当智能体看似信标:模型上下文协议流量对网络入侵检测系统的规避
When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic
浏览论文内容
中文总结 AI 辅助
本研究揭示MCP流量在结构上类似C2信标,但现有NIDS无法检测,并提出智能体原生网络指示标准以弥补可见性缺口。
中文摘要 AI 辅助
模型上下文协议(MCP)标准化了自主人工智能(AI)智能体与远程工具之间通过流式HTTP进行的通信。这一转变将一类机器生成、经过认证且高频率的JSON-RPC流量直接引入企业网络。企业网络防御者历来依赖机器般的节奏作为入侵指标(IoC)。在本研究中,我们表明,在没有明确网络层指示的情况下,MCP流量在结构上和时间上类似于命令与控制(C2)信标行为,特别是类似于Cobalt Strike等高级持续性威胁所使用的轮询架构。与关于机器生成轮询的理论假设相反,我们的测量揭示了一个可见性缺口:标准企业入侵检测系统(IDS)和基于行为的信标评分框架在我们的测试台范围内未将MCP远程工具使用分类为异常。通过一个受控的基于Docker的测试台,模拟了三种TLS条件(不透明、TLS检查和明文)下的十一种数学定义的流量配置文件,我们评估了Suricata签名匹配和RITA行为评分对MCP JSON-RPC模式的表现。我们的结果表明,无论时间涂抹(抖动)或TLS检查可见性如何,MCP流量在此配置中都能规避检测,在Emerging Threats(ET)开放规则集下产生一致为0.0的行为信标评分和接近零的IDS内容警报。虽然不透明TLS掩盖了HTTP内容,但它使智能体流量暴露于流级时间分析;然而,针对识别传统恶意软件而调优的网络入侵检测系统(NIDS)启发式规则并未标记生成式AI推理循环特有的对数正态到达间隔分布。为解决这一缺口,我们提出了一种智能体原生的网络指示标准,包括智能体原生ALPN和标准化的带外头部。
英文摘要
The Model Context Protocol (MCP) standardizes communication between autonomous Artificial Intelligence (AI) agents and remote tools over Streamable HTTP. This shift introduces a class of machine-generated, authenticated, and high-frequency JSON-RPC traffic directly into enterprise networks. Enterprise network defenders have historically relied on machine-like cadence as an Indicator of Compromise (IoC). In this study, we show that without explicit network-layer indication, MCP traffic structurally and temporally resembles Command and Control (C2) beaconing behavior, specifically the polling architectures used by advanced persistent threats like Cobalt Strike. Counter to theoretical assumptions about machine-generated polling, our measurements reveal a visibility gap: standard enterprise Intrusion Detection Systems (IDS) and behavioral beacon-scoring frameworks do not classify MCP remote tool usage as anomalous within our testbed scope. Through a controlled Docker-based testbed simulating eleven mathematically defined traffic profiles across three TLS conditions (Opaque, TLS-Inspected, and Cleartext), we evaluate Suricata signature matching and RITA behavioral scoring against MCP JSON-RPC patterns. Our results show that MCP traffic, regardless of temporal smearing (jitter) or TLS inspection visibility, evades detection within this configuration, yielding a consistent 0.0 behavioral beacon score and near-zero IDS content alerts under the Emerging Threats (ET) Open ruleset. While opaque TLS obscures HTTP content, it exposes agent traffic to flow-level temporal analysis; however, NIDS heuristics tuned to identify traditional malware do not flag the lognormal inter-arrival distributions characteristic of generative AI reasoning loops. To address this gap, we propose an agent-native network indication standard including Agent-Native ALPN and standardized out-of-band headers.
发表机构
- University of Calgary(卡尔加里大学)
机构由 AI 辅助整理,请以论文原文为准。