arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

远程MCP生态系统中的网络集中性与可观测性表征

Characterizing Network Centralization and Observability in the Remote MCP Ecosystem

Muhammad Abdullah Sohail

arXiv 2609.19100首次发表:更新:

发表机构

University of Calgary(卡尔加里大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出三层可观测性框架,实证分析179个远程MCP端点,揭示高度基础设施集中(HHI=0.736)及安全与可观测性之间的权衡,为AI网关安全评估提供依据。

AI 中文摘要

模型上下文协议(MCP)已成为连接自主智能体与外部数据源及执行环境的主导接口。该生态系统从本地进程执行向远程流式HTTP部署的转变,引入了大规模下未充分衡量的架构与安全约束。本文提出一个三层可观测性框架,包括目录元数据(O_0)、被动合规信号(O_1)和实时漏洞分析(O_2),并将其应用于对公共MCP服务器生态系统的经验性表征。对来自两个主要公共注册中心的179个远程端点的分层样本进行评估,揭示了显著的基础设施整合现象。基于自治系统编号(ASN)分布计算的赫芬达尔-赫希曼指数(HHI)值为0.736,远高于高度集中市场0.25的阈值。分析进一步表明,服务器认证与托管平台选择强相关,而非单个运营商的配置,95%的商业PaaS托管服务器强制执行带有PKCE的网关级OAuth 2.1。实证结果识别出当前生态系统中存在的安全-可观测性权衡:保护大多数服务器的平台级认证机制同时限制了自动化漏洞扫描能力,制约了AI网关运营商在未预先提供凭据的情况下评估工具投毒向量的能力。

英文摘要

The Model Context Protocol (MCP) has emerged as the dominant interface for connecting autonomous agents to external data sources and execution environments. The ecosystem's transition from local process execution to remote Streamable HTTP deployments introduces unmeasured architectural and security constraints at scale. This paper presents a three-tier observability framework comprising catalog metadata (O_0), passive compliance signals (O_1), and live vulnerability analysis (O_2), applied to empirically characterize the public MCP server ecosystem. Evaluation of a stratified sample of 179 remote endpoints across two primary public registries reveals significant infrastructural consolidation. The Herfindahl-Hirschman Index (HHI) computed over the Autonomous System Number (ASN) distribution yields a value of 0.736, well above the 0.25 threshold for a highly concentrated market. Analysis further indicates that server authentication is strongly correlated with hosting platform choice rather than individual operator configuration, with 95\% of commercial PaaS-hosted servers enforcing gateway-level OAuth 2.1 with PKCE. The empirical results identify a Security-Observability Tradeoff observed in the current ecosystem: the platform-level authentication mechanisms that secure the majority of servers simultaneously limit automated vulnerability scanning capabilities, constraining the ability of AI gateway operators to assess tool-poisoning vectors without prior credential provisioning.

Comments6 pages, 3 figures. Accepted at the 1st IEEE ICNP Workshop on Network Infrastructure and Protocols for AI Agents (NIPA 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑