Using separate vector stores and network boundaries to limit cross-tenant exposure Why security shortcuts taken during an MVP become difficult and expensive to correct Protecting private enterprise data when using open-source and commercial AI models The central message is simple: Do not trust the prompt layer to protect sensitive data. Enforce identity, authorization, isolation, and governance as close as possible to the data and action being requested. ABOUT SUNDAR KRISHNAMURTHY Sundar Krishnamurthy is a Senior Security Architect at Expedia Group. He conducts architecture reviews across applications, cloud, networks, infrastructure, and AI and machine learning security. His background includes work with AWS, SAP Concur, and Microsoft, and he has shared security lessons at BSides events and IBM InterConnect. ZERO TRUST READINESS ASSESSMENT Responsible for ICAM, Zero Trust, or identity security within a federal agency, prime contractor, or large regulated enterprise? If you are trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment: https://zephon.tech/zt Questions or guest suggestions? [defend@zephon.tech](mailto:defend@zephon.tech) CHAPTERS 00:00 Why we trust AI more than we should 02:18 Security controls that survive code changes 07:42 Prompt injection is a data-access problem 11:50 Identity context for AI agents 14:47 Why companies overtrust AI 21:16 Using isolation to reduce the blast radius 25:32 When AI blurs data and control 37:11 AI, machine learning, and open-source models 46:20 Getting to know Sundar 49:18 Stuxnet, autonomous pentesting, and emerging threats 53:56 Envelope encryption and practical security lessons 58:16 Zero Trust readiness assessment