剖析AI模型与外部工具通信标准MCP的架构与安全风险
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
- 构建MCP全生命周期框架,分四个阶段16个活动
- 识别四类攻击者16种威胁场景,验证真实攻击面
- 提出分阶段安全防护方案,适合系统设计者参考
Model Context Protocol (MCP) 是一项新兴的开放标准,定义了AI模型与外部工具或资源之间的双向通信与动态发现协议,旨在提升异构系统间的互操作性并减少碎片化。本文从架构与安全双重视角对MCP进行系统研究。首先,将MCP服务器全生命周期划分为创建、部署、运行和维护四个阶段,并细化为16项关键活动以刻画其功能演进。基于此,构建涵盖四类攻击者(恶意开发者、外部攻击者、恶意用户、安全缺陷)的全面威胁分类体系,识别出16种具体威胁场景。通过开发并分析真实案例,验证了实施中的攻击面与漏洞表现。据此提出针对各生命周期阶段与威胁类别的细粒度安全防护措施,提供可落地的安全指导。同时分析当前MCP生态,涵盖行业采纳、集成模式与支持工具,揭示其技术优势及限制因素。最后,提出未来研究方向,聚焦于强化标准化、信任边界与可持续发展,推动工具增强型AI系统的演进。
原文摘要 · Abstract (English)
The Model Context Protocol (MCP) is an emerging open standard that defines a unified, bi-directional communication and dynamic discovery protocol between AI models and external tools or resources, aiming to enhance interoperability and reduce fragmentation across diverse systems. This paper presents a systematic study of MCP from both architectural and security perspectives. We first define the full lifecycle of an MCP server, comprising four phases (creation, deployment, operation, and maintenance), further decomposed into 16 key activities that capture its functional evolution. Building on this lifecycle analysis, we construct a comprehensive threat taxonomy that categorizes security and privacy risks across four major attacker types: malicious developers, external attackers, malicious users, and security flaws, encompassing 16 distinct threat scenarios. To validate these risks, we develop and analyze real-world case studies that demonstrate concrete attack surfaces and vulnerability manifestations within MCP implementations. Based on these findings, the paper proposes a set of fine-grained, actionable security safeguards tailored to each lifecycle phase and threat category, offering practical guidance for secure MCP adoption. We also analyze the current MCP landscape, covering industry adoption, integration patterns, and supporting tools, to identify its technological strengths as well as existing limitations that constrain broader deployment. Finally, we outline future research and development directions aimed at strengthening MCP's standardization, trust boundaries, and sustainable growth within the evolving ecosystem of tool-augmented AI systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。