为MCP智能体构建安全框架,系统梳理威胁并提出高效防御方案。
A Formal Security Framework for MCP-Based AI Agents: Threat Taxonomy, Verification Models, and Defense Mechanisms
- 基于17.7万工具分析,建立分层威胁分类体系。
- 集成防御架构覆盖91%威胁,远超单一防护手段的34%。
- 适合安全研究者与平台开发者参考,推动智能体生态安全
Model Context Protocol(MCP)自2024年11月由Anthropic推出以来,已成为连接大语言模型(LLM)智能体与外部工具及数据源的事实标准,月度SDK下载量超9700万,注册工具超17.7万个。然而,其快速普及暴露出缺乏统一、形式化安全框架的问题,现有研究分散于孤立攻击论文、基准测试和局部防御机制中。本文提出MCPSHIELD,一个全面的MCP智能体安全框架,贡献包括:(1)基于对超过17.7万个MCP工具的分析,构建包含7类威胁、23种攻击路径的分层威胁分类体系,覆盖四个攻击面;(2)基于带信任边界标注的标记转移系统的正式验证模型,支持静态与运行时分析;(3)对12种现有防御机制的系统评估,揭示其在威胁分类中的覆盖缺口;(4)提出纵深防御参考架构,集成基于能力的访问控制、加密工具认证、信息流追踪与运行时策略执行。分析表明,现有单一防御最多覆盖34%威胁,而MCPSHIELD集成架构理论覆盖率可达91%。此外,本文识别出七个需解决的开放性研究挑战,以保障下一代代理式AI系统的安全。
原文摘要 · Abstract (English)
The Model Context Protocol (MCP), introduced by Anthropic in November 2024 and now governed by the Linux Foundation's Agentic AI Foundation, has rapidly become the de facto standard for connecting large language model (LLM)-based agents to external tools and data sources, with over 97 million monthly SDK downloads and more than 177000 registered tools. However, this explosive adoption has exposed a critical gap: the absence of a unified, formal security framework capable of systematically characterizing, analyzing, and mitigating the diverse threats facing MCP-based agent ecosystems. Existing security research remains fragmented across individual attack papers, isolated benchmarks, and point defense mechanisms. This paper presents MCPSHIELD, a comprehensive formal security framework for MCP-based AI agents. We make four principal contributions: (1) a hierarchical threat taxonomy comprising 7 threat categories and 23 distinct attack vectors organized across four attack surfaces, grounded in the analysis of over 177000 MCP tools; (2) a formal verification model based on labeled transition systems with trust boundary annotations that enables static and runtime analysis of MCP tool interaction chains; (3) a systematic comparative evaluation of 12 existing defense mechanisms, identifying coverage gaps across our threat taxonomy; and (4) a defense in depth reference architecture integrating capability based access control, cryptographic tool attestation, information flow tracking, and runtime policy enforcement. Our analysis reveals that no existing single defense covers more than 34 percent of the identified threat landscape, whereas MCPSHIELD's integrated architecture achieves theoretical coverage of 91 percent. We further identify seven open research challenges that must be addressed to secure the next generation of agentic AI systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。