Security

Module
Security
Progress
100%

MCP Security: Comprehensive Protection for AI Systems

Security is fundamental to AI system design, which is why we prioritize it as our second section.

This aligns with Microsoft's Secure by Design principle from the Secure Future Initiative.

The Model Context Protocol (MCP) brings powerful new capabilities to AI-driven applications while introducing unique security challenges that extend beyond traditional software risks.

MCP systems face both established security concerns (secure coding, least privilege, supply chain security) and new AI-specific threats including prompt injection, tool poisoning, session hijacking, confused deputy attacks, token passthrough vulnerabilities, and dynamic capability modification.

This lesson explores the most critical security risks in MCP implementationsโ€”covering authentication, authorization, excessive permissions, indirect prompt injection, session security, confused deputy problems, token management, and supply chain vulnerabilities.

You'll learn actionable controls and best practices to mitigate these risks while leveraging Microsoft solutions like Prompt Shields, Azure Content Safety, and GitHub Advanced Security to strengthen your MCP deployment.

Learning Objectives

By the end of this lesson, you will be able to:

  • Identify MCP-Specific Threats: Recognize unique security risks in MCP systems including prompt injection, tool poisoning, excessive permissions, session hijacking, confused deputy problems, token passthrough vulnerabilities, and supply chain risks
  • Apply Security Controls: Implement effective mitigations including robust authentication, least privilege access, secure token management, session security controls, and supply chain verification
  • Leverage Microsoft Security Solutions: Understand and deploy Microsoft Prompt Shields, Azure Content Safety, and GitHub Advanced Security for MCP workload protection
  • Validate Tool Security: Recognize the importance of tool metadata validation, monitoring for dynamic changes, and defending against indirect prompt injection attacks
  • Integrate Best Practices: Combine established security fundamentals (secure coding, server hardening, zero trust) with MCP-specific controls for comprehensive protection
  • MCP Security Architecture & Controls

    Modern MCP implementations require layered security approaches that address both traditional software security and AI-specific threats.

    The rapidly evolving MCP specification continues to mature its security controls, enabling better integration with enterprise security architectures and established best practices.

    Research from the Microsoft Digital Defense Report demonstrates that 98% of reported breaches would be prevented by robust security hygiene.

    The most effective protection strategy combines foundational security practices with MCP-specific controlsโ€”proven baseline security measures remain the most impactful in reducing overall security risk.

    Current Security Landscape

    > Note: This information reflects MCP security standards as of February 5, 2026, aligned with MCP Specification 2025-11-25.

    The MCP protocol continues evolving rapidly, and future implementations may introduce new authentication patterns and enhanced controls.

    Always refer to the current MCP Specification, MCP GitHub repository, and security best practices documentation for the latest guidance.

    ๐Ÿ”๏ธ MCP Security Summit Workshop (Sherpa)

    For hands-on security training, we highly recommend the MCP Security Summit Workshop (Sherpa) - a comprehensive guided expedition to securing MCP servers in Microsoft Azure.

    Workshop Overview

    The MCP Security Summit Workshop provides practical, actionable security training through a proven "vulnerable โ†’ exploit โ†’ fix โ†’ validate" methodology.

    You'll:

  • Learn by Breaking Things: Experience vulnerabilities firsthand by exploiting intentionally insecure servers
  • Use Azure-Native Security: Leverage Azure Entra ID, Key Vault, API Management, and AI Content Safety
  • Follow Defense-in-Depth: Progress through camps building comprehensive security layers
  • Apply OWASP Standards: Every technique maps to the OWASP MCP Azure Security Guide
  • Get Production Code: Walk away with working, tested implementations
  • The Expedition Route

    | Camp | Focus | OWASP Risks Covered |

    |------|-------|---------------------|

    | Base Camp | MCP fundamentals & authentication vulnerabilities | MCP01, MCP07 |

    | Camp 1: Identity | OAuth 2.1, Azure Managed Identity, Key Vault | MCP01, MCP02, MCP07 |

    | Camp 2: Gateway | API Management, Private Endpoints, governance | MCP02, MCP06, MCP07, MCP09 |

    | Camp 3: I/O Security | Prompt injection, PII protection, content safety | MCP03, MCP05, MCP06, MCP10 |

    | Camp 4: Monitoring | Log Analytics, dashboards, threat detection | MCP04, MCP08 |

    | The Summit | Red Team / Blue Team integration test | All |

    Get Started: https://azure-samples.github.io/sherpa/

    OWASP MCP Top 10 Security Risks

    The OWASP MCP Azure Security Guide details the ten most critical security risks for MCP implementations:

    | Risk | Description | Azure Mitigation |

    |------|-------------|------------------|

    | MCP01 | Token Mismanagement & Secret Exposure | Azure Key Vault, Managed Identity |

    | MCP02 | Privilege Escalation via Scope Creep | RBAC, Conditional Access |

    | MCP03 | Tool Poisoning | Tool validation, integrity verification |

    | MCP04 | Software Supply Chain Attacks & Dependency Tampering | GitHub Advanced Security, dependency scanning |

    | MCP05 | Command Injection & Execution | Input validation, sandboxing |

    | MCP06 | Intent Flow Subversion | Azure AI Content Safety, Prompt Shields |

    | MCP07 | Insufficient Authentication & Authorization | Azure Entra ID, OAuth 2.1 with PKCE |

    | MCP08 | Lack of Audit and Telemetry | Azure Monitor, Application Insights |

    | MCP09 | Shadow MCP Servers | API Center governance, network isolation |

    | MCP10 | Context Injection & Over-Sharing | Data classification, minimal exposure |

    Evolution of MCP Authentication

    The MCP specification has evolved significantly in its approach to authentication and authorization:

  • Original Approach: Early specifications required developers to implement custom authentication servers, with MCP servers acting as OAuth 2.0 Authorization Servers managing user authentication directly
  • Current Standard (2025-11-25): Updated specification allows MCP servers to delegate authentication to external identity providers (such as Microsoft Entra ID), improving security posture and reducing implementation complexity
  • Transport Layer Security: Enhanced support for secure transport mechanisms with proper authentication patterns for both local (STDIO) and remote (Streamable HTTP) connections
  • Authentication & Authorization Security

    Current Security Challenges

    Modern MCP implementations face several authentication and authorization challenges:

    Risks & Threat Vectors

  • Misconfigured Authorization Logic: Flawed authorization implementation in MCP servers can expose sensitive data and incorrectly apply access controls
  • OAuth Token Compromise: Local MCP server token theft enables attackers to impersonate servers and access downstream services
  • Token Passthrough Vulnerabilities: Improper token handling creates security control bypasses and accountability gaps
  • Excessive Permissions: Over-privileged MCP servers violate least privilege principles and expand attack surfaces
  • Token Passthrough: A Critical Anti-Pattern

    Token passthrough is explicitly prohibited in the current MCP authorization specification due to severe security implications:

    ##### Security Control Circumvention

  • MCP servers and downstream APIs implement critical security controls (rate limiting, request validation, traffic monitoring) that depend on proper token validation
  • Direct client-to-API token usage bypasses these essential protections, undermining the security architecture
  • ##### Accountability & Audit Challenges

  • MCP servers cannot distinguish between clients using upstream-issued tokens, breaking audit trails
  • Downstream resource server logs show misleading request origins rather than actual MCP server intermediaries
  • Incident investigation and compliance auditing become significantly more difficult
  • ##### Data Exfiltration Risks

  • Unvalidated token claims enable malicious actors with stolen tokens to use MCP servers as proxies for data exfiltration
  • Trust boundary violations allow unauthorized access patterns that bypass intended security controls
  • ##### Multi-Service Attack Vectors

  • Compromised tokens accepted by multiple services enable lateral movement across connected systems
  • Trust assumptions between services may be violated when token origins cannot be verified
  • Security Controls & Mitigations

    Critical Security Requirements:

    > MANDATORY: MCP servers MUST NOT accept any tokens that were not explicitly issued for the MCP server

    Authentication & Authorization Controls
  • Rigorous Authorization Review: Conduct comprehensive audits of MCP server authorization logic to ensure only intended users and clients can access sensitive resources
  • - Implementation Guide: Azure API Management as Authentication Gateway for MCP Servers

    - Identity Integration: Using Microsoft Entra ID for MCP Server Authentication

  • Secure Token Management: Implement Microsoft's token validation and lifecycle best practices
  • - Validate token audience claims match MCP server identity

    - Implement proper token rotation and expiration policies

    - Prevent token replay attacks and unauthorized usage

  • Protected Token Storage: Secure token storage with encryption both at rest and in transit
  • - Best Practices: Secure Token Storage and Encryption Guidelines

    Access Control Implementation
  • Principle of Least Privilege: Grant MCP servers only minimum permissions required for intended functionality
  • - Regular permission reviews and updates to prevent privilege creep

    - Microsoft Documentation: Secure Least-Privileged Access

  • Role-Based Access Control (RBAC): Implement fine-grained role assignments
  • - Scope roles tightly to specific resources and actions

    - Avoid broad or unnecessary permissions that expand attack surfaces

  • Continuous Permission Monitoring: Implement ongoing access auditing and monitoring
  • - Monitor permission usage patterns for anomalies

    - Promptly remediate excessive or unused privileges

    AI-Specific Security Threats

    Prompt Injection & Tool Manipulation Attacks

    Modern MCP implementations face sophisticated AI-specific attack vectors that traditional security measures cannot fully address:

    Indirect Prompt Injection (Cross-Domain Prompt Injection)

    Indirect Prompt Injection represents one of the most critical vulnerabilities in MCP-enabled AI systems.

    Attackers embed malicious instructions within external contentโ€”documents, web pages, emails, or data sourcesโ€”that AI systems subsequently process as legitimate commands.

    Attack Scenarios:

  • Document-based Injection: Malicious instructions hidden in processed documents that trigger unintended AI actions
  • Web Content Exploitation: Compromised web pages containing embedded prompts that manipulate AI behavior when scraped
  • Email-based Attacks: Malicious prompts in emails that cause AI assistants to leak information or perform unauthorized actions
  • Data Source Contamination: Compromised databases or APIs serving tainted content to AI systems
  • Real-World Impact: These attacks can result in data exfiltration, privacy breaches, generation of harmful content, and manipulation of user interactions.

    For detailed analysis, see Prompt Injection in MCP (Simon Willison).

    Tool Poisoning Attacks

    Tool Poisoning targets the metadata that defines MCP tools, exploiting how LLMs interpret tool descriptions and parameters to make execution decisions.

    Attack Mechanisms:

  • Metadata Manipulation: Attackers inject malicious instructions into tool descriptions, parameter definitions, or usage examples
  • Invisible Instructions: Hidden prompts in tool metadata that are processed by AI models but invisible to human users
  • Dynamic Tool Modification ("Rug Pulls"): Tools approved by users are later modified to perform malicious actions without user awareness
  • Parameter Injection: Malicious content embedded in tool parameter schemas that influence model behavior
  • Hosted Server Risks: Remote MCP servers present elevated risks as tool definitions can be updated after initial user approval, creating scenarios where previously safe tools become malicious.

    For comprehensive analysis, see Tool Poisoning Attacks (Invariant Labs).

    Additional AI Attack Vectors
  • Cross-Domain Prompt Injection (XPIA): Sophisticated attacks that leverage content from multiple domains to bypass security controls
  • Dynamic Capability Modification: Real-time changes to tool capabilities that escape initial security assessments
  • Context Window Poisoning: Attacks that manipulate large context windows to hide malicious instructions
  • Model Confusion Attacks: Exploiting model limitations to create unpredictable or unsafe behaviors
  • AI Security Risk Impact

    High-Impact Consequences:

  • Data Exfiltration: Unauthorized access and theft of sensitive enterprise or personal data
  • Privacy Breaches: Exposure of personally identifiable information (PII) and confidential business data
  • System Manipulation: Unintended modifications to critical systems and workflows
  • Credential Theft: Compromise of authentication tokens and service credentials
  • Lateral Movement: Use of compromised AI systems as pivots for broader network attacks
  • Microsoft AI Security Solutions

    AI Prompt Shields: Advanced Protection Against Injection Attacks

    Microsoft AI Prompt Shields provide comprehensive defense against both direct and indirect prompt injection attacks through multiple security layers:

    ##### Core Protection Mechanisms:

    1. Advanced Detection & Filtering

    - Machine learning algorithms and NLP techniques detect malicious instructions in external content

    - Real-time analysis of documents, web pages, emails, and data sources for embedded threats

    - Contextual understanding of legitimate vs. malicious prompt patterns

    2. Spotlighting Techniques

    - Distinguishes between trusted system instructions and potentially compromised external inputs

    - Text transformation methods that enhance model relevance while isolating malicious content

    - Helps AI systems maintain proper instruction hierarchy and ignore injected commands

    3. Delimiter & Datamarking Systems

    - Explicit boundary definition between trusted system messages and external input text

    - Special markers highlight boundaries between trusted and untrusted data sources

    - Clear separation prevents instruction confusion and unauthorized command execution

    4. Continuous Threat Intelligence

    - Microsoft continuously monitors emerging attack patterns and updates defenses

    - Proactive threat hunting for new injection techniques and attack vectors

    - Regular security model updates to maintain effectiveness against evolving threats

    5. Azure Content Safety Integration

    - Part of comprehensive Azure AI Content Safety suite

    - Additional detection for jailbreak attempts, harmful content, and security policy violations

    - Unified security controls across AI application components

    Implementation Resources: Microsoft Prompt Shields Documentation

    Advanced MCP Security Threats

    Session Hijacking Vulnerabilities

    Session hijacking represents a critical attack vector in stateful MCP implementations where unauthorized parties obtain and abuse legitimate session identifiers to impersonate clients and perform unauthorized actions.

    Attack Scenarios & Risks
  • Session Hijack Prompt Injection: Attackers with stolen session IDs inject malicious events into servers sharing session state, potentially triggering harmful actions or accessing sensitive data
  • Direct Impersonation: Stolen session IDs enable direct MCP server calls that bypass authentication, treating attackers as legitimate users
  • Compromised Resumable Streams: Attackers can terminate requests prematurely, causing legitimate clients to resume with potentially malicious content
  • Security Controls for Session Management

    Critical Requirements:

  • Authorization Verification: MCP servers implementing authorization MUST verify ALL inbound requests and MUST NOT rely on sessions for authentication
  • Secure Session Generation: Use cryptographically secure, non-deterministic session IDs generated with secure random number generators
  • User-Specific Binding: Bind session IDs to user-specific information using formats like : to prevent cross-user session abuse
  • Session Lifecycle Management: Implement proper expiration, rotation, and invalidation to limit vulnerability windows
  • Transport Security: Mandatory HTTPS for all communication to prevent session ID interception
  • Confused Deputy Problem

    The confused deputy problem occurs when MCP servers act as authentication proxies between clients and third-party services, creating opportunities for authorization bypass through static client ID exploitation.

    Attack Mechanics & Risks
  • Cookie-based Consent Bypass: Previous user authentication creates consent cookies that attackers exploit through malicious authorization requests with crafted redirect URIs
  • Authorization Code Theft: Existing consent cookies may cause authorization servers to skip consent screens, redirecting codes to attacker-controlled endpoints
  • Unauthorized API Access: Stolen authorization codes enable token exchange and user impersonation without explicit approval
  • Mitigation Strategies

    Mandatory Controls:

  • Explicit Consent Requirements: MCP proxy servers using static client IDs MUST obtain user consent for each dynamically registered client
  • OAuth 2.1 Security Implementation: Follow current OAuth security best practices including PKCE (Proof Key for Code Exchange) for all authorization requests
  • Strict Client Validation: Implement rigorous validation of redirect URIs and client identifiers to prevent exploitation
  • Token Passthrough Vulnerabilities

    Token passthrough represents an explicit anti-pattern where MCP servers accept client tokens without proper validation and forward them to downstream APIs, violating MCP authorization specifications.

    Security Implications
  • Control Circumvention: Direct client-to-API token usage bypasses critical rate limiting, validation, and monitoring controls
  • Audit Trail Corruption: Upstream-issued tokens make client identification impossible, breaking incident investigation capabilities
  • Proxy-based Data Exfiltration: Unvalidated tokens enable malicious actors to use servers as proxies for unauthorized data access
  • Trust Boundary Violations: Downstream services' trust assumptions may be violated when token origins cannot be verified
  • Multi-service Attack Expansion: Compromised tokens accepted across multiple services enable lateral movement
  • Required Security Controls

    Non-negotiable Requirements:

  • Token Validation: MCP servers MUST NOT accept tokens not explicitly issued for the MCP server
  • Audience Verification: Always validate token audience claims match the MCP server's identity
  • Proper Token Lifecycle: Implement short-lived access tokens with secure rotation practices
  • Supply Chain Security for AI Systems

    Supply chain security has evolved beyond traditional software dependencies to encompass the entire AI ecosystem.

    Modern MCP implementations must rigorously verify and monitor all AI-related components, as each introduces potential vulnerabilities that could compromise system integrity.

    Expanded AI Supply Chain Components

    Traditional Software Dependencies:

  • Open-source libraries and frameworks
  • Container images and base systems
  • Development tools and build pipelines
  • Infrastructure components and services
  • AI-Specific Supply Chain Elements:

  • Foundation Models: Pre-trained models from various providers requiring provenance verification
  • Embedding Services: External vectorization and semantic search services
  • Context Providers: Data sources, knowledge bases, and document repositories
  • Third-party APIs: External AI services, ML pipelines, and data processing endpoints
  • Model Artifacts: Weights, configurations, and fine-tuned model variants
  • Training Data Sources: Datasets used for model training and fine-tuning
  • Comprehensive Supply Chain Security Strategy

    Component Verification & Trust
  • Provenance Validation: Verify the origin, licensing, and integrity of all AI components before integration
  • Security Assessment: Conduct vulnerability scans and security reviews for models, data sources, and AI services
  • Reputation Analysis: Evaluate the security track record and practices of AI service providers
  • Compliance Verification: Ensure all components meet organizational security and regulatory requirements
  • Secure Deployment Pipelines
  • Automated CI/CD Security: Integrate security scanning throughout automated deployment pipelines
  • Artifact Integrity: Implement cryptographic verification for all deployed artifacts (code, models, configurations)
  • Staged Deployment: Use progressive deployment strategies with security validation at each stage
  • Trusted Artifact Repositories: Deploy only from verified, secure artifact registries and repositories
  • Continuous Monitoring & Response
  • Dependency Scanning: Ongoing vulnerability monitoring for all software and AI component dependencies
  • Model Monitoring: Continuous assessment of model behavior, performance drift, and security anomalies
  • Service Health Tracking: Monitor external AI services for availability, security incidents, and policy changes
  • Threat Intelligence Integration: Incorporate threat feeds specific to AI and ML security risks
  • Access Control & Least Privilege
  • Component-level Permissions: Restrict access to models, data, and services based on business necessity
  • Service Account Management: Implement dedicated service accounts with minimal required permissions
  • Network Segmentation: Isolate AI components and limit network access between services
  • API Gateway Controls: Use centralized API gateways to control and monitor access to external AI services
  • Incident Response & Recovery
  • Rapid Response Procedures: Established processes for patching or replacing compromised AI components
  • Credential Rotation: Automated systems for rotating secrets, API keys, and service credentials
  • Rollback Capabilities: Ability to quickly revert to previous known-good versions of AI components
  • Supply Chain Breach Recovery: Specific procedures for responding to upstream AI service compromises
  • Microsoft Security Tools & Integration

    GitHub Advanced Security provides comprehensive supply chain protection including:

  • Secret Scanning: Automated detection of credentials, API keys, and tokens in repositories
  • Dependency Scanning: Vulnerability assessment for open-source dependencies and libraries
  • CodeQL Analysis: Static code analysis for security vulnerabilities and coding issues
  • Supply Chain Insights: Visibility into dependency health and security status
  • Azure DevOps & Azure Repos Integration:

  • Seamless security scanning integration across Microsoft development platforms
  • Automated security checks in Azure Pipelines for AI workloads
  • Policy enforcement for secure AI component deployment
  • Microsoft Internal Practices:

    Microsoft implements extensive supply chain security practices across all products.

    Learn about proven approaches in The Journey to Secure the Software Supply Chain at Microsoft.

    Foundation Security Best Practices

    MCP implementations inherit and build upon your organization's existing security posture. Strengthening foundational security practices significantly enhances the overall security of AI systems and MCP deployments.

    Core Security Fundamentals

    Secure Development Practices
  • OWASP Compliance: Protect against OWASP Top 10 web application vulnerabilities
  • AI-Specific Protections: Implement controls for OWASP Top 10 for LLMs
  • Secure Secrets Management: Use dedicated vaults for tokens, API keys, and sensitive configuration data
  • End-to-End Encryption: Implement secure communications across all application components and data flows
  • Input Validation: Rigorous validation of all user inputs, API parameters, and data sources
  • Infrastructure Hardening
  • Multi-Factor Authentication: Mandatory MFA for all administrative and service accounts
  • Patch Management: Automated, timely patching for operating systems, frameworks, and dependencies
  • Identity Provider Integration: Centralized identity management through enterprise identity providers (Microsoft Entra ID, Active Directory)
  • Network Segmentation: Logical isolation of MCP components to limit lateral movement potential
  • Principle of Least Privilege: Minimal required permissions for all system components and accounts
  • Security Monitoring & Detection
  • Comprehensive Logging: Detailed logging of AI application activities, including MCP client-server interactions
  • SIEM Integration: Centralized security information and event management for anomaly detection
  • Behavioral Analytics: AI-powered monitoring to detect unusual patterns in system and user behavior
  • Threat Intelligence: Integration of external threat feeds and indicators of compromise (IOCs)
  • Incident Response: Well-defined procedures for security incident detection, response, and recovery
  • Zero Trust Architecture
  • Never Trust, Always Verify: Continuous verification of users, devices, and network connections
  • Micro-Segmentation: Granular network controls that isolate individual workloads and services
  • Identity-Centric Security: Security policies based on verified identities rather than network location
  • Continuous Risk Assessment: Dynamic security posture evaluation based on current context and behavior
  • Conditional Access: Access controls that adapt based on risk factors, location, and device trust
  • Enterprise Integration Patterns

    Microsoft Security Ecosystem Integration
  • Microsoft Defender for Cloud: Comprehensive cloud security posture management
  • Azure Sentinel: Cloud-native SIEM and SOAR capabilities for AI workload protection
  • Microsoft Entra ID: Enterprise identity and access management with conditional access policies
  • Azure Key Vault: Centralized secrets management with hardware security module (HSM) backing
  • Microsoft Purview: Data governance and compliance for AI data sources and workflows
  • Compliance & Governance
  • Regulatory Alignment: Ensure MCP implementations meet industry-specific compliance requirements (GDPR, HIPAA, SOC 2)
  • Data Classification: Proper categorization and handling of sensitive data processed by AI systems
  • Audit Trails: Comprehensive logging for regulatory compliance and forensic investigation
  • Privacy Controls: Implementation of privacy-by-design principles in AI system architecture
  • Change Management: Formal processes for security reviews of AI system modifications
  • These foundational practices create a robust security baseline that enhances the effectiveness of MCP-specific security controls and provides comprehensive protection for AI-driven applications.

    Key Security Takeaways

  • Layered Security Approach: Combine foundational security practices (secure coding, least privilege, supply chain verification, continuous monitoring) with AI-specific controls for comprehensive protection
  • AI-Specific Threat Landscape: MCP systems face unique risks including prompt injection, tool poisoning, session hijacking, confused deputy problems, token passthrough vulnerabilities, and excessive permissions that require specialized mitigations
  • Authentication & Authorization Excellence: Implement robust authentication using external identity providers (Microsoft Entra ID), enforce proper token validation, and never accept tokens not explicitly issued for your MCP server
  • AI Attack Prevention: Deploy Microsoft Prompt Shields and Azure Content Safety to defend against indirect prompt injection and tool poisoning attacks, while validating tool metadata and monitoring for dynamic changes
  • Session & Transport Security: Use cryptographically secure, non-deterministic session IDs bound to user identities, implement proper session lifecycle management, and never use sessions for authentication
  • OAuth Security Best Practices: Prevent confused deputy attacks through explicit user consent for dynamically registered clients, proper OAuth 2.1 implementation with PKCE, and strict redirect URI validation
  • Token Security Principles: Avoid token passthrough anti-patterns, validate token audience claims, implement short-lived tokens with secure rotation, and maintain clear trust boundaries
  • Comprehensive Supply Chain Security: Treat all AI ecosystem components (models, embeddings, context providers, external APIs) with the same security rigor as traditional software dependencies
  • Continuous Evolution: Stay current with rapidly evolving MCP specifications, contribute to security community standards, and maintain adaptive security postures as the protocol matures
  • Microsoft Security Integration: Leverage Microsoft's comprehensive security ecosystem (Prompt Shields, Azure Content Safety, GitHub Advanced Security, Entra ID) for enhanced MCP deployment protection
  • Comprehensive Resources

    Official MCP Security Documentation

  • MCP Specification (Current: 2025-11-25)
  • MCP Security Best Practices
  • MCP Authorization Specification
  • MCP GitHub Repository
  • OWASP MCP Security Resources

  • OWASP MCP Azure Security Guide - Comprehensive OWASP MCP Top 10 with Azure implementation guidance
  • OWASP MCP Top 10 - Official OWASP MCP security risks
  • MCP Security Summit Workshop (Sherpa) - Hands-on security training for MCP on Azure
  • Security Standards & Best Practices

  • OAuth 2.0 Security Best Practices (RFC 9700)
  • OWASP Top 10 Web Application Security
  • OWASP Top 10 for Large Language Models
  • Microsoft Digital Defense Report
  • AI Security Research & Analysis

  • Prompt Injection in MCP (Simon Willison)
  • Tool Poisoning Attacks (Invariant Labs)
  • MCP Security Research Briefing (Wiz Security)
  • Microsoft Security Solutions

  • Microsoft Prompt Shields Documentation
  • Azure Content Safety Service
  • Microsoft Entra ID Security
  • Azure Token Management Best Practices
  • GitHub Advanced Security
  • Implementation Guides & Tutorials

  • Azure API Management as MCP Authentication Gateway
  • Microsoft Entra ID Authentication with MCP Servers
  • Secure Token Storage and Encryption (Video)
  • DevOps & Supply Chain Security

  • Azure DevOps Security
  • Azure Repos Security
  • Microsoft Supply Chain Security Journey
  • Additional Security Documentation

    For comprehensive security guidance, refer to these specialized documents in this section:

  • MCP Security Best Practices 2025 - Complete security best practices for MCP implementations
  • Azure Content Safety Implementation - Practical implementation examples for Azure Content Safety integration
  • MCP Security Controls 2025 - Latest security controls and techniques for MCP deployments
  • MCP Best Practices Quick Reference - Quick reference guide for essential MCP security practices
  • BlueHat 2026: Securing the future of AI: Securing MCP with defense in depth patterns - Defense-in-depth patterns from the Microsoft Security Response Center (MSRC)
  • Hands-On Security Training

  • MCP Security Summit Workshop (Sherpa) - Comprehensive hands-on workshop for securing MCP servers in Azure with progressive camps from Base Camp to Summit
  • OWASP MCP Azure Security Guide - Reference architecture and implementation guidance for all OWASP MCP Top 10 risks
  • ---

    What's Next

    Next: Chapter 3: Getting Started

    MCP ๋ณด์•ˆ: AI ์‹œ์Šคํ…œ์„ ์œ„ํ•œ ์ข…ํ•ฉ ๋ณดํ˜ธ

    _(์œ„ ์ด๋ฏธ์ง€๋ฅผ ํด๋ฆญํ•˜๋ฉด ์ด ์ˆ˜์—…์˜ ๋™์˜์ƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค)_

    ๋ณด์•ˆ์€ AI ์‹œ์Šคํ…œ ์„ค๊ณ„์˜ ๊ธฐ๋ณธ์ด๋ฏ€๋กœ ๋‘ ๋ฒˆ์งธ ์„น์…˜์œผ๋กœ ์šฐ์„ ์ˆœ์œ„๋ฅผ ๋‘ก๋‹ˆ๋‹ค.

    ์ด๋Š” Microsoft์˜ Secure Future Initiative์— ๋ช…์‹œ๋œ Secure by Design ์›์น™๊ณผ ์ผ์น˜ํ•ฉ๋‹ˆ๋‹ค.

    ๋ชจ๋ธ ์ปจํ…์ŠคํŠธ ํ”„๋กœํ† ์ฝœ(MCP)์€ AI ๊ธฐ๋ฐ˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๊ฐ•๋ ฅํ•œ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๋Š” ๋™์‹œ์— ์ „ํ†ต์ ์ธ ์†Œํ”„ํŠธ์›จ์–ด ์œ„ํ—˜์„ ๋„˜์–ด์„  ๋…ํŠนํ•œ ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ์ œ๊ธฐํ•ฉ๋‹ˆ๋‹ค. MCP ์‹œ์Šคํ…œ์€ ๊ฒ€์ฆ๋œ ๋ณด์•ˆ ๋ฌธ์ œ(์•ˆ์ „ํ•œ ์ฝ”๋”ฉ, ์ตœ์†Œ ๊ถŒํ•œ, ๊ณต๊ธ‰๋ง ๋ณด์•ˆ)๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…, ๋„๊ตฌ ์˜ค์—ผ, ์„ธ์…˜ ํƒˆ์ทจ, ํ˜ผ๋™๋œ ๋Œ€๋ฆฌ์ธ ๊ณต๊ฒฉ, ํ† ํฐ ์ „๋‹ฌ ์ทจ์•ฝ์„ฑ, ๋™์  ๊ถŒํ•œ ์ˆ˜์ • ๊ฐ™์€ AI ํŠน์œ  ์œ„ํ˜‘์—๋„ ์ง๋ฉดํ•ฉ๋‹ˆ๋‹ค.

    ์ด ์ˆ˜์—…์—์„œ๋Š” MCP ๊ตฌํ˜„์—์„œ ๊ฐ€์žฅ ์ค‘์š”ํ•œ ๋ณด์•ˆ ์œ„ํ—˜๋“ค์„ ํƒ๊ตฌํ•ฉ๋‹ˆ๋‹คโ€”์ธ์ฆ, ๊ถŒํ•œ ๋ถ€์—ฌ, ๊ณผ๋„ํ•œ ๊ถŒํ•œ, ๊ฐ„์ ‘ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…, ์„ธ์…˜ ๋ณด์•ˆ, ํ˜ผ๋™๋œ ๋Œ€๋ฆฌ์ธ ๋ฌธ์ œ, ํ† ํฐ ๊ด€๋ฆฌ, ๊ณต๊ธ‰๋ง ์ทจ์•ฝ์„ฑ์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค. ๋˜ํ•œ Microsoft์˜ Prompt Shields, Azure Content Safety, GitHub Advanced Security์™€ ๊ฐ™์€ ์†”๋ฃจ์…˜์„ ํ™œ์šฉํ•˜์—ฌ MCP ๋ฐฐํฌ๋ฅผ ๊ฐ•ํ™”ํ•˜๋Š” ์‹คํ–‰ ๊ฐ€๋Šฅํ•œ ์ œ์–ด ๋ฐ ๋ชจ๋ฒ” ์‚ฌ๋ก€๋ฅผ ๋ฐฐ์›๋‹ˆ๋‹ค.

    ํ•™์Šต ๋ชฉํ‘œ

    ์ด ์ˆ˜์—…์„ ๋งˆ์น˜๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • MCP ํŠน์œ  ์œ„ํ˜‘ ์‹๋ณ„: ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…, ๋„๊ตฌ ์˜ค์—ผ, ๊ณผ๋„ํ•œ ๊ถŒํ•œ, ์„ธ์…˜ ํƒˆ์ทจ, ํ˜ผ๋™๋œ ๋Œ€๋ฆฌ์ธ ๋ฌธ์ œ, ํ† ํฐ ์ „๋‹ฌ ์ทจ์•ฝ์„ฑ, ๊ณต๊ธ‰๋ง ์œ„ํ—˜ ๋“ฑ MCP ์‹œ์Šคํ…œ ๊ณ ์œ  ๋ณด์•ˆ ์œ„ํ—˜์„ ์ธ์‹
  • ๋ณด์•ˆ ์ œ์–ด ์ ์šฉ: ๊ฐ•๋ ฅํ•œ ์ธ์ฆ, ์ตœ์†Œ ๊ถŒํ•œ ์ ‘๊ทผ, ์•ˆ์ „ํ•œ ํ† ํฐ ๊ด€๋ฆฌ, ์„ธ์…˜ ๋ณด์•ˆ ์ œ์–ด, ๊ณต๊ธ‰๋ง ๊ฒ€์ฆ ๋“ฑ ํšจ๊ณผ์ ์ธ ์™„ํ™”์ฑ… ๊ตฌํ˜„
  • Microsoft ๋ณด์•ˆ ์†”๋ฃจ์…˜ ํ™œ์šฉ: MCP ์ž‘์—… ๋ถ€ํ•˜ ๋ณดํ˜ธ๋ฅผ ์œ„ํ•œ Microsoft Prompt Shields, Azure Content Safety, GitHub Advanced Security ์ดํ•ด ๋ฐ ๋ฐฐํฌ
  • ๋„๊ตฌ ๋ณด์•ˆ ๊ฒ€์ฆ: ๋„๊ตฌ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ๊ฒ€์ฆ ์ค‘์š”์„ฑ ์ธ์‹, ๋™์  ๋ณ€๊ฒฝ ๋ชจ๋‹ˆํ„ฐ๋ง, ๊ฐ„์ ‘ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž… ๊ณต๊ฒฉ ๋ฐฉ์–ด
  • ๋ชจ๋ฒ” ์‚ฌ๋ก€ ํ†ตํ•ฉ: ๊ฒ€์ฆ๋œ ๋ณด์•ˆ ๊ธฐ๋ณธ ์›์น™(์•ˆ์ „ํ•œ ์ฝ”๋”ฉ, ์„œ๋ฒ„ ๊ฐ•ํ™”, ์ œ๋กœ ํŠธ๋Ÿฌ์ŠคํŠธ)๊ณผ MCP ํŠนํ™” ์ œ์–ด๋ฅผ ๊ฒฐํ•ฉํ•œ ์ข…ํ•ฉ ๋ณดํ˜ธ ๊ตฌํ˜„
  • MCP ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜ ๋ฐ ์ œ์–ด

    ์ตœ์‹  MCP ๊ตฌํ˜„์€ ์ „ํ†ต์ ์ธ ์†Œํ”„ํŠธ์›จ์–ด ๋ณด์•ˆ๊ณผ AI ํŠนํ™” ์œ„ํ˜‘์„ ๋ชจ๋‘ ํ•ด๊ฒฐํ•˜๋Š” ๋‹ค์ธต ๋ณด์•ˆ ์ ‘๊ทผ๋ฒ•์„ ํ•„์š”๋กœ ํ•ฉ๋‹ˆ๋‹ค. ๋น ๋ฅด๊ฒŒ ์ง„ํ™”ํ•˜๋Š” MCP ๋ช…์„ธ๋Š” ๋ณด์•ˆ ์ œ์–ด๋ฅผ ์ง€์†์ ์œผ๋กœ ์„ฑ์ˆ™์‹œ์ผœ ๊ธฐ์—… ๋ณด์•ˆ ์•„ํ‚คํ…์ฒ˜์™€ ๊ฒ€์ฆ๋œ ๋ชจ๋ฒ” ์‚ฌ๋ก€์™€์˜ ํ†ตํ•ฉ์„ ๊ฐœ์„ ํ•ฉ๋‹ˆ๋‹ค.

    ํ˜„์žฌ ๋ณด์•ˆ ํ™˜๊ฒฝ

    > ์ฐธ๊ณ : ์ด ์ •๋ณด๋Š” 2026๋…„ 2์›” 5์ผ ๊ธฐ์ค€ MCP ๋ณด์•ˆ ํ‘œ์ค€์„ ๋ฐ˜์˜ํ•˜๋ฉฐ, MCP Specification 2025-11-25์™€ ์ผ์น˜ํ•ฉ๋‹ˆ๋‹ค.

    MCP ํ”„๋กœํ† ์ฝœ์€ ๋น ๋ฅด๊ฒŒ ์ง„ํ™”ํ•˜๊ณ  ์žˆ์œผ๋ฉฐ, ํ–ฅํ›„ ๊ตฌํ˜„์—์„œ๋Š” ์ƒˆ๋กœ์šด ์ธ์ฆ ํŒจํ„ด๊ณผ ๊ฐ•ํ™”๋œ ์ œ์–ด๊ฐ€ ๋„์ž…๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    ํ•ญ์ƒ ์ตœ์‹  ์ง€์นจ์€ MCP Specification, MCP GitHub ์ €์žฅ์†Œ, ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€ ๋ฌธ์„œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

    ๐Ÿ”๏ธ MCP ๋ณด์•ˆ ์ •์ƒ ํšŒ์˜ ์›Œํฌ์ˆ (Sherpa)

    ์‹ค๋ฌดํ˜• ๋ณด์•ˆ ๊ต์œก์„ ์œ„ํ•ด์„œ๋Š” Microsoft Azure์—์„œ MCP ์„œ๋ฒ„ ๋ณด์•ˆ์„ ์œ„ํ•œ ํฌ๊ด„์  ๊ฒฝ๋กœ๋ฅผ ์ œ๊ณตํ•˜๋Š” MCP Security Summit Workshop (Sherpa)๋ฅผ ๊ฐ•๋ ฅํžˆ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

    ์›Œํฌ์ˆ ๊ฐœ์š”

  • ๋ฌธ์ œ ํ•ด๊ฒฐ ํ•™์Šต: ๊ณ ์˜๋กœ ์ทจ์•ฝํ•œ ์„œ๋ฒ„๋ฅผ ๊ณต๊ฒฉํ•˜์—ฌ ์ทจ์•ฝ์  ์ง์ ‘ ๊ฒฝํ—˜
  • Azure ๋„ค์ดํ‹ฐ๋ธŒ ๋ณด์•ˆ ํ™œ์šฉ: Azure Entra ID, Key Vault, API Management, AI Content Safety ํ™œ์šฉ
  • ๋ฐฉ์–ด ์‹ฌ์ธต ์ „๋žต ์ ์šฉ: ์บ ํ”„๋ณ„ ๋‹จ๊ณ„์  ๋ณด์•ˆ ๊ณ„์ธต ๊ตฌ์ถ•
  • OWASP ํ‘œ์ค€ ๋”ฐ๋ฅด๊ธฐ: ๋ชจ๋“  ๊ธฐ๋ฒ•์€ OWASP MCP Azure Security Guide์— ๋งคํ•‘
  • ํ”„๋กœ๋•์…˜ ์ฝ”๋“œ ํš๋“: ํ…Œ์ŠคํŠธ๋œ ์‹ค๋ฌด ๊ตฌํ˜„ ์ฝ”๋“œ ์ œ๊ณต
  • ํƒํ—˜ ๊ฒฝ๋กœ

    | ์บ ํ”„ | ์ง‘์ค‘ ๋‚ด์šฉ | ๋‹ค๋ฃจ๋Š” OWASP ์œ„ํ—˜ |

    |------|----------|-------------------|

    | Base Camp | MCP ๊ธฐ๋ณธ ์›๋ฆฌ ๋ฐ ์ธ์ฆ ์ทจ์•ฝ์  | MCP01, MCP07 |

    | Camp 1: Identity | OAuth 2.1, Azure Managed Identity, Key Vault | MCP01, MCP02, MCP07 |

    | Camp 2: Gateway | API Management, Private Endpoints, ๊ฑฐ๋ฒ„๋„Œ์Šค | MCP02, MCP07, MCP09 |

    | Camp 3: I/O Security | ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…, PII ๋ณดํ˜ธ, ์ฝ˜ํ…์ธ  ์•ˆ์ „ | MCP03, MCP05, MCP06 |

    | Camp 4: Monitoring | ๋กœ๊ทธ ๋ถ„์„, ๋Œ€์‹œ๋ณด๋“œ, ์œ„ํ˜‘ ํƒ์ง€ | MCP08 |

    | ์ •์ƒ ํšŒ์˜ | ๋ ˆ๋“œ ํŒ€ / ๋ธ”๋ฃจ ํŒ€ ํ†ตํ•ฉ ํ…Œ์ŠคํŠธ | ์ „์ฒด |

    ์‹œ์ž‘ํ•˜๊ธฐ: https://azure-samples.github.io/sherpa/

    OWASP MCP Top 10 ๋ณด์•ˆ ์œ„ํ—˜

    | ์œ„ํ—˜ | ์„ค๋ช… | Azure ์™„ํ™”์ฑ… |

    |------|---------|--------------|

    | MCP01 | ํ† ํฐ ๊ด€๋ฆฌ ์˜ค๋ฅ˜ ๋ฐ ๋น„๋ฐ€ ๋…ธ์ถœ | Azure Key Vault, Managed Identity |

    | MCP02 | ๊ถŒํ•œ ์ƒ์Šน(์Šค์ฝ”ํ”„ ํ™•๋Œ€) | RBAC, Conditional Access |

    | MCP03 | ๋„๊ตฌ ์˜ค์—ผ | ๋„๊ตฌ ๊ฒ€์ฆ, ๋ฌด๊ฒฐ์„ฑ ํ™•์ธ |

    | MCP04 | ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ | GitHub Advanced Security, ์ข…์†์„ฑ ์Šค์บ” |

    | MCP05 | ๋ช…๋ น ์ฃผ์ž… ๋ฐ ์‹คํ–‰ | ์ž…๋ ฅ ๊ฒ€์ฆ, ์ƒŒ๋“œ๋ฐ•์‹ฑ |

    | MCP06 | ์ปจํ…์ŠคํŠธ ๊ธฐ๋ฐ˜ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž… | Azure AI Content Safety, Prompt Shields |

    | MCP07 | ๋ฏธํกํ•œ ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ | Azure Entra ID, PKCE ํฌํ•จ OAuth 2.1 |

    | MCP08 | ๊ฐ์‚ฌ ๋ฐ ์›๊ฒฉ ์ธก์ • ๋ถ€์กฑ | Azure Monitor, Application Insights |

    | MCP09 | ์„€๋„์šฐ MCP ์„œ๋ฒ„ | API ์„ผํ„ฐ ๊ฑฐ๋ฒ„๋„Œ์Šค, ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ |

    | MCP10 | ์ปจํ…์ŠคํŠธ ์ฃผ์ž… ๋ฐ ๊ณผ๋‹ค ๋…ธ์ถœ | ๋ฐ์ดํ„ฐ ๋ถ„๋ฅ˜, ์ตœ์†Œ ๋…ธ์ถœ |

    MCP ์ธ์ฆ ์ง„ํ™”

    MCP ๋ช…์„ธ๋Š” ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ ์ ‘๊ทผ๋ฒ•์—์„œ ์ƒ๋‹นํ•œ ์ง„ํ™”๋ฅผ ๊ฒช์—ˆ์Šต๋‹ˆ๋‹ค:

  • ์ดˆ๊ธฐ ์ ‘๊ทผ ๋ฐฉ์‹: ์ดˆ๊ธฐ ๋ช…์„ธ๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ์ปค์Šคํ…€ ์ธ์ฆ ์„œ๋ฒ„๋ฅผ ๊ตฌํ˜„ํ•˜๋„๋ก ์š”๊ตฌํ–ˆ์œผ๋ฉฐ, MCP ์„œ๋ฒ„๋Š” ์‚ฌ์šฉ์ž ์ธ์ฆ์„ ์ง์ ‘ ๊ด€๋ฆฌํ•˜๋Š” OAuth 2.0 ๊ถŒํ•œ ์„œ๋ฒ„ ์—ญํ•  ์ˆ˜ํ–‰
  • ํ˜„์žฌ ํ‘œ์ค€ (2025-11-25): ์—…๋ฐ์ดํŠธ๋œ ๋ช…์„ธ๋Š” MCP ์„œ๋ฒ„๊ฐ€ ์™ธ๋ถ€ ID ๊ณต๊ธ‰์ž(์˜ˆ: Microsoft Entra ID)์—๊ฒŒ ์ธ์ฆ์„ ์œ„์ž„ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•˜์—ฌ ๋ณด์•ˆ ์ž์„ธ๋ฅผ ๊ฐœ์„ ํ•˜๊ณ  ๊ตฌํ˜„ ๋ณต์žก์„ฑ ๊ฐ์†Œ
  • ์ „์†ก ๊ณ„์ธต ๋ณด์•ˆ: ๋กœ์ปฌ(STDIO) ๋ฐ ์›๊ฒฉ(Streamable HTTP) ์—ฐ๊ฒฐ ๋ชจ๋‘์— ์ ํ•ฉํ•œ ์ธ์ฆ ํŒจํ„ด๊ณผ ํ•จ๊ป˜ ๊ฐ•ํ™”๋œ ๋ณด์•ˆ ์ „์†ก ๋ฉ”์ปค๋‹ˆ์ฆ˜ ์ง€์›
  • ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ ๋ณด์•ˆ

    ํ˜„์žฌ ๋ณด์•ˆ ๋ฌธ์ œ

    ํ˜„๋Œ€ MCP ๊ตฌํ˜„์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ ๋ฌธ์ œ์— ์ง๋ฉดํ•ด ์žˆ์Šต๋‹ˆ๋‹ค:

    ์œ„ํ—˜ ๋ฐ ์œ„ํ˜‘ ๋ฒกํ„ฐ

  • ์ž˜๋ชป๋œ ๊ถŒํ•œ ๋ถ€์—ฌ ๋…ผ๋ฆฌ: MCP ์„œ๋ฒ„์˜ ์˜ฌ๋ฐ”๋ฅด์ง€ ์•Š์€ ๊ถŒํ•œ ๋ถ€์—ฌ ๊ตฌํ˜„์€ ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ ๋…ธ์ถœ์ด๋‚˜ ์ž˜๋ชป๋œ ์ ‘๊ทผ ํ†ต์ œ ์ ์šฉ ๊ฐ€๋Šฅ์„ฑ
  • OAuth ํ† ํฐ ํƒˆ์ทจ: ๋กœ์ปฌ MCP ์„œ๋ฒ„ ํ† ํฐ ๋„๋‚œ ์‹œ ๊ณต๊ฒฉ์ž๊ฐ€ ์„œ๋ฒ„๋ฅผ ๊ฐ€์žฅํ•ด ํ•˜์œ„ ์„œ๋น„์Šค์— ์ ‘๊ทผ ๊ฐ€๋Šฅ
  • ํ† ํฐ ์ „๋‹ฌ ์ทจ์•ฝ์ : ๋ถ€์ ์ ˆํ•œ ํ† ํฐ ์ฒ˜๋ฆฌ๋กœ ๋ณด์•ˆ ์ œ์–ด ์šฐํšŒ ๋ฐ ์ฑ…์ž„ ์ถ”์  ์–ด๋ ค์›€ ๋ฐœ์ƒ
  • ๊ณผ๋„ํ•œ ๊ถŒํ•œ: ๊ณผ๋„ ๊ถŒํ•œ ๋ถ€์—ฌ๋œ MCP ์„œ๋ฒ„๋Š” ์ตœ์†Œ ๊ถŒํ•œ ์›์น™ ์œ„๋ฐ˜ ๋ฐ ๊ณต๊ฒฉ ๋ฒ”์œ„ ํ™•์žฅ
  • ํ† ํฐ ์ „๋‹ฌ: ์‹ฌ๊ฐํ•œ ์•ˆํ‹ฐ ํŒจํ„ด

    ํ˜„์žฌ MCP ๊ถŒํ•œ ๋ถ€์—ฌ ๋ช…์„ธ์—์„œ๋Š” ํ† ํฐ ์ „๋‹ฌ์ด ๋ช…๋ฐฑํžˆ ๊ธˆ์ง€๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ์‹ฌ๊ฐํ•œ ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ์•ผ๊ธฐํ•˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค:

    ##### ๋ณด์•ˆ ์ œ์–ด ์šฐํšŒ

  • MCP ์„œ๋ฒ„์™€ ํ•˜์œ„ API๋“ค์€ ์ ์ ˆํ•œ ํ† ํฐ ๊ฒ€์ฆ์— ์˜์กดํ•˜๋Š” ์ค‘์š”ํ•œ ๋ณด์•ˆ ์ œ์–ด(์†๋„ ์ œํ•œ, ์š”์ฒญ ๊ฒ€์ฆ, ํŠธ๋ž˜ํ”ฝ ๋ชจ๋‹ˆํ„ฐ๋ง)๋ฅผ ๊ตฌํ˜„
  • ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ง์ ‘ API ํ† ํฐ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์€ ์ด ํ•ต์‹ฌ ๋ณดํ˜ธ์žฅ์น˜๋ฅผ ์šฐํšŒ, ๋ณด์•ˆ ๊ตฌ์กฐ๋ฅผ ํ›ผ์†
  • ##### ์ฑ…์ž„ ์ถ”์  ๋ฐ ๊ฐ์‚ฌ ๋ฌธ์ œ

  • MCP ์„œ๋ฒ„๋Š” ์ƒ๋ฅ˜์—์„œ ๋ฐœํ–‰๋œ ํ† ํฐ์„ ์‚ฌ์šฉํ•˜๋Š” ํด๋ผ์ด์–ธํŠธ๋ฅผ ๊ตฌ๋ถ„ํ•  ์ˆ˜ ์—†์–ด ๊ฐ์‚ฌ ์ถ”์  ํ๋ฆ„ ํŒŒ๊ดด
  • ํ•˜์œ„ ๋ฆฌ์†Œ์Šค ์„œ๋ฒ„ ๋กœ๊ทธ๋Š” ์‹ค์ œ MCP ์„œ๋ฒ„ ์ค‘๊ณ„์ž ๋Œ€์‹  ์ž˜๋ชป๋œ ์š”์ฒญ ์ถœ์ฒ˜ ํ‘œ์‹œ
  • ์‚ฌ๊ณ  ์กฐ์‚ฌ ๋ฐ ๊ทœ์ • ์ค€์ˆ˜ ๊ฐ์‚ฌ๊ฐ€ ๋งค์šฐ ์–ด๋ ค์›Œ์ง
  • ##### ๋ฐ์ดํ„ฐ ์œ ์ถœ ์œ„ํ—˜

  • ๊ฒ€์ฆ๋˜์ง€ ์•Š์€ ํ† ํฐ ์ฒญ๊ตฌ๋Š” ํ† ํฐ ํƒˆ์ทจ์ž๊ฐ€ MCP ์„œ๋ฒ„๋ฅผ ํ†ตํ•ด ๋ฐ์ดํ„ฐ๋ฅผ ๋นผ๋Œ๋ฆฌ๋Š” ํ”„๋ก์‹œ๋กœ ์•…์šฉ ๊ฐ€๋Šฅ
  • ์‹ ๋ขฐ ๊ฒฝ๊ณ„ ์œ„๋ฐ˜์œผ๋กœ ์˜๋„๋œ ๋ณด์•ˆ ์ œ์–ด๋ฅผ ์šฐํšŒํ•˜๋Š” ๋ฌด๋‹จ ์ ‘๊ทผ ํŒจํ„ด ํ—ˆ์šฉ
  • ##### ๋‹ค์ค‘ ์„œ๋น„์Šค ๊ณต๊ฒฉ ๋ฒกํ„ฐ

  • ์—ฌ๋Ÿฌ ์„œ๋น„์Šค๊ฐ€ ๋™์ผํ•œ ํ† ํฐ์„ ์‹ ๋ขฐํ•˜๋ฉด ๊ฐ€๋กœ ์›€์ง์ž„์ด ๊ฐ€๋Šฅ
  • ํ† ํฐ ์ถœ์ฒ˜ ํ™•์ธ ๋ถˆ๊ฐ€๋Šฅ ์‹œ ์„œ๋น„์Šค ๊ฐ„ ์‹ ๋ขฐ ๊ฐ€์ • ์œ„๋ฐฐ ๊ฐ€๋Šฅ
  • ๋ณด์•ˆ ์ œ์–ด ๋ฐ ์™„ํ™”์ฑ…

    ์ค‘์š” ๋ณด์•ˆ ์š”๊ตฌ ์‚ฌํ•ญ:

    > ์˜๋ฌด ์‚ฌํ•ญ: MCP ์„œ๋ฒ„๋Š” ๋ช…์‹œ์ ์œผ๋กœ MCP ์„œ๋ฒ„๋ฅผ ์œ„ํ•ด ๋ฐœํ–‰๋œ ํ† ํฐ๋งŒ ํ—ˆ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค

    ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ ์ œ์–ด
  • ์—„๊ฒฉํ•œ ๊ถŒํ•œ ๋ถ€์—ฌ ๊ฒ€ํ† : MCP ์„œ๋ฒ„ ๊ถŒํ•œ ๋กœ์ง์„ ์ฒ ์ €ํžˆ ์ ๊ฒ€ํ•ด ๋ฏผ๊ฐ ์ž์›์— ๋Œ€ํ•ด ์˜๋„๋œ ์‚ฌ์šฉ์ž์™€ ํด๋ผ์ด์–ธํŠธ๋งŒ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๋„๋ก ๋ณด์žฅ
  • - ๊ตฌํ˜„ ๊ฐ€์ด๋“œ: Azure API Management๋ฅผ MCP ์„œ๋ฒ„ ์ธ์ฆ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์‚ฌ์šฉ

    - ID ํ†ตํ•ฉ: Microsoft Entra ID๋ฅผ MCP ์„œ๋ฒ„ ์ธ์ฆ์— ์‚ฌ์šฉํ•˜๊ธฐ

  • ์•ˆ์ „ํ•œ ํ† ํฐ ๊ด€๋ฆฌ: Microsoft ํ† ํฐ ๊ฒ€์ฆ ๋ฐ ์ˆ˜๋ช…์ฃผ๊ธฐ ๋ชจ๋ฒ” ์‚ฌ๋ก€ ์ ์šฉ
  • - ํ† ํฐ ๋Œ€์ƒ ์ฒญ๊ตฌ๊ฐ€ MCP ์„œ๋ฒ„ ID์™€ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธ

    - ์ ์ ˆํ•œ ํ† ํฐ ๊ฐฑ์‹  ๋ฐ ๋งŒ๋ฃŒ ์ •์ฑ… ๊ตฌํ˜„

    - ์žฌ์‚ฌ์šฉ ๊ณต๊ฒฉ ๋ฐ ๋ฌด๋‹จ ์‚ฌ์šฉ ๋ฐฉ์ง€

  • ๋ณดํ˜ธ๋œ ํ† ํฐ ์ €์žฅ: ์•”ํ˜ธํ™”๋ฅผ ํ†ตํ•ด ์•ˆ์ „ํ•œ ์ €์žฅ(ํœด์ง€ ๋ฐ ์ „์†ก ์ค‘ ๋ชจ๋‘)
  • - ๋ชจ๋ฒ” ์‚ฌ๋ก€: ํ† ํฐ ์ €์žฅ ๋ฐ ์•”ํ˜ธํ™” ๊ฐ€์ด๋“œ๋ผ์ธ

    ์ ‘๊ทผ ์ œ์–ด ๊ตฌํ˜„
  • ์ตœ์†Œ ๊ถŒํ•œ ์›์น™: MCP ์„œ๋ฒ„์— ๊ธฐ๋Šฅ์— ํ•„์š”ํ•œ ์ตœ์†Œ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌ
  • - ์ •๊ธฐ์  ๊ถŒํ•œ ๊ฒ€ํ†  ๋ฐ ๊ถŒํ•œ ์ƒ์Šน ๋ฐฉ์ง€

    - Microsoft ๋ฌธ์„œ: ์•ˆ์ „ํ•œ ์ตœ์†Œ ๊ถŒํ•œ ์ ‘๊ทผ

  • ์—ญํ•  ๊ธฐ๋ฐ˜ ์ ‘๊ทผ ์ œ์–ด(RBAC): ์„ธ๋ฐ€ํ•œ ์—ญํ•  ํ• ๋‹น ๊ตฌํ˜„
  • - ์—ญํ• ์„ ํŠน์ • ์ž์› ๋ฐ ์ž‘์—…์— ์—„๊ฒฉํžˆ ์ œํ•œ

    - ๊ณต๊ฒฉ ๋ฒ”์œ„๋ฅผ ํ™•๋Œ€ํ•˜๋Š” ๊ณผ๋„ํ•˜๊ฑฐ๋‚˜ ๋ถˆํ•„์š”ํ•œ ๊ถŒํ•œ ๋ถ€์—ฌ ๊ธˆ์ง€

  • ์ง€์†์  ๊ถŒํ•œ ๋ชจ๋‹ˆํ„ฐ๋ง: ์ ‘๊ทผ ๊ฐ์‚ฌ ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง ํ™œ์„ฑํ™”
  • - ๋น„์ •์ƒ ๊ถŒํ•œ ์‚ฌ์šฉ ํŒจํ„ด ๊ฐ์‹œ

    - ๊ณผ๋„ํ•˜๊ฑฐ๋‚˜ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์‹ ์† ๋ณด์™„

    AI ํŠนํ™” ๋ณด์•ˆ ์œ„ํ˜‘

    ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž… ๋ฐ ๋„๊ตฌ ์กฐ์ž‘ ๊ณต๊ฒฉ

    ์ตœ์‹  MCP ๊ตฌํ˜„์€ ์ „ํ†ต ๋ณด์•ˆ ์กฐ์น˜๋กœ๋Š” ์™„์ „ํžˆ ๋ฐฉ์–ด ๋ชป ํ•˜๋Š” ์ •๊ตํ•œ AI ํŠน์œ  ๊ณต๊ฒฉ ๋ฒกํ„ฐ์— ์ง๋ฉดํ•ด ์žˆ์Šต๋‹ˆ๋‹ค:

    ๊ฐ„์ ‘ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž… (ํฌ๋กœ์Šค ๋„๋ฉ”์ธ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…)

    ๊ฐ„์ ‘ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…์€ MCP ๊ธฐ๋ฐ˜ AI ์‹œ์Šคํ…œ์—์„œ ๊ฐ€์žฅ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์  ์ค‘ ํ•˜๋‚˜์ž…๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ๋ฌธ์„œ, ์›น ํŽ˜์ด์ง€, ์ด๋ฉ”์ผ, ๋ฐ์ดํ„ฐ ์†Œ์Šค ๋“ฑ ์™ธ๋ถ€ ์ฝ˜ํ…์ธ ์— ์•…์„ฑ ๋ช…๋ น์„ ์ˆจ๊ธฐ๊ณ  AI ์‹œ์Šคํ…œ์ด ์ด๋ฅผ ํ•ฉ๋ฒ• ๋ช…๋ น์œผ๋กœ ์ฒ˜๋ฆฌํ•˜๋„๋ก ์œ ๋„ํ•ฉ๋‹ˆ๋‹ค.

    ๊ณต๊ฒฉ ์‹œ๋‚˜๋ฆฌ์˜ค:

  • ๋ฌธ์„œ ๊ธฐ๋ฐ˜ ์ฃผ์ž…: ์ฒ˜๋ฆฌ๋˜๋Š” ๋ฌธ์„œ์— ์ˆจ๊ฒจ์ง„ ์•…์„ฑ ๋ช…๋ น์ด ์˜๋„์น˜ ์•Š์€ AI ๋™์ž‘ ์œ ๋ฐœ
  • ์›น ์ฝ˜ํ…์ธ  ์•…์šฉ: ์Šคํฌ๋ž˜ํ•‘ ์‹œ AI ํ–‰๋™์„ ์กฐ์ž‘ํ•˜๋Š” ํ”„๋กฌํ”„ํŠธ๊ฐ€ ํฌํ•จ๋œ ์†์ƒ๋œ ์›น ํŽ˜์ด์ง€
  • ์ด๋ฉ”์ผ ๊ณต๊ฒฉ: AI ๋ณด์กฐ ์‹œ์Šคํ…œ์ด ์ •๋ณด ์œ ์ถœ ๋˜๋Š” ๋ฌด๋‹จ ์ž‘์—… ์‹คํ–‰ํ•˜๋„๋ก ์œ ๋„ํ•˜๋Š” ์•…์„ฑ ์ด๋ฉ”์ผ ํ”„๋กฌํ”„ํŠธ
  • ๋ฐ์ดํ„ฐ ์†Œ์Šค ์˜ค์—ผ: ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋‚˜ API๊ฐ€ ์กฐ์ž‘๋œ ๋‚ด์šฉ์„ AI์— ์ œ๊ณต
  • ์‹ค์ œ ์˜ํ–ฅ: ๋ฐ์ดํ„ฐ ์œ ์ถœ, ๊ฐœ์ธ์ •๋ณด ์นจํ•ด, ์œ ํ•ด ์ฝ˜ํ…์ธ  ์ƒ์„ฑ, ์‚ฌ์šฉ์ž ์ƒํ˜ธ์ž‘์šฉ ์กฐ์ž‘ ๋“ฑ์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋ถ„์„์€ Prompt Injection in MCP (Simon Willison) ์ฐธ๊ณ ํ•˜์‹ญ์‹œ์˜ค.

    ๋„๊ตฌ ์˜ค์—ผ ๊ณต๊ฒฉ

    ๋„๊ตฌ ์˜ค์—ผ์€ MCP ๋„๊ตฌ๋ฅผ ์ •์˜ํ•˜๋Š” ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ํƒ€๊ฒŸ์œผ๋กœ ํ•˜๋ฉฐ, LLM์ด ๋„๊ตฌ ์„ค๋ช…๊ณผ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ํ•ด์„ํ•ด ์‹คํ–‰ ๊ฒฐ์ •์„ ๋‚ด๋ฆฌ๋Š” ๋ฐฉ์‹์„ ์•…์šฉํ•ฉ๋‹ˆ๋‹ค.

    ๊ณต๊ฒฉ ๋ฉ”์ปค๋‹ˆ์ฆ˜:

  • ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ์กฐ์ž‘: ๊ณต๊ฒฉ์ž๊ฐ€ ๋„๊ตฌ ์„ค๋ช…, ๋งค๊ฐœ๋ณ€์ˆ˜ ์ •์˜, ์‚ฌ์šฉ ์˜ˆ์‹œ ๋“ฑ์— ์•…์„ฑ ๋ช…๋ น ์‚ฝ์ž…
  • ์ˆจ๊ฒจ์ง„ ๋ช…๋ น์–ด: ์ธ๊ฐ„ ์‚ฌ์šฉ์ž์—๊ฒŒ๋Š” ๋ณด์ด์ง€ ์•Š์ง€๋งŒ AI ๋ชจ๋ธ์ด ์ฒ˜๋ฆฌํ•˜๋Š” ์€๋ฐ€ํ•œ ํ”„๋กฌํ”„ํŠธ
  • ๋™์  ๋„๊ตฌ ๋ณ€๊ฒฝ("๋Ÿฌ๊ทธ ํ’€"): ์‚ฌ์šฉ์ž๊ฐ€ ์Šน์ธํ•œ ๋„๊ตฌ๊ฐ€ ์ดํ›„ ์•…์„ฑ ์ž‘์—… ์ˆ˜ํ–‰ํ•˜๋„๋ก ๋ชฐ๋ž˜ ๋ณ€๊ฒฝ
  • ๋งค๊ฐœ๋ณ€์ˆ˜ ์‚ฝ์ž…: ๋„๊ตฌ ๋งค๊ฐœ๋ณ€์ˆ˜ ์Šคํ‚ค๋งˆ์— ์•…์„ฑ ์ฝ˜ํ…์ธ  ํฌํ•จ, ๋ชจ๋ธ ํ–‰๋™์— ์˜ํ–ฅ
  • ํ˜ธ์ŠคํŒ… ์„œ๋ฒ„ ์œ„ํ—˜: ์›๊ฒฉ MCP ์„œ๋ฒ„๋Š” ๋„๊ตฌ ์ •์˜๋ฅผ ์ดˆ๊ธฐ ์Šน์ธ ํ›„์—๋„ ์—…๋ฐ์ดํŠธํ•  ์ˆ˜ ์žˆ์–ด, ์ด์ „์— ์•ˆ์ „ํ–ˆ๋˜ ๋„๊ตฌ๊ฐ€ ์•…์„ฑ์œผ๋กœ ๋ณ€ํ•  ์œ„ํ—˜ ์กด์žฌ.

    ์ž์„ธํ•œ ๋ถ„์„์€ Tool Poisoning Attacks (Invariant Labs) ์ฐธ๊ณ ํ•˜์‹ญ์‹œ์˜ค.

    ์ถ”๊ฐ€ AI ๊ณต๊ฒฉ ๋ฒกํ„ฐ
  • ํฌ๋กœ์Šค ๋„๋ฉ”์ธ ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž… (XPIA): ์—ฌ๋Ÿฌ ๋„๋ฉ”์ธ ์ฝ˜ํ…์ธ ๋ฅผ ํ™œ์šฉํ•ด ๋ณด์•ˆ ์ œ์–ด๋ฅผ ์šฐํšŒํ•˜๋Š” ์ •๊ตํ•œ ๊ณต๊ฒฉ
  • ๋™์  ๊ธฐ๋Šฅ ์ˆ˜์ •: ์ดˆ๊ธฐ ๋ณด์•ˆ ํ‰๊ฐ€๋ฅผ ํ†ต๊ณผํ•˜๋Š” ๋„๊ตฌ ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ์‹ค์‹œ๊ฐ„ ๋ณ€๊ฒฝ
  • ์ปจํ…์ŠคํŠธ ์œˆ๋„์šฐ ๋ณ€์กฐ ๊ณต๊ฒฉ: ์•…์˜์ ์ธ ๋ช…๋ น์„ ์ˆจ๊ธฐ๊ธฐ ์œ„ํ•ด ํฐ ์ปจํ…์ŠคํŠธ ์œˆ๋„์šฐ๋ฅผ ์กฐ์ž‘ํ•˜๋Š” ๊ณต๊ฒฉ
  • ๋ชจ๋ธ ํ˜ผ๋ž€ ๊ณต๊ฒฉ: ๋ชจ๋ธ์˜ ํ•œ๊ณ„๋ฅผ ์ด์šฉํ•ด ์˜ˆ์ธก ๋ถˆ๊ฐ€๋Šฅํ•˜๊ฑฐ๋‚˜ ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ๋™์ž‘์„ ์œ ๋ฐœํ•˜๋Š” ๊ณต๊ฒฉ
  • AI ๋ณด์•ˆ ์œ„ํ—˜ ์˜ํ–ฅ

    ๋†’์€ ์˜ํ–ฅ์˜ ๊ฒฐ๊ณผ:

  • ๋ฐ์ดํ„ฐ ์œ ์ถœ: ๊ถŒํ•œ ์—†๋Š” ๋ฏผ๊ฐํ•œ ๊ธฐ์—… ๋˜๋Š” ๊ฐœ์ธ ๋ฐ์ดํ„ฐ ์ ‘๊ทผ ๋ฐ ๋„๋‚œ
  • ๊ฐœ์ธ์ •๋ณด ์นจํ•ด: ๊ฐœ์ธ ์‹๋ณ„ ์ •๋ณด(PII) ๋ฐ ๊ธฐ๋ฐ€ ์‚ฌ์—… ๋ฐ์ดํ„ฐ ๋…ธ์ถœ
  • ์‹œ์Šคํ…œ ์กฐ์ž‘: ์ค‘์š” ์‹œ์Šคํ…œ ๋ฐ ์›Œํฌํ”Œ๋กœ์˜ ์˜๋„์น˜ ์•Š์€ ์ˆ˜์ •
  • ์ธ์ฆ ์ •๋ณด ๋„๋‚œ: ์ธ์ฆ ํ† ํฐ ๋ฐ ์„œ๋น„์Šค ์ž๊ฒฉ ์ฆ๋ช… ์†์ƒ
  • ์ธก๋ฉด ์ด๋™ ๊ณต๊ฒฉ: ์†์ƒ๋œ AI ์‹œ์Šคํ…œ์„ ๋„“์€ ๋„คํŠธ์›Œํฌ ๊ณต๊ฒฉ์„ ์œ„ํ•œ ๊ต์ฐจ ์ง€์ ์œผ๋กœ ์‚ฌ์šฉ
  • Microsoft AI ๋ณด์•ˆ ์†”๋ฃจ์…˜

    AI ํ”„๋กฌํ”„ํŠธ ์‰ด๋“œ: ์ฃผ์ž… ๊ณต๊ฒฉ์— ๋Œ€ํ•œ ๊ณ ๊ธ‰ ๋ฐฉ์–ด

    Microsoft AI ํ”„๋กฌํ”„ํŠธ ์‰ด๋“œ๋Š” ์ง์ ‘์  ๋ฐ ๊ฐ„์ ‘์  ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž… ๊ณต๊ฒฉ์— ๋Œ€ํ•ด ๋‹ค์ค‘ ๋ณด์•ˆ ๊ณ„์ธต์„ ํ†ตํ•œ ํฌ๊ด„์ ์ธ ๋ฐฉ์–ด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค:

    ##### ํ•ต์‹ฌ ๋ณดํ˜ธ ๋ฉ”์ปค๋‹ˆ์ฆ˜:

    1. ๊ณ ๊ธ‰ ํƒ์ง€ ๋ฐ ํ•„ํ„ฐ๋ง

    - ๋จธ์‹  ๋Ÿฌ๋‹ ์•Œ๊ณ ๋ฆฌ์ฆ˜๊ณผ ์ž์—ฐ์–ด ์ฒ˜๋ฆฌ ๊ธฐ์ˆ ๋กœ ์™ธ๋ถ€ ์ปจํ…์ธ  ๋‚ด ์•…์˜์  ๋ช…๋ น ํƒ์ง€

    - ๋ฌธ์„œ, ์›น ํŽ˜์ด์ง€, ์ด๋ฉ”์ผ, ๋ฐ์ดํ„ฐ ์†Œ์Šค์—์„œ ๋‚ด์žฅ ์œ„ํ˜‘์„ ์‹ค์‹œ๊ฐ„ ๋ถ„์„

    - ์ •์ƒ์  ํ”„๋กฌํ”„ํŠธ ํŒจํ„ด๊ณผ ์•…์˜์  ํŒจํ„ด์˜ ๋งฅ๋ฝ์  ์ดํ•ด

    2. ์ŠคํฌํŠธ๋ผ์ดํŒ… ๊ธฐ๋ฒ•

    - ์‹ ๋ขฐ๋œ ์‹œ์Šคํ…œ ๋ช…๋ น๊ณผ ์ž ์žฌ์ ์œผ๋กœ ์†์ƒ๋œ ์™ธ๋ถ€ ์ž…๋ ฅ ๊ตฌ๋ถ„

    - ๋ชจ๋ธ ์ ํ•ฉ๋„๋ฅผ ๋†’์ด๋ฉด์„œ ์•…์„ฑ ์ปจํ…์ธ ๋ฅผ ๋ถ„๋ฆฌํ•˜๋Š” ํ…์ŠคํŠธ ๋ณ€ํ™˜ ๋ฐฉ๋ฒ•

    - AI ์‹œ์Šคํ…œ์ด ๋ช…๋ น ๊ณ„์ธต์„ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์œ ์ง€ํ•˜๊ณ  ์ฃผ์ž…๋œ ๋ช…๋ น ๋ฌด์‹œ ์ง€์›

    3. ๊ตฌ๋ถ„์ž ๋ฐ ๋ฐ์ดํ„ฐ๋งˆํ‚น ์‹œ์Šคํ…œ

    - ์‹ ๋ขฐ๋œ ์‹œ์Šคํ…œ ๋ฉ”์‹œ์ง€์™€ ์™ธ๋ถ€ ์ž…๋ ฅ ํ…์ŠคํŠธ ๊ฐ„ ๋ช…ํ™•ํ•œ ๊ฒฝ๊ณ„ ์ •์˜

    - ์‹ ๋ขฐ๋œ ์†Œ์Šค์™€ ์‹ ๋ขฐ๋˜์ง€ ์•Š์€ ๋ฐ์ดํ„ฐ ์†Œ์Šค ๊ฐ„ ๊ฒฝ๊ณ„๋ฅผ ๊ฐ•์กฐํ•˜๋Š” ํŠน์ˆ˜ ๋งˆ์ปค

    - ๋ช…๋ น ํ˜ผ๋™๊ณผ ๋ฌด๋‹จ ๋ช…๋ น ์‹คํ–‰ ๋ฐฉ์ง€ ์œ„ํ•œ ๋ช…ํ™•ํ•œ ๋ถ„๋ฆฌ

    4. ์ง€์†์ ์ธ ์œ„ํ˜‘ ์ธํ…”๋ฆฌ์ „์Šค

    - Microsoft๋Š” ์ง€์†์ ์œผ๋กœ ์ƒˆ๋กœ์šด ๊ณต๊ฒฉ ํŒจํ„ด์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ๋ฐฉ์–ด์ฑ…์„ ์—…๋ฐ์ดํŠธ

    - ์ƒˆ๋กœ์šด ์ฃผ์ž… ๊ธฐ๋ฒ• ๋ฐ ๊ณต๊ฒฉ ๋ฒกํ„ฐ์— ๋Œ€ํ•œ ์„ ์ œ์  ์œ„ํ˜‘ ํƒ์ƒ‰

    - ์ง„ํ™”ํ•˜๋Š” ์œ„ํ˜‘์— ๋Œ€์‘ํ•˜๋Š” ๋ณด์•ˆ ๋ชจ๋ธ ์ •๊ธฐ ์—…๋ฐ์ดํŠธ

    5. Azure ์ฝ˜ํ…์ธ  ์•ˆ์ „ ํ†ตํ•ฉ

    - ์ข…ํ•ฉ Azure AI ์ฝ˜ํ…์ธ  ์•ˆ์ „ ์ œํ’ˆ๊ตฐ์˜ ์ผ๋ถ€

    - ํƒˆ์˜ฅ ์‹œ๋„, ์œ ํ•ด ์ฝ˜ํ…์ธ  ๋ฐ ๋ณด์•ˆ ์ •์ฑ… ์œ„๋ฐ˜์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ํƒ์ง€

    - AI ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ตฌ์„ฑ์š”์†Œ ์ „๋ฐ˜์— ๊ฑธ์นœ ํ†ตํ•ฉ ๋ณด์•ˆ ์ œ์–ด

    ๊ตฌํ˜„ ๋ฆฌ์†Œ์Šค: Microsoft Prompt Shields Documentation

    ๊ณ ๊ธ‰ MCP ๋ณด์•ˆ ์œ„ํ˜‘

    ์„ธ์…˜ ํ•˜์ด์žฌํ‚น ์ทจ์•ฝ์ 

    ์„ธ์…˜ ํ•˜์ด์žฌํ‚น์€ ์ƒํƒœ ์ •๋ณด๋ฅผ ๊ฐ€์ง„ MCP ๊ตฌํ˜„์—์„œ ์ค‘์š”ํ•œ ๊ณต๊ฒฉ ๋ฒกํ„ฐ๋กœ, ๊ถŒํ•œ ์—†๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์ •๋‹นํ•œ ์„ธ์…˜ ์‹๋ณ„์ž๋ฅผ ํš๋“ํ•ด ํด๋ผ์ด์–ธํŠธ๋ฅผ ๊ฐ€์žฅํ•˜๊ณ  ๋ฌด๋‹จ ํ–‰๋™์„ ์ˆ˜ํ–‰ํ•˜๋Š” ํ–‰์œ„์ž…๋‹ˆ๋‹ค.

    ๊ณต๊ฒฉ ์‹œ๋‚˜๋ฆฌ์˜ค ๋ฐ ์œ„ํ—˜
  • ์„ธ์…˜ ํ•˜์ด์žฌํ‚น ํ”„๋กฌํ”„ํŠธ ์ฃผ์ž…: ๋„๋‚œ๋‹นํ•œ ์„ธ์…˜ ID๋กœ ์„ธ์…˜ ์ƒํƒœ๋ฅผ ๊ณต์œ ํ•˜๋Š” ์„œ๋ฒ„์— ์•…์˜์ ์ธ ์ด๋ฒคํŠธ๋ฅผ ์ฃผ์ž…ํ•ด ์œ ํ•ด ๋™์ž‘ ์œ ๋ฐœ ๋˜๋Š” ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ ์ ‘๊ทผ
  • ์ง์ ‘ ๊ฐ€์žฅ ๊ณต๊ฒฉ: ๋„๋‚œ๋œ ์„ธ์…˜ ID๋กœ ์ธ์ฆ ์šฐํšŒ MCP ์„œ๋ฒ„ ํ˜ธ์ถœ์ด ๊ฐ€๋Šฅํ•ด ๊ณต๊ฒฉ์ž๋ฅผ ์ •๋‹น ์‚ฌ์šฉ์ž๋กœ ์ฒ˜๋ฆฌ
  • ์†์ƒ๋œ ์žฌ๊ฐœ ๊ฐ€๋Šฅ ์ŠคํŠธ๋ฆผ: ๊ณต๊ฒฉ์ž๊ฐ€ ์š”์ฒญ์„ ์กฐ๊ธฐ ์ข…๋ฃŒํ•˜์—ฌ ์ •์ƒ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์•…์„ฑ ์ปจํ…์ธ ๋กœ ์žฌ๊ฐœํ•˜๊ฒŒ ๋งŒ๋“ฆ
  • ์„ธ์…˜ ๊ด€๋ฆฌ ๋ณด์•ˆ ์ œ์–ด

    ์ค‘์š” ์š”๊ตฌ์‚ฌํ•ญ:

  • ๊ถŒํ•œ ํ™•์ธ: ๊ถŒํ•œ ํ™•์ธ์„ ๊ตฌํ˜„ํ•˜๋Š” MCP ์„œ๋ฒ„๋Š” ๋ชจ๋“  ์ˆ˜์‹  ์š”์ฒญ์„ ๊ฒ€์ฆํ•ด์•ผ ํ•˜๋ฉฐ, ์„ธ์…˜์— ์˜์กดํ•ด ์ธ์ฆํ•ด์„œ๋Š” ์•ˆ ๋จ
  • ๋ณด์•ˆ ์„ธ์…˜ ์ƒ์„ฑ: ์•”ํ˜ธํ•™์ ์œผ๋กœ ์•ˆ์ „ํ•œ ๋žœ๋ค ๋ฒˆํ˜ธ ์ƒ์„ฑ๊ธฐ๋กœ ๋น„๊ฒฐ์ •๋ก ์  ์„ธ์…˜ ID ์ƒ์„ฑ
  • ์‚ฌ์šฉ์ž๋ณ„ ๋ฐ”์ธ๋”ฉ: ๊ต์ฐจ ์‚ฌ์šฉ์ž ์„ธ์…˜ ์˜ค์šฉ ๋ฐฉ์ง€๋ฅผ ์œ„ํ•ด : ๊ฐ™์€ ํฌ๋งท์œผ๋กœ ์‚ฌ์šฉ์ž๋ณ„๋กœ ์„ธ์…˜ ID ๋ฐ”์ธ๋”ฉ
  • ์„ธ์…˜ ์ˆ˜๋ช… ์ฃผ๊ธฐ ๊ด€๋ฆฌ: ์ ์ ˆํ•œ ๋งŒ๋ฃŒ, ๊ฐฑ์‹ , ๋ฌดํšจํ™”๋กœ ์ทจ์•ฝ์  ๋…ธ์ถœ ์‹œ๊ฐ„ ์ œํ•œ
  • ์ „์†ก ๋ณด์•ˆ: ์„ธ์…˜ ID ํƒˆ์ทจ ๋ฐฉ์ง€๋ฅผ ์œ„ํ•œ ๋ชจ๋“  ํ†ต์‹  HTTPS ํ•„์ˆ˜
  • ํ˜ผ๋ž€๋œ ๋Œ€๋ฆฌ์ธ ๋ฌธ์ œ

    ํ˜ผ๋ž€๋œ ๋Œ€๋ฆฌ์ธ ๋ฌธ์ œ๋Š” MCP ์„œ๋ฒ„๊ฐ€ ํด๋ผ์ด์–ธํŠธ์™€ ์ œ3์ž ์„œ๋น„์Šค ์‚ฌ์ด ์ธ์ฆ ํ”„๋ก์‹œ ์—ญํ• ์„ ํ•  ๋•Œ ๋ฐœ์ƒํ•˜๋ฉฐ, ์ •์  ํด๋ผ์ด์–ธํŠธ ID ์•…์šฉ์„ ํ†ตํ•œ ๊ถŒํ•œ ์šฐํšŒ ๊ธฐํšŒ๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    ๊ณต๊ฒฉ ๋ฉ”์ปค๋‹ˆ์ฆ˜ ๋ฐ ์œ„ํ—˜
  • ์ฟ ํ‚ค ๊ธฐ๋ฐ˜ ๋™์˜ ์šฐํšŒ: ์ด์ „ ์‚ฌ์šฉ์ž ์ธ์ฆ์ด ์ƒ์„ฑํ•œ ๋™์˜ ์ฟ ํ‚ค๋ฅผ ๊ณต๊ฒฉ์ž๊ฐ€ ์•…์„ฑ ๊ถŒํ•œ ์š”์ฒญ๊ณผ ์กฐ์ž‘๋œ ๋ฆฌ๋””๋ ‰์…˜ URI๋กœ ์•…์šฉ
  • ๊ถŒํ•œ ์ฝ”๋“œ ๋„๋‚œ: ๊ธฐ์กด ๋™์˜ ์ฟ ํ‚ค๋กœ ์ธํ•ด ๊ถŒํ•œ ์„œ๋ฒ„๊ฐ€ ๋™์˜ ํ™”๋ฉด์„ ๊ฑด๋„ˆ๋›ฐ๊ณ  ๊ณต๊ฒฉ์ž ์ œ์–ด ์—”๋“œํฌ์ธํŠธ๋กœ ์ฝ”๋“œ ๋ฆฌ๋””๋ ‰์…˜
  • ๋ฌด๋‹จ API ์ ‘๊ทผ: ๋„๋‚œ๋œ ๊ถŒํ•œ ์ฝ”๋“œ๋กœ ํ† ํฐ ๊ตํ™˜ ๋ฐ ์‚ฌ์šฉ์ž ๊ฐ€์žฅ ๊ฐ€๋Šฅ, ๋ช…์‹œ์  ์Šน์ธ ์—†์ด ์ˆ˜ํ–‰
  • ์™„ํ™” ์ „๋žต

    ํ•„์ˆ˜ ์ œ์–ด:

  • ๋ช…์‹œ์  ๋™์˜ ์š”๊ตฌ: ์ •์  ํด๋ผ์ด์–ธํŠธ ID๋ฅผ ์‚ฌ์šฉํ•˜๋Š” MCP ํ”„๋ก์‹œ ์„œ๋ฒ„๋Š” ๋™์ ์œผ๋กœ ๋“ฑ๋ก๋œ ๊ฐ ํด๋ผ์ด์–ธํŠธ์— ๋Œ€ํ•ด ์‚ฌ์šฉ์ž ๋™์˜ ํ™•๋ณด ํ•„์ˆ˜
  • OAuth 2.1 ๋ณด์•ˆ ๊ตฌํ˜„: ๋ชจ๋“  ๊ถŒํ•œ ์š”์ฒญ์— ๋Œ€ํ•ด PKCE(Proof Key for Code Exchange)๋ฅผ ํฌํ•จํ•œ ์ตœ์‹  OAuth ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€ ์ค€์ˆ˜
  • ์—„๊ฒฉํ•œ ํด๋ผ์ด์–ธํŠธ ๊ฒ€์ฆ: ๋ฆฌ๋””๋ ‰์…˜ URI ๋ฐ ํด๋ผ์ด์–ธํŠธ ID์— ๋Œ€ํ•œ ์—„๋ฐ€ํ•œ ๊ฒ€์ฆ์œผ๋กœ ์•…์šฉ ๋ฐฉ์ง€
  • ํ† ํฐ ์ „๋‹ฌ ์ทจ์•ฝ์ 

    ํ† ํฐ ์ „๋‹ฌ์€ MCP ์„œ๋ฒ„๊ฐ€ ํด๋ผ์ด์–ธํŠธ ํ† ํฐ์„ ์ ์ ˆํ•œ ๊ฒ€์ฆ ์—†์ด ์ˆ˜๋ฝํ•˜๊ณ  ํ•˜์œ„ API์— ์ „๋‹ฌํ•˜๋Š” ๋ช…๋ฐฑํ•œ ๋ฐ˜ํŒจํ„ด์œผ๋กœ, MCP ๊ถŒํ•œ ์‚ฌ์–‘์„ ์œ„๋ฐ˜ํ•ฉ๋‹ˆ๋‹ค.

    ๋ณด์•ˆ ์˜ํ–ฅ
  • ํ†ต์ œ ํšŒํ”ผ: ํด๋ผ์ด์–ธํŠธ์—์„œ API๋กœ ์ง์ ‘ ํ† ํฐ ์‚ฌ์šฉ ์‹œ ํ•ต์‹ฌ ์†๋„ ์ œํ•œ, ๊ฒ€์ฆ, ๋ชจ๋‹ˆํ„ฐ๋ง ์šฐํšŒ
  • ๊ฐ์‚ฌ ์ถ”์  ๋ฌด๊ฒฐ์„ฑ ํ›ผ์†: ์ƒ์œ„ ๋ฐœ๊ธ‰ ํ† ํฐ ๋•Œ๋ฌธ์— ํด๋ผ์ด์–ธํŠธ ์‹๋ณ„ ๋ถˆ๊ฐ€๋Šฅ, ์‚ฌ๊ณ  ์กฐ์‚ฌ ๋ถˆ๊ฐ€
  • ํ”„๋ก์‹œ ๋ฐ์ดํ„ฐ ์œ ์ถœ: ๊ฒ€์ฆ๋˜์ง€ ์•Š์€ ํ† ํฐ์œผ๋กœ ์•…์„ฑ ํ–‰์œ„์ž๊ฐ€ ์„œ๋ฒ„๋ฅผ ๋ถˆ๋ฒ• ๋ฐ์ดํ„ฐ ์ ‘๊ทผ ํ”„๋ก์‹œ๋กœ ์‚ฌ์šฉ
  • ์‹ ๋ขฐ ๊ฒฝ๊ณ„ ์œ„๋ฐ˜: ํ† ํฐ ์ถœ์ฒ˜ ํ™•์ธ ๋ถˆ๊ฐ€ ์‹œ ํ•˜์œ„ ์„œ๋น„์Šค ์‹ ๋ขฐ ๊ฐ€์ • ๋ถ•๊ดด
  • ๋‹ค์ค‘ ์„œ๋น„์Šค ๊ณต๊ฒฉ ํ™•์‚ฐ: ์—ฌ๋Ÿฌ ์„œ๋น„์Šค์—์„œ ์ˆ˜๋ฝ๋œ ์†์ƒ๋œ ํ† ํฐ์œผ๋กœ ์ธก๋ฉด ์ด๋™ ๊ฐ€๋Šฅ
  • ํ•„์ˆ˜ ๋ณด์•ˆ ์ œ์–ด

    ๋น„ํ˜‘์ƒ ์š”๊ตฌ์‚ฌํ•ญ:

  • ํ† ํฐ ๊ฒ€์ฆ: MCP ์„œ๋ฒ„๋Š” MCP ์„œ๋ฒ„ ๋Œ€์ƒ์ด ์•„๋‹Œ ํ† ํฐ์„ ์ ˆ๋Œ€ ์ˆ˜๋ฝํ•˜์ง€ ๋ง์•„์•ผ ํ•จ
  • ๋Œ€์ƒ ๊ฒ€์ฆ: ํ† ํฐ์˜ audience ํด๋ ˆ์ž„์ด MCP ์„œ๋ฒ„ ์‹ ์›๊ณผ ์ผ์น˜ํ•˜๋Š”์ง€ ํ•ญ์ƒ ํ™•์ธ
  • ์ ์ ˆํ•œ ํ† ํฐ ์ˆ˜๋ช… ๊ด€๋ฆฌ: ์งง์€ ์ˆ˜๋ช…์˜ ์•ก์„ธ์Šค ํ† ํฐ๊ณผ ์•ˆ์ „ํ•œ ๊ฐฑ์‹  ๊ด€ํ–‰ ๊ตฌํ˜„
  • AI ์‹œ์Šคํ…œ ๊ณต๊ธ‰๋ง ๋ณด์•ˆ

    ๊ณต๊ธ‰๋ง ๋ณด์•ˆ์€ ์ „ํ†ต์ ์ธ ์†Œํ”„ํŠธ์›จ์–ด ์ข…์†์„ฑ์„ ๋„˜์–ด AI ์ƒํƒœ๊ณ„ ์ „์ฒด๋ฅผ ํฌ๊ด„ํ•ฉ๋‹ˆ๋‹ค. ์ตœ์‹  MCP ๊ตฌํ˜„์€ AI ๊ด€๋ จ ๋ชจ๋“  ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ์—„๊ฒฉํžˆ ๊ฒ€์ฆ ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋งํ•ด์•ผ ํ•˜๋ฉฐ, ๊ฐ ์š”์†Œ๋Š” ์‹œ์Šคํ…œ ๋ฌด๊ฒฐ์„ฑ์„ ์†์ƒ์‹œํ‚ฌ ์ž ์žฌ์  ์ทจ์•ฝ์ ์„ ๋‚ดํฌํ•ฉ๋‹ˆ๋‹ค.

    ํ™•๋Œ€๋œ AI ๊ณต๊ธ‰๋ง ๊ตฌ์„ฑ์š”์†Œ

    ์ „ํ†ต์  ์†Œํ”„ํŠธ์›จ์–ด ์ข…์†์„ฑ:

  • ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ฐ ํ”„๋ ˆ์ž„์›Œํฌ
  • ์ปจํ…Œ์ด๋„ˆ ์ด๋ฏธ์ง€ ๋ฐ ๋ฒ ์ด์Šค ์‹œ์Šคํ…œ
  • ๊ฐœ๋ฐœ ๋„๊ตฌ ๋ฐ ๋นŒ๋“œ ํŒŒ์ดํ”„๋ผ์ธ
  • ์ธํ”„๋ผ ๊ตฌ์„ฑ์š”์†Œ ๋ฐ ์„œ๋น„์Šค
  • AI ์ „์šฉ ๊ณต๊ธ‰๋ง ์š”์†Œ:

  • ๊ธฐ์ดˆ ๋ชจ๋ธ: ์—ฌ๋Ÿฌ ๊ณต๊ธ‰์ž์˜ ์‚ฌ์ „ ํ•™์Šต ๋ชจ๋ธ๋กœ ์ถœ์ฒ˜ ๊ฒ€์ฆ ํ•„์š”
  • ์ž„๋ฒ ๋”ฉ ์„œ๋น„์Šค: ์™ธ๋ถ€ ๋ฒกํ„ฐํ™” ๋ฐ ์˜๋ฏธ ๊ธฐ๋ฐ˜ ๊ฒ€์ƒ‰ ์„œ๋น„์Šค
  • ์ปจํ…์ŠคํŠธ ์ œ๊ณต์ž: ๋ฐ์ดํ„ฐ ์†Œ์Šค, ์ง€์‹ ๋ฒ ์ด์Šค, ๋ฌธ์„œ ์ €์žฅ์†Œ
  • ์„œ๋“œํŒŒํ‹ฐ API: ์™ธ๋ถ€ AI ์„œ๋น„์Šค, ML ํŒŒ์ดํ”„๋ผ์ธ, ๋ฐ์ดํ„ฐ ์ฒ˜๋ฆฌ ์—”๋“œํฌ์ธํŠธ
  • ๋ชจ๋ธ ์•„ํ‹ฐํŒฉํŠธ: ๊ฐ€์ค‘์น˜, ๊ตฌ์„ฑ, ์„ธ๋ฐ€ ํŠœ๋‹ ๋ชจ๋ธ ๋ณ€ํ˜•
  • ํ•™์Šต ๋ฐ์ดํ„ฐ ์†Œ์Šค: ๋ชจ๋ธ ํ›ˆ๋ จ ๋ฐ ์„ธ๋ฐ€ ์กฐ์ •์— ์‚ฌ์šฉ๋˜๋Š” ๋ฐ์ดํ„ฐ์…‹
  • ํฌ๊ด„์ ์ธ ๊ณต๊ธ‰๋ง ๋ณด์•ˆ ์ „๋žต

    ๊ตฌ์„ฑ์š”์†Œ ๊ฒ€์ฆ ๋ฐ ์‹ ๋ขฐ
  • ์ถœ์ฒ˜ ๊ฒ€์ฆ: AI ๊ตฌ์„ฑ์š”์†Œ ํ†ตํ•ฉ ์ „ ์ถœ์ฒ˜, ๋ผ์ด์„ ์Šค, ๋ฌด๊ฒฐ์„ฑ ํ™•์ธ
  • ๋ณด์•ˆ ํ‰๊ฐ€: ๋ชจ๋ธ, ๋ฐ์ดํ„ฐ ์†Œ์Šค, AI ์„œ๋น„์Šค ์ทจ์•ฝ์  ์Šค์บ” ๋ฐ ๋ณด์•ˆ ๋ฆฌ๋ทฐ
  • ํ‰ํŒ ๋ถ„์„: AI ์„œ๋น„์Šค ๊ณต๊ธ‰์ž ๋ณด์•ˆ ์ด๋ ฅ ๋ฐ ๊ด€ํ–‰ ํ‰๊ฐ€
  • ์ค€์ˆ˜ ๊ฒ€์ฆ: ๋ชจ๋“  ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ ์กฐ์ง ๋ณด์•ˆ ๋ฐ ๊ทœ์ œ ๊ธฐ์ค€ ์ถฉ์กฑ ํ™•์ธ
  • ์•ˆ์ „ํ•œ ๋ฐฐํฌ ํŒŒ์ดํ”„๋ผ์ธ
  • ์ž๋™ํ™” CI/CD ๋ณด์•ˆ: ์ž๋™ ๋ฐฐํฌ ํŒŒ์ดํ”„๋ผ์ธ ์ „๋ฐ˜์— ๋ณด์•ˆ ์Šค์บ” ํ†ตํ•ฉ
  • ์•„ํ‹ฐํŒฉํŠธ ๋ฌด๊ฒฐ์„ฑ: ๋ชจ๋“  ๋ฐฐํฌ ์•„ํ‹ฐํŒฉํŠธ(์ฝ”๋“œ, ๋ชจ๋ธ, ๊ตฌ์„ฑ)์— ๋Œ€ํ•œ ์•”ํ˜ธํ™” ๊ฒ€์ฆ
  • ์ ์ง„์  ๋ฐฐํฌ: ๊ฐ ๋‹จ๊ณ„์—์„œ ๋ณด์•ˆ ๊ฒ€์ฆ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๋‹จ๊ณ„๋ณ„ ๋ฐฐํฌ ์ „๋žต ์‚ฌ์šฉ
  • ์‹ ๋ขฐ ๊ฐ€๋Šฅํ•œ ์•„ํ‹ฐํŒฉํŠธ ์ €์žฅ์†Œ: ๊ฒ€์ฆ๋œ ์•ˆ์ „ ์ €์žฅ์†Œ ๋ฐ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์—์„œ๋งŒ ๋ฐฐํฌ
  • ์ง€์†์  ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ๋Œ€์‘
  • ์ข…์†์„ฑ ์Šค์บ”: ๋ชจ๋“  ์†Œํ”„ํŠธ์›จ์–ด ๋ฐ AI ๊ตฌ์„ฑ์š”์†Œ ์ข…์†์„ฑ์— ๋Œ€ํ•œ ์ทจ์•ฝ์  ์ง€์† ๋ชจ๋‹ˆํ„ฐ๋ง
  • ๋ชจ๋ธ ๋ชจ๋‹ˆํ„ฐ๋ง: ๋ชจ๋ธ ๋™์ž‘, ์„ฑ๋Šฅ ๋ณ€๋™, ๋ณด์•ˆ ์ด์ƒ ์ง€์† ํ‰๊ฐ€
  • ์„œ๋น„์Šค ์ƒํƒœ ์ถ”์ : ์™ธ๋ถ€ AI ์„œ๋น„์Šค์˜ ๊ฐ€์šฉ์„ฑ, ๋ณด์•ˆ ์‚ฌ๊ณ  ๋ฐ ์ •์ฑ… ๋ณ€๊ฒฝ ๋ชจ๋‹ˆํ„ฐ๋ง
  • ์œ„ํ˜‘ ์ธํ…”๋ฆฌ์ „์Šค ํ†ตํ•ฉ: AI ๋ฐ ML ๋ณด์•ˆ ์œ„ํ—˜ ๊ด€๋ จ ์œ„ํ˜‘ ํ”ผ๋“œ ํ†ตํ•ฉ
  • ์ ‘๊ทผ ์ œ์–ด ๋ฐ ์ตœ์†Œ ๊ถŒํ•œ ์›์น™
  • ๊ตฌ์„ฑ์š”์†Œ๋ณ„ ๊ถŒํ•œ ์ œํ•œ: ๋น„์ฆˆ๋‹ˆ์Šค ํ•„์š”์— ๋”ฐ๋ฅธ ๋ชจ๋ธ, ๋ฐ์ดํ„ฐ, ์„œ๋น„์Šค ์ ‘๊ทผ ์ œํ•œ
  • ์„œ๋น„์Šค ๊ณ„์ • ๊ด€๋ฆฌ: ์ตœ์†Œ ๊ถŒํ•œ์ด ํ• ๋‹น๋œ ์ „์šฉ ์„œ๋น„์Šค ๊ณ„์ • ์šด์˜
  • ๋„คํŠธ์›Œํฌ ๋ถ„ํ• : AI ๊ตฌ์„ฑ์š”์†Œ ๊ฒฉ๋ฆฌ ๋ฐ ์„œ๋น„์Šค ๊ฐ„ ๋„คํŠธ์›Œํฌ ์ ‘๊ทผ ์ œํ•œ
  • API ๊ฒŒ์ดํŠธ์›จ์ด ์ œ์–ด: ์ค‘์•™ ์ง‘์ค‘์‹ API ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์™ธ๋ถ€ AI ์„œ๋น„์Šค ์ ‘๊ทผ ํ†ต์ œ ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง
  • ์‚ฌ๊ฑด ๋Œ€์‘ ๋ฐ ๋ณต๊ตฌ
  • ์‹ ์† ๋Œ€์‘ ์ ˆ์ฐจ: ์†์ƒ๋œ AI ๊ตฌ์„ฑ์š”์†Œ ํŒจ์น˜ ๋˜๋Š” ๊ต์ฒด๋ฅผ ์œ„ํ•œ ์ˆ˜๋ฆฝ๋œ ํ”„๋กœ์„ธ์Šค
  • ์ž๊ฒฉ ์ฆ๋ช… ๊ฐฑ์‹ : ๋น„๋ฐ€, API ํ‚ค, ์„œ๋น„์Šค ์ž๊ฒฉ์ฆ๋ช… ์ž๋™ ๊ฐฑ์‹  ์‹œ์Šคํ…œ
  • ๋กค๋ฐฑ ๊ธฐ๋Šฅ: ์•Œ๋ ค์ง„ ์ •์ƒ ๋ฒ„์ „์œผ๋กœ ์‹ ์† ๋ณต๊ท€ ๊ธฐ๋Šฅ
  • ๊ณต๊ธ‰๋ง ์นจํ•ด ๋ณต๊ตฌ: ์ƒ๋ฅ˜ AI ์„œ๋น„์Šค ์†์ƒ์— ๋Œ€์‘ํ•˜๋Š” ๊ตฌ์ฒด์  ์ ˆ์ฐจ
  • Microsoft ๋ณด์•ˆ ๋„๊ตฌ ๋ฐ ํ†ตํ•ฉ

    GitHub Advanced Security๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํฌ๊ด„์  ๊ณต๊ธ‰๋ง ๋ณดํ˜ธ ๊ธฐ๋Šฅ ์ œ๊ณต:

  • ๋น„๋ฐ€ ์Šค์บ๋‹: ์ €์žฅ์†Œ ๋‚ด ์ž๊ฒฉ ์ฆ๋ช…, API ํ‚ค, ํ† ํฐ ์ž๋™ ํƒ์ง€
  • ์ข…์†์„ฑ ์Šค์บ๋‹: ์˜คํ”ˆ์†Œ์Šค ์ข…์†์„ฑ ๋ฐ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ทจ์•ฝ์  ํ‰๊ฐ€
  • CodeQL ๋ถ„์„: ๋ณด์•ˆ ์ทจ์•ฝ์  ๋ฐ ์ฝ”๋“œ ๋ฌธ์ œ์— ๋Œ€ํ•œ ์ •์  ์ฝ”๋“œ ๋ถ„์„
  • ๊ณต๊ธ‰๋ง ์ธ์‚ฌ์ดํŠธ: ์ข…์†์„ฑ ๊ฑด๊ฐ• ์ƒํƒœ ๋ฐ ๋ณด์•ˆ ํ˜„ํ™ฉ ๊ฐ€์‹œ์„ฑ
  • Azure DevOps ๋ฐ Azure Repos ํ†ตํ•ฉ:

  • Microsoft ๊ฐœ๋ฐœ ํ”Œ๋žซํผ ์ „๋ฐ˜์— ๊ฑธ์นœ ์›ํ™œํ•œ ๋ณด์•ˆ ์Šค์บ” ํ†ตํ•ฉ
  • AI ์›Œํฌ๋กœ๋“œ์šฉ Azure Pipelines ๋‚ด ์ž๋™ ๋ณด์•ˆ ๊ฒ€์‚ฌ
  • ์•ˆ์ „ํ•œ AI ๊ตฌ์„ฑ์š”์†Œ ๋ฐฐํฌ๋ฅผ ์œ„ํ•œ ์ •์ฑ… ์‹œํ–‰
  • Microsoft ๋‚ด๋ถ€ ๊ด€ํ–‰:

    Microsoft๋Š” ๋ชจ๋“  ์ œํ’ˆ์—์„œ ๊ด‘๋ฒ”์œ„ํ•œ ๊ณต๊ธ‰๋ง ๋ณด์•ˆ ๊ด€ํ–‰์„ ๊ตฌํ˜„ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

    ์ž์„ธํ•œ ๋‚ด์šฉ์€ The Journey to Secure the Software Supply Chain at Microsoft์—์„œ ํ™•์ธํ•˜์„ธ์š”.

    ๊ธฐ์ดˆ ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€

    MCP ๊ตฌํ˜„์€ ์กฐ์ง์˜ ๊ธฐ์กด ๋ณด์•ˆ ํƒœ์„ธ๋ฅผ ์ƒ์† ๋ฐ ํ™•์žฅํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ์ดˆ ๋ณด์•ˆ ๊ด€ํ–‰์„ ๊ฐ•ํ™”ํ•˜๋ฉด AI ์‹œ์Šคํ…œ ๋ฐ MCP ๋ฐฐํฌ์˜ ์ „๋ฐ˜์  ๋ณด์•ˆ์„ ํฌ๊ฒŒ ํ–ฅ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    ํ•ต์‹ฌ ๋ณด์•ˆ ๊ธฐ๋ณธ ์›์น™

    ์•ˆ์ „ํ•œ ๊ฐœ๋ฐœ ๊ด€ํ–‰
  • OWASP ์ค€์ˆ˜: OWASP Top 10 ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ทจ์•ฝ์  ๋Œ€๋น„
  • AI ํŠนํ™” ๋ณดํ˜ธ: OWASP LLMs Top 10์— ๋Œ€ํ•œ ์ œ์–ด ์ ์šฉ
  • ์•ˆ์ „ํ•œ ๋น„๋ฐ€ ๊ด€๋ฆฌ: ํ† ํฐ, API ํ‚ค, ๋ฏผ๊ฐ ๊ตฌ์„ฑ ๋ฐ์ดํ„ฐ ์ „์šฉ ๊ธˆ๊ณ  ์‚ฌ์šฉ
  • ์ข…๋‹จ ๊ฐ„ ์•”ํ˜ธํ™”: ๋ชจ๋“  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ตฌ์„ฑ์š”์†Œ์™€ ๋ฐ์ดํ„ฐ ํ๋ฆ„์— ์•ˆ์ „ํ•œ ํ†ต์‹  ๊ตฌํ˜„
  • ์ž…๋ ฅ ๊ฒ€์ฆ: ๋ชจ๋“  ์‚ฌ์šฉ์ž ์ž…๋ ฅ, API ํŒŒ๋ผ๋ฏธํ„ฐ, ๋ฐ์ดํ„ฐ ์†Œ์Šค์— ๋Œ€ํ•œ ์—„๊ฒฉํ•œ ๊ฒ€์ฆ
  • ์ธํ”„๋ผ ๊ตฌ์กฐ ๊ฐ•ํ™”
  • ๋‹ค์ค‘ ์š”์†Œ ์ธ์ฆ: ๋ชจ๋“  ๊ด€๋ฆฌ์ž ๋ฐ ์„œ๋น„์Šค ๊ณ„์ •์— MFA ํ•„์ˆ˜
  • ํŒจ์น˜ ๊ด€๋ฆฌ: ์šด์˜์ฒด์ œ, ํ”„๋ ˆ์ž„์›Œํฌ, ์ข…์†์„ฑ์— ๋Œ€ํ•œ ์ž๋™ํ™”๋œ ์ ์‹œ ํŒจ์น˜
  • ID ๊ณต๊ธ‰์ž ํ†ตํ•ฉ: ๊ธฐ์—… ID ๊ณต๊ธ‰์ž(์˜ˆ: Microsoft Entra ID, Active Directory)๋ฅผ ํ†ตํ•œ ์ค‘์•™ ์ง‘์ค‘์‹ ID ๊ด€๋ฆฌ
  • ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ: MCP ๊ตฌ์„ฑ์š”์†Œ์˜ ๋…ผ๋ฆฌ์  ๋ถ„๋ฆฌ๋กœ ์ธก๋ฉด ์ด๋™ ๊ฐ€๋Šฅ์„ฑ ์ œํ•œ
  • ์ตœ์†Œ ๊ถŒํ•œ ์›์น™: ๋ชจ๋“  ์‹œ์Šคํ…œ ๊ตฌ์„ฑ์š”์†Œ์™€ ๊ณ„์ •์— ์ตœ์†Œ ์š”๊ตฌ ๊ถŒํ•œ ์ ์šฉ
  • ๋ณด์•ˆ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ํƒ์ง€
  • ํฌ๊ด„์  ๋กœ๊น…: AI ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ™œ๋™ ๋ฐ MCP ํด๋ผ์ด์–ธํŠธ-์„œ๋ฒ„ ์ƒํ˜ธ์ž‘์šฉ ์ƒ์„ธ ๊ธฐ๋ก
  • SIEM ํ†ตํ•ฉ: ์ด์ƒ ํƒ์ง€๋ฅผ ์œ„ํ•œ ์ค‘์•™์ง‘์ค‘์‹ ๋ณด์•ˆ ์ •๋ณด ๋ฐ ์ด๋ฒคํŠธ ๊ด€๋ฆฌ
  • ํ–‰๋™ ๋ถ„์„: ์‹œ์Šคํ…œ ๋ฐ ์‚ฌ์šฉ์ž ํ–‰๋™์˜ ๋น„์ •์ƒ ํŒจํ„ด์„ ํƒ์ง€ํ•˜๋Š” AI ๊ธฐ๋ฐ˜ ๋ชจ๋‹ˆํ„ฐ๋ง
  • ์œ„ํ˜‘ ์ธํ…”๋ฆฌ์ „์Šค: ์™ธ๋ถ€ ์œ„ํ˜‘ ํ”ผ๋“œ ๋ฐ ์นจํ•ด ์ง€ํ‘œ(IOC) ํ†ตํ•ฉ
  • ์‚ฌ๊ฑด ๋Œ€์‘: ๋ณด์•ˆ ์‚ฌ๊ณ  ํƒ์ง€, ๋Œ€์‘, ๋ณต๊ตฌ๋ฅผ ์œ„ํ•œ ๋ช…ํ™•ํ•œ ์ ˆ์ฐจ
  • ์ œ๋กœ ํŠธ๋Ÿฌ์ŠคํŠธ ์•„ํ‚คํ…์ฒ˜
  • ์ ˆ๋Œ€ ์‹ ๋ขฐ ๊ธˆ์ง€, ํ•ญ์ƒ ๊ฒ€์ฆ: ์‚ฌ์šฉ์ž, ๋””๋ฐ”์ด์Šค, ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ์ง€์† ๊ฒ€์ฆ
  • ๋งˆ์ดํฌ๋กœ ์„ธ๋ถ„ํ™”: ๊ฐœ๋ณ„ ์›Œํฌ๋กœ๋“œ ๋ฐ ์„œ๋น„์Šค ๊ฒฉ๋ฆฌ๋ฅผ ์œ„ํ•œ ์„ธ๋ถ„ํ™”๋œ ๋„คํŠธ์›Œํฌ ์ œ์–ด
  • ID ์ค‘์‹ฌ ๋ณด์•ˆ: ๋„คํŠธ์›Œํฌ ์œ„์น˜๋ณด๋‹ค ๊ฒ€์ฆ๋œ ID ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ์ •์ฑ…
  • ์ง€์†์  ์œ„ํ—˜ ํ‰๊ฐ€: ํ˜„์žฌ ๋งฅ๋ฝ๊ณผ ํ–‰๋™์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ ๋™์  ๋ณด์•ˆ ํƒœ์„ธ ํ‰๊ฐ€
  • ์กฐ๊ฑด๋ถ€ ์ ‘๊ทผ: ์œ„ํ—˜ ์š”์†Œ, ์œ„์น˜, ๋””๋ฐ”์ด์Šค ์‹ ๋ขฐ๋„์— ๋”ฐ๋ผ ์ ์‘ํ•˜๋Š” ์ ‘๊ทผ ์ œ์–ด
  • ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ํ†ตํ•ฉ ํŒจํ„ด

    Microsoft ๋ณด์•ˆ ์ƒํƒœ๊ณ„ ํ†ตํ•ฉ
  • Microsoft Defender for Cloud: ํฌ๊ด„์  ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ํƒœ์„ธ ๊ด€๋ฆฌ
  • Azure Sentinel: AI ์›Œํฌ๋กœ๋“œ ๋ณดํ˜ธ๋ฅผ ์œ„ํ•œ ํด๋ผ์šฐ๋“œ ๋„ค์ดํ‹ฐ๋ธŒ SIEM ๋ฐ SOAR ๊ธฐ๋Šฅ
  • Microsoft Entra ID: ์กฐ๊ฑด๋ถ€ ์ ‘๊ทผ ์ •์ฑ…์„ ๊ฐ–์ถ˜ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ID ๋ฐ ์ ‘๊ทผ ๊ด€๋ฆฌ
  • Azure Key Vault: ํ•˜๋“œ์›จ์–ด ๋ณด์•ˆ ๋ชจ๋“ˆ(HSM) ์ง€์› ์ค‘์•™ ๋น„๋ฐ€ ๊ด€๋ฆฌ
  • Microsoft Purview: AI ๋ฐ์ดํ„ฐ ์†Œ์Šค ๋ฐ ์›Œํฌํ”Œ๋กœ์— ๋Œ€ํ•œ ๋ฐ์ดํ„ฐ ๊ฑฐ๋ฒ„๋„Œ์Šค ๋ฐ ๊ทœ์ • ์ค€์ˆ˜
  • ์ค€์ˆ˜ ๋ฐ ๊ฑฐ๋ฒ„๋„Œ์Šค
  • ๊ทœ์ œ ์ค€์ˆ˜ ๋งž์ถคํ™”: MCP ๊ตฌํ˜„์ด GDPR, HIPAA, SOC 2 ๋“ฑ ์‚ฐ์—…๋ณ„ ๊ทœ์ œ ์š”๊ฑด ์ถฉ์กฑ ๋ณด์žฅ
  • ๋ฐ์ดํ„ฐ ๋ถ„๋ฅ˜: AI ์‹œ์Šคํ…œ์ด ์ฒ˜๋ฆฌํ•˜๋Š” ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ ์ ์ ˆ ๋ถ„๋ฅ˜ ๋ฐ ๊ด€๋ฆฌ
  • ๊ฐ์‚ฌ ์ถ”์ : ๊ทœ์ œ ์ค€์ˆ˜ ๋ฐ ํฌ๋ Œ์‹ ์กฐ์‚ฌ๋ฅผ ์œ„ํ•œ ํฌ๊ด„์  ๋กœ๊ทธ ๊ธฐ๋ก
  • ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ ์ œ์–ด: AI ์‹œ์Šคํ…œ ์•„ํ‚คํ…์ฒ˜์— ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ ์„ค๊ณ„ ์›์น™ ๋„์ž…
  • ๋ณ€๊ฒฝ ๊ด€๋ฆฌ: AI ์‹œ์Šคํ…œ ๋ณ€๊ฒฝ์— ๋Œ€ํ•œ ๋ณด์•ˆ ๊ฒ€ํ† ๋ฅผ ์œ„ํ•œ ๊ณต์‹ ํ”„๋กœ์„ธ์Šค
  • ์ด๋Ÿฌํ•œ ๊ธฐ์ดˆ ๊ด€ํ–‰์€ MCP ํŠนํ™” ๋ณด์•ˆ ์ œ์–ด์˜ ํšจ์œจ์„ฑ์„ ๋†’์ด๊ณ  AI ๊ธฐ๋ฐ˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•œ ํฌ๊ด„์  ๋ณดํ˜ธ ๊ธฐ๋ฐ˜์„ ๋งˆ๋ จํ•ฉ๋‹ˆ๋‹ค.

    ์ฃผ์š” ๋ณด์•ˆ ์‹œ์‚ฌ์ 

  • ๊ณ„์ธตํ™”๋œ ๋ณด์•ˆ ์ ‘๊ทผ๋ฒ•: ๊ธฐ๋ณธ์ ์ธ ๋ณด์•ˆ ๊ด€ํ–‰(์•ˆ์ „ํ•œ ์ฝ”๋”ฉ, ์ตœ์†Œ ๊ถŒํ•œ, ๊ณต๊ธ‰๋ง ๊ฒ€์ฆ, ์ง€์†์  ๋ชจ๋‹ˆํ„ฐ๋ง)๊ณผ AI ํŠน์ • ์ œ์–ด๋ฅผ ๊ฒฐํ•ฉํ•˜์—ฌ ํฌ๊ด„์ ์ธ ๋ณดํ˜ธ ์ œ๊ณต
  • AI ํŠน์œ ์˜ ์œ„ํ˜‘ ํ™˜๊ฒฝ: MCP ์‹œ์Šคํ…œ์€ ํ”„๋กฌํ”„ํŠธ ์ธ์ ์…˜, ๋„๊ตฌ ์ค‘๋…, ์„ธ์…˜ ํƒˆ์ทจ, ํ˜ผ๋ž€์Šค๋Ÿฌ์šด ๋Œ€๋ฆฌ ๋ฌธ์ œ, ํ† ํฐ ์ „๋‹ฌ ์ทจ์•ฝ์ , ๊ณผ๋„ํ•œ ๊ถŒํ•œ ๋“ฑ ํŠน์ˆ˜ํ•œ ์œ„ํ—˜์— ์ง๋ฉดํ•˜๋ฉฐ ์ด๋ฅผ ์œ„ํ•ด ์ „๋ฌธ์ ์ธ ์™„ํ™”์ฑ… ํ•„์š”
  • ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ์˜ ํƒ์›”์„ฑ: ์™ธ๋ถ€ ID ๊ณต๊ธ‰์ž(Microsoft Entra ID)๋ฅผ ์‚ฌ์šฉํ•œ ๊ฐ•๋ ฅํ•œ ์ธ์ฆ ๊ตฌํ˜„, ์ ์ ˆํ•œ ํ† ํฐ ๊ฒ€์ฆ ์ ์šฉ, MCP ์„œ๋ฒ„์šฉ์œผ๋กœ ๋ช…์‹œ์ ์œผ๋กœ ๋ฐœ๊ธ‰๋˜์ง€ ์•Š์€ ํ† ํฐ์€ ์ ˆ๋Œ€ ์ˆ˜๋ฝํ•˜์ง€ ์•Š์Œ
  • AI ๊ณต๊ฒฉ ๋ฐฉ์ง€: Microsoft Prompt Shields ๋ฐ Azure Content Safety๋ฅผ ๋ฐฐํฌํ•˜์—ฌ ๊ฐ„์ ‘์ ์ธ ํ”„๋กฌํ”„ํŠธ ์ธ์ ์…˜๊ณผ ๋„๊ตฌ ์ค‘๋… ๊ณต๊ฒฉ ๋ฐฉ์–ด, ๋„๊ตฌ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ๊ฒ€์ฆ ๋ฐ ๋™์  ๋ณ€๊ฒฝ ๋ชจ๋‹ˆํ„ฐ๋ง ์ˆ˜ํ–‰
  • ์„ธ์…˜ ๋ฐ ์ „์†ก ๋ณด์•ˆ: ์‚ฌ์šฉ์ž ์‹ ์›์— ๋ฐ”์ธ๋”ฉ๋œ ์•”ํ˜ธํ•™์ ์œผ๋กœ ์•ˆ์ „ํ•˜๊ณ  ๋น„๊ฒฐ์ •์ ์ธ ์„ธ์…˜ ID ์‚ฌ์šฉ, ์ ์ ˆํ•œ ์„ธ์…˜ ์ˆ˜๋ช… ์ฃผ๊ธฐ ๊ด€๋ฆฌ ๊ตฌํ˜„, ์ธ์ฆ์— ์„ธ์…˜ ์‚ฌ์šฉ ๊ธˆ์ง€
  • OAuth ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€: ๋™์  ๋“ฑ๋ก ํด๋ผ์ด์–ธํŠธ์— ๋Œ€ํ•ด ๋ช…์‹œ์ ์ธ ์‚ฌ์šฉ์ž ๋™์˜๋ฅผ ํ†ตํ•ด ํ˜ผ๋ž€์Šค๋Ÿฌ์šด ๋Œ€๋ฆฌ ๊ณต๊ฒฉ ๋ฐฉ์ง€, PKCE๊ฐ€ ํฌํ•จ๋œ ์ ์ ˆํ•œ OAuth 2.1 ๊ตฌํ˜„, ์—„๊ฒฉํ•œ ๋ฆฌ๋””๋ ‰์…˜ URI ๊ฒ€์ฆ ์‹ค์‹œ
  • ํ† ํฐ ๋ณด์•ˆ ์›์น™: ํ† ํฐ ์ „๋‹ฌ ๋ฐ˜ํŒจํ„ด ํšŒํ”ผ, ํ† ํฐ ์ˆ˜์‹ ์ž ํด๋ ˆ์ž„ ์ฒ ์ € ๊ฒ€์ฆ, ์งง์€ ์ˆ˜๋ช… ํ† ํฐ๊ณผ ๋ณด์•ˆ ํšŒ์ „ ๊ตฌํ˜„, ๋ช…ํ™•ํ•œ ์‹ ๋ขฐ ๊ฒฝ๊ณ„ ์œ ์ง€
  • ํฌ๊ด„์  ๊ณต๊ธ‰๋ง ๋ณด์•ˆ: ๋ชจ๋ธ, ์ž„๋ฒ ๋”ฉ, ์ปจํ…์ŠคํŠธ ์ œ๊ณต์ž, ์™ธ๋ถ€ API ๋“ฑ ๋ชจ๋“  AI ์ƒํƒœ๊ณ„ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ์ „ํ†ต์ ์ธ ์†Œํ”„ํŠธ์›จ์–ด ์˜์กด์„ฑ๊ณผ ๋™์ผํ•œ ๋ณด์•ˆ ์ˆ˜์ค€์œผ๋กœ ์ทจ๊ธ‰
  • ์ง€์†์  ์ง„ํ™”: ๊ธ‰๋ณ€ํ•˜๋Š” MCP ๋ช…์„ธ์— ์ตœ์‹  ์ƒํƒœ ์œ ์ง€, ๋ณด์•ˆ ์ปค๋ฎค๋‹ˆํ‹ฐ ํ‘œ์ค€์— ๊ธฐ์—ฌ, ํ”„๋กœํ† ์ฝœ ์„ฑ์ˆ™์— ๋”ฐ๋ฅธ ์ ์‘ํ˜• ๋ณด์•ˆ ์ž์„ธ ์œ ์ง€
  • ๋งˆ์ดํฌ๋กœ์†Œํ”„ํŠธ ๋ณด์•ˆ ํ†ตํ•ฉ: Microsoft์˜ ํฌ๊ด„์  ๋ณด์•ˆ ์ƒํƒœ๊ณ„(Prompt Shields, Azure Content Safety, GitHub Advanced Security, Entra ID)๋ฅผ ํ™œ์šฉํ•˜์—ฌ MCP ๋ฐฐํฌ ๋ณดํ˜ธ ๊ฐ•ํ™”
  • ํฌ๊ด„์  ์ž๋ฃŒ

    ๊ณต์‹ MCP ๋ณด์•ˆ ๋ฌธ์„œ

  • MCP ๋ช…์„ธ (ํ˜„์žฌ: 2025-11-25)
  • MCP ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€
  • MCP ๊ถŒํ•œ ๋ถ€์—ฌ ๋ช…์„ธ
  • MCP GitHub ์ €์žฅ์†Œ
  • OWASP MCP ๋ณด์•ˆ ์ž๋ฃŒ

  • OWASP MCP Azure ๋ณด์•ˆ ๊ฐ€์ด๋“œ - Azure ๊ตฌํ˜„ ๊ฐ€์ด๋“œ๊ฐ€ ํฌํ•จ๋œ ํฌ๊ด„์  OWASP MCP Top 10
  • OWASP MCP Top 10 - ๊ณต์‹ OWASP MCP ๋ณด์•ˆ ์œ„ํ—˜
  • MCP ๋ณด์•ˆ ์„œ๋ฐ‹ ์›Œํฌ์ˆ (Sherpa) - Azure์—์„œ MCP๋ฅผ ์œ„ํ•œ ์‹ค์Šต ๋ณด์•ˆ ๊ต์œก
  • ๋ณด์•ˆ ํ‘œ์ค€ ๋ฐ ๋ชจ๋ฒ” ์‚ฌ๋ก€

  • OAuth 2.0 ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€ (RFC 9700)
  • OWASP ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ Top 10
  • ๋Œ€ํ˜• ์–ธ์–ด ๋ชจ๋ธ์šฉ OWASP Top 10
  • Microsoft ๋””์ง€ํ„ธ ๋ฐฉ์–ด ๋ณด๊ณ ์„œ
  • AI ๋ณด์•ˆ ์—ฐ๊ตฌ ๋ฐ ๋ถ„์„

  • MCP์˜ ํ”„๋กฌํ”„ํŠธ ์ธ์ ์…˜ (Simon Willison)
  • ๋„๊ตฌ ์ค‘๋… ๊ณต๊ฒฉ (Invariant Labs)
  • MCP ๋ณด์•ˆ ์—ฐ๊ตฌ ๋ธŒ๋ฆฌํ•‘ (Wiz Security)
  • ๋งˆ์ดํฌ๋กœ์†Œํ”„ํŠธ ๋ณด์•ˆ ์†”๋ฃจ์…˜

  • Microsoft Prompt Shields ๋ฌธ์„œ
  • Azure Content Safety ์„œ๋น„์Šค
  • Microsoft Entra ID ๋ณด์•ˆ
  • Azure ํ† ํฐ ๊ด€๋ฆฌ ๋ชจ๋ฒ” ์‚ฌ๋ก€
  • GitHub ๊ณ ๊ธ‰ ๋ณด์•ˆ
  • ๊ตฌํ˜„ ๊ฐ€์ด๋“œ ๋ฐ ํŠœํ† ๋ฆฌ์–ผ

  • Azure API Management๋ฅผ MCP ์ธ์ฆ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์‚ฌ์šฉ
  • MCP ์„œ๋ฒ„์™€ Microsoft Entra ID ์ธ์ฆ
  • ์•ˆ์ „ํ•œ ํ† ํฐ ์ €์žฅ ๋ฐ ์•”ํ˜ธํ™” (๋น„๋””์˜ค)
  • DevOps ๋ฐ ๊ณต๊ธ‰๋ง ๋ณด์•ˆ

  • Azure DevOps ๋ณด์•ˆ
  • Azure Repos ๋ณด์•ˆ
  • Microsoft ๊ณต๊ธ‰๋ง ๋ณด์•ˆ ์—ฌ์ •
  • ์ถ”๊ฐ€ ๋ณด์•ˆ ๋ฌธ์„œ

    ํฌ๊ด„์  ๋ณด์•ˆ ์ง€์นจ์€ ๋ณธ ์„น์…˜์˜ ์ „๋ฌธ ๋ฌธ์„œ๋ฅผ ์ฐธ์กฐํ•˜์‹ญ์‹œ์˜ค:

  • MCP ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€ 2025 - MCP ๊ตฌํ˜„์„ ์œ„ํ•œ ์™„๋ฒฝํ•œ ๋ณด์•ˆ ๋ชจ๋ฒ” ์‚ฌ๋ก€
  • Azure Content Safety ๊ตฌํ˜„ - Azure Content Safety ํ†ตํ•ฉ์— ๋Œ€ํ•œ ์‹ค์ „ ๊ตฌํ˜„ ์˜ˆ์ œ
  • MCP ๋ณด์•ˆ ์ œ์–ด 2025 - MCP ๋ฐฐํฌ๋ฅผ ์œ„ํ•œ ์ตœ์‹  ๋ณด์•ˆ ์ œ์–ด ๋ฐ ๊ธฐ๋ฒ•
  • MCP ๋ชจ๋ฒ” ์‚ฌ๋ก€ ๋น ๋ฅธ ์ฐธ์กฐ - ํ•„์ˆ˜ MCP ๋ณด์•ˆ ๊ด€ํ–‰์— ๋Œ€ํ•œ ๋น ๋ฅธ ์ฐธ์กฐ ๊ฐ€์ด๋“œ
  • ์‹ค์Šต ๋ณด์•ˆ ๊ต์œก

  • MCP ๋ณด์•ˆ ์„œ๋ฐ‹ ์›Œํฌ์ˆ (Sherpa) - Base Camp๋ถ€ํ„ฐ Summit๊นŒ์ง€ ๋‹จ๊ณ„๋ณ„ ์บ ํ”„๋ฅผ ํฌํ•จํ•œ Azure์—์„œ MCP ์„œ๋ฒ„ ๋ณด์•ˆ์„ ์œ„ํ•œ ํฌ๊ด„์  ์‹ค์Šต ์›Œํฌ์ˆ
  • OWASP MCP Azure ๋ณด์•ˆ ๊ฐ€์ด๋“œ - ๋ชจ๋“  OWASP MCP Top 10 ์œ„ํ—˜์— ๋Œ€ํ•œ ์ฐธ์กฐ ์•„ํ‚คํ…์ฒ˜ ๋ฐ ๊ตฌํ˜„ ์ง€์นจ
  • ---

    ๋‹ค์Œ ๋‹จ๊ณ„

    ๋‹ค์Œ: 3์žฅ: ์‹œ์ž‘ํ•˜๊ธฐ

    ---

    ๋ฉด์ฑ… ์กฐํ•ญ:

    ์ด ๋ฌธ์„œ๋Š” AI ๋ฒˆ์—ญ ์„œ๋น„์Šค Co-op Translator๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฒˆ์—ญ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

    ์ •ํ™•์„ฑ์„ ์œ„ํ•ด ์ตœ์„ ์„ ๋‹คํ•˜๊ณ  ์žˆ์ง€๋งŒ, ์ž๋™ ๋ฒˆ์—ญ์—๋Š” ์˜ค๋ฅ˜๋‚˜ ๋ถ€์ •ํ™•ํ•œ ๋‚ด์šฉ์ด ํฌํ•จ๋  ์ˆ˜ ์žˆ์Œ์„ ์œ ์˜ํ•˜์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค.

    ์›๋ฌธ ๋ฌธ์„œ๋Š” ํ•ด๋‹น ์–ธ์–ด์˜ ๊ถŒ์œ„ ์žˆ๋Š” ์ถœ์ฒ˜๋กœ ๊ฐ„์ฃผ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

    ์ค‘์š”ํ•œ ์ •๋ณด์˜ ๊ฒฝ์šฐ ์ „๋ฌธ์ ์ธ ์ธ๊ฐ„ ๋ฒˆ์—ญ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

    ๋ณธ ๋ฒˆ์—ญ ์‚ฌ์šฉ์œผ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•˜๋Š” ์˜คํ•ด๋‚˜ ํ•ด์„์ƒ์˜ ๋ฌธ์ œ์— ๋Œ€ํ•ด์„œ๋Š” ๋‹น์‚ฌ๊ฐ€ ์ฑ…์ž„์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

    MCP Academy — microsoft/mcp-for-beginners