Artículos relacionados a Threat Modeling GenAI Apps: Assets, Attack Paths, and...

Threat Modeling GenAI Apps: Assets, Attack Paths, and Controls That Work - Tapa blanda

Team, Trex

 
9798896653509: Threat Modeling GenAI Apps: Assets, Attack Paths, and Controls That Work

Sinopsis

"Threat Modeling GenAI Apps: Assets, Attack Paths, and Controls That Work"

GenAI systems fail in ways that traditional application security models do not fully capture: untrusted prompts become instructions, retrieved content becomes an attack vector, and model output can trigger real-world actions. This book is written for experienced security engineers, architects, platform leads, and senior developers who need a rigorous way to analyze these systems without relying on hype, hand-waving, or fragile prompt-only defenses.

Across a practical, architecture-driven workflow, the book shows how to scope GenAI threat models, identify and classify assets, map data flows and trust boundaries, enumerate attack paths, and select controls that hold under pressure. Readers will learn how to reason about prompt injection, RAG poisoning, retrieval authorization failures, data leakage, tool and agent abuse, memory risks, observability exposure, and model supply chain threats. Just as importantly, they will learn how to turn threat models into concrete engineering outputs: security requirements, regression tests, telemetry, and operational runbooks.

Rather than treating GenAI security as a checklist, this book organizes the field around durable control principles such as isolation, authorization, sandboxing, and verification. Familiarity with application security, cloud systems, and threat modeling is assumed. The result is a focused, advanced guide for teams building GenAI applications that must be not only innovative, but defensible.

"Sinopsis" puede pertenecer a otra edición de este libro.