Defending Cloud AI Applications with Fortinet
The scalability, GPU access, and managed services of public cloud make it the natural platform for developing and deploying AI and LLM-based applications—and why this changes the architecture of security itself. Fortinet is focusing on securing AI applications in the cloud, a topic that dominates its conversations with customers. They emphasize the cloud’s unique ability to provide the scalability needed to run GPUs and TPUs, simplifying deployment and accelerating the development of agentic services. They are seeing increased reports of model theft and prompt injection attacks, alongside traditional hygiene issues like misconfigurations and stolen credentials, highlighting the growing need for robust security measures in cloud-based AI deployments.
Fortinet’s approach involves a layered security strategy that incorporates tools such as FortiOS for zero-trust access and continuous posture assessment, FortiCNAP for vulnerability scanning throughout the AI workload lifecycle, and FortiWeb for web application and API protection. FortiWeb uses machine learning to detect anomalous activities and sanitize LLM user input, addressing the OWASP Top 10 threats to LLMs. The company also highlights the importance of data protection, implementing data leak prevention measures on endpoints and in-line to control access to sensitive data and training data.
The presentation outlines a demo environment showcasing a segmented network with standard security measures in place. Fortinet will inspect both north-south and east-west traffic between nodes, monitoring the environment with FortiCNAP. The demo will demonstrate how a combination of old and new attacks, such as SQL injection escalating into SSRF and model corruption, can compromise AI applications. The aim is to highlight the importance of securing access, implementing robust data protection measures, and maintaining vigilance against evolving AI-specific threats.
Presented by Aidan Walden, Global Director, Cloud DevOps Engineering & Architecture, Fortinet. Recorded live at Cloud Field Day in Emeryville on October 21, 2025. Watch the entire presentation at https://techfieldday.com/event/cfd24/ or visit https://www.fortinet.com/ for more information.
Transcript
My name is Aiden Walden. And what we're doing at Fortinet is with respect to the cloud, is, is having a really, a daily conversation about AI applications. It is the conversation, uh, that predominates, uh, how and what we talk about, uh, securing in the cloud at this point.
And so we thought it fitting to bring this use case, which we, we talk about regularly with our customers, uh, to the cloud field day. So we will be talking about some other stuff. Um, as a preview, we will talk, uh, or participate in the AI field day.
Um, and I have teammates that will, um, represent us there. But, uh, that conversation is so linked and, and inextricably because really the, the, the cloud platform is the only platform that really presents the, presents, the scalability to run GPUs and TPUs. Um, and to do that in a way that allows the customer to do it very quickly and, and, and, and taking away some of the overhead of, you know, managing the runtime environment and making it very simple to deploy.
And at the end of the day, you know, customers, um, can benefit from tremendous velocity because it's very, very competitive at this point to get these, these applications, uh, these agentic services deployed. And I think it's, you know, pretty self-evident. Uh, this, this fact.
When you see that Nvidia, uh, supplies, well, 50% of their revenue really comes from three customers, and you can guess who they are. So we know that cloud, um, is very important to ai. It's the conversation we have with our customers, with the cloud providers who are pushing to sell, um, the, that compute and, um, that capability our customers bring these challenges.
And what's, what is really, um, kind of been an experience to have over the last six months, and I say six months because that's not a long time. These statistics that call out like, you know, almost half of enterprises reporting theft or access, uh, of, um, of model, uh, or excuse me, um, almost half of customers reporting access to models or theft of models, uh, or 35%, you know, reporting, you know, being victimized by a prompt injection just a few months ago. Uh, that was somewhat anecdotal.
You know, we knew that it could happen. Uh, there were not enough AI apps deployed across enterprises, and not, not enough maturity maybe to see that realize, but we are definitely, uh, realizing that now, um, tons of customers are really still struggling with the challenge of hygiene, which makes them more vulnerable. Uh, specifically as they roll out more of these, uh, cloud-based AI applications.
Uh, they, they report that, you know, misconfigurations and vulnerable applications, stolen credentials, credentials that are posted, uh, you know, maybe, uh, in, in public repositories. You know, we see that all the time. And, uh, this is, this is common.
And, you know, half of customers, you know, along with Nvidia, you know, half of their revenues going to the top three cloud providers. You know, half of AI applications are reported to be deployed in a public cloud environment. The, the, I think the really interesting, uh, fact that kind of rides with that is the f that 12% of AI PO projects have been realized and fully implemented to date.
So we're gonna see a lot more of these projects come to maturity, um, in, in the very near future here. And so, what is our story about? Well, we, we like to bring in true stories, and we, we have run into this and we, we see a lot of attack paths that are executed, um, and customers have, you know, are looking to solve for very specific, uh, use case problems.
And so we're, we're kind of revisiting that, uh, you know, a, a circumstance that we've seen will protect the names of, of the, of, of the victims, uh, so as not to, uh, uh, call anybody out, but, um, what what we're really seeing is this combination of, uh, old attacks being, uh, mixed with new attack types, right? The, when you're deploying these AI applications, the, the application types in and of themselves are presenting a, a brand new attack surface. Uh, you all know being cloud experts that cloud networks are, are very flat.
There's lots of ingress and egress points, and, um, you have to turn knobs on. And, and there's a lot of hygiene issue with, with that, uh, with some of the security controls maybe not being in place by default. Um, and a lot of, you know, drift that goes along with that, but we can, attackers can use, you know, classic, uh, SQL injections.
We're gonna do that today. We're gonna show you how an attack path escalates and then really gets to something, um, very, very interesting. So it starts with a a an SQL injection.
Uh, then we, you know, are going to show how that, uh, ends up, uh, escalating into an SSRF attack. And then, and then finally, we're going to do some model corruption. Now, this is all gonna be very interesting if in full transparency, as they say, the demo guides may, uh, may not be with us today because we are going to be working with, uh, a real foundation model.
Uh, and, and, uh, they, it, it's never the same interaction twice. So, uh, we're doing, we're taking a little bit of risk, but we think we, uh, we've got a, a really good demo now in our demo, we're all, we're gonna be talking about MCP, uh, I'm making the assumption that everybody here is familiar with MCP, uh, but, uh, you know, the, the network folks love this. The, the application folks, uh, like it, it's providing simplicity for, you know, uh, if you're bringing in legacy, uh, you know, APIs that need to interact with agent services and, uh, facilitates the standard communication protocol.
But Docker had this funny cartoon, this comic that I thought was hilarious, um, and so I wanted to include it, but, uh, this is how MCP is. It's a lot of MCP applications are being vibe coded. They're, they're pretty sketchy, um, many of them.
Um, and we're finding that they're exposing services that they may not, uh, or they should not be. Um, but we're gonna use MCP, uh, to intermediate the information that's provided to our JU juice shop app, and then ultimately is provided to the language model. Um, now, uh, this presents for us an attack, uh, uh, an attack type.
So we can, we're gonna try to manipulate, uh, you know, show some protocol manipulation. Um, and the reason that this is part of our demo, again, we're, it's very customer centric, and our customers are asking us how to secure this. And so we spent some effort on the Fortinet side doing just that.
Now, I, I've been at Fortinet for about 10 years, uh, all, for most all of that. I've been part of the cloud effort and being part of that cloud effort. Uh, uh, back, uh, a decade ago I was talking about, uh, uh, you know, uh, neural networks and, and ai, you know, a long time ago.
And, and, and back then, to be honest, people weren't that interested. But we had a really fantastic, uh, service that PR enabled Fortinet to scale our threat intelligence to be a, a, a world class threat, threat intelligence platform. Uh, I, I would still, you know, bet it's, uh, you know, in my opinion, it's probably the best you'll find.
And over time, we continue to evolve our services. And in the last cloud field day, um, and, and maybe even before that, and, and a couple of others, we've shown the value that we can bring in helping the SOC scale, right? We're the, the classic challenge of not having enough security practitioners, uh, having too much data volume that overwhelms them.
And how can, uh, both machine learning and generative AI help those operators digest more signal, prioritize that signal, and then get ahead of the challenges and ultimately reduce their MTTR and risk based lines. We think we've done a really good job there. Where we're focused now and into the future, is really bringing the AgTech AI services to the fore.
And, uh, again, forecasting into our, into our AI field day that we'll participate in. We'll talk about, uh, what we, what we'll call 40 ai, really, which is a program and a, and a, a set of services across our portfolio that will enhance, uh, the protection, uh, of the assistance with and the security for, uh, AI across our portfolio. And we'll, we'll talk about some of that a little bit today.
Now, we have focused on, we've actually demonstrated some of this before. So if I harken back to prior cloud field days, if you were part of that, showed have, we could, uh, as an example, generate, use generative ai AI to write playbooks on its own, build the API connections, and then, you know, execute those playbooks, uh, with, with some, a large degree of success, you know, um, and so we've done that. So, but what, what we're gonna focus on in the strategic areas of interest are security for ai.
So our application is an AI application. We're gonna talk about, um, and, and walk through in the demo of the, the observability of the platform. That'll actually be a little later in the demonstration.
But we want to make sure that our, our posture or hygiene are, are very solid within our, um, service and toolkit. We can, um, look at posture and then provide some guidance, uh, with the help of AI there. Um, prompt security will be a big part of this, so we will get to that as well as, uh, MCP protection.
Um, so as we move through this demonstration, we'll be talking about these, uh, particular areas of focus, but we'll also cast them in the broader context of, and this is just a reminder for my teammates that we'll be talking about, uh, the best practices of security in the cloud. Now, um, these are the threats that we see, um, and, and we hear from our customers, uh, daily. Uh, and these are the things that we're going to, you know, really look to address and, and we can address in our security portfolio.
But as we're investing in these areas of, in these use cases, they really tie into, um, something that we've been focused on is the O os top ten four LLMs. Uh, the platform that, uh, we, we will use and show some of that in today, which is our, our 40 web platform, um, is looking to specifically target those o os, uh, threats against LLMs. Now, uh, I want to orient this just a little bit more before I hand it over to my, our teammates.
And, and I would be remiss if I, I didn't talk and orient you towards some of the toolkit that will bring to bear. So as we demonstrate, uh, security, uh, for the, you know, the cloud, uh, environment, um, and the applications that we're gonna run therein, uh, these are some of the, uh, toolkit that we will bring to bear, uh, in the demonstration. So we're a very broad spectrum security provider, um, in our cloud portfolio.
Uh, we cover, uh, cloud networking, the applications that run on cloud and the underlying substrate as a platform. So think of C nab, CSPM capabilities. Um, and so the tooling that we're going bring and, and what we're going to talk about is starts with just as a security effort, securing access to your cloud environment into that AI workload.
Uh, we can do that with, um, you know, the, from the time that, uh, a user accesses the platform by applying zero trust principles, continually assessing posture. That's provided, uh, for by our Cord OS operating system, which runs our, our inline network firewall services. We're going to include in our tools, uh, today, uh, the 40 CNA, uh, set of capabilities.
So our CNA platform starts with, uh, in inspecting code as it's being factored and compiled. Uh, we can inspect the application at runtime through dynamic application testing, which uses some of, uh, some AI features to, um, or, or looks for certain ai, uh, functionality. Uh, we will then, uh, talk about, uh, posture management on that platform.
So securing the entire enclave and having visibility therein. And then we'll talk about, and we'll move into order web Now. Order web is our web application and API protection service, which provides defense for, um, well, it's really a machine learning platform that, uh, looks for activities that are anomalous and decides if those are benign or malicious, and can differentiate between them, uh, using some advanced, uh, machine learning analytics.
And then finally, and, and most importantly, data, uh, protection. At the end of the day, attackers want to get to the data, uh, the data that is, uh, uh, sensitive, um, confidential, also the training data that drives these services that customers are delivering. And so we do that in a couple ways, both on the endpoint, um, by, uh, inspecting the types of content that are on that endpoint, preventing, uh, egress, uh, from the endpoints themselves, uh, and then also, uh, providing similar, um, or, uh, analogous services in line on the same, uh, uh, security operating system for the os.
So I can apply data leak profiles to, as an example, um, A-Z-T-N-A service where, you know, I have a certain user type that is permitted to access certain types of data, but not other types of data. Um, what's also very interesting as a best practice as we support more agent services, uh, that are deployed across, across the cloud and implementing segmentation for those AI services, and then also treating them, uh, on those segments as if they're ZT and A users. So, um, making sure that they only have permissions to the network paths that, uh, that they need at the time.
They need them continually assessing the posture so that a vulnerable application or service that also coexists with that, with that ai, uh, agent, um, cannot, you know, maybe corrupt that or, uh, create a lateral threat, um, in that communication. So, going a little deeper. Um, so what we wanna do is, uh, firstly, uh, we're, we're focusing on ZTNA.
Now, we're not gonna dig deep into ZTNA during this presentation, but we don't, as a security principle, we want to always reinforce the access principles, uh, in the cloud. So, uh, I mentioned we can apply data access security profiles that map to ZTNA services and, and profiles. Um, and, uh, we can enforce, uh, trust boundaries, uh, really granularly across these different segments of the cloud.
And I'll show you what the architecture looks like in a few minutes that it shows how we'll simply model a segmented environment. Uh, CAPP is really looking at the full life cycle of the AI workload. So from the time it's developed, uh, we're continuously scanning, uh, for vulnerabilities, misconfigurations, um, uh, uh, you know, poorly factored, uh, software, uh, embedded secrets, things like that.
And then once the, the application is factored, uh, uh, and built, um, then we're applying both agent base and agent list scanning into those environments, into that cloud enclave, uh, to uncover, uh, runtime vulnerabilities, um, and, and other security vulnerabilities, um, in, uh, in the cloud. Now, um, the identity and protection services, uh, a little bit deeper, uh, with respect to detecting AI services. So when a, when a user interacts with an AI service, we can detect that on the network.
Uh, we, we can profile that application, um, and report on, uh, how that user is interacting with it. So, um, once they're authenticated, we wanna continue to track, uh, how, how that AI service is being used, uh, what associated risks there are with that particular service. Um, what type of, um, you know, information are they getting out of that, you potentially, uh, from that AI service.
And so we want to continue to monitor from that. And so we provide pretty well, I would say, very granular detail around, around the visibility of the AI applications that are traversing the network. Hi, this is Kimberly Bates.
Um, yeah, Hi. It's regards to cracking AI workloads is what is really different about the AI workload versus a database workload or something else that you're tracking to secure. What did you need to do that was different?
Uh, well, there's, uh, we're in, so what's different about it is how, how a user, uh, will interact with the applications. So, um, the, the interactions are one risky from the sense that if a user has, um, maybe a certain set of limited permissions on the network to applications, but they can access the AI application, there's an opportunity for maybe a, um, a, uh, privilege escalation, and so they could get information. So we wanna know what information is, is coming out of that AI application.
Um, data leak prevention is, is a big part of that. Um, we want to, um, uh, the way the user interacts with the application is also very different because it's, it's very just colloquial language, um, that they're using. Um, and so I think the risk there is that you don't, and, and actually Julian's gonna demonstrate this, the, the level of expertise and how you prompt is much different than factoring like CLI commands, which can be very easily picked up in RegX patterns, potentially.
Um, so the, just the, the threat profile I think looks different for that particular type of application. Did I answer your question? I, I wonder if I left something?
Yeah, you did answer the question. The, the follow on to that is, and I guess you're gonna demonstrate this, the what you did. Yeah, yeah.
We will, we Will demonstrate what are the things that you had to do so differently for this use case mm-hmm. Than you did with the other areas. Um, and I understand what you're saying is that it's more, more colloquial language that's being used as opposed traditional program.
Yes. Um, I, so we will, we will demonstrate that. I, I don't wanna steal everybody's thunder here, but, uh, we'll, we will demonstrate.
So would you ask your question again? Uh, if it doesn't get answered about halfway through. Okay.
Awesome. Thank you. Okay.
Um, so I mentioned some of these things that we can do, uh, within our web application and API protection platform. Uh, this is where we're going to invoke, uh, you know, API inspections we're, we're looking for, um, you know, what is, uh, what is acceptable, um, uh, an acceptable request to the API. Uh, we're constantly learning the patterns, uh, and the schema of the API so that we can tighten security as we see more and more interactions.
Uh, and then this is where we're gonna look to filter and sanitize LLM user input, which I think might get to your, the, the specific question therein. Um, and then finally, you know, what's really important, and this is actually becoming, I, I think rather common is using AI based bots that can, um, hit a very high volume of attack rates and iterations on a particular attack type. And so rate limiting, um, is actually becoming very important in, in, you know, how we allow people to interact with these, with these AI applications.
Okay. Our environment. And then I'm gonna hand it over to Derek who's gonna dig into the actual workflow.
Um, but what we have is what would be typical at an extremely high level, uh, right. Uh, so, uh, this is a, a segmented network. Uh, we have a standard security enclave.
So, uh, SJA and Julian are gonna be, uh, working within the, the security VPC here. And then we have segmentation across our app, um, our application stack. Now, uh, there will be external communication out of the network, uh, to the, the AI service, or excuse me, the LLM.
Um, but what we are doing and what we do will do is, um, inspect both north, south and east west traffic between these, um, uh, between these nodes. So, um, the last piece I will mention is, uh, all of this is gonna be monitored with four to capp. So in the demonstration, we're actually gonna come back around to, uh, look at what we saw on the platform, um, from four to capp after we go through some of the, uh, inline controls, uh, through this, uh, attack path.
Uh, so for to CAPP will or does have the ability to kind of look across network and platform and kind of aggregate the, um, uh, the attack path details and, and, and, and with a lot of enrichment.