Uppsats

Designing and Evaluating a Secure MCP Server for AI-Assisted Troubleshooting

Yrkesexamen på avancerad nivå

Blekinge Tekniska Högskola/Institutionen för programvaruteknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

The growing complexity of distributed software systems makes troubleshooting increasingly difficult, requiring engineers to manually correlate data across logs, metrics, alarms, and configuration stores. The Model Context Protocol (MCP) has emerged as a standardized way to connect Large Language Models (LLMs) to external tools and data sources, but its application to operational troubleshooting and the security implications of doing so remain largely unexplored in academic research, despite growing adoption in industry. Using a Design Science Research methodology, we elicited requirements, constructed a STRIDE-based threat model, and developed and evaluated a secure MCP server with Agent Skills for AI-assisted troubleshooting in an industrial environment. The threat model identified twelve security threats spanning all six STRIDE categories, with a recurring challenge being the reliance on prompt-based enforcement rather than technical controls for guiding LLM behavior. The artifact combined standardized tool integration through MCP, structured domain knowledge through Skills, and security controls informed by the threat model. Five industrial practitioners evaluated the artifact through scenario-based sessions followed by semi-structured interviews, with screen recordings reviewed for behavioral observations and interview transcripts analyzed using thematic analysis.All five participants evaluated the artifact positively, identifying cross-source correlation as the most valuable capability. Practitioners adopted a "trust but verify" approach, and their security perceptions were shaped by two distinctions: between internal test systems and live customer environments, and between read and write operations. We conclude that MCP-based AI-assisted troubleshooting is technically feasible and positively perceived by practitioners.However, the flexibility that makes LLM-based tools useful also makes them difficult to secure and control.Adoption beyond internal test systems will require addressing the trust and security concerns identified in this study.

Information

Lärosäte / institution
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publiceringsdatum
2026
Uppsatstyp
Yrkesexamen på avancerad nivå
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.