상세 보기
Hierarchical Approaches for Development of an MCP Security Framework
- Jang, Myongwon;
- Lee, Kyungho
WEB OF SCIENCE
0SCOPUS
0초록
Model Context Protocol (MCP), a protocol that standardizes connections between AI systems and tools, is rapidly proliferating without formal security design, thus harboring critical security vulnerabilities. Indeed, threats exploiting MCP vulnerabilities materialized through the postmark-mcp incident in September 2025. To address these security threats, this study aims to establish a security framework for establishing a secure MCP ecosystem. To this end, we identify 28 currently reported MCP threats and empirically demonstrate the existence of unreported potential vulnerabilities through experimentation. Subsequently, to encompass these threats, through characteristic analysis of vulnerabilities, we identify that MCP systems incorporate threats from connected systems and, based on this characteristic, apply a hierarchical analysis methodology to propose a tripartite classification: MCP-specific threats, LLM-inherited threats, and cyber attack-inherited threats. Based on this classification, we develop a MCP Security Framework. The framework proposes four strategies: MCP-Specific Defense Strategy with 11 countermeasures, LLM Inherent Defense Strategy with 3 countermeasures, Cyber Security Inherent Strategy connecting to cybersecurity frameworks, and MCP Firewall technology. This framework features a flexible and scalable structure designed to cover currently known threats while supporting analytical extensibility for reasoning about emerging threat scenarios. The MCP Security Framework proposed in this research, being both concrete and actionable, is expected to significantly contribute to establishing a secure foundation for the advancing AI ecosystem.
키워드
- 제목
- Hierarchical Approaches for Development of an MCP Security Framework
- 저자
- Jang, Myongwon; Lee, Kyungho
- 발행일
- 2026
- 유형
- Article
- 저널명
- IEEE Access
- 권
- 14
- 페이지
- 77148 ~ 77164