Hierarchical Approaches for Development of an MCP Security Framework

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Model Context Protocol (MCP), a protocol that standardizes connections between AI systems and tools, is rapidly proliferating without formal security design, thus harboring critical security vulnerabilities. Indeed, threats exploiting MCP vulnerabilities materialized through the postmark-mcp incident in September 2025. To address these security threats, this study aims to establish a security framework for establishing a secure MCP ecosystem. To this end, we identify 28 currently reported MCP threats and empirically demonstrate the existence of unreported potential vulnerabilities through experimentation. Subsequently, to encompass these threats, through characteristic analysis of vulnerabilities, we identify that MCP systems incorporate threats from connected systems and, based on this characteristic, apply a hierarchical analysis methodology to propose a tripartite classification: MCP-specific threats, LLM-inherited threats, and cyber attack-inherited threats. Based on this classification, we develop a MCP Security Framework. The framework proposes four strategies: MCP-Specific Defense Strategy with 11 countermeasures, LLM Inherent Defense Strategy with 3 countermeasures, Cyber Security Inherent Strategy connecting to cybersecurity frameworks, and MCP Firewall technology. This framework features a flexible and scalable structure designed to cover currently known threats while supporting analytical extensibility for reasoning about emerging threat scenarios. The MCP Security Framework proposed in this research, being both concrete and actionable, is expected to significantly contribute to establishing a secure foundation for the advancing AI ecosystem.

키워드

LicensesModelingNuclear facility regulationSecurityServersToolsComputer securityLarge language modelsTechnologyArtificial intelligenceModel context protocolMCP securityMCP security frameworkhierarchical threat analysisLLM securityAI securitycyber security
제목
Hierarchical Approaches for Development of an MCP Security Framework
저자
Jang, MyongwonLee, Kyungho
DOI
10.1109/ACCESS.2026.3694881
발행일
2026
유형
Article
저널명
IEEE Access
14
페이지
77148 ~ 77164