Agentic AI Threat Modeling
摘要
This chapter introduces the MAESTRO (Multi-Agent Environment, Security, Threat, Risk, and Outcome) framework, a novel approach specifically designed for threat modeling Agentic AI systems. It begins by defining Agentic AI, highlighting its key components and technical drivers, and contrasting its unique challenges with traditional software systems. The chapter then critically examines the limitations of existing threat modeling frameworks, such as STRIDE, DREAD, PASTA, OCTAVE, and LINDDUN, in addressing the emergent properties of Agentic AI, including non-determinism, autonomy, agent identity, and agent-to-agent communication. MAESTRO is then presented as a seven-layer framework that systematically addresses these gaps. Each layer—Foundation Models, Data Operations, Agent Frameworks, Deployment Infrastructure, Evaluation and Observability, Security and Compliance, and Agent Ecosystem—is explored in detail, with concrete examples of potential threats. The chapter emphasizes the importance of analyzing cross-layer threats, where vulnerabilities in one layer can cascade and amplify risks in others. A case study demonstrating the application of MAESTRO to an enterprise copilot illustrates its practical use. Finally, the chapter contrasts MAESTRO with list-based frameworks, highlighting its layered granularity, cross-layer focus, agent-specific threats, and structured methodology. This chapter provides readers with a robust foundation in Agentic AI threat modeling, equipping them to proactively identify and mitigate risks.