arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.10854cs.CRcs.AI

无盒漏洞分析:MCP服务器中间接提示注入漏洞的仅描述性检测

No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers

Zehua Zhang, Jie Hu, Pratham Hegde, Aditya Maheshbhai Gabani, Souradip Nath, Yibo Liu, Siyu Liu, Hongkai Chen, Hulin Wang, Zhuoer Lyu, Chang Zhu, Divij Handa, Y… 展开作者

Zehua Zhang, Jie Hu, Pratham Hegde, Aditya Maheshbhai Gabani, Souradip Nath, Yibo Liu, Siyu Liu, Hongkai Chen, Hulin Wang, Zhuoer Lyu, Chang Zhu, Divij Handa, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang, Adam Doupé

首次发表
浏览论文内容

中文总结 AI 辅助

提出无盒漏洞分析新范式,仅凭功能元数据即可检测MCP服务器间接提示注入漏洞,原型MCPSEC在177个工具上实现98.9%召回率,验证了该方法的实用性。

中文摘要 AI 辅助

传统漏洞分析依赖于系统访问或动态交互,而这些对于审计闭源、远程托管、关键现场系统或商业受限软件的第三方分析人员来说,可能均不可用。因此,我们提出了一种无盒漏洞分析的新范式,在这种范式中,既无法获得访问权限,也无法进行运行时交互,仅能获取功能元数据。此类元数据定义了系统的预期行为,包括其输入、输出和副作用,同时限制了与该行为一致的实现空间。我们提出在无需观察或与目标系统交互的情况下,对给定系统元数据的所有可能实现中存在的漏洞进行假设。当获得额外访问权限时,分析人员可以在后续验证这些假设。我们通过实现一个名为MCPSEC的原型来展示无盒漏洞分析的可行性,该原型仅利用服务器注册时暴露的工具元数据,对模型上下文协议(MCP)服务器进行间接提示注入漏洞审计。我们在20个广泛部署的MCP服务器上评估了MCPSEC,这些服务器包含177个工具,其中人工评估者确认了95个易受攻击的工具。MCPSEC识别出143个工具为易受攻击,并为每个易受攻击的工具生成了一个假设的漏洞及利用技术。仅使用元数据,MCPSEC预测了94个(召回率98.9%)真实已验证的漏洞,而LLM基线的召回率为80个(召回率84.2%)。总体而言,我们的结果引入了无盒漏洞分析作为一种新的分析范式,并证明了其在现实系统中的实际可行性。

英文摘要

Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available. Such metadata defines the intended behavior of the system, including its inputs, outputs, and side effects, while constraining the space of implementations consistent with that behavior. We propose hypothesizing about vulnerabilities that exist across all possible implementations of a given system metadata, without observing or interacting with the target system. An analyst can later validate these hypotheses when additional access is available. We showcase the feasibility of no-box vulnerability analysis through implementing a prototype called MCPSEC, which audits Model Context Protocol (MCP) servers for indirect prompt injection vulnerabilities using only the tool metadata exposed at server registration time. We evaluate MCPSEC on 20 widely deployed MCP servers comprising 177 tools, among which human evaluators confirm 95 vulnerable tools. MCPSEC identified 143 tools as vulnerable, and for each vulnerable tool, it produced a hypothesized vulnerability along with exploitation technique. Using metadata alone, MCPSEC predicted 94 (98.9% recall) real verified vulnerabilities, compared against an LLM baseline with 80 (84.2% recall). Overall, our results introduce no-box vulnerability analysis as a new analysis paradigm and demonstrate its practical feasibility in realistic systems.

发表机构

  • Arizona State University(亚利桑那州立大学)

机构由 AI 辅助整理,请以论文原文为准。

↑