KI-Denial-of-Service-Angriff

KI-Denial-of-Service-Angriff

Ein offengelegter API-Schlüssel kann Ihr KI-Budget an einem Nachmittag aufbrauchen.

Was ist KI-Denial-of-Service-Angriff?

Every call to a large model buys compute, so an unprotected AI endpoint is a spending account with an API in front of it. Attackers do not need to take the service down, only to keep it busy. You'll find an API key in a public commit and run up the bill with a slow trickle of maximum-cost prompts, then take the defender's seat: read the budget alert, watch cost and latency climb, trace the requests through the console logs, revoke the key, and set a rate limit and a spend threshold.

Was Sie lernen in KI-Denial-of-Service-Angriff

KI-Denial-of-Service-Angriff — Trainingsschritte

  1. Den Scan vorbereiten

    Bob öffnet sein Dashboard zum Scannen von Zugangsdaten. Das Tool überwacht öffentliche Code-Repositorys auf offengelegte API-Schlüssel, Token und Cloud-Secrets. Nun nimmt er die öffentliche GitHub-Organisation von CypherPeak Technologies ins Visier.

  2. Den Scan ausführen

    Bob gibt die URL von CypherPeaks GitHub-Organisation in den Scanner ein und durchsucht alle öffentlichen Repositorys nach Zugangsdaten.

  3. Ein kritischer Befund

    Der Scanner analysierte 847 Repositorys und 12.403 jüngere Commits. Unter sechs gefundenen Secrets sticht eines hervor: Ein produktiver OpenAI-API-Schlüssel steht in einer Konfigurationsdatei, die erst vor wenigen Minuten im Projekt für CypherPeaks KI-Gateway veröffentlicht wurde.

  4. Den Commit untersuchen

    Bob öffnet den ursprünglichen Commit, um die Zugangsdaten im Quellkontext zu prüfen. Das GitHub-Commit-Diff zeigt die gesamte Konfigurationsdatei mit dem API-Schlüssel im Klartext.

  5. Der offengelegte API-Schlüssel

    Das Commit-Diff zeigt einen produktiven API-Schlüssel, der direkt in einer Python-Konfigurationsdatei steht. Er gewährt uneingeschränkten Zugriff auf CypherPeaks KI-Plattform-API; weder Rate Limits noch Budgetgrenzen sind eingerichtet.

  6. Den Angriff vorbereiten

    Bob prüft im Terminal, ob der gestohlene API-Schlüssel noch aktiv ist. Funktioniert er ohne Rate Limit, kann Bob mit einem Denial-of-Wallet-Angriff das gesamte KI-Budget von CypherPeak aufbrauchen.

  7. Den gestohlenen Schlüssel testen

    Bob sendet mit dem gestohlenen Schlüssel eine einfache API-Anfrage. Eine erfolgreiche Antwort ohne Header für Rate Limits würde bestätigen, dass der Schlüssel missbraucht werden kann.

  8. Der Schlüssel funktioniert

    Die API antwortet erfolgreich. Der Schlüssel ist gültig. Besonders kritisch: Die Felder rate_limit und budget_cap stehen beide auf null . Dieser Schlüssel ist durch keine der beiden Kostenbegrenzungen geschützt.

  9. Den Angriff starten

    The key works and has no protections. Bob launches an automated attack script that sends recursive expansion prompts, each designed to consume the maximum 32,768 tokens per request. He runs only 3 worker threads: the request rate stays close to CypherPeak's normal traffic, so no request-rate alarm fires, while every request is as expensive as he can make it.

  10. Angriff im Gange

    The attack script starts 3 worker threads, each sending recursive expansion prompts at maximum token output. Each request takes about a minute to generate, so the workers send about 3 requests a minute. Within the first minute the cost rate reaches $12.40 per minute, over $700 per hour.

Abdeckung der Sicherheits-Frameworks

OWASP LLM Top 10

  • LLM06:2026 Unbounded Consumption
  • LLM10:2025 Unbounded Consumption

CWE

  • CWE-770 Allocation of Resources Without Limits or Throttling

CIS Controls

  • CIS 16 Application Software Security

NIST CSF

  • PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
  • PR.PS Platform Security