Breaking the Model Context Protocol
Autor Srinivasan Sekar, Thejes Sree Satheesh Kumaren Limba Engleză Paperback – 14 sep 2026
The book begins by mapping today’s MCP trust boundaries and explaining why traditional security assumptions don’t hold when the “client” is an LLM. You’ll explore real attack stories and hands¿on labs demonstrating tool¿poisoning techniques, signature cloaking, and sampling¿based abuses. You’ll then learn how attackers target the surrounding environment through DNS rebinding, malicious MCP servers, and confused¿deputy patterns that turn over¿permissioned tools into high¿impact attack paths.
From there, the book provides defensive approaches built on schemas, contracts, monitoring, least privilege, and continuous red¿team testing. Each chapter helps you apply the ideas to real deployments. Drawing on active MCP security research and real¿world agent testing, this book offers a focused roadmap for securing the next generation of AI systems.
What You Will Learn
- Understand how MCP architectures function in real AI agent systems
- Identify trust boundaries and map emerging attack surfaces
- Use sampling¿based and elicitation¿based techniques to assess model behavior
- Protect MCP environments from DNS rebinding and confused¿deputy risks
This book is for security engineers, AI platform teams, red¿teamers, DevSecOps practitioners, MCP implementers, agent¿framework developers, and technical leaders responsible for securing AI¿driven systems and LLM¿powered applications.
Preț: 196.27 lei
Preț vechi: 245.34 lei
-20% Precomandă
Puncte Express: 294
Carte nepublicată încă
Livrare prin curier în România Precomanda se expediază când titlul devine disponibil.
Transport gratuit de la 400.00 lei Plată online sau ramburs, în funcție de opțiunile comenzii.
Retur gratuit în 14 zile Comandă securizată și suport în română.
Doresc să fiu notificat când acest titlu va fi disponibil:
Se trimite...
Specificații
ISBN-13: 9798868829673
Pagini: 277
Ilustrații: XXV, 277 p. 80 illus., 78 illus. in color.
Dimensiuni: 178 x 254 x 17 mm
Greutate: 0.53 kg
Ediția:First Edition
Editura: Apress
Pagini: 277
Ilustrații: XXV, 277 p. 80 illus., 78 illus. in color.
Dimensiuni: 178 x 254 x 17 mm
Greutate: 0.53 kg
Ediția:First Edition
Editura: Apress
Notă biografică
Thejes sree Satheesh kumar is a Quality Analyst – Consultant at ThoughtWorks, specialising in application and AI security testing. She is a Certified Ethical Hacker and holds CompTIA Security+, ISC2 Certified in Cybersecurity and Google Cybersecurity Professional certifications. With a strong background in automation testing using Playwright, Selenium, WebdriverIO, and Appium, Thejes combines quality engineering and security practices to build resilient software systems. She is passionate regarding secure AI ecosystems and advancing defensive strategies for emerging technologies like the Model Context Protocol (MCP). She is a speaker at various conferences, including NullCon and TechXpresso.
Srinivasan Sekar is an AI enthusiast and the Director of Engineering at TestMu AI (formerly LambdaTest), where he leads innovation in Agentic AI. His work focuses on building next-generation AI platforms and leveraging the Model Context Protocol (MCP) to create intelligent agentic applications. A passionate advocate for open source, Srinivasan is a recognised Appium member and an active contributor to several prominent projects, including Selenium, Appium, and Webdriver.io. He is a frequent speaker at international technology conferences, providing his deep expertise at events such as SeleniumConf, AppiumConf, and FOSDEM on the architecture and practical application of emerging AI technologies
Srinivasan Sekar is an AI enthusiast and the Director of Engineering at TestMu AI (formerly LambdaTest), where he leads innovation in Agentic AI. His work focuses on building next-generation AI platforms and leveraging the Model Context Protocol (MCP) to create intelligent agentic applications. A passionate advocate for open source, Srinivasan is a recognised Appium member and an active contributor to several prominent projects, including Selenium, Appium, and Webdriver.io. He is a frequent speaker at international technology conferences, providing his deep expertise at events such as SeleniumConf, AppiumConf, and FOSDEM on the architecture and practical application of emerging AI technologies
Cuprins
Part I – Foundations: The Agentic Threat Landscape.- Chapter 1: From Architecture to Attack Surface.- Chapter 2: Deconstructing the MCP Trust Boundaries.- Chapter 3: Thinking Like an Attacker (The Red Team Mindset).- Part II – Tool and MCP-Specific Abuse.- Chapter 4: Advanced Tool Poisoning Attack (ATPA) – Output Poisoning.- Chapter 5: Signature Cloaking: The Invisible MCP Parameters.- Part III – Sampling and Elicitation Attacks.- Chapter 6: Sampling Abuse and the Hijacked Assistant.- Chapter 7: Elicitation Attacks: Weaponising Forms and URLs.- Part IV – Network and Environment Abuse.- Chapter 8: DNS Rebinding and Turning Your Agent Against Your Own Network.- Chapter 9: The Confused Deputy: The Agent With Too Many Keys.- Part V – WebMCP.- Chapter 10: WebMCP and the Browser as an MCP Server.- Chapter 11: WebMCP Security and the Authenticated Attack Surface.- Part VI – Putting It All Together.- Chapter 12: The Defender’s Pocket Playbook.