Επιστροφή στις Ειδήσεις
ΑσφάλειαAI Understanding ενημέρωση

Η Cisco περιγράφει τη μετάβαση από τον έλεγχο πρόσβασης στον έλεγχο δράσης για πράκτορες AI

Η ομάδα ταυτότητας της Cisco υποστηρίζει ότι οι παραδοσιακές πλατφόρμες IAM είναι ανεπαρκείς για πράκτορες τεχνητής νοημοσύνης, προτείνοντας ένα νέο πλαίσιο που βασίζεται στην ταυτότητα χρόνου εκτέλεσης και την αναλυτική εξουσιοδότηση σε επίπεδο δράσης.

4 min readRead the original reporting
Source-provided image accompanying Cisco outlines shift from access control to action control for AI agents
Αναφορά που αποδίδεταιΗ πηγή καταγράφηκε
Εκδότης
venturebeat.com
Σύνδεσμος πηγής
venturebeat.comhttps://venturebeat.com/security/ai-agents-need-more-than-access-control-they-need-identity-at-runtime
Τύπος πηγής
Αναφορά από ειδησεογραφικό μέσο — όχι έγγραφο πρώτου μέρους.

Αυτό που δεν μπορέσαμε να επιβεβαιώσουμε ανεξάρτητα: Αυτός ο ισχυρισμός αποδίδεται στο ονομαζόμενο κατάστημα. Δεν το επαληθεύσαμε με έγγραφο πρώτου μέρους. (venturebeat.com)

ΠλαίσιοΚαταλάβετε αυτό σε 60 δευτερόλεπτα

Ξεκινήστε εδώ

Βασικοί όροι

MCP (Model Context Protocol)
Ένα ανοιχτό πρωτόκολλο που επιτρέπει στις εφαρμογές τεχνητής νοημοσύνης να συνδέονται με εξωτερικά εργαλεία, πηγές δεδομένων και παρόχους περιβάλλοντος με τυπικό τρόπο.
Πράκτορας AI
Ένα σύστημα λογισμικού που μπορεί να παρατηρεί, να αιτιολογεί και να κάνει ενέργειες για την επίτευξη ενός στόχου, χρησιμοποιώντας συχνά εργαλεία και μνήμη.
Δοκιμάστε τον εαυτό σαςΚουίζ για πράκτορες AI

Τι έγινε

Cisco’s identity division, represented by VP of product Matt Caulfield, has outlined a new security framework for managing AI agents in enterprise environments. The report argues that existing Identity and Access Management (IAM) systems, designed for human users, are inadequate for the rapid, non-human scale of deployment. Cisco proposes moving beyond static access control toward 'action control,' which requires continuous verification and cryptographic identity binding at runtime.

Cisco’s identity team asserts that the current enterprise approach to AI security is failing because it treats agents as extensions of human users rather than distinct entities. Because agents are deployed in minutes rather than the weeks or months required for human onboarding, they lack the background checks and identity verification processes standard for employees.

The proposed framework requires four core capabilities: discovery of active agents, hardware-bound cryptographic credentials, authorization at the level of individual actions, and continuous audit logging. This moves security away from 'least privilege'—which might grant an agent access to an entire GitHub repository—toward 'action control,' where an agent is authorized only to perform a specific task, such as merging a single pull request, for a limited window of time.

Cisco is integrating these concepts into its Duo platform, which now treats agents as first-class identities. Through the acquisition of Astrix, Cisco aims to provide visibility into non-human identities, including the secrets and permissions they utilize. The platform supports OAuth and authorization specifications used by the Model Context Protocol (MCP) to manage these scoped permissions.

Στοιχεία πηγής: venturebeat.com ↗

Γιατί έχει σημασία

As enterprises deploy AI agents that operate at machine speed, traditional security models—which grant broad, role-based permissions—create significant risks of unauthorized data access or system manipulation. By shifting to action-level authorization, organizations can restrict agents to specific, time-bound tasks rather than granting them the full permissions of the human users they emulate. This approach addresses the 'identity gap' where agents currently bypass security by inheriting human credentials, providing a necessary layer of governance for autonomous software.

The primary risk identified is that agents currently act as 'proxies' for humans. If a human uses a password-based authentication method, they may inadvertently or intentionally pass those credentials to an agent, making the agent indistinguishable from the human in the eyes of the system.

Traditional Zero Trust architectures, while effective for users and devices, often fail to account for the specific, high-frequency actions of AI agents. By implementing action control, organizations can prevent an agent from performing unauthorized operations, such as force-pushing to production branches, even if the agent has legitimate access to the broader application environment.

This shift represents a fundamental change in enterprise security strategy, requiring organizations to re-evaluate network, endpoint, and data security through the specific lens of agentic behavior rather than relying on legacy IAM assumptions.

Interactive Mechanism

Διαδραστικός Μηχανισμός: Πώς λειτουργεί στην πραγματικότητα

Εξερευνήστε την υποκείμενη τεχνολογία πίσω από αυτήν την εξέλιξη διαδραστικά.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Διαδραστικός Έλεγχος Έννοιας+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

Τι να παρακολουθήσετε στη συνέχεια

Security leaders are increasingly prioritizing the discovery of 'shadow' agents already operating within their networks. Future developments will likely focus on how effectively platforms like Cisco’s Duo and its integrated Astrix technology can map non-human identities and enforce granular, just-in-time permissions across diverse cloud and on-premises environments. The industry's ability to standardize these agent-specific identity protocols remains a critical, unresolved challenge.

The effectiveness of discovery tools in identifying 'rogue' or unmanaged agents remains a key metric for security teams. Without a complete inventory of agents, governance policies cannot be enforced.

The industry is moving toward standardizing how agents authenticate. Watch for further adoption of phishing-resistant authentication and hardware-bound credentials as the baseline for non-human identity.

The integration of agent-specific security into broader enterprise stacks will be a major trend. Cisco’s focus on the Model Context Protocol (MCP) suggests that interoperability between agent frameworks and security platforms will be a critical area for development in the coming months.

Σχετικοί οδηγοί και κουίζ

Πράκτορες AIΗθική του AIΕπεξήγηση μοντέλων AIΔοκιμάστε τι γνωρίζετε — δοκιμάστε ένα δωρεάν κουίζ AIΑναζητήστε έναν όρο AI στο γλωσσάρι μαςΑκολουθήστε το πρόγραμμα παρακολούθησης ρυθμίσεων AI
Βρήκατε αυτό χρήσιμο;