Cisco Secure Access Help

PDF

Cisco Secure Access Help

AI Semantic Inspection Report

Want to summarize with AI?

Log in

Describes AI Semantic Inspection Report in Cisco Secure Access. As enterprises rapidly adopt AI agents to automate and optimize business operations, many are using the Model Context Protocol (MCP) to enable AI agents to access data and perform reasoning tasks in a standardized way.


As enterprises rapidly adopt AI agents to automate and optimize business operations, many are using the Model Context Protocol (MCP) to enable AI agents to access data and perform reasoning tasks in a standardized way. Because these tools often handle mission-critical enterprise data, ensuring visibility, security assurance, threat protection, and prevention of data breaches is essential. Securing interactions between AI agents (acting as MCP clients) and enterprise systems is a key challenge in deploying agentic AI safely.

Overview

Cisco Secure Access introduces the MCP Semantics Inspection Proxy, designed to analyze MCP protocol messages between AI agents/applications and MCP servers. This proxy identifies and blocks suspicious or policy-violating requests and responses, mitigating threats such as prompt injection, tool poisoning, reconnaissance, and data exfiltration that exploit MCP server-side vulnerabilities.

The Secure Access AI Semantics Inspection Dashboard provides visibility into detected threats by showing the number of blocked MCP messages and allowing users to drill down into detailed event reports. Threat detection and blocking are enabled by default for all MCP traffic, requiring no additional configuration or installation on client endpoints or MCP servers.

Key Features

  • Semantic Inspection Proxy: Analyzes MCP traffic flowing through Secure Access, detecting MCP messages for risky actions such as prompt injection, tool poisoning, and data exfiltration, performed by the AI agents.

  • Verdict Assignment: The semantic inspection proxy works in conjunction with Cisco Foundation AI model to assign each MCP message a verdict of Block or Allow.

  • Logging and Insights: MCP messages are logged on each observed MCP server, with actionable insights displayed to users.

  • AI Semantic Inspection dashboard: The AI Semantic Inspection dashboard on Secure Access provides visibility into detected threats, MCP server endpoint URLs and allows users to drill down into details about the security events.

  • Automatic Protection: Threat detection and blocking operate automatically on all MCP traffic visible to Secure Access, without client-side dependencies.

Current Scope and Constraints

  • This version inspects MCP requests only for agents accessing MCP servers publicly hosted on the internet, such as GitHub, Slack, Atlassian, Langchain, or Playwright.

  • Inspection applies to MCP traffic entering Secure Access via Remote Access VPN, SD-WAN, or IPSec/CNHE tunnels.

  • There is no dependency on client-side software; any MCP traffic visible to Secure Web Gateway (SWG) is analyzed.

Requirements for AI Semantic Inspection

To enable AI Semantic Inspection for your organization, follow these steps:

  • Configure a Security Profile for internet access with Decryption and AI Semantic Inspection enabled. For detailed guidance, refer to the documentation on Security Profiles for Internet Access.

  • Create at least one internet access rule that allows traffic and applies the Security Profile with Decryption enabled. See Security Profile for instructions.

  • Ensure MCP traffic inspection is enabled on Remote Access VPN connections and Branch office connections to Secure Access via SD-WAN or IPsec tunnels.

Detection of Specific Threats and Security Risks

Cisco Secure Access intercepts and evaluates MCP messages between MCP clients and servers to identify security risks and threats. These are consolidated into four key categories:

  • Data Exfiltration: Attempts to extract, export, or transfer sensitive data such as credentials, personally identifiable information (PII), training data, customer data, or internal datasets. This includes risks like data exposure via agent tooling, training data leaks, and intellectual property compromise.

  • Prompt Injection: Attempts to override instructions, jailbreak the AI model, or manipulate system or developer directives. This category covers direct prompt injection and jailbreak attempts aimed at altering AI behavior.

  • Tool Poisoning: Attempts to compromise tools, plugins, configurations, or the supply chain by embedding hidden instructions, backdoors, or persistence mechanisms. This includes tool exploitation, supply chain compromise, configuration persistence, and protocol manipulation.

  • Tool Shadowing: Attempts to register a tool with the same name as a legitimate tool so the agent resolves to the attacker’s version, enabling call interception, data theft, or false result injection without detection.

View AI Semantic Inspection Events in Reports


View AI Semantic Inspection Report

The Cisco AI Semantic Inspection Report provides detailed statistics on MCP messages observed by Secure Access within your organization. It detects, evaluates, and logs MCP communications to protect against threats and security risks related to these interactions.

Secure Access continuously monitors MCP traffic to safeguard your organization from potential vulnerabilities and malicious activities.

Before you begin

  • Ensure you have at least a Read-only user role in Secure Access.

  • Configure a Security profile for internet access with Decryption and AI Semantic Inspection enabled. For more information, see Security Profiles for Internet Access.

  • Create at least one internet access rule with the Allow action selected and associate it with a Security profile that has Decryption enabled. For more information, see Security Profiles.

    These prerequisites ensure that Secure Access can properly inspect and report on MCP traffic for your organization.

Procedure

  1. Navigate to Monitor > AI Semantic Inspection.

    The Semantic Inspection Heading Summary 10 10 interface.
  2. For Time Range, choose a time frame to review the MCP messages on the MCP servers. The default time range is the last 24 hours.

    The Semantic Inspection Time Range 10 10 interface.
  3. Navigate to Status summary.

    View the statistics about the MCP messages on the MCP servers observed by Secure Access.

    • Total messages inspected—The total number of MCP messages analyzed by Secure Access on the MCP servers.

    • Total threats blocked—The total number of MCP messages blocked by Secure Access on the MCP servers.

  4. Navigate to Semantic inspection totals.

    Secure Access displays the number and percentage of Blocked, Allowed, and Monitored MCP messages on the MCP servers for the organization.

    The Semantic Inspection Totals interface.
  5. Navigate to Top 5 threat categories blocked.

    Secure Access displays the top five threat categories associated with the MCP messages on the MCP servers, the number of threats blocked for each category, and the percentage of threats blocked on the threat category.

    The Top Threat Categories Blocked Ai Semantic Inspection Dashboard interface.
  6. Navigate to Semantic inspection details.

    View the URL of the MCP servers observed by Secure Access. For each MCP server, Secure Access shows the number of MCP messages inspected, blocked, or allowed.

    • MCP server—The URL of the MCP server.

    • Messages inspected—The total number of MCP messages inspected by Secure Access on the MCP server.

    • Messages blocked—The total number of MCP messages blocked by Secure Access on the MCP server.

    • Messages allowed—The total number of MCP messages allowed by Secure Access on the MCP server.

    The Semantic Inspection Details 10 10 interface.
  7. For an MCP server, navigate to a column of MCP messages, and then click the number in the column.

    Secure Access shows the events for the MCP messages in the Activity Search report. For more information, see View AI Semantic Inspection Events in Activity Search Report.