Uppsats
Designing and Evaluating a Secure MCP Server for AI-Assisted Troubleshooting
Yrkesexamen på avancerad nivå
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publicerad: 2026
Språk: Engelska
Sammanfattning
The growing complexity of distributed software systems makes troubleshooting increasingly difficult, requiring engineers to manually correlate data across logs, metrics, alarms, and configuration stores. The Model Context Protocol (MCP) has emerged as a standardized way to connect Large Language Models (LLMs) to external tools and data sources, but its application to operational troubleshooting and the security implications of doing so remain largely unexplored in academic research, despite growing adoption in industry. Using a Design Science Research methodology, we elicited requirements, constructed a STRIDE-based threat model, and developed and evaluated a secure MCP server with Agent Skills for AI-assisted troubleshooting in an industrial environment. The threat model identified twelve security threats spanning all six STRIDE categories, with a recurring challenge being the reliance on prompt-based enforcement rather than technical controls for guiding LLM behavior. The artifact combined standardized tool integration through MCP, structured domain knowledge through Skills, and security controls informed by the threat model. Five industrial practitioners evaluated the artifact through scenario-based sessions followed by semi-structured interviews, with screen recordings reviewed for behavioral observations and interview transcripts analyzed using thematic analysis.All five participants evaluated the artifact positively, identifying cross-source correlation as the most valuable capability. Practitioners adopted a "trust but verify" approach, and their security perceptions were shaped by two distinctions: between internal test systems and live customer environments, and between read and write operations. We conclude that MCP-based AI-assisted troubleshooting is technically feasible and positively perceived by practitioners.However, the flexibility that makes LLM-based tools useful also makes them difficult to secure and control.Adoption beyond internal test systems will require addressing the trust and security concerns identified in this study.
Information
- Författare
- Gustafsson, William, Hedin, Christoffer
- Lärosäte / institution
- Blekinge Tekniska Högskola/Institutionen för programvaruteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- Yrkesexamen på avancerad nivå
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Kandidat-uppsats, KTH/Hälsoinformatik och logistik
Tadesse, Bemnet
Publicerad: 2026
Kandidat-uppsats, Karlstads universitet/Institutionen för matematik och datavetenskap (from 2013)
Rodrigo Verdu, Juan
Publicerad: 2026
Magister-uppsats, Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Mantzouranidis, Savvas
Publicerad: 2026
Kandidat-uppsats, KTH/Hälsoinformatik och logistik
Abdulnoor, Tia, Bygde, Thea
Publicerad: 2026
Kandidat-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Norberg, Rasmus
Publicerad: 2026
Kandidat-uppsats, KTH/Hälsoinformatik och logistik
Westermark Karlsson, Edvin, Alzin, Osama
Publicerad: 2026