When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic

📅 2026-09-16
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
"This study addresses the challenge that MCP traffic in enterprise networks exhibits behavior similar to malware C2 beacons, making it difficult for traditional NIDS to distinguish. The research establishes a Docker-based test environment to simulate MCP JSON-RPC traffic patterns under various TLS conditions, evaluating the performance of Suricata signature matching and RITA behavioral scoring. This work proposes a set of native network indicators for AI agents, including Agent-Native ALPN and standardized out-of-band headers, to enhance the detection capabilities of NIDS for generative AI inference loop traffic. Experimental results demonstrate that, across all tested conditions, MCP traffic consistently evades detection, with a uniform behavioral beacon score of 0.0 and minimal content alerts."
📝 Abstract
The Model Context Protocol (MCP) standardizes communication between autonomous Artificial Intelligence (AI) agents and remote tools over Streamable HTTP. This shift introduces a class of machine-generated, authenticated, and high-frequency JSON-RPC traffic directly into enterprise networks. Enterprise network defenders have historically relied on machine-like cadence as an Indicator of Compromise (IoC). In this study, we show that without explicit network-layer indication, MCP traffic structurally and temporally resembles Command and Control (C2) beaconing behavior, specifically the polling architectures used by advanced persistent threats like Cobalt Strike. Counter to theoretical assumptions about machine-generated polling, our measurements reveal a visibility gap: standard enterprise Intrusion Detection Systems (IDS) and behavioral beacon-scoring frameworks do not classify MCP remote tool usage as anomalous within our testbed scope. Through a controlled Docker-based testbed simulating eleven mathematically defined traffic profiles across three TLS conditions (Opaque, TLS-Inspected, and Cleartext), we evaluate Suricata signature matching and RITA behavioral scoring against MCP JSON-RPC patterns. Our results show that MCP traffic, regardless of temporal smearing (jitter) or TLS inspection visibility, evades detection within this configuration, yielding a consistent 0.0 behavioral beacon score and near-zero IDS content alerts under the Emerging Threats (ET) Open ruleset. While opaque TLS obscures HTTP content, it exposes agent traffic to flow-level temporal analysis; however, NIDS heuristics tuned to identify traditional malware do not flag the lognormal inter-arrival distributions characteristic of generative AI reasoning loops. To address this gap, we propose an agent-native network indication standard including Agent-Native ALPN and standardized out-of-band headers.
Problem

Research questions and friction points this paper is trying to address.

Model Context Protocol
Intrusion Detection Systems
Command and Control
beaconing behavior
enterprise networks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Model Context Protocol
Intrusion Detection Systems
C2 beaconing
Agent-Native ALPN
behavioral scoring
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Muhammad Abdullah Sohail
University of Calgary