跳到正文
O'Reilly Radar· Vicki Reyzelman·· 2 小时前AI 评分46

从身份验证转向意图验证:AI 智能体时代的企业安全新范式

Intent, Not Identity

AI 导读

互联网上非人类流量与人类的比例已达 144:1,自主 AI 智能体兼具类人的操作范围和概率性推理,使传统身份验证体系失效。Web Bot Auth 等签名机制只能证明请求者身份,无法验证意图,提示词注入可劫持已验证的智能体。企业需转向执行时持续验证,包括短时凭证、加密入口验证、浏览器层意图分类和提示词注入防护。

正文

On a recent episode of This Week in AI, we discussed that the number of nonhumans on the internet is greater than humans, 144 to 1. It’s an estimate, and the order of magnitude is more important than the number itself. What matters is what a ratio anywhere in that range does to a security architecture. For more than two decades, systems were engineered around two foundational assumptions: either verifying a human user exercising discretionary judgment or validating the account executing hardcoded predictable logic. Autonomous AI agents shatter both sides of this legacy identity taxonomy because they possess broad, human-like operational scope across multiple internal and external applications while remaining inherently nondeterministic and probabilistic in their reasoning.

Today, because the agent is interacting on behalf of a human through a genuine browser with standard extensions, its technical fingerprint looks identical to a normal human user’s device. Agents call tools, observe results, and revise. A person browses, hands off to an agent, and takes the session back. All the activity appears to be coming from the same user.

Signed agents help the identity problem, and they’re arriving. Web Bot Auth is a thin layer over RFC 9421 HTTP Message Signatures where an agent declares its identity and purpose. But they only help with the identity problem: The signature proves who is making the request, not the intent behind it. Prompt injection and other techniques can be used to steer a verified, well-behaved agent into acting against your interest without its operator ever knowing.

The organizations getting this right are treating agent policy as a commercial question with a security implementation. The following questions need to be answered:

  • Which agents do we allow to use our service?
  • What endpoints do we need to protect? 
  • How will agent management security policies impact revenue?

Here are the techniques successful companies are using to secure in the agentic era. A phased strategic roadmap implementing continuous execution-time verification. These are the steps:

  1. Establish execution-time machine identity and scoped delegation. Replace static, long-lived API keys with machine single sign-on mechanisms that issue short-lived, context-bound credentials at the time of tool execution. Enforce strict delegation policies so that autonomous agents operate within verified “green zones” without inheriting broad human privileges.
  2. Deploy cryptographic ingress verification. Upgrade edge infrastructure to inspect Web Bot Auth HTTP Message Signatures, in order to separate cryptographically verified crawlers from anonymous traffic.
  3. Upgrade edge defenses to browser-layer intent classification. Transition legacy network-layer antibot web application firewall (WAF) to client-side browser-layer detection platforms. 
  4. Harden agent execution pipelines against prompt injection. Instrument robust input sanitization, instruction hierarchy enforcement, and design-level safeguards around all LLM ingestion channels to neutralize indirect prompt injection attacks before external web content reaches execution tools.
  5. Adopt standardization for agentic commerce and admission. Integrate emerging trust frameworks such as the Framework for Agentic Commerce Trust (FACT), a neutral real-time trust layer for AI-driven transactions in addition to verification protocols like CAPTCHA to validate agentic capability vectors before delegating sensitive interagent tasks.

The rapid transition from human-directed software to autonomous AI agents breaks traditional enterprise security paradigms. AI agents operate with broad operational scope but nondeterministic, probabilistic reasoning. This is causing static perimeter defenses to fail. The teams that come through this well will be the ones that stopped asking “Who’s on the other end of the connection?” and started asking “What’s this request for, and what happens if it succeeds?”

来源:O'Reilly Radar · oreilly.com