<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="review-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">1</article-id>
      <title-group>
        <article-title>Systematization of open protection mechanisms for agent systems based on large language models and analysis of threat landscape coverage</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Систематизация открытых механизмов защиты агентных систем на основе больших языковых моделей и анализ покрытия ландшафта угроз</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0007-8669-8081</contrib-id>
          <name>
            <surname>Istomina</surname>
            <given-names>Anastasiya</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>isto.anastasiya@gmail.com</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0008-9678-2428</contrib-id>
          <name>
            <surname>Iakovlev</surname>
            <given-names>Andrei</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>Andrew42ru@icloud.com</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <aff id="aff2">JSC “Positive Technologies”</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-10-09">
        <day>09</day>
        <month>10</month>
        <year>2026</year>
      </pub-date>
      <issue>3</issue>
      <fpage>9</fpage>
      <lpage>24</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/images/oblozhki/3_2026.png"/>
      <abstract xml:lang="en">
        <p>Protection tools for agent systems based on large language models develop in a fragmented way. They exist as separate open-source projects, commercial products, and research publications, and there is no unified view of how completely they cover current threat classes. This work systematizes the protection mechanisms of agent systems and assesses how completely they cover the threat landscape. A two-axis classification is proposed, in which each mechanism is characterized by its architectural level of application and its nature of impact. Following a unified scheme, 46 mechanisms selected from a catalog of 118 repositories are described. A quantitative coverage map of threats and mechanisms is built against the OWASP Top 10 for Agentic Applications 2026 and the OWASP Top 10 for Large Language Model Applications 2025. A defensein-depth indicator is introduced. The set of mechanisms covers all 10 classes of agentic threats, but coverage depth is distributed unevenly. “Tool misuse” is covered most fully, while “memory poisoning”, “insecure inter agent communication”, and “compromised agents” remain structural gaps without a mature preventive tool. Typical misconceptions in selecting protection tools are identified, and a minimal set of protections for designing agent systems is proposed.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Agent systems</kwd>
        <kwd>large language models</kwd>
        <kwd>protection mechanisms</kwd>
        <kwd>threat landscape</kwd>
        <kwd>OWASP</kwd>
        <kwd>prompt injection</kwd>
        <kwd>threat coverage map</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
