Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

How to protect your MCP Server with Fastly

Дата публикации: 09-07-2026 00:00:00

Protect your AI infrastructure with Fastly. Learn how our MCP server security architecture mitigates OWASP and AI-specific threats while maintaining edge performance.

Основное содержимое страницы с новостью.

David King

Group Product Marketing Manager, Security

As organizations rapidly adopt AI agents and agentic workflows, Model Context Protocol (MCP) servers are becoming a foundational integration layer between AI models and enterprise systems. While they accelerate development and simplify tool integration, they also introduce a new class of security challenges. Unlike traditional API traffic that’s typically deterministic and narrowly scoped, MCP traffic enables dynamic tool discovery, natural language-driven interactions, and orchestration across trust boundaries. These characteristics expand the attack surface and require security controls that extend beyond conventional API protection.

When a major global publisher approached Fastly asking for help securing their MCP server backbone connecting their AI agents with real-time financial data and tools, our team sprang into action to build a prototype that any organization can follow the architecture of to protect theirs. The following outlines the process and outcomes they achieved, providing a practical reference for organizations working to secure their own MCP environments.

Fastly MCP Protection Prototype

To protect their MCP server, the Fastly prototype needed to adhere to three key requirements: 

  • Detect and mitigate AI-specific attack vectors – OWASP and AI-specific attacks targeting the MCP server must be mitigated

  • Ensure production-scale performance – Sub-100ms latency is mandatory and the solution must handle at least 100Mbps throughput

  • Allow authentication complexity – A mix of IP-based, token-based, and mTLS authentication models must be allowed without false positives

To address these requirements, the prototype combined the flexibility and customization of multiple existing Fastly capabilities. While we won’t dive into the details of their unique implementation (but are happy to help your organization mirror the security outcomes privately), each of these solutions provided the customer with another layer of protection for their MCP server. 

Here’s how the prototype paired them together to solve the customer’s requirements: 

  • Fastly’s Global Network provides more than just 578 Tbps global capacity and performance benefits, enabling customers to implement custom traffic logic as it enters the network. This configuration flexibility allowed rules to be implemented as intended MCP traffic hit our network that automatically blocked unexpected content types like xml and restrict HTTP methods.

  • Fastly Bot Management provides visibility into the automated traffic heading to the MCP server, allowing rules to be created to block unwanted automation clients, bots with bad fingerprints, and generally malicious bot traffic.

  • Fastly Next-Gen WAF provides the ability to mitigate OWASP attacks and LLM-specific attacks like encoded prompt injection and jailbreak phrases. The prototype leverages its rate limiting capabilities to incorporate policies against IPs or API keys that exceeded expected norms.

  • Fastly Media Shield provides a designated Fastly POP as anchor for all MCP server traffic before it ultimately goes to origin. This enables the prototype to reduce origin load while speeding up connections by reducing the time required for costly multi-roundtrip handshakes.

Key results

With these four solutions implemented and tuned for protecting the customer’s MCP server, the team ran a 10-week trial to see how it stacked up against the customer’s requirements and found it far exceeded them.

Requirement

Desired Metric

Result

Latency (average)

< 100ms

Sub 50 ms

Upload throughput

100 Mbps

Achieved

Max payload size

200MB+

500MB+ without timeouts

Authentication Flexibility

IP-based, token-based, and mTLS model acceptance

Achieved

Fastly for AI Infrastructure

Fastly's platform is uniquely positioned in the request path to secure and accelerate AI agent infrastructure because it was purpose-built for the edge where performance and security must coexist.

  • Performance without compromise:  Inspection adds negligible latency; Fastly's global scale and resilience keeps AI agents performant 

  • Programmable security: Network and Next Gen-WAF rules can be tuned for the novel patterns of MCP and agentic traffic

  • Real-time visibility: Security teams see everything, in near real-time, without waiting for batch log exports

  • AI-native threat mitigation: Policies for prompt injection, tool abuse, and bot-driven enumeration can be easily created and paired with out-of-the-box OWASP-style attack protections

As AI and associated technologies continue to rise in adoption, Fastly’s MCP server protection prototype is just one example of how Fastly can help your business confidently adopt emerging technologies without increasing risk. Contact us if you’d like to learn more about the prototype or how we can help your business in the AI era.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1MCP at the Edge: What Changes When MCP Runs Securely in Every POP011.5819-08-2026
2Beyond the Bot Block: How Fastly and Experian Are Turning AI Agent Traffic into Revenue05.1506-08-2026
3Automated Payments at the Edge with x402 and Fastly Compute05.8527-07-2026
4How to Prove the Business Value of Your Edge Infrastructure06.2425-06-2026
5AI Content Provenance is Gaining Momentum: Get C2PA Support Now with Image Optimizer06.3104-08-2026
6AI Security Monitoring: Risks, Detection, and Automated Response04.7307-07-2026
7Why AI Infrastructure Is The Key To Enterprise AI Success06.2121-04-2026
8Securing the AI era: Outpace AI-powered attacks with unified security and observability010.9809-06-2026
9AI Agent Governance: Securing Autonomous Agents in Production010.4124-07-2026
10Shared Context: How an MCP Server Exposed a Private Equity Firm | UpGuard07.0218-05-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.43. Источник: www.fastly.com.