Zum Hauptinhalt springen Zur Suche springen Zur Hauptnavigation springen

Breaking the Model Context Protocol

Regulärer Preis:

39,99 €

Sofort verfügbar

Format auswählen

Breaking the Model Context Protocol, Apress
Agentic Attacks and Defenses for MCP-Powered AI Systems
Von Thejes sree Satheesh kumar, Srinivasan Sekar, im heise shop in digitaler Fassung erhältlich

Produktinformationen "Breaking the Model Context Protocol"

As AI agents plug into more tools and internal systems, the Model Context Protocol (MCP) is becoming a core part of how modern platforms work. With this shift comes a fast‑growing challenge: understanding the new attack surfaces created when probabilistic models interact with real APIs, data, and networks. This book gives practitioners a clear, practical guide to navigating that emerging threat landscape by showing how MCP architectures behave in production and where hidden risks often appear. The book begins by mapping today’s MCP trust boundaries and explaining why traditional security assumptions don’t hold when the “client” is an LLM. You’ll explore real attack stories and hands‑on labs demonstrating tool‑poisoning techniques, signature cloaking, and sampling‑based abuses. You’ll then learn how attackers target the surrounding environment through DNS rebinding, malicious MCP servers, and confused‑deputy patterns that turn over‑permissioned tools into high‑impact attack paths. From there, the book provides defensive approaches built on schemas, contracts, monitoring, least privilege, and continuous red‑team testing. Each chapter helps you apply the ideas to real deployments. Drawing on active MCP security research and real‑world agent testing, this book offers a focused roadmap for securing the next generation of AI systems. What You Will Learn
  • Understand how MCP architectures function in real AI agent systems
  • Identify trust boundaries and map emerging attack surfaces
  • Use sampling‑based and elicitation‑based techniques to assess model behavior
  • Protect MCP environments from DNS rebinding and confused‑deputy risks
Who This Book is For This book is for security engineers, AI platform teams, red‑teamers, DevSecOps practitioners, MCP implementers, agent‑framework developers, and technical leaders responsible for securing AI‑driven systems and LLM‑powered applications.

Artikel-Details

Anbieter:
Apress
Autor:
Thejes sree Satheesh kumar, Srinivasan Sekar
Artikelnummer:
9798868829680
Veröffentlicht:
25.08.26

Barrierefreiheit

This PDF has been created in accordance with the PDF/UA-1 standard to enhance accessibility, including screen reader support, described non-text content (images, graphs), bookmarks for easy navigation

  • entspricht den Vorgaben der PDF / UA 1 (05)
  • keine Vorlesefunktionen des Lesesystems deaktiviert (bis auf) (10)
  • navigierbares Inhaltsverzeichnis (11)
  • logische Lesereihenfolge eingehalten (13)
  • kurze Alternativtexte (z.B für Abbildungen) vorhanden (14)
  • Inhalt auch ohne Farbwahrnehmung verständlich dargestellt (25)
  • hoher Kontrast zwischen Text und Hintergrund (26)
  • Navigation über vor-/zurück-Elemente (29)
  • alle zum Verständnis notwendigen Inhalte über Screenreader zugänglich (52)
  • Kontakt zum Herausgeber für weitere Informationen zur Barrierefreiheit (99)