MCP over Streamable HTTP scores a flat 0.0 behavioral beacon score against enterprise NIDS, jitter or TLS inspection notwithstanding
MCP traffic between an autonomous agent and remote tools structurally resembles command-and-control beaconing: regular machine-generated intervals, long-lived sessions, encrypted payloads. Controlled lab testing across eleven traffic profiles and three encryption scenarios found standard enterprise intrusion detection consistently assigned MCP activity a 0.0 behavioral beacon score, independent of temporal smearing (jitter) or whether TLS inspection was available. Encryption hides the content but exposes machine-generated timing to statistical analysis, and conventional heuristics simply do not flag the distributions that AI reasoning loops produce. For anyone deploying agents inside a corporate network this is a blind spot in both directions: real exfiltration over MCP will not trip the beacon detector, and the authors propose agent-specific protocols and standardized signaling as the fix.
↳ Follow the thread