Skip to content
Search
paperAugust 2026UnreviewedOpen access

Design of a Security Framework for Multi-Agent Systems Based on Model Context Protocol in SOC Environments

Rodrigo Tavares de Pina Simões, Xavier Larriva-Novo, Carmen Sánchez-Zas, V. A. Villagrá, Andrés I. Marín López

Applied Sciences

Abstract

Security Operations Centers (SOCs) rely on Level 1 analysts to triage increasing alert volumes amid alert fatigue and tool fragmentation. LLM-based multi-agent systems using the Model Context Protocol (MCP) are being adopted to automate these tasks, but their autonomy and tool access expose them to attacks such as tool poisoning, indirect prompt injection, and confused deputy exploitation. To address this gap, this work proposes a security framework for MCP-based multi-agent SOC pipelines, imple

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@article{simoes2026design,
  title = {{Design of a Security Framework for Multi-Agent Systems Based on Model Context Protocol in SOC Environments}},
  author = {Rodrigo Tavares de Pina Simões and Xavier Larriva-Novo and Carmen Sánchez-Zas and V. A. Villagrá and Andrés I. Marín López},
  year = {2026},
  month = aug,
  journal = {Applied Sciences},
  doi = {10.3390/app16167915},
  url = {https://www.semanticscholar.org/paper/0817f247f0d795c3fd996bdb21e7ab0c3d23f942}
}