Cantitate/Preț
Produs

Breaking the Model Context Protocol

Autor Srinivasan Sekar, Thejes Sree Satheesh Kumar
en Limba Engleză Paperback – 14 sep 2026
As AI agents plug into more tools and internal systems, the Model Context Protocol (MCP) is becoming a core part of how modern platforms work. With this shift comes a fast¿growing challenge: understanding the new attack surfaces created when probabilistic models interact with real APIs, data, and networks. This book gives practitioners a clear, practical guide to navigating that emerging threat landscape by showing how MCP architectures behave in production and where hidden risks often appear.
The book begins by mapping today’s MCP trust boundaries and explaining why traditional security assumptions don’t hold when the “client” is an LLM. You’ll explore real attack stories and hands¿on labs demonstrating tool¿poisoning techniques, signature cloaking, and sampling¿based abuses. You’ll then learn how attackers target the surrounding environment through DNS rebinding, malicious MCP servers, and confused¿deputy patterns that turn over¿permissioned tools into high¿impact attack paths.
From there, the book provides defensive approaches built on schemas, contracts, monitoring, least privilege, and continuous red¿team testing. Each chapter helps you apply the ideas to real deployments. Drawing on active MCP security research and real¿world agent testing, this book offers a focused roadmap for securing the next generation of AI systems.
What You Will Learn
  • Understand how MCP architectures function in real AI agent systems
  • Identify trust boundaries and map emerging attack surfaces
  • Use sampling¿based and elicitation¿based techniques to assess model behavior
  • Protect MCP environments from DNS rebinding and confused¿deputy risks
Who This Book is For
This book is for security engineers, AI platform teams, red¿teamers, DevSecOps practitioners, MCP implementers, agent¿framework developers, and technical leaders responsible for securing AI¿driven systems and LLM¿powered applications.
Citește tot Restrânge

Preț: 19627 lei

Preț vechi: 24534 lei
-20% Precomandă

Puncte Express: 294

Carte nepublicată încă

Livrare prin curier în România Precomanda se expediază când titlul devine disponibil.
Transport gratuit de la 40000 lei Plată online sau ramburs, în funcție de opțiunile comenzii.
Retur gratuit în 14 zile Comandă securizată și suport în română.
Doresc să fiu notificat când acest titlu va fi disponibil:

Specificații

ISBN-13: 9798868829673
Pagini: 277
Ilustrații: XXV, 277 p. 80 illus., 78 illus. in color.
Dimensiuni: 178 x 254 x 17 mm
Greutate: 0.53 kg
Ediția:First Edition
Editura: Apress

Notă biografică

Thejes sree Satheesh kumar is a Quality Analyst – Consultant at ThoughtWorks, specialising in application and AI security testing. She is a Certified Ethical Hacker and holds CompTIA Security+, ISC2 Certified in Cybersecurity and Google Cybersecurity Professional certifications. With a strong background in automation testing using Playwright, Selenium, WebdriverIO, and Appium, Thejes combines quality engineering and security practices to build resilient software systems. She is passionate regarding secure AI ecosystems and advancing defensive strategies for emerging technologies like the Model Context Protocol (MCP). She is a speaker at various conferences, including NullCon and TechXpresso.

Srinivasan Sekar
is an AI enthusiast and the Director of Engineering at TestMu AI (formerly LambdaTest), where he leads innovation in Agentic AI. His work focuses on building next-generation AI platforms and leveraging the Model Context Protocol (MCP) to create intelligent agentic applications. A passionate advocate for open source, Srinivasan is a recognised Appium member and an active contributor to several prominent projects, including Selenium, Appium, and Webdriver.io. He is a frequent speaker at international technology conferences, providing his deep expertise at events such as SeleniumConf, AppiumConf, and FOSDEM on the architecture and practical application of emerging AI technologies

Cuprins

Part I – Foundations: The Agentic Threat Landscape.- Chapter 1: From Architecture to Attack Surface.- Chapter 2: Deconstructing the MCP Trust Boundaries.- Chapter 3: Thinking Like an Attacker (The Red Team Mindset).- Part II – Tool and MCP-Specific Abuse.- Chapter 4: Advanced Tool Poisoning Attack (ATPA) – Output Poisoning.- Chapter 5: Signature Cloaking: The Invisible MCP Parameters.- Part III – Sampling and Elicitation Attacks.- Chapter 6: Sampling Abuse and the Hijacked Assistant.- Chapter 7: Elicitation Attacks: Weaponising Forms and URLs.- Part IV – Network and Environment Abuse.- Chapter 8: DNS Rebinding and Turning Your Agent Against Your Own Network.- Chapter 9: The Confused Deputy: The Agent With Too Many Keys.- Part V – WebMCP.- Chapter 10: WebMCP and the Browser as an MCP Server.- Chapter 11: WebMCP Security and the Authenticated Attack Surface.- Part VI – Putting It All Together.- Chapter 12: The Defender’s Pocket Playbook.