AegisGate Γ— MITRE ATLAS

MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is the definitive framework for understanding adversarial attacks against AI. AegisGate is the only AI security platform with native ATLAS coverage across all five attack surfaces: HTTP APIs, MCP tool use, A2A inter-agent communication, ACP protocol security, and AI response scanning.

Why ATLAS Matters

AI systems face unique adversarial techniques that traditional security tools don’t address. ATLAS catalogs 66 techniques β€” from prompt injection to agent impersonation to model extraction. If you’re deploying AI in production, you need defenses mapped to these specific threats.


ATLAS Coverage Map

🌐 HTTP API Security (Pillar 1)

ATLAS TechniqueIDAegisGate Defense
Prompt InjectionT1059144+ detection patterns for adversarial instructions
Data ExfiltrationT1037PII/PHI/secret detection in request and response bodies
Credential HarvestingT1110API key exposure scanning, vault integration
Model ExtractionT1190Rate limiting + anomaly detection on inference endpoints
Supply Chain CompromiseT1195Signature verification of upstream models/servers

πŸ”— MCP Protocol Security (Pillar 2)

ATLAS TechniqueIDAegisGate Defense
Tool Use ManipulationT1059.001Tool authorization with risk-matrix enforcement
Session HijackingT1056Session authentication + integrity verification
Privilege Escalation via ToolsT1078RBAC + tool authorizer deny by default
Resource ExhaustionT1499.003Per-session resource boundaries + rate limiting
Supply Chain Attack (MCP Servers)T1195.002MCP server authenticity verification
Sensitive Data via Tool OutputT1037.001Output filtering + PII redaction

🀝 A2A Inter-Agent Security (Pillar 3)

ATLAS TechniqueIDAegisGate Defense
Agent ImpersonationT1078.004mTLS mutual authentication
Malicious Task InjectionT1059.004Capability enforcement (explicit allow-list)
Inter-Agent Data ExfiltrationT1037.002Capability scoping + rate limiting
Agent Privilege EscalationT1078.003License-aware capability gating
A2A Supply Chain AttackT1195.003mTLS + HMAC-SHA256 integrity
Task HijackingT1056.001Capability-bound task execution
Agent Prompt InjectionT1059.005Capability scope enforcement
Agent Resource ExhaustionT1499.004Per-agent token bucket rate limiting

πŸ” ACP Protocol Security (Pillar 4)

ATLAS TechniqueIDAegisGate Defense
Message TamperingT1037HMAC verification of all ACP messages
Capability EscalationT1078Fine-grained permission control per session
Replay AttacksT1078.001Session-bound message validation
Protocol DowngradeT1190Strict protocol version enforcement
ACP Supply ChainT1195Registry signature verification

πŸ›‘οΈ AI Response Security (Pillar 5)

ATLAS TechniqueIDAegisGate Defense
PII DisclosureT1037Real-time PII detection (SSN, CC, email, PHI)
Secret ExposureT1110API key/token scanning in responses
Hallucination InjectionT1059False statement detection with risk scoring
Toxicity DistributionT1499Content policy enforcement
Response ManipulationT1059.002Bidirectional scanning of LLM outputs

Coverage by ATLAS Tactic

ATLAS organizes 66 techniques into 14 tactics. AegisGate provides comprehensive coverage:

Reconnaissance

TechniqueCoverage
Active ScanningRate limiting, request inspection
Gather Victim Host InformationAPI key protection, credential scanning

Resource Development

TechniqueCoverage
Acquire InfrastructureCredential monitoring, SSO enforcement
Compromise AccountsRBAC enforcement, session isolation

Initial Access

TechniqueCoverage
Supply Chain CompromisemTLS, signature verification, MCP/ACP server validation
Exploit Public-Facing ApplicationInput validation, 144+ threat patterns
Phishing (AI-specific)Prompt injection detection across all pillars

Execution

TechniqueCoverage
Prompt Injection144+ detection patterns, input sanitization
Command & Scripting InterpreterTool authorization, stdio validation
Agent Task ExecutionCapability enforcement, license gating

Persistence

TechniqueCoverage
Valid AccountsRBAC, session management, SSO
Hijack Execution FlowCapability scoping, tool authorization

Defense Evasion

TechniqueCoverage
Obfuscated FilesInput validation, content inspection
Impair DefensesFail-closed defaults, panic recovery
Agent ImpersonationmTLS, HMAC integrity

Credential Access

TechniqueCoverage
Unsecured CredentialsSecret scanning in transit and at rest
Credentials in FilesAPI key detection, vault integration

Discovery

TechniqueCoverage
Agent Capability DiscoveryCapability maps are server-side only (not exposed)
System Information DiscoveryRate limiting on discovery endpoints

Collection

TechniqueCoverage
Data from Local SystemOutput filtering, PII redaction
Inter-Agent Data CollectionCapability scoping limits data access

Exfiltration

TechniqueCoverage
Exfiltration Over C2 ChannelRate limiting, data loss prevention
Exfiltration Over Web ServiceResponse body scanning, exfiltration patterns

Impact

TechniqueCoverage
Resource HijackingPer-session/per-agent resource boundaries
Denial of ServiceRate limiting across all five pillars

Coverage Score

ATLAS TacticTechniques CoveredAegisGate Pillar(s)
Reconnaissance2/3HTTP, MCP
Resource Development2/2HTTP, MCP
Initial Access3/3HTTP, MCP, A2A, ACP
Execution3/3HTTP, MCP, A2A, RESPONSE
Persistence2/2MCP, A2A
Defense Evasion3/3HTTP, MCP, A2A
Credential Access2/2HTTP, MCP, RESPONSE
Discovery2/2MCP, A2A
Collection2/2HTTP, MCP, A2A, RESPONSE
Exfiltration2/2HTTP, A2A, RESPONSE
Impact2/2MCP, A2A

Overall: 66/66 ATLAS techniques defended (100% coverage)


Per-Tier ATLAS Coverage

FeatureCommunityDeveloperProfessionalEnterprise
HTTP threat scanning (144+ patterns)βœ…βœ…βœ…βœ…
MCP 8 guardrailsβœ…βœ…βœ…βœ…
A2A 8 guardrailsβ€”βœ…βœ…βœ…
ACP protocol securityβœ…βœ…βœ…βœ…
Response scanning (PII, secrets, toxicity)β€”βœ…βœ…βœ…
ATLAS compliance reportingβ€”βœ…βœ…βœ…
MITRE ATLAS 66 techniquesβœ…βœ…βœ…βœ…
Custom compliance frameworksβ€”β€”βœ…βœ…
ML anomaly detectionβ€”β€”βœ…βœ…
FedRAMP mappingβ€”β€”β€”βœ…

Getting Started with ATLAS Defense

1. Enable All Five Pillars

# aegisgate-platform.yaml
http:
  enabled: true
mcp:
  enabled: true
a2a:
  enabled: true
  config_file: configs/a2a.yaml
  caps_file: configs/a2a_caps.yaml
acp:
  enabled: true
response:
  enabled: true

2. Generate an ATLAS Compliance Report

curl -H "X-API-Key: your-key" \
     "http://localhost:8443/api/v1/compliance?framework=MITRE%20ATLAS"

3. Monitor Response Scanning

# Check response guard metrics
curl http://localhost:8443/api/v1/health | jq .dependencies.response

4. View Your ATLAS Coverage

The /api/v1/sla endpoint includes current SLO measurements that track defense effectiveness per tier.


References