AI工具Score B (64)

Secure Claude Enterprise with Cisco AI Defense

1 小时前2 viewsSource: blogs.cisco.com
Artificial Intelligence - AI Secure Claude Enterprise with Cisco AI Defense 3 min read Siddhant Dash , Barry Yuan Teams are putting Claude Enterprise to work fast, and not just for chat. Claude, Claude Code, and Claude Cowork act on behalf of users. They read documents, call tools, and run tasks. That makes the prompt an attack surface. A jailbreak can try to bypass the assistant’s guardrails. A prompt injection hidden in a shared file can hijack an agent and turn its own tools against you. Traditional data loss prevention tools were built to watch for sensitive data leaving the building. They were not built to see the model being manipulated, and that is the exposure that matters most here. Anthropic recently introduced inference hooks, which let an organization send each governed prompt to an AI security service before inference begins. When configured, an inference hook is able to call Cisco AI Defense, which inspects the prompt for artificial intelligence (AI) threats and returns a verdict, allow or deny. When a user submits a prompt, Claude Enterprise passes it to Cisco AI Defense, which inspects it for AI threats and returns a verdict. Safe prompts go through. A prompt carrying an injection or a jailbreak is blocked, and the model never runs. This is where the AI-first focus of Cisco shows. Here is the difference in plain terms. Traditional data loss prevention is designed to identify sensitive data. Cisco AI Defense reads intent. It catches prompt injection and jailbreaks that target the model, its tools, and the agents acting on its behalf, and it evaluates agent activity in the conversation transcript. When Claude Code or Cowork calls a tool, including tools connected over the Model Context Protocol (MCP), the transcript can include the tool call and its result, so poisoned content can be caught before the next inference continues. Cisco AI Defense runs both privacy and manipulation guardrails on that transcript: it flags sensitive data the way data loss prevention would, plus the injection and jailbreak attempts data loss prevention was never built to see. Put simply: data loss prevention watches for data leaving; Cisco AI Defense watches the conversation itself, catching both data leaving and the model being turned against you. That reflects how we think about the whole problem. This Claude Enterprise integration is one runtime enforcement point in a much broader platform. Cisco AI Defense secures the full AI lifecycle: it discovers and inventories your AI assets like agents, skills, MCP servers and tools, and models; assesses their risk through validation, red-teaming, and supply chain and model scanning; and protects them at runtime with guardrails like this one. It is part of Cisco Cloud Control , Cisco’s unified platform and secure harness for the agentic era . You can read more about our full-lifecycle approach to agent security in Cisco AI Defense Gets Personal with Agent Security . The result is real-time protection delivered through the hook, an additional integration layer for comprehensive AI coverage that adds enforcement without adding infrastructure to the user’s workflow. It gives security leaders a direct enforcement point for AI policy across governed Claude Enterprise requests. Enterprise users of Claude keep the fast, native experience they signed up for. For security leaders, this turns Claude Enterprise from something you either trust or block into something you can govern against real AI threats. For the teams using it, that protection arrives without a single change to how they work. How it works Cisco AI Defense plugs into Anthropic’s inference hooks, so protection runs inline on every governed prompt: Prompt is sent for inspection. Claude Enterprise sends each governed prompt, across Claude, Claude Code, and Cowork, to Cisco AI Defense through the inference hook, before the model runs. Request is cryptographically verified. Every call is signed with a one-time signing secret. Cisco AI Defense checks that signature and confirms the request is authentic before it inspects anything. Conversation is inspected against your policy. Cisco AI Defense reads the full conversation, including tool calls and their results, and evaluates it against your runtime policy for prompt injection, jailbreaks, tool exploitation, and sensitive data. A verdict returns before inference. Cisco AI Defense returns allow or deny. Safe prompts continue; a malicious prompt is blocked, and the model never runs. Availability Cisco AI Defense inspects both prompts and responses. This integration uses Anthropic’s inference hook, which currently fires on each governed prompt before the model runs, so that is where we enforce right now. As Anthropic extends the hook to responses, response-side enforcement can use the same integration path. Over time, we expect this enforcement to become a native part of the Cisco AI Defense Inspect API, so turning it on will be a few steps in your Claude Enterprise settings. It works with Claude Enterprise today, and inference hooks are in beta. Want to see it? Try the playground in our developer portal ; enter a prompt and watch the live inspection and the real verdict. See how Cisco AI Defense stands up to AI threats. Schedule time with our team. Authors Siddhant Dash Senior Product Manager - AI Defense AI Software & Platform Barry Yuan Sr. Solutions Engineer Cisco Global Partner Sales

Read the full original article:

blogs.cisco.com
#Claude