AI Agents 相关度: 9/10

MCPThreatHive: Automated Threat Intelligence for Model Context Protocol Ecosystems

Yi Ting Shen, Kentaroh Toyoda, Alex Leung
arXiv: 2604.13849v1 发布: 2026-04-15 更新: 2026-04-15

AI 摘要

MCPThreatHive平台自动化MCP威胁情报生命周期,填补现有安全工具的不足。

主要贡献

  • 自动化MCP威胁情报生命周期
  • 构建MCP-38威胁分类体系
  • 提出组合风险评分模型

方法论

通过多源数据收集,AI驱动的威胁提取和分类,构建知识图谱和交互式可视化。

原文摘要

The rapid proliferation of Model Context Protocol (MCP)-based agentic systems has introduced a new category of security threats that existing frameworks are inadequately equipped to address. We present MCPThreatHive, an open-source platform that automates the end-to-end lifecycle of MCP threat intelligence: from continuous, multi-source data collection through AI-driven threat extraction and classification, to structured knowledge graph storage and interactive visualization. The platform operationalizes the MCP-38 threat taxonomy, a curated set of 38 MCP-specific threat patterns mapped to STRIDE, OWASP Top 10 for LLM Applications, and OWASP Top 10 for Agentic Applications. A composite risk scoring model provides quantitative prioritization. Through a comparative analysis of representative existing MCP security tools, we identify three critical coverage gaps that MCPThreatHive addresses: incomplete compositional attack modeling, absence of continuous threat intelligence, and lack of unified multi-framework classification.

标签

MCP 威胁情报 安全 Agent

arXiv 分类

cs.CR cs.AI