diff --git a/detections/application/ollama_abnormal_network_connectivity.yml b/detections/application/ollama_abnormal_network_connectivity.yml index c12fe51364c..2a48c920127 100644 --- a/detections/application/ollama_abnormal_network_connectivity.yml +++ b/detections/application/ollama_abnormal_network_connectivity.yml @@ -1,54 +1,79 @@ name: Ollama Abnormal Network Connectivity id: 19ec30ad-faa2-496a-a6a9-f2e5f778fbdb -version: 5 +version: 6 creation_date: '2025-10-13' -modification_date: '2026-05-13' -author: Rod Soto -status: experimental +modification_date: '2026-10-09' +author: Rod Soto, Nasreddine Bencherchali, Splunk +status: production type: Anomaly -description: Detects abnormal network activity and connectivity issues in Ollama including non-localhost API access attempts and warning-level network errors such as DNS lookup failures, TCP connection issues, or host resolution problems that may indicate network-based attacks, unauthorized access attempts, or infrastructure reconnaissance activity. +description: |- + Detects repeated Ollama warning-level network errors, such as DNS lookup failures, TCP connection issues, or host resolution problems. These events can indicate a connectivity issue and warrant investigation, but do not by themselves establish unauthorized access or reconnaissance. data_source: - Ollama Server search: |- - `ollama_server` level=WARN (msg="*failed*" OR msg="*dial tcp*" OR msg="*lookup*" OR msg="*no such host*" OR msg="*connection*" OR msg="*network*" OR msg="*timeout*" OR msg="*unreachable*" OR msg="*refused*") - | eval src=coalesce(src, src_ip, "N/A") - | stats count as incidents, values(src) as src, values(msg) as warning_messages, latest(_time) as last_incident - BY host - | eval last_incident=strftime(last_incident, "%Y-%m-%d %H:%M:%S") - | eval severity="medium" - | eval attack_type="Abnormal Network Connectivity" - | stats count - BY last_incident, host, incidents, - src, warning_messages, severity, - attack_type - | `ollama_abnormal_network_connectivity_filter` -how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.' -known_false_positives: Legitimate remote access from authorized users or applications connecting from non-localhost addresses, temporary network infrastructure issues causing DNS resolution failures, firewall or network configuration changes resulting in connection timeouts, cloud-hosted Ollama instances receiving valid external API requests, or intermittent connectivity problems during network maintenance may trigger this detection during normal operations. + `ollama_server` + level=WARN + msg IN ( + "*connection*", + "*dial tcp*", + "*failed*", + "*lookup*", + "*network*", + "*no such host*", + "*refused*", + "*timeout*", + "*unreachable*" + ) + + | bin _time span=5m + | stats count as incidents + values(msg) as warning_messages + latest(_time) as last_incident + by _time dest + + | where incidents > 3 + + | eval last_incident=strftime(last_incident, "%Y-%m-%d %H:%M:%S") + + | eval severity="medium" + + | eval attack_type="Abnormal Network Connectivity" + + | table last_incident dest incidents warning_messages severity attack_type + + | `ollama_abnormal_network_connectivity_filter` +how_to_implement: |- + Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections. +known_false_positives: |- + Legitimate remote access from authorized users or applications connecting from non-localhost addresses, temporary network infrastructure issues causing DNS resolution failures, firewall or network configuration changes resulting in connection timeouts, cloud-hosted Ollama instances receiving valid external API requests, or intermittent connectivity problems during network maintenance may trigger this detection during normal operations. references: - https://github.com/rosplk/ta-ollama drilldown_searches: - - name: View the detection results for - "$src$" - search: '%original_detection_search% | search "$src = "$src$"' + - name: View the detection results for - "$dest$" + search: |- + %original_detection_search% + | search dest="$dest$" earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - - name: View risk events for the last 7 days for - "$src$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$",) | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + - name: View risk events for the last 7 days for - "$dest$" + search: |- + from datamodel Risk.All_Risk + | search normalized_risk_object IN ("$dest$") + | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` earliest_offset: 7d latest_offset: "0" intermediate_findings: entities: - - field: host + - field: dest type: system score: 20 - message: 'Abnormal network activity detected on $host$ with $incidents$ incidents from $src$. Investigation needed for network errors: $warning_messages$.' -threat_objects: - - field: src - type: system + message: Abnormal network activity on [$dest$] with [$incidents$] matching warnings [$warning_messages$]. Investigate DNS and network reachability. analytic_story: - Suspicious Ollama Activities asset_type: Web Application -mitre_attack_id: - - T1571 +mitre_attack_id: [] product: - Splunk Enterprise - Splunk Enterprise Security @@ -61,5 +86,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log sourcetype: ollama:server source: app.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit diff --git a/detections/application/ollama_excessive_api_requests.yml b/detections/application/ollama_excessive_api_requests.yml index 42f4958876a..76eb6313a1f 100644 --- a/detections/application/ollama_excessive_api_requests.yml +++ b/detections/application/ollama_excessive_api_requests.yml @@ -1,26 +1,62 @@ name: Ollama Excessive API Requests id: 1cfab663-9adc-4169-a88c-6bae29ba3c70 -version: 4 +version: 5 creation_date: '2025-10-13' -modification_date: '2026-05-13' -author: Rod Soto -status: experimental +modification_date: '2026-10-09' +author: Rod Soto, Nasreddine Bencherchali, Splunk +status: production type: Anomaly -description: Detects potential Distributed Denial of Service (DDoS) attacks or rate limit abuse against Ollama API endpoints by identifying excessive request volumes from individual client IP addresses. This detection monitors GIN-formatted Ollama server logs to identify clients generating abnormally high request rates within short time windows, which may indicate automated attacks, botnet activity, or resource exhaustion attempts targeting local AI model infrastructure. +description: Detects high Ollama API request volumes from a single client in a short time window. A burst may indicate automated abuse or contribute to resource contention, but GIN access logs do not establish malicious intent or service impact; validate the client and workload against local usage baselines. data_source: - Ollama Server -search: '`ollama_server` | rex field=_raw "\|\s+(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s+\|" | eval src=coalesce(src, client_ip) | eval dest=coalesce(dest, url, uripath, endpoint) | bin _time span=5m | stats count as request_count by _time, src, dest, host | where request_count > 120 | eval severity="high" | eval attack_type="Rate Limit Abuse / DDoS" | stats count by _time, host, src, dest, request_count, severity, attack_type | `ollama_excessive_api_requests_filter`' -how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.' -known_false_positives: Legitimate automated services (CI/CD pipelines, monitoring tools, batch jobs), multiple users behind NAT/proxy infrastructure, or authorized load testing activities may trigger this detection during normal operations. Operator must adjust threshold accordingly. +search: |- + `ollama_server` + "[GIN]" + + | rex field=_raw "\|\s+(?\d+)\s+\|\s+(?[\d\.]+(?:µs|ms|s))\s+\|\s+(?[^|]+?)\s+\|\s+(?\w+)\s+\"(?[^\"]+)\"" + + | eval src=coalesce(src, trim(raw_src)) + | eval uri_path=coalesce(uri_path, raw_path) + | eval http_method=coalesce(http_method, raw_method) + | eval http_response_code=coalesce(http_response_code, raw_status) + | eval response_time_ms=coalesce(response_time_ms, case(match(raw_latency, "µs$"), tonumber(replace(raw_latency, "µs", ""))/1000, match(raw_latency, "ms$"), tonumber(replace(raw_latency, "ms", "")), match(raw_latency, "s$"), tonumber(replace(raw_latency, "s", ""))*1000)) + + | where isnotnull(src) + + | bin _time span=5m + + | stats count as request_count + dc(uri_path) as distinct_endpoints + values(uri_path) as endpoints + by _time src + + | where request_count > 120 + + | eval severity="medium" + + | eval attack_type="High Volume API Activity" + + | `ollama_excessive_api_requests_filter` +how_to_implement: |- + Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections. +known_false_positives: |- + Legitimate automated services (CI/CD pipelines, monitoring tools, batch jobs), multiple users behind NAT/proxy infrastructure, or authorized load testing activities may trigger this detection during normal operations. Operator must adjust threshold accordingly. references: - https://github.com/rosplk/ta-ollama drilldown_searches: - name: View the detection results for - "$src$" - search: '%original_detection_search% | search "$src = "$src$"' + search: |- + %original_detection_search% + | search src="$src$" earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$src$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: |- + from datamodel Risk.All_Risk + | search normalized_risk_object IN ("$src$") + | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` earliest_offset: 7d latest_offset: "0" intermediate_findings: @@ -28,7 +64,7 @@ intermediate_findings: - field: src type: system score: 20 - message: Possible DDoS attack from $src$ against Ollama server detected with request count $request_count$ in 1 minute, potentially causing service degradation or complete unavailability. + message: '[$request_count$] Ollama API requests from [$src$] across [$distinct_endpoints$] endpoints were observed in 5 minutes. Validate the client and workload before attributing the burst to abuse or service impact.' analytic_story: - Suspicious Ollama Activities asset_type: Web Application @@ -46,5 +82,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log sourcetype: ollama:server source: server.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit diff --git a/detections/application/ollama_long_running_inference_requests.yml b/detections/application/ollama_long_running_inference_requests.yml new file mode 100644 index 00000000000..f7a3853554f --- /dev/null +++ b/detections/application/ollama_long_running_inference_requests.yml @@ -0,0 +1,97 @@ +name: Ollama Long-Running Inference Requests +id: 7619c98c-f53b-445f-87ca-b148e8560340 +version: 1 +creation_date: '2026-10-09' +modification_date: '2026-10-09' +author: Rod Soto, Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: |- + Identifies repeated Ollama inference requests with long response times on /api/generate, /api/chat, and /v1/chat/completions. + Long response time can result from model size, prompt length, host resources, or normal workload. GIN access logs do not include prompt content and cannot establish a prompt injection or jailbreak attempt, so use this as an exploratory performance signal. +data_source: + - Ollama Server +search: |- + `ollama_server` + "[GIN]" + + | rex field=_raw "\|\s+(?\d+)\s+\|\s+(?(?:\d+m)?[\d\.]+(?:µs|ms|s))\s+\|\s+(?[^|]+?)\s+\|\s+(?\w+)\s+\"(?[^\"]+)\"" + + | eval src=coalesce(src, trim(raw_src)) + | eval uri_path=coalesce(uri_path, raw_path) + | eval http_method=coalesce(http_method, raw_method) + | eval http_response_code=coalesce(http_response_code, raw_status) + | rex field=raw_latency "^(?:(?\d+)m)?(?[\d\.]+)(?µs|ms|s)$" + | eval response_time_ms=coalesce(response_time_ms, (coalesce(tonumber(raw_latency_minutes), 0) * 60000) + (tonumber(raw_latency_value) * case(raw_latency_unit="µs", 0.001, raw_latency_unit="ms", 1, raw_latency_unit="s", 1000))) + + | where isnotnull(src) AND in(uri_path, "/api/generate", "/api/chat", "/v1/chat/completions") AND response_time_ms > 30000 + + | eval response_time_seconds=response_time_ms/1000 + + | bin _time span=10m + + | stats count as long_request_count + avg(response_time_seconds) as avg_response_time + max(response_time_seconds) as max_response_time + values(uri_path) as uri_path + values(http_response_code) as status_codes + by _time src host + + | where long_request_count > 1 + + | eval avg_response_time=round(avg_response_time, 2) + | eval max_response_time=round(max_response_time, 2) + | eval severity=case(max_response_time > 55, "high", 1=1, "medium") + | eval attack_type="Long-Running Inference Requests" + + | table _time host src uri_path long_request_count + avg_response_time max_response_time + status_codes severity attack_type + + | `ollama_long_running_inference_requests_filter` +how_to_implement: |- + Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections. +known_false_positives: |- + Legitimate complex queries requiring extensive model reasoning, large context windows processing substantial amounts of text, batch processing operations, or resource-constrained systems experiencing performance degradation may trigger this detection during normal operations. +references: + - https://github.com/rosplk/ta-ollama + - https://github.com/OWASP/www-project-ai-testing-guide +drilldown_searches: + - name: View the detection results for - "$src$" + search: |- + %original_detection_search% + | search src="$src$" + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: |- + from datamodel Risk.All_Risk + | search normalized_risk_object IN ("$src$") + | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: src + type: system + score: 20 + message: '[$long_request_count$] long-running inference requests from [$src$] averaged [$avg_response_time$] seconds and reached [$max_response_time$] seconds. Investigate workload, model size, prompt length, and host capacity; access logs do not establish prompt injection or data exfiltration.' +analytic_story: + - Suspicious Ollama Activities +asset_type: Web Application +mitre_attack_id: [] +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: application +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log + sourcetype: ollama:server + source: server.log + test_type: unit diff --git a/detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml b/detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml index aa1b54cd733..524253871e7 100644 --- a/detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml +++ b/detections/application/ollama_possible_api_endpoint_scan_reconnaissance.yml @@ -1,38 +1,69 @@ name: Ollama Possible API Endpoint Scan Reconnaissance id: ad3f352a-0347-48ee-86b9-670b5025a548 -version: 5 +version: 6 creation_date: '2025-10-13' -modification_date: '2026-05-13' -author: Rod Soto -status: experimental +modification_date: '2026-10-09' +author: Rod Soto, Nasreddine Bencherchali, Splunk +status: production type: Anomaly -description: Detects API reconnaissance and endpoint scanning activity against Ollama servers by identifying sources probing multiple API endpoints within short timeframes, particularly when using HEAD requests or accessing diverse endpoint paths, which indicates systematic enumeration to map the API surface, discover hidden endpoints, or identify vulnerabilities before launching targeted attacks. +description: |- + Detects API reconnaissance and endpoint scanning activity against Ollama servers by identifying sources probing multiple API endpoints within short timeframes, particularly when using HEAD requests or accessing diverse endpoint paths, which indicates systematic enumeration to map the API surface, discover hidden endpoints, or identify vulnerabilities before launching targeted attacks. data_source: - Ollama Server search: |- - `ollama_server` "[GIN]" - | bin _time span=5m - | stats count as total_requests, values(dest) as dest, values(http_method) as methods, values(status) as status_codes - BY _time, src, host - | where total_requests > 120 - | eval severity="medium" - | eval attack_type="API Activity Surge" - | stats count - BY _time, host, src, - total_requests, dest, methods, - status_codes, severity, attack_type - | `ollama_possible_api_endpoint_scan_reconnaissance_filter` -how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.' -known_false_positives: Legitimate web application clients or mobile apps that access multiple API endpoints as part of normal functionality, monitoring and health check systems probing various endpoints for availability, load balancers performing health checks across different paths, API testing frameworks during development and QA processes, or users navigating through web interfaces that trigger multiple API calls may generate similar patterns during normal operations. + `ollama_server` + "[GIN]" + + | rex field=_raw "\|\s+(?\d+)\s+\|\s+(?[\d\.]+(?:µs|ms|s))\s+\|\s+(?[^|]+?)\s+\|\s+(?\w+)\s+\"(?[^\"]+)\"" + + | eval src=coalesce(src, trim(raw_src)) + | eval uri_path=coalesce(uri_path, raw_path) + | eval http_method=coalesce(http_method, raw_method) + | eval http_response_code=coalesce(http_response_code, raw_status) + | eval response_time_ms=coalesce(response_time_ms, case(match(raw_latency, "µs$"), tonumber(replace(raw_latency, "µs", ""))/1000, match(raw_latency, "ms$"), tonumber(replace(raw_latency, "ms", "")), match(raw_latency, "s$"), tonumber(replace(raw_latency, "s", ""))*1000)) + + | where isnotnull(src) AND isnotnull(uri_path) + + | bin _time span=5m + + | stats count as total_requests + dc(uri_path) as distinct_endpoints + count(eval(http_method="HEAD")) as head_requests + values(uri_path) as endpoints + values(http_method) as methods + values(http_response_code) as status_codes + by _time src host + + | where total_requests > 120 AND (distinct_endpoints >= 3 OR (distinct_endpoints >= 2 AND head_requests > 0)) + + | eval severity="medium" + | eval attack_type="API Activity Surge" + + | table _time host src total_requests + distinct_endpoints endpoints methods + status_codes severity attack_type + + | `ollama_possible_api_endpoint_scan_reconnaissance_filter` +how_to_implement: |- + Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections. +known_false_positives: |- + Legitimate web application clients or mobile apps that access multiple API endpoints as part of normal functionality, monitoring and health check systems probing various endpoints for availability, load balancers performing health checks across different paths, API testing frameworks during development and QA processes, or users navigating through web interfaces that trigger multiple API calls may generate similar patterns during normal operations. references: - https://github.com/rosplk/ta-ollama drilldown_searches: - name: View the detection results for - "$src$" - search: '%original_detection_search% | search "$src = "$src$"' + search: |- + %original_detection_search% + | search src="$src$" earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$src$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: |- + from datamodel Risk.All_Risk + | search normalized_risk_object IN ("$src$") + | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` earliest_offset: 7d latest_offset: "0" intermediate_findings: @@ -40,7 +71,7 @@ intermediate_findings: - field: src type: system score: 20 - message: API reconnaissance activity detected from $src$ on $host$ with $total_requests$ requests across different endpoints using methods $methods$ and receiving status codes $status_codes$, indicating systematic endpoint enumeration to map API attack surface and identify potential vulnerabilities. + message: 'Possible API reconnaissance from [$src$] on [$host$] with [$total_requests$] requests across [$distinct_endpoints$] endpoints ([$endpoints$]) using methods [$methods$] and receiving status codes [$status_codes$].' analytic_story: - Suspicious Ollama Activities asset_type: Web Application @@ -58,5 +89,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log sourcetype: ollama:server source: server.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit diff --git a/detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml b/detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml index 6b9e2b38cbc..a124408fcbb 100644 --- a/detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml +++ b/detections/application/ollama_possible_memory_exhaustion_resource_abuse.yml @@ -1,26 +1,70 @@ name: Ollama Possible Memory Exhaustion Resource Abuse id: ca96297f-e82e-4749-8cc9-d1ab555abb57 -version: 4 +version: 5 creation_date: '2025-10-13' -modification_date: '2026-05-13' -author: Rod Soto -status: experimental +modification_date: '2026-10-09' +author: Rod Soto, Nasreddine Bencherchali, Splunk +status: production type: Anomaly -description: Detects abnormal memory allocation patterns and excessive runner operations in Ollama that may indicate resource exhaustion attacks, memory abuse through malicious model loading, or attempts to degrade system performance by overwhelming GPU/CPU resources. Adversaries may deliberately load multiple large models, trigger repeated model initialization cycles, or exploit memory allocation mechanisms to exhaust available system resources, causing denial of service conditions or degrading performance for legitimate users. +description: |- + Identifies high Ollama runner counts and large model buffer allocations as possible resource pressure indicators. Memory values vary with model size and hardware, and these operational logs do not establish malicious intent; validate against host capacity and workload baselines. data_source: - Ollama Server -search: '`ollama_server` ("*llama_kv_cache*" OR "*compute buffer*" OR "*llama runner started*" OR "*loaded runners*") | rex field=_raw "count=(?\d+)" | rex field=_raw "size\s*=\s*(?[\d\.]+)\s+MiB" | rex field=_raw "started in\s*(?[\d\.]+)\s*seconds" | rex field=_raw "source=(?[^\s]+)" | bin _time span=5m | stats count as operations, sum(runner_count) as total_runners, dc(code_source) as unique_sources, values(code_source) as code_sources, avg(memory_mb) as avg_memory, max(memory_mb) as max_memory, sum(memory_mb) as total_memory, avg(load_time) as avg_load_time, max(load_time) as max_load_time by _time, host | where operations > 5 OR total_runners > 0 OR max_memory > 400 OR total_memory > 500 | eval avg_memory=round(avg_memory, 2) | eval max_memory=round(max_memory, 2) | eval total_memory=round(total_memory, 2) | eval avg_load_time=round(avg_load_time, 2) | eval severity=case( max_memory > 500 OR total_memory > 1000, "critical", max_memory > 400 OR operations > 20, "high", operations > 10, "medium", 1=1, "low" ) | eval attack_type="Resource Exhaustion / Memory Abuse" | sort -_time | table _time, host, operations, total_runners, unique_sources, avg_memory, max_memory, total_memory, avg_load_time, max_load_time, severity, attack_type | `ollama_possible_memory_exhaustion_resource_abuse_filter`' -how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.' -known_false_positives: Legitimate high-volume production workloads processing multiple concurrent requests, users loading large language models (7B+ parameters) that naturally require substantial memory allocation, simultaneous multi-model deployments during system scaling, batch processing operations, or initial system startup sequences may generate similar memory allocation patterns during normal operations. +search: |- + `ollama_server` + ("*llama_kv_cache*" OR "*compute buffer*" OR "*llama runner started*" OR "*loaded runners*") + + | rex field=_raw "count=(?\d+)" + | rex field=_raw "(?[\d\.]+)\s+MiB" + | rex field=_raw "started in\s*(?[\d\.]+)\s*seconds" + | rex field=_raw "source=(?[^\s]+)" + + | bin _time span=5m + + | stats count as operations + avg(load_time) as avg_load_time + avg(memory_mb) as avg_memory + dc(code_source) as unique_sources + max(load_time) as max_load_time + max(memory_mb) as max_memory + max(runner_count) as peak_loaded_runners + values(code_source) as code_sources + by _time host + + | where operations > 10 OR peak_loaded_runners > 5 OR max_memory > 400 + + | eval avg_memory=round(avg_memory, 2) + | eval max_memory=round(max_memory, 2) + | eval avg_load_time=round(avg_load_time, 2) + | eval max_load_time=round(max_load_time, 2) + | eval severity=case(peak_loaded_runners > 10, "critical", peak_loaded_runners > 5 OR operations > 20, "high", max_memory > 400 OR operations > 10, "medium", 1=1, "low") + | eval attack_type="Resource Pressure / Memory Allocation" + + | table _time host operations peak_loaded_runners + unique_sources avg_memory max_memory + avg_load_time max_load_time severity attack_type + + | `ollama_possible_memory_exhaustion_resource_abuse_filter` +how_to_implement: |- + Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections. +known_false_positives: |- + Legitimate high-volume production workloads processing multiple concurrent requests, users loading large language models (7B+ parameters) that naturally require substantial memory allocation, simultaneous multi-model deployments during system scaling, batch processing operations, or initial system startup sequences may generate similar memory allocation patterns during normal operations. references: - https://github.com/rosplk/ta-ollama drilldown_searches: - name: View the detection results for - "$host$" - search: '%original_detection_search% | search "$host = "$host$"' + search: |- + %original_detection_search% + | search host="$host$" earliest_offset: $info_min_time$ latest_offset: $info_max_time$ - name: View risk events for the last 7 days for - "$host$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$host$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + search: |- + from datamodel Risk.All_Risk + | search normalized_risk_object IN ("$host$") + | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` earliest_offset: 7d latest_offset: "0" intermediate_findings: @@ -28,7 +72,7 @@ intermediate_findings: - field: host type: system score: 20 - message: Potential resource exhaustion attack detected on $host$ with $operations$ memory operations in 5 minutes, utilizing $max_memory$ MiB peak memory and $total_runners$ runners, indicating possible attempts to exhaust system resources through excessive model loading or memory abuse. + message: 'Ollama resource pressure indicators on [$host$]: [$peak_loaded_runners$] peak loaded runners and [$max_memory$] MiB largest observed buffer across [$operations$] log events in 5 minutes. Compare with expected workloads before escalation.' analytic_story: - Suspicious Ollama Activities asset_type: Web Application @@ -46,5 +90,4 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log sourcetype: ollama:server source: server.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit diff --git a/detections/application/ollama_repeated_application_errors.yml b/detections/application/ollama_repeated_application_errors.yml new file mode 100644 index 00000000000..0dd0538dec1 --- /dev/null +++ b/detections/application/ollama_repeated_application_errors.yml @@ -0,0 +1,85 @@ +name: Ollama Repeated Application Errors +id: e0fff27e-ee9b-4b8d-b247-f93a93cefa71 +version: 1 +creation_date: '2026-10-09' +modification_date: '2026-10-09' +author: Rod Soto, Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: |- + Detects repeated Ollama application error events as a possible availability issue. Ollama application logs do not reliably record process termination, so this search cannot confirm a service crash without operating system or service manager telemetry. +data_source: + - Ollama Server +search: |- + `ollama_server` + (level=ERROR OR level=FATAL) + + | rex field=_raw "msg=\"(?[^\"]+)\"" + | rex field=_raw "exit_code=(?\d+)" + + | bin _time span=5m + + | stats count as error_count + earliest(_time) as first_seen + latest(_time) as last_seen + values(msg) as error_messages + values(exit_code) as exit_codes + dc(msg) as unique_errors + by _time host + + | where error_count > 1 + + | eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S") + | eval last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S") + | eval severity=case(error_count > 5, "critical", error_count > 2, "high", 1=1, "medium") + | eval attack_type="Repeated Ollama Application Errors" + + | table first_seen last_seen host error_count + unique_errors error_messages severity attack_type + + | `ollama_repeated_application_errors_filter` +how_to_implement: |- + Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections. +known_false_positives: |- + Recoverable model load failures, temporary registry or network errors, resource constraints, and other repeated application errors may trigger this exploratory signal without causing a service outage. +references: + - https://github.com/rosplk/ta-ollama +drilldown_searches: + - name: View the detection results for - "$host$" + search: |- + %original_detection_search% + | search host="$host$" + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$host$" + search: |- + from datamodel Risk.All_Risk + | search normalized_risk_object IN ("$host$") + | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: host + type: system + score: 20 + message: 'Repeated Ollama application errors detected on host [$host$] between [$first_seen$] and [$last_seen$]: [$error_count$] events and [$unique_errors$] unique error types. Correlate with service manager logs to determine whether availability was affected. Error messages: [$error_messages$].' +analytic_story: + - Suspicious Ollama Activities +asset_type: Web Application +mitre_attack_id: [] +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: application +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log + sourcetype: ollama:server + source: app.log + test_type: unit diff --git a/detections/application/ollama_abnormal_service_crash_availability_attack.yml b/detections/deprecated/ollama_abnormal_service_crash_availability_attack.yml similarity index 90% rename from detections/application/ollama_abnormal_service_crash_availability_attack.yml rename to detections/deprecated/ollama_abnormal_service_crash_availability_attack.yml index e37ebbe1b63..9c14555e326 100644 --- a/detections/application/ollama_abnormal_service_crash_availability_attack.yml +++ b/detections/deprecated/ollama_abnormal_service_crash_availability_attack.yml @@ -1,10 +1,10 @@ name: Ollama Abnormal Service Crash Availability Attack id: 327fa152-9b56-4e4e-bc0b-2795d4068afa -version: 4 +version: 5 creation_date: '2025-10-13' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Rod Soto -status: experimental +status: deprecated type: Anomaly description: Detects critical service crashes, fatal errors, and abnormal process terminations in Ollama that may indicate exploitation attempts, resource exhaustion attacks, malicious input triggering unhandled exceptions, or deliberate denial of service attacks designed to disrupt AI model availability and degrade system stability. data_source: @@ -46,5 +46,9 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log sourcetype: ollama:server source: app.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit +deprecation_info: + reason: This experimental rule is being deprecated while we enhance Ollama availability detection. Application errors alone do not confirm a service outage, so we are improving the evidence needed to identify service interruptions reliably. + removed_in_version: 6.12.0 + replacement_content: + - Ollama Repeated Application Errors diff --git a/detections/application/ollama_possible_model_exfiltration_data_leakage.yml b/detections/deprecated/ollama_possible_model_exfiltration_data_leakage.yml similarity index 92% rename from detections/application/ollama_possible_model_exfiltration_data_leakage.yml rename to detections/deprecated/ollama_possible_model_exfiltration_data_leakage.yml index 3140267adc4..f04b73cb26f 100644 --- a/detections/application/ollama_possible_model_exfiltration_data_leakage.yml +++ b/detections/deprecated/ollama_possible_model_exfiltration_data_leakage.yml @@ -1,10 +1,10 @@ name: Ollama Possible Model Exfiltration Data Leakage id: c9fd1a54-0eab-4470-8970-d5fcc3c740fb -version: 4 +version: 5 creation_date: '2025-10-13' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Rod Soto -status: experimental +status: deprecated type: Anomaly description: Detects data leakage and exfiltration attempts targeting Ollama model metadata and configuration endpoints. Adversaries repeatedly query /api/show, /api/tags, and /api/v1/models to systematically extract sensitive model information including architecture details, fine-tuning parameters, system paths, Modelfile configurations, and proprietary customizations. Multiple inspection attempts within a 15-minute window indicate automated exfiltration of valuable intellectual property such as custom model configurations, system prompts, and internal model specifications. This activity represents unauthorized data disclosure that could enable competitive intelligence gathering, model replication, or preparation for advanced attacks against the AI infrastructure. data_source: @@ -48,3 +48,7 @@ tests: source: server.log test_type: experimental description: This test is a legacy experimental test and may not be accurate. +deprecation_info: + reason: This experimental rule is being deprecated while we enhance Ollama exfiltration detection. Access requests and response timing alone do not show what data was returned or transferred, so stronger evidence and correlation are needed. + removed_in_version: 6.12.0 + replacement_content: [] diff --git a/detections/application/ollama_possible_rce_via_model_loading.yml b/detections/deprecated/ollama_possible_rce_via_model_loading.yml similarity index 92% rename from detections/application/ollama_possible_rce_via_model_loading.yml rename to detections/deprecated/ollama_possible_rce_via_model_loading.yml index be366b8ce8f..8fdeddd5eea 100644 --- a/detections/application/ollama_possible_rce_via_model_loading.yml +++ b/detections/deprecated/ollama_possible_rce_via_model_loading.yml @@ -1,10 +1,10 @@ name: Ollama Possible RCE via Model Loading id: 3f28c930-5208-425d-a7b9-53d349756d91 -version: 4 +version: 5 creation_date: '2025-10-13' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Rod Soto -status: experimental +status: deprecated type: Anomaly description: Detects Ollama server errors and failures during model loading operations that may indicate malicious model injection, path traversal attempts, or exploitation of model loading mechanisms to achieve remote code execution. Adversaries may attempt to load specially crafted malicious models or exploit vulnerabilities in the model loading process to execute arbitrary code on the server. This detection monitors error messages and failure patterns that could signal attempts to abuse model loading functionality for malicious purposes. data_source: @@ -46,5 +46,8 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log sourcetype: ollama:server source: app.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit +deprecation_info: + reason: This experimental rule is being deprecated while we enhance Ollama model-loading detection. Model-loading errors alone do not confirm code execution, so the detection needs stronger evidence of execution. + removed_in_version: 6.12.0 + replacement_content: [] diff --git a/detections/application/ollama_suspicious_prompt_injection_jailbreak.yml b/detections/deprecated/ollama_suspicious_prompt_injection_jailbreak.yml similarity index 90% rename from detections/application/ollama_suspicious_prompt_injection_jailbreak.yml rename to detections/deprecated/ollama_suspicious_prompt_injection_jailbreak.yml index 3fdfeb434f1..691b8187d54 100644 --- a/detections/application/ollama_suspicious_prompt_injection_jailbreak.yml +++ b/detections/deprecated/ollama_suspicious_prompt_injection_jailbreak.yml @@ -1,10 +1,10 @@ name: Ollama Suspicious Prompt Injection Jailbreak id: aac5df6f-9151-4da6-bdb2-5691aa6e376f -version: 4 +version: 5 creation_date: '2025-10-13' -modification_date: '2026-05-13' +modification_date: '2026-10-09' author: Rod Soto -status: experimental +status: deprecated type: Anomaly description: Detects potential prompt injection or jailbreak attempts against Ollama API endpoints by identifying requests with abnormally long response times. Attackers often craft complex, layered prompts designed to bypass AI safety controls, which typically result in extended processing times as the model attempts to parse and respond to these malicious inputs. This detection monitors /api/generate and /api/chat endpoints for requests exceeding 30 seconds, which may indicate sophisticated jailbreak techniques, multi-stage prompt injections, or attempts to extract sensitive information from the model. data_source: @@ -48,5 +48,9 @@ tests: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log sourcetype: ollama:server source: server.log - test_type: experimental - description: This test is a legacy experimental test and may not be accurate. + test_type: unit +deprecation_info: + reason: This experimental rule is being deprecated while we enhance Ollama prompt-injection detection. Long response times do not reveal prompt content or show that safeguards were bypassed, so they are not enough to identify these attacks reliably. + removed_in_version: 6.12.0 + replacement_content: + - Ollama Long-Running Inference Requests