<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>协议分析 on MessageDaily</title><link>https://inkeast.github.io/MessageDaily/tags/%E5%8D%8F%E8%AE%AE%E5%88%86%E6%9E%90/</link><description>Recent content in 协议分析 on MessageDaily</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://inkeast.github.io/MessageDaily/tags/%E5%8D%8F%E8%AE%AE%E5%88%86%E6%9E%90/index.xml" rel="self" type="application/rss+xml"/><item><title>A2ABreak 精读：把 A2A 协议规范编译成状态机之后，11 个新漏洞自己浮出水面</title><link>https://inkeast.github.io/MessageDaily/posts/2026-09-12-a2abreak-protocol-security-paper-reading/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://inkeast.github.io/MessageDaily/posts/2026-09-12-a2abreak-protocol-security-paper-reading/</guid><description>Purdue+UT Dallas（Elisa Bertino 组）对 Linux 基金会 A2A 协议做首个系统性安全分析：NL 规范→验证 FSM→受限 LLM 推理+对抗验证的三阶段框架。FSM 构建在 TCP ground-truth 上恢复 11/11 状态、19/20 转移（F1 0.84）；在“攻击者完全合规”假设下发现 11 个新漏洞——跨客户端上下文注入、委托链多跳身份丢失凭证收割等，全部无需实现缺陷。</description></item></channel></rss>