|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/agentic-ai-security-threats-architectures-mitigations/
课程评论:没有评论
**课程名称:** Agentic AI Security- 威胁、架构与缓解措施 **课程概述:** 本课程为开发者、安全工程师、AI架构师和风险官员提供全面的培训,旨在帮助他们防御下一代自主系统。课程从基础的AI Agent概念入手,解释了现代AI Agent如何感知、推理、规划和自主行动(与传统模型不同)。 **核心内容:** * **AI Agent基础:** 讲解AI Agent的核心能力,如记忆、工具使用和目标分解。 * **架构与框架:** 介绍单Agent和多Agent系统的架构基础,以及LangChain和AutoGen等Agent框架。 * **安全威胁与模型:** 深入探讨使用STRIDE、PASTA和MAESTRO等框架进行威胁建模,并详细介绍OWASP的Agentic威胁模型和分类导航器。 * **专项威胁:** 重点分析推理漂移、记忆投毒、工具滥用、身份欺骗、人工干预(HITL)利用和多Agent协调失败等威胁。 * **缓解措施:** 提供六种缓解策略,包括推理验证、记忆控制、工具执行加固、身份强化、HITL优化和Agent间信任保障。 * **架构解决方案:** 探讨模块化Agent设计、执行守护、回滚系统和纵深防御策略。 * **部署实践:** 强调容器化、策略驱动的API访问以及从真实Agent事件吸取的教训。 * **实战演练:** 包括设计红队、搭建安全模拟实验室,以及利用LangChain构建易受攻击的Agent进行培训。通过模拟记忆投毒和共识操纵等实验进行动手实践。 * **合规与集成:** 将Agentic威胁与现有安全框架(如OWASP、MITRE ATLAS和NIST AI RMF)进行整合,确保企业治理和合规性。 **学习目标:** 学员将能设计、测试和部署安全、可解释且可审计的AI Agent。
Agentic AI Security: Threats, Architectures & Mitigations is a comprehensive course designed to prepare developers, security engineers, AI architects, and risk officers to defend the next generation of autonomous systems. The course begins by grounding learners in the fundamentals of agentic AI, explaining how modern AI agents-unlike traditional models-perceive, reason, plan, and act with increasing autonomy. It explores the pivotal role of OWASP's Agentic Security Initiative and introduces the architectural foundations of single-agent and multi-agent systems, showcasing the core capabilities of agents, including memory, tool use, and goal decomposition. Learners are introduced to orchestration layers, agent frameworks like LangChain and AutoGen, and real-world agentic patterns and use cases. As the course progresses, it delves into threat modeling with STRIDE, PASTA, and MAESTRO frameworks, before detailing OWASP's reference agentic threat model and taxonomy navigator.The midsection focuses on deep-dives into specialized threats-reasoning drift, memory poisoning, tool misuse, identity spoofing, HITL exploitation, and multi-agent coordination failures. Six mitigation playbooks provide practical countermeasures: reasoning validation, memory control, tool execution hardening, identity strengthening, HITL optimization, and inter-agent trust assurance. Learners then transition into architectural solutions including modular agent design, execution guards, rollback systems, and defense-in-depth strategies. The deployment section emphasizes containerization, policy-driven API access, and lessons from real-world agent incidents. To ensure proactive defense, the course includes guidance on designing red teams, secure simulation labs, and building vulnerable agents for training purposes using LangChain. Hands-on labs like simulating memory poisoning and consensus manipulation are also included. The course concludes by integrating agentic threats into existing security frameworks-mapping OWASP threats to MITRE ATLAS and NIST AI RMF-thus aligning advanced agent risks with enterprise governance and compliance expectations. Learners emerge prepared to design, test, and deploy secure, interpretable, and auditable AI agents.