为开源MCP服务器构建安全风险评估框架,识别可被利用的漏洞。
MCP-in-SoS: Risk assessment framework for open-source MCP servers
- 通过静态代码分析定位常见缺陷(CWE),映射真实攻击模式。
- 发现多个开源MCP服务器存在影响机密性、完整性和可用性的漏洞。
- 适合关注LLM代理安全的开发者与企业安全团队参考。
模型上下文协议(MCP)服务器在过去一年中迅速兴起,成为大型语言模型(LLM)代理访问动态现实工具的广泛采用方式。随着MCP服务器通过开源发布日益普及,理解其安全风险对可靠生产级代理部署至关重要。尽管已有研究提出威胁分类、缓解措施并演示实际攻击,但据我们所知,尚无先前研究对开源MCP服务器进行系统性、大规模的弱点评估。为此,我们应用静态代码分析识别通用缺陷(CWE),并借助MITRE CAPEC将这些缺陷映射到常见攻击模式和威胁类别,使风险与真实世界威胁挂钩。随后,我们提出一种结合多指标评分(可能性与影响)的MCP生态风险评估框架。结果表明,许多开源MCP服务器包含可被利用的弱点,可能危及机密性、完整性与可用性,凸显了安全优先设计的重要性。
原文摘要 · Abstract (English)
Model Context Protocol (MCP) servers have rapidly emerged over the past year as a widely adopted way to enable Large Language Model (LLM) agents to access dynamic, real-world tools. As MCP servers proliferate and become easy to adopt via open-source releases, understanding their security risks becomes essential for dependable production agent deployments. Recent work has developed MCP threat taxonomies, proposed mitigations, and demonstrated practical attacks. However, to the best of our knowledge, no prior study has conducted a systematic, large-scale assessment of weaknesses in open-source MCP servers. Motivated by this gap, we apply static code analysis to identify Common Weakness Enumeration (CWE) weaknesses and map them to common attack patterns and threat categories using the MITRE Common Attack Pattern Enumerations and Classifications (CAPEC) to ground risk in real-world threats. We then introduce a risk-assessment framework for the MCP landscape that combines these threats using a multi-metric scoring of likelihood and impact. Our findings show that many open-source MCP servers contain exploitable weaknesses that can compromise confidentiality, integrity, and availability, underscoring the need for secure-by-design MCP server development.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。