AI Runtime End-to-End Security Workflow
Focus
Focus
Prisma AIRS

AI Runtime End-to-End Security Workflow

Table of Contents


AI Runtime End-to-End Security Workflow

Understand the end-to-end workflow for deploying and operating Prisma AIRS in your cloud environment.
Where Can I Use This?What Do I Need?
  • Prisma AIRS
  • No prerequisites needed
The Prisma AIRS instance monitors both AI and non-AI traffic within the protected workloads of your cloud environment. Its security posture offers a comprehensive workflow covering ingress, egress, and east-west traffic.
Deployment Profile Activation on Hub
To begin with, activate your AI Runtime licenses, and create an AI runtime deployment profile in the Palo Alto Customer Support Portal (CSP), associate it with a TSG, and activate the cloud tenant.
Activation and Onboarding of Cloud Account in Strata Cloud Manager
This involves configuring the cloud account in the Strata Cloud Manager with the service account and deploying the generated Terraform in your cloud environment. The Terraform script creates Prisma AIRS resources and grants necessary permissions to enable asset discovery from Strata Cloud Manager.
Discovery of Application Workloads
Following the successful activation of your account, the Strata Cloud Manager InsightsAI Runtime Security dashboard provides a consolidated overview of the identified cloud assets and the network traffic pathways—between applications and AI models, user applications to the internet, and external applications to user applications. This interactive view assists in analyzing risks associated with unprotected applications and evaluating potential threats.
AI Runtime Security instance Deployment in the Cloud
Deploy the Prisma AIRS instance in your cloud environment to protect vulnerable assets and monitor network traffic flow based on the risk analysis from the Strata Cloud Manager dashboard.
Defend with Granular Security Policies
To defend and prevent potential AI attacks create specific security policies and push the onboarding rules and policy configuration snippets from Strata Cloud Manager to the AI Runtime Security instance.
Define AI security profiles for application protection, AI model protection, and data protection with capabilities for alert actions, blocking actions, and log forwarding.
You can define security policy rules for a zone or a Dynamic Address Group.
As AI traffic flows from VM-based applications to models, the deployed AI Runtime Security instance connects to the cloud service to fetch the AI traffic and threat logs. It monitors and applies the security rules to identify threats. Detailed logs are available for analysis in Strata Cloud Manager under Incidents and AlertsLog ViewerFirewall/AI Security.