Skip to main content

Welcome to our updated site!

Skyhigh Security

Skyhigh Security for ChatGPT

Prerequisites

Make sure that you have any one of the following products to begin with:

  • Skyhigh Security Shadow IT 
  • Skyhigh SSE (Cloud Proxy)

or

  • Skyhigh Secure Web Gateway

About Skyhigh Security Capabilities for ChatGPT

This topic explains how Skyhigh Security can assist organizations with Artificial Intelligence (AI) tools such as ChatGPT. Skyhigh Security provides administrators the ability to manage AI applications in their Cloud, Hybrid, and On-Prem deployments via the following features:

  1. Increased visibility for ChatGPT in your organization.
  2. Determine the volume of data being uploaded
  3. Identify which of your top talkers/users are using ChatGPT
  4. Block complete access to ChatGPT and other AI applications
  5. Apply specific controls, such as blocking uploads or logging into ChatGPT
  6. Prevent sensitive data from being uploaded to ChatGPT

Visibility 

Monitor Usage

Skyhigh Security monitors ChatGPT along with other social engineering applications in the Skyhigh Cloud Registry under the Artificial Intelligence category. This provides visibility into the AI services used within your organization. For details, see About the Cloud Registry.
clipboard_ec38136890859d7b8bbacd9dc766bf4b3.png

Understand Data Usage

You can leverage your Shadow IT data to determine the number of users and the volume of data uploaded to the ChatGPT service. For details, see About Services.

Use the OpenAI – ChatGPT filter to determine the following: 

  1. Number of users using the ChatGPT site. 
  2. Data volume linked with the ChatGPT site. 
  3. Your existing proxy/firewall is blocking or allowing access to the ChatGPT site.

clipboard_e8ecae443c0e8433e4dc9545a4a649f76.png

Block AI Services (Completely)

Create Skyhigh Service Groups

Skyhigh Security allows you to create a service group on the Skyhigh CASB dashboard based on the Artificial Intelligence category or the OpenAI - ChatGPT service name. The following example uses an AI Warning service group to share this information with your proxy/firewall. For details, see Create a Service Group.

NOTES

  • You can name the service group based on your requirement.
  • Skyhigh Security recommends that you create service groups using the Artificial Intelligence category.

 

 

 

clipboard_e268719a692e259fc8d77b5df7db86e15.png

Configure Closed Loop Remediation

You must configure Closed Loop Remediation so that your Skyhigh environment acts as an external web server, providing a URL to be used in the destination field of your proxy/firewall ruleset. For details, see About Firewall and Proxy Integrations.

clipboard_e59fd9f98da1f48c6083b2cbf84deffd9.png

You can now copy and paste the highlighted URL into the destination field of your proxy/firewall ruleset. Once done, you can then choose whether to block or coach users who attempt to access this website. 

Block AI Services (based on User Activity)

You can block the AI services used within your organization based on the user activity (login, upload) as show in the following example from Skyhigh SSE Cloud Proxy.

  1. Under Web Policy > Application Control, select Activity Control.
  2. Apply these activity controls to the AI Warning service group created earlier to this configuration.
  3. Edit these rules to apply to all traffic, and add the ChatGPT URL/Domain/Host information.
    clipboard_ec277c053eb7ad2e3e61be1d1f563bb8c.png

NOTE: For Secure Web Gateway users, contact your Skyhigh Security engineer to understand how this is set up in the App Prism ruleset.   

 

Coach users but allow access to ChatGPT

Skyhigh Security allows you to limit access to AI services used within your organization by providing access only to users with a business justification.

  1. Go to Web Policy > Web Filtering.
  2. Select or configure the Category & Domain Coaching rule. 
  3. Select and edit Coach & Allow access to these domains.
  4. When presented, populate Smart Match with the ChatGPT domain under the Add New items view.  
  5. Click Save, and Publish your policy.
    clipboard_ee4a9ee0ee1a3d1b8c4f4aadbfe6c1278.png

Coach with DLP filtering applied

Skyhigh Security allows you to block sensitive information or DLP (Data Loss Prevention) content from leaving the organization.

  1. Go to Web Policy > Data Protection (DLP).  
  2. Select or configure These rules apply to all traffic, then choose URL/Domain/Host to populate the ChatGPT URL/Domain/Host information or select the AI service group.
    clipboard_eb3752934ae3f8f1e59301ed6b2dedce2.png  
  3. Create or build DLP Classifications within your DLP policies to only block content that matches your DLP Classifications and is posted to your AI service group or ChatGPT url.
    clipboard_e3434800ea52ff1af6cda9bb4df5e100d.png

Reporting

You can now generate reports or schedule reports for delivery.  

For Secure Web Gateway (On-Prem) users

If you are using Skyhigh Security Shadow IT or SSE/UCE, you can use the lists generated from the Skyhigh Cloud Registry to perform activities such as block, monitor, coach by subscribing to those lists in your policies. For details, see Configure Closed Loop Remediation.

If you are using Secure Web Gateway (On-Prem), then coaching or blocking on-premise must be done via a URL list obtained from an external source because there is no built-in AI category or list. For coaching, you can use the standard coaching ruleset and modify the base ruleset as follows: 

clipboard_e9ec23cff3e836aca9e3c0f8a51b62a9c.png

clipboard_e0d1e9cbd0b080bcc61db679de5a1b0d8.png

While syncing a DLP policy from Secure Web Gateway to the cloud, Skyhigh Security recommends using the standard coaching ruleset for Secure Web Gateway (On-Prem) filtering, and the Coaching with Cookies ruleset for the cloud. You can do this by using a criteria in the cloud which equals to True for the cookie-based ruleset and False for the standard coaching ruleset. 

NOTES

 

  • The Coaching with Cookies ruleset is available on the online ruleset library found at contentsecurity.skyhigh.cloud.
  • The standard coaching and Coaching with Cookies rulesets are enabled, but only the cookie-based ruleset is set to sync to the cloud.

 

  • Was this article helpful?