公開MCPサーバーの集中度と観測の制約を調べる
Characterizing Network Centralization and Observability in the Remote MCP Ecosystem
この論文をやさしく読む
ひとことで言うと
公開リモートMCPのホスティングがどこに集中し、認証が外部からの安全性調査にどう影響するかを測った研究です。
何に役立つ?
MCPの接続先を評価する際、公開情報だけで分かることと認証が必要なことを分ける材料になります。基盤選定と認証の関係も把握できます。
この研究の面白いところ
認証がサーバーを守る一方、外部からの自動検査も難しくするという関係を、集中度の測定と一緒に扱っています。
どこまで分かった?
調査対象は二つのレジストリから抽出した179エンドポイントです。認証で観測できないことは、脆弱性があることを意味しません。市場集中のしきい値はASN分布の解釈に用いられています。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
Model Context Protocol(MCP)は、自律エージェントを外部データ源や実行環境につなぐ主要なインターフェースとなっている。その環境がローカルプロセス実行からリモートのStreamable HTTP配置へ移行することは、大規模な構成上・セキュリティ上の未測定の制約をもたらす。本論文では、カタログのメタデータ(O₀)、受動的な準拠シグナル(O₁)、稼働中の脆弱性分析(O₂)からなる三段階の観測可能性の枠組みを提示し、公開MCPサーバー環境の実証的な特徴付けに適用する。 主要な二つの公開レジストリから層化抽出した179のリモートエンドポイントを評価したところ、インフラの顕著な集中が明らかになった。自律システム番号(ASN)の分布に対して計算したHerfindahl–Hirschman指数(HHI)は0.736で、高度に集中した市場を示すしきい値0.25を大きく上回る。また、サーバー認証は個々の運営者の設定よりもホスティング基盤の選択と強く相関し、商用PaaSでホストされたサーバーの95%が、ゲートウェイ段階でPKCE付きOAuth 2.1を強制していた。 実証結果は、現在の環境におけるセキュリティと観測可能性のトレードオフを示す。多数のサーバーを守る基盤側の認証機構は、同時に自動脆弱性スキャンの能力を制限し、AIゲートウェイ運営者が認証情報を事前に用意せずにツール汚染の経路を評価することを難しくしている。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-16(UTC)
- 最新改訂
- 2026-09-16 · v1
- 査読・掲載
- 査読状況未確認
更新履歴
- v1 2026-09-16 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
The Model Context Protocol (MCP) has emerged as the dominant interface for connecting autonomous agents to external data sources and execution environments. The ecosystem's transition from local process execution to remote Streamable HTTP deployments introduces unmeasured architectural and security constraints at scale. This paper presents a three-tier observability framework comprising catalog metadata (O_0), passive compliance signals (O_1), and live vulnerability analysis (O_2), applied to empirically characterize the public MCP server ecosystem. Evaluation of a stratified sample of 179 remote endpoints across two primary public registries reveals significant infrastructural consolidation. The Herfindahl-Hirschman Index (HHI) computed over the Autonomous System Number (ASN) distribution yields a value of 0.736, well above the 0.25 threshold for a highly concentrated market. Analysis further indicates that server authentication is strongly correlated with hosting platform choice rather than individual operator configuration, with 95\% of commercial PaaS-hosted servers enforcing gateway-level OAuth 2.1 with PKCE. The empirical results identify a Security-Observability Tradeoff observed in the current ecosystem: the platform-level authentication mechanisms that secure the majority of servers simultaneously limit automated vulnerability scanning capabilities, constraining the ability of AI gateway operators to assess tool-poisoning vectors without prior credential provisioning.
著者のコメント
6 pages, 3 figures. Accepted at the 1st IEEE ICNP Workshop on Network Infrastructure and Protocols for AI Agents (NIPA 2026)
arXiv ID: 2609.19100 / 要約の誤りについて