Learn about view Prisma AIRS Violations View.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS AI Runtime Security
|
|
The Prisma AIRS API Violations View provides insight into specific instances of
atomic synchronous API scans identified as threats and subsequently blocked. This
view presents individual API calls containing detected threats, offering a focused
perspective on security incidents within your AI applications. It serves as your
primary interface for understanding and investigating blocked API traffic, which
Prisma AIRS defines as violations.
Prisma AIRS processes your API traffic using a hierarchical data model. Your Tenant
Service Group (TSG) in Strata Cloud Manager (SCM) contains applications, each
generating sessions of API calls. Individual scan requests within these sessions are
the atomic units of API calls that undergo security analysis.
Your associated security profile dictates which detection services, such as Prompt
Injection, URL Filtering, and Data Leak Detection, analyze various payload types
within the scan request. A violation occurs when any detection service
returns a malicious verdict, triggering a "Block" action for that specific scan
request. Logs are generated for these verdicts, providing detailed records for your
investigation.
The Violations View feature provides the following benefits:
- Focused investigation – Investigate the highest risk API violations to protect
your environment.
- Detection efficacy validation – Determine the effectiveness and accuracy of
Prisma AIRS detections in your network.
- Hardened AI security posture – Strengthen the security posture of your AI
applications, models, and agents.
- Comprehensive API threat visibility – Gain visibility into the nature and scope
of API threats targeting your AI infrastructure.
- Streamlined analyst workflow – Provide your security analysts with critical
insights to perform daily threat investigation tasks.
Limitations / Scope
The Prisma AIRS Violations View has specific boundaries and current constraints.
Understanding these limitations helps you set accurate expectations for the
feature's capabilities in your environment.
Use the Violations View exclusively within your Prisma
AIRS API product to monitor API security threats. This feature specifically
focuses on detections made by Prisma AIRS API; you will not see violation data
from Prisma AIRS Network Intercept or Agent Security Fabric within this
view.
Snippet Availability Limitations
Not all threat detectors currently support displaying "Violated Snippets" within the
Transaction Overview flyout. While a threat may be detected and a violation
recorded, the specific content snippet that triggered the detection might not be
visible for certain detectors. Detectors without snippet support include:
contextual-grounding
topic-guardrails
agent-security
command-injection
For detectors without snippet support, the UI
displays "Snippets are currently not supported for [detector type]" in the
Transaction Overview flyout; this message applies to contextual
grounding, topic guardrails and agent security detector types.
Security profile changes for Data Loss
Prevention (DLP) patterns are currently not supported. This limitation exists
because the configuration option for
Snippet Viewing and Masking in the
Data Loss Prevention section of Strata Cloud Manager (SCM) does not
currently provide a toggle to
Store Snippets of Sensitive Data. This
functionality will be available in a future update.
Best practices/ Recommendations
Consider these factors when implementing the API Violations View in your network:
Prioritize Investigations – Focus on high-severity
violations first to address the most critical risks to your AI applications
and data.
Validate Detection Efficacy – Regularly review detected
violations and their associated snippets to ensure Prisma AIRS detections
are accurate and effective for your specific use cases.
Refine Security Profiles – Use insights from the Violations
View to iteratively harden your AI Security Profiles, reducing false
positives and strengthening overall protection.