自动化构建MCP生态安全威胁情报,填补三大防护空白
MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems
- 多源数据自动采集+AI提取分类,构建威胁知识图谱
- 基于MCP-38分类体系,实现38类特定威胁精准识别
- 支持持续更新与可视化,适合安全团队快速定位风险
Model Context Protocol(MCP)驱动的智能体系统迅猛发展,催生了现有安全框架难以应对的新威胁。本文提出MCPThreatHive——一个开源平台,实现MCP威胁情报的全流程自动化:从多源数据持续采集,经由AI驱动的威胁提取与分类,到结构化知识图谱存储与交互式可视化。平台贯彻MCP-38威胁分类体系,涵盖38种针对MCP的特定威胁模式,映射至STRIDE、LLM应用OWASP Top 10及智能体应用OWASP Top 10。复合风险评分模型提供量化优先级。通过对比分析主流MCP安全工具,我们识别出三项关键缺失:组合攻击建模不完整、缺乏持续威胁情报、无统一多框架分类。MCPThreatHive有效弥补上述短板。
原文摘要 · Abstract (English)
The rapid proliferation of Model Context Protocol (MCP)-based agentic systems has introduced a new category of security threats that existing frameworks are inadequately equipped to address. We present MCPThreatHive, an open-source platform that automates the end-to-end lifecycle of MCP threat intelligence: from continuous, multi-source data collection through AI-driven threat extraction and classification, to structured knowledge graph storage and interactive visualization. The platform operationalizes the MCP-38 threat taxonomy, a curated set of 38 MCP-specific threat patterns mapped to STRIDE, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic Applications. A composite risk scoring model provides quantitative prioritization. Through a comparative analysis of representative existing MCP security tools, we identify three critical coverage gaps that MCPThreatHive addresses: incomplete compositional attack modeling, absence of continuous threat intelligence, and lack of unified multi-framework classification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。