{"id":8403,"date":"2026-03-05T09:55:24","date_gmt":"2026-03-05T15:55:24","guid":{"rendered":"https:\/\/www.infoblox.com\/blog\/?p=13030"},"modified":"2026-03-05T09:55:24","modified_gmt":"2026-03-05T15:55:24","slug":"agent-discovery-a-foundational-security-issue-for-the-agentic-web","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2026\/03\/05\/agent-discovery-a-foundational-security-issue-for-the-agentic-web\/","title":{"rendered":"Agent Discovery: A Foundational Security Issue for the Agentic Web"},"content":{"rendered":"<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/03\/agent-discovery-a-foundational-security-issue-for-the-agentic-web.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>Infoblox recently submitted consultation responses to two key policy efforts shaping the future of AI security: the <a href=\"https:\/\/www.csa.gov.sg\/resources\/publications\/addendum-on-securing-ai-systems\/\" target=\"_blank\">Cyber Security Agency of Singapore\u2019s (CSA) Draft Addendum on Securing Agentic AI Systems<\/a> and <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/ir\/2025\/NIST.IR.8596.iprd.pdf\" target=\"_blank\">the U.S. National Institute of Standards and Technology\u2019s (NIST) Cyber AI Profile<\/a>. These consultations are designed to help governments and standards bodies understand emerging risks associated with agentic AI, or systems capable of autonomous, multi-step decision-making. The intended result is governments ensuring their guidance is practical, interoperable and grounded in real-world security operations.<\/p>\n<p>We chose to engage in both consultations because agentic AI represents a structural shift in how software systems interact with networks, services and each other. As agents increasingly discover and invoke external tools and peer agents on their own, traditional security assumptions need to evolve as well. Our submissions focused on highlighting these architectural changes and offering concrete recommendations to help policymakers address security blind spots before they become systemic risks.<\/p>\n<p>As AI systems innovate toward more autonomous, agentic models, cybersecurity risk shifts in important ways. Agentic AI systems do not just generate outputs; they discover, select and interact with other agents, tools and external services. That makes discovery, how agents find, trust and talk to each other, a foundational security issue.<\/p>\n<h3>Infoblox\u2019s Stance: DNS as a Foundational Control for Agent-to-Agent Discovery<\/h3>\n<p>Securing agentic AI requires addressing risks at multiple layers. Most discussions about AI agent security focus on familiar, single-agent vulnerabilities: prompt injection, data exfiltration and adversarial persuasion. The moment agents begin operating in multi-agent environments, an entirely new category of risk emerges. A compromised or malicious agent can now impersonate a trusted service by exploiting weak discovery mechanisms to insert itself into critical processes. Securing agentic AI demands a defense-in-depth strategy where agent-to-agent discovery, the process by which agents find, trust and communicate with external tools and peer agents, represents a foundational layer in a comprehensive defense-in-depth strategy.<\/p>\n<p>In our submissions to Singapore CSA and NIST, we emphasized that agent discovery is a foundational security control that should be part of any organization\u2019s layered approach to securing agentic AI. From a security perspective, this matters because whoever controls discovery influences an agent\u2019s attack surface. If agents can be misdirected to malicious or unvetted endpoints, even strong model-layer guardrails can be circumvented, allowing compromise to spread across multi-agent environments. Our perspective and expertise are sourced from experience in organizations listing and discovering traditional services today via the Domain Name System (DNS) and securing that communication through our Secure DNS offerings.<\/p>\n<p>We believe organizations should retain clear control over what their AI agents can discover, trust and use for communication. In practice, this means anchoring agent discovery and reachability in authoritative, verifiable and auditable infrastructure complementing application-layer security controls, rather than relying solely on centralized registries that can introduce systemic risk, single points of failure, compliance and\/or sovereignty concerns.<\/p>\n<p>Across both consultations, we highlighted the role of existing internet infrastructure, particularly the DNS and DNS-based security controls, as a practical way to enforce policy, integrity and least privilege for agentic systems. Because agents cannot communicate until discovery and resolution occur, securing this layer provides defense-in-depth safeguards that complement application-layer AI controls and integrate naturally with existing enterprise security architectures, including zero trust frameworks.<\/p>\n<h3>DNS\u2011AID: An Open Discovery Layer for Agents<\/h3>\n<p>We also emphasized that organizations should have access to standardized, distributed discovery architectures rooted in the internet\u2019s existing critical infrastructure. In particular, we highlighted the DNS\u2011AID approach set out in the <em>Brokered Agent Network for DNS AI Discovery<\/em> internet-draft presented at the Internet Engineering Task Force (IETF). Co\u2011authored by Infoblox\u2019s Jim Mozley and Nic Williams, the draft aims to leverage DNS\u2019s hierarchical namespace to support federated agent discovery. By anchoring agent discovery in DNS, DNS\u2011AID proposes an already deployed, globally distributed infrastructure layer to publish authoritative records about agents and tools, bind them to the right organizational domains and enforce reachability boundaries without introducing a new centralized directory layer.<\/p>\n<p>For security purposes, DNS-AID aligns agent discovery with zero\u2011trust principles: operators can use DNS naming and records to publish which agents and tools are authorized, and which destinations should be treated as trustworthy. While DNS is used in the discovery process, it is not replacing any existing agent-specific communication protocols, nor is it proposed that DNS is used to catalogue all an organization\u2019s agents. Rather, DNS is used to identify a secure well-known endpoint to begin discovery. The process works equally well for internal networks as it does with the internet.<\/p>\n<h3>Open Internet Principles for the Agentic Web<\/h3>\n<p>A critical theme in our submissions is ensuring agent discovery does not become concentrated in a few registries. If agent discovery becomes dependent on select registries, those services become single points of failure, attractive targets for adversaries, and are liable to create fragmentation in the event the solution becomes unsupported. While curated directories can add convenience, they should remain a choice rather than the only path to connectivity.<\/p>\n<p>More broadly, policy and standards decisions made today will shape the emerging \u201cAgentic Web\u201d: the next evolution of the internet, moving from static pages to a system where autonomous AI agents proactively perform complex, multi\u2011step tasks for users. As with the DNS-AID framework before the IETF, we believe governments and internet governance bodies should guide the development of standardized, decentralized agent\u2011to\u2011agent discovery architectures rooted in the internet\u2019s existing critical network infrastructure. While private\u2011sector innovation will continue to shape AI technologies, public\u2011sector leadership is essential to avoid centralized directories that commoditize user data, prevent control by adversarial states or monopolistic data brokers, and ensure openness rather than a fragmented landscape of incompatible protocols.<\/p>\n<p>By promoting this foundational approach, governments can help ensure that core values of an open, interoperable and democratized internet carry forward into the next generation of AI connectivity.<\/p>\n<h3>Looking Ahead: Engagement on NIST SP 800-53 AI Overlays and AI Agent Concept Paper<\/h3>\n<p>As standards and guidance for AI security continue to mature, Infoblox intends to remain actively engaged. NIST\u2019s National Cybersecurity Center of Excellence has released a draft concept paper, <em>Accelerating the Adoption of Software and AI Agent Identity and Authorization<\/em>, outlining a proposed project to develop practical, standards\u2011based guidance for managing the identity and authorization of software and AI agents in enterprise environments.<\/p>\n<p>In parallel, NIST will also be releasing a series of AI overlays for the NIST SP 800-53 <em>Security and Privacy Controls for Information Systems and Organizations controls<\/em>. These controls are used widely by U.S. federal agencies and many private-sector organizations as a baseline for securing systems and protecting data. The AI overlays are being developed to translate the existing SP 800-\u201153 security and privacy controls into concrete, AI s\u2011pecific implementation guidance rather than creating a new set of AI\u2011only controls. We look forward to engaging NIST on both efforts, with a focus on ensuring that agentic and multi-agent discovery is addressed explicitly.<\/p>\n<p>Our goal is to help advance AI guidance that is interoperable, resilient and grounded in real-world operational security so organizations can deploy agentic AI without concentrating risk or sacrificing control. We look forward to continued collaboration with policymakers, standards bodies and the broader security community as the foundations of the emerging agentic ecosystem take shape.<\/p>\n<style>\n.savy-seahorse-table {\nfont-size:14px;\nword-break: keep-all;\n}\n.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {\npadding-right:10px;\n}\n.code-format { font-family: 'Courier New';\n}\n.image-caption { font-size: 12px;\nmargin-top:auto;\n}\n.list-spacing li{margin-bottom:20px}\n.img-container, .img-container-3-col {\ndisplay: flex;\nflex-wrap: wrap;\njustify-content: space-between;\n}\n.img-container img {\nwidth: 49%;\nmargin-bottom: 10px;\n}\n.img-container-3-col img {\nwidth: 30%;\nmargin-bottom: 10px;\n}\n@media (max-width: 767px) {\n.img-container, .img-container-3-col {\ndisplay: block;\n}\n.img-container img, .img-container-3-col img {\nwidth: 100%;\n}\n.grid-container { grid-template-columns: 1fr!important; }\n}\n@media (min-width: 767px) {\n.img-50{width:50%;}\n}\n.grid-container { display: grid; grid-template-columns: repeat(2, 1fr); gap: 40px; max-width: 800px; margin: 0 auto; align-items: stretch;\n}\n.grid-item { display: flex; flex-direction: column; justify-content: flex-start;\n}\n.grid-item img { width: 100%; height: auto;\n}\n<\/style>\n<p> <a href=\"https:\/\/www.infoblox.com\/blog\/company\/agent-discovery-a-foundational-security-issue-for-the-agentic-web\/\">Infoblox Original<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infoblox recently submitted consultation responses to two key policy efforts<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4037,6127,6121,6129,329,6128,6125,6123,6130,6122,6131,6124,6126],"tags":[4038,6138,6132,6140,333,6139,6136,6134,6141,6133,6142,6135,6137],"class_list":["post-8403","post","type-post","status-publish","format-standard","hentry","category-agentic-ai","category-agentic-web","category-ai-agent-discovery","category-ai-identity-and-authorization","category-company","category-defense-in-depth-for-ai","category-dns-aid","category-dns-based-ai-security","category-internet-governance-for-ai-systems","category-multi-agent-systems-security","category-policy-recommendations-for-securing-agentic-ai-systems","category-secure-dns","category-zero-trust-agent-discovery","tag-agentic-ai","tag-agentic-web","tag-ai-agent-discovery","tag-ai-identity-and-authorization","tag-company","tag-defense-in-depth-for-ai","tag-dns-aid","tag-dns-based-ai-security","tag-internet-governance-for-ai-systems","tag-multi-agent-systems-security","tag-policy-recommendations-for-securing-agentic-ai-systems","tag-secure-dns","tag-zero-trust-agent-discovery"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Infoblox","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/infoblox\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/agentic-ai\/\" rel=\"category tag\">Agentic AI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/agentic-web\/\" rel=\"category tag\">Agentic Web<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ai-agent-discovery\/\" rel=\"category tag\">AI agent discovery<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ai-identity-and-authorization\/\" rel=\"category tag\">AI identity and authorization<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/company\/\" rel=\"category tag\">Company<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/defense-in-depth-for-ai\/\" rel=\"category tag\">defense-in-depth for AI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-aid\/\" rel=\"category tag\">DNS-AID<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-based-ai-security\/\" rel=\"category tag\">DNS-based AI security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/internet-governance-for-ai-systems\/\" rel=\"category tag\">internet governance for AI systems<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/multi-agent-systems-security\/\" rel=\"category tag\">multi-agent systems security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/policy-recommendations-for-securing-agentic-ai-systems\/\" rel=\"category tag\">policy recommendations for securing agentic AI systems<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/secure-dns\/\" rel=\"category tag\">Secure DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/zero-trust-agent-discovery\/\" rel=\"category tag\">zero-trust agent discovery<\/a>","tag_info":"zero-trust agent discovery","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=8403"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8403\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=8403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=8403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=8403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}