arXiv:2603.18063cs.CRcs.AI2026-03被引 7

为新型模型上下文协议设计38类安全威胁分类,填补现有框架空白。

MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)

  • 基于四阶段方法构建协议专属威胁分类体系
  • 涵盖工具描述污染、间接提示注入等38类新威胁
  • 适合作为自动化威胁平台的理论基础

模型上下文协议(MCP)引入了结构上独特的攻击面,现有威胁框架对传统软件系统或通用大模型部署的覆盖不充分。本文提出MCP-38,一个包含38个威胁类别(MCP-01至MCP-38)的协议专用威胁分类体系。该分类通过系统化的四阶段方法推导:协议分解、多框架交叉映射、真实事件整合与修复面分类。每个类别均映射至STRIDE、OWASP LLM应用2025版(LLM01–LLM10)及智能体应用2026版(ASI01–ASI10)。MCP-38涵盖MCP语义攻击面带来的关键威胁,如工具描述污染、间接提示注入、寄生工具链和动态信任违规,这些均未被先前工作充分捕捉。MCP-38为自动化威胁情报平台提供了定义性和实证性基础。

原文摘要 · Abstract (English)

The Model Context Protocol (MCP) introduces a structurally distinct attack surface that existing threat frameworks, designed for traditional software systems or generic LLM deployments, do not adequately cover. This paper presents MCP-38, a protocol-specific threat taxonomy consisting of 38 threat categories (MCP-01 through MCP-38). The taxonomy was derived through a systematic four-phase methodology: protocol decomposition, multi-framework cross-mapping, real-world incident synthesis, and remediation-surface categorization. Each category is mapped to STRIDE, OWASP Top 10 for LLM Applications (2025, LLM01--LLM10), and the OWASP Top 10 for Agentic Applications (2026, ASI01--ASI10). MCP-38 addresses critical threats arising from MCP's semantic attack surface (tool description poisoning, indirect prompt injection, parasitic tool chaining, and dynamic trust violations), none of which are adequately captured by prior work. MCP-38 provides the definitional and empirical foundation for automated threat intelligence platforms.

威胁建模大模型安全协议安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。