arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ChainWatch:基于杀伤链的顺序检测框架,用于基于MCP的人工智能代理系统中的多步攻击

ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems

Om Narayan, Rashmi Jyoti, Ramkinker Singh

arXiv 2607.19432首次发表:更新:

发表机构

Computer Science New York University New York, USA; Cybersecurity University of Maryland, College Park MD, USA; Carnegie Mellon University Pittsburgh, USA(计算机科学 新 York 大学 新 York 美国; 网络安全 美国马里兰大学College Park分校 MD 美国; 卡内基梅隆大学 彭博 美国)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对基于MCP的人工智能代理系统中现有防御无法可靠检测多步攻击的问题,提出ChainWatch框架,用六阶段杀伤链建模攻击进展,结合隐马尔可夫模型分类工具调用序列,能检测逃避传统机制的攻击链。

AI 中文摘要

模型上下文协议(MCP)是一种开源标准,允许人工智能代理连接到外部工具、数据库和服务。这种连接性虽然增强了代理功能,但也引入了现有逐调用防御无法可靠检测的多步攻击。攻击者可将单个良性工具调用组合成恶意序列以逃避单独检查。本文提出ChainWatch,一种用于识别基于MCP的人工智能代理系统中多步攻击的顺序检测框架。ChainWatch使用六阶段杀伤链对攻击进展建模,并应用隐马尔可夫模型(HMM)对工具调用序列进行分类。当会话在多个阶段呈现可疑进展时触发检测规则。该框架由涵盖直接顺序攻击、间接提示注入链和混合多阶段攻击的结构化威胁模型支持。一个20维特征提取模式捕获工具交互的行为信号。我们使用安全文献中的五个代表性攻击场景演示了该方法,展示了ChainWatch如何检测逃避传统逐调用安全机制的攻击链。

英文摘要

The Model Context Protocol (MCP) is an open-source standard that allows AI agents to connect to external tools, databases, and services. While this connectivity enables powerful agent capabilities, it also introduces multi-step attacks that existing per-call defenses cannot reliably detect. Attackers can compose individually benign tool invocations into malicious sequences that evade isolated inspection. This paper presents ChainWatch, a sequential detection framework for identifying multi-step attacks in MCP-based AI agent systems. ChainWatch models attack progression using a six-stage kill chain and applies a Hidden Markov Model (HMM) to classify tool-call sequences. Detection rules are triggered when a session exhibits suspicious progression across multiple stages. The framework is supported by a structured threat model covering direct sequential attacks, indirect prompt injection chains, and hybrid multi-stage attacks. A 20-dimensional feature extraction schema captures behavioral signals from tool interactions. We demonstrate the approach using five representative attack scenarios from the security literature, showing how ChainWatch detects attack chains that evade traditional per-call security mechanisms.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑