arXiv:2504.12757cs.CRcs.AI2025-04被引 51

为AI系统数据交互设计安全防护层,防止恶意攻击与数据泄露。

MCP Guardian: A Security-First Layer for Safeguarding MCP-Based AI System

  • 通过认证、限流、日志追踪等机制强化MCP通信安全
  • 实测表明能有效抵御攻击且开销极低
  • 适合构建可扩展、高可靠性的AI应用系统

随着代理型AI逐渐普及,行业在模型能力上投入巨大,推理与质量实现快速提升。然而,这些系统仍局限于数据孤岛,每次新集成都需定制逻辑,难以规模化。模型上下文协议(MCP)通过定义通用开放标准,实现了AI应用(MCP客户端)与数据源(MCP服务器)的安全连接。但MCP的灵活性也带来了新风险,包括恶意工具服务器和数据完整性受损。本文提出MCP Guardian框架,通过认证、限流、日志记录、追踪及Web应用防火墙(WAF)扫描,增强MCP通信的安全性。基于真实场景与实证测试,结果表明该框架能有效防御攻击并实现高效监管,同时保持极低开销。该方案推动了AI助手的安全可扩展数据访问,强调了纵深防御策略对构建更安全、透明的AI环境的重要性。

原文摘要 · Abstract (English)

As Agentic AI gain mainstream adoption, the industry invests heavily in model capabilities, achieving rapid leaps in reasoning and quality. However, these systems remain largely confined to data silos, and each new integration requires custom logic that is difficult to scale. The Model Context Protocol (MCP) addresses this challenge by defining a universal, open standard for securely connecting AI-based applications (MCP clients) to data sources (MCP servers). However, the flexibility of the MCP introduces new risks, including malicious tool servers and compromised data integrity. We present MCP Guardian, a framework that strengthens MCP-based communication with authentication, rate-limiting, logging, tracing, and Web Application Firewall (WAF) scanning. Through real-world scenarios and empirical testing, we demonstrate how MCP Guardian effectively mitigates attacks and ensures robust oversight with minimal overheads. Our approach fosters secure, scalable data access for AI assistants, underscoring the importance of a defense-in-depth approach that enables safer and more transparent innovation in AI-driven environments.

AI安全MCP协议防御机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。