כתבה
arXiv cs.AI ·
בדיקת חולשות: זיהוי חולשות פתיחה-בלתי-מוגדרות בשרתי MCP
No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers
בדיקת חולשות חדשה: זיהוי חולשות פתיחה-בלתי-מוגדרות בשרתי MCP. המחקר מציג פרדיגמה חדשה לבדיקת חולשות, המשתמשת במטא-נתונים כדי לזהות חולשות בשרתי MCP. המחקר כולל ניסויים על 20 שרתי MCP ומציע תיקון ל-95% מהחולשות שהתגלו.
תקציר מקורי באנגליתarXiv:2609.10854v1 Announce Type: cross Abstract: Conventional vulnerability analysis relies on either system access or dynamic interaction, all of which may be unavailable to third-party analysts auditing closed-source, remotely hosted, critical in situ systems, or commercially gated software. Therefore, we propose a new paradigm of no-box vulnerability analysis in which neither access nor runtime interaction is available, and only functionality metadata is available. Such metadata defines the intended behavior of the system, including its inputs, outputs, and side effects, while constraining the space of implementations consistent with that behavior. We propose hypothesizing about vulnerabilities that exist across all possible implementations of a given system metadata, without observing
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית