Conceptio › Archive › arXiv CS
arXiv CSopen access

Agentic Network Traffic Monitoring

Manuel Tsoukatos et al. · arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
distributed-systemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

Agentic Network Traffic Monitoring Manuel Tsoukatos1,2 , Hayden Jananthan2 , Jeremy Kepner2 1

arXiv:2609.32778v1 [cs.AI] 26 Sep 2026

2

United States Air Force Massachusetts Institute of Technology

Abstract—As the use of agentic artificial intelligence increases in nearly every industry, there exists a widening attack surface. It is necessary to monitor agents to ensure that agents are acting in a way that is aligned with the users intent. Auditing an agent’s network traffic provides a clear record of the agent interactions. This work presents a novel approach to monitoring the network traffic of agentic systems using complex valued hypersparse traffic matrices by integrating DBOS (DataBase OS), the OneSparse PostgreSQL database, and the GraphBLAS math library. To develop these concepts an agentic simulator was constructed, allowing a varying numbers of AI agents to collectively survey a virtual environment using different strategies. The resulting network traffic matrices enable easy monitoring of the AI agents.

I. I NTRODUCTION Artificial intelligence is an incredibly fast growing field and over the last year the rise in AI agents has accelerated. The use of AI agents in web services, financial applications, and many other applications, requires that users have ways to audit and monitor agent behavior. [1]. AI agents have potential to significantly enhance efficiency, but at the same time create significant security vulnerabilities with things like prompt injections, data leaks, and adversarial actors [2]–[4]. Network traffic is at the heart of agentic systems. As the data that flows across a network from source to destination it may cross many other nodes while in transit, and the modeling/analysis of network traffic can provide insights into agent behavior [5], [6]. Traffic matrices have emerged as compact, efficient, and scalable way to monitor network traffic. A common use of traffic matrices defines rows as sources and the columns as destination. The value in a particular (row, column) position corresponds to the number of packets of information sent from that source to that destination [7]. If the sources and destinations span a large potential range (e.g., network Internet Protocol - IP - address) they can be very large. Because the vast majority of values in the matrix are 0 it is common to use hypersparse matrix to store these matrices. GraphBLAS is an open source standard library for creating and operating on hypersparse matrices [8]–[10]. More specifically for this project, the PostgreSQL extension OneSparse, binds Research was sponsored by the Department of the Air Force Artificial Intelligence Accelerator and was accomplished under Cooperative Agreement Number FA8750-19-2-1000. The views and conclusions contained in this document are those of the authors and should not be interpreted as representing the official policies, either expressed or implied, of the Department of the Air Force or the U.S. Government. The U.S. Government is authorized to reproduce and distribute reprints for Government purposes notwithstanding any copyright notation herein.

the GraphBLAS library to PostgreSQL databases and enables GraphBLAS matrices to be operated on as a PostreSQL type with an SQL table [11]. DBOS (Database-Oriented Operating System) is a durable workflow system that has become popular for supporting long running AI agents. DBOS connects to PostreSQL database to save all events as structured data in a database [12]. Recent DBOS advancements have added workflow guarantees that ensure: exactly once execution with no workflow duplication, every workflow runs to completion even if a crash occurs, and logically correct and reverse workflow actions [13]. Because agentic workflows are often complex and run for potentially very long times, DBOS and its guarantees, provide an excellent way to track and manage AI agent workflows, by saving state and allowing for durable execution [14]. Combining of these different technologies (DBOS, Graphblas, Onesparse) can be used to create a scalable robust system for tracking and analyzing agentic workflows and their networ traffic [15], [16]. Our work applies these concepts in the context of an agentic simulator that allows varying numbers of AI agents to collectively survey a virtual environment using different strategies. The resulting network traffic matrices demonstrate the ability to monitor AI agents with this approach that requires no internal knowledge of the agents. II. M ETHOD The approach taken is a customizable testbed to simulate multi-agent interaction. The goal is to try and encompass as many different scenarios as possible, in physical situations where range/distance factors may apply as well as other variations. To begin, a world map is generated. It is a twodimensional grid of specifiable variable size, with a combination of impassable walls, and passable open space. There is an orchestrator agent, fixed in place in the top left corner and its goal is to create a mental map of the ground truth environment using subagents that can move around the environment. The orchestrator and subagents have different views and actions they can take. The orchestrator only sees information that is relayed back to it from what the subagents directly observe in their immediate three by three grid surroundings. As can be seen in Figure 1 the orchestrator passes orders to the subagents which tell them to go to an unkown position. Subagents, upon moving, interact with the ground truth database with DBOS steps that write the subagents new position, and read the new surroundings. The subagents maintain local knowledge of all places they have been and do route planning based off of this knowledge. After an agent moves and observes something new,

Ground Truth

Orchestrator View

(Full map, walls, subagents)

ia te ed m Im

o) et ov + (m ge rs ed s de wl ing Or no nd l K ou ca rr Lo 3 su rts 3x po nt Re urre c

Su rro un di ng s

(Only reported information)

Subagents

M

es ov

pd (U

es at

n) io at c lo

√ A(i, j) = v + u −1

(Local Knowledge + Route Planning)

Fig. 1. Information flow diagram

Orchestrator

SIMNET

gA Lo

De

liv er

t

p tem

M

es

sa

t

ge

Postgres (world, packet log, matrices)

passed to other recipients before the final destination. Agentic systems engaging in very dynamic communications over a range of time scales and frequently timeout or abort activities. Thus, a key element to track in agentic systems is unsuccessful messages sent. For both matrices, the real component is the number of successfully delivered messages and the imaginary component is the number of unsuccessful messages sent. In both cases, the entries of a complex valued traffic matrix A are given by the following

Dashboard

DBOS (Workflows, inboxes)

Subagents

Fig. 2. Communication protocol diagram

it reports back what it has have seen. When arriving at assigned destination, the agent sends a ready message to the orchestrator who then provides a new destination. The only way the orchestrator can talk to the subagents is through a custom function that simulates network communication. In Figure 2 this is visible with the SIMNET block. This simulated networking produces network traffic logs that are then stored in a PostgreSQL Database. If the message is able to be completed by meeting the connection success criteria, it is sent to the recipient with the DBOS.send command that durably logs the message. The result of whether the message was successfully delivered is also logged with the DBOS.step command to store all traffic for later analysis. This is then displayed in dashboard for live monitoring and for visualization. The network traffic, is then aggregated into two complex valued GraphBLAS matrices using OneSparse. One matrix holds the true source to true destination of every message. A second maps all intermediary connections or hops along the route, which will differ from the first matrix if the message was

where v is the number of successful communications sent from i to j and u is the number of unsuccessful communications attempted from i to j. The total number of messages sent is given by the matrix Re(A)+Im(A). This approaches takes advantage of the builtin GraphBLAS support for complex values and is an efficient way to track a more complete picture of the network traffic. In the simulation display, only the real component is shown unless the imaginary dropped component is non-zero, in which case it is displayed as (real, imaginary). There are many potential agent control scenarios that can be explored with this simple system. The baseline scenario involves a simple heuristic where the orchestrator agents select the nearest unknown position and send to the nearest subagent ready to receive an order. The baseline scenario assumes the orchestrator has constant two way communication with the subagents with unlimited range. The subagents send reports to the orchestrator to convey information and to request a new order. When subagents receive a new order, they perform a breadth-first search (BFS) over their local knowledge of places they have seen. The baseline scenario creates many possibilities for variation that includes 1) Subagents sending peers messages with updates about their local knowledge 2) A range limitation which prevents messages from being delivered if the distance between two parties is greater than a specific value 3) Daisy chaining as a way to solve the range limitation problem where subagents can act as a mesh network and pass messages intended for other recipients to the next closest subagent or true recipient 4) Delegation that creates a hierarchy of subagents where higher ranked subagents receive general areas to explore and then divide it up amongst themselves and their subordinate subagents 5) Using an large language model (LLM) as the brain for the reasoning instead of a simple heuristic III. R ESULTS All of these different settings and design choices allow for a wide variety of robust situations to simulate agentic behavior. The traffic matrices provide a way to visualize the often invisible connections between agents as they move autonomously in any task. This testbed serves as a foundation

Mental Map

End to End

All Comms

Low range

Hierarchical

Daisy Chain

Baseline

Ground Truth

Fig. 3. The above displays the key aspects of each simulation. The rows are individual simulations, showcasing the baseline, daisy chain, hierarchical, and low-range daisy chain scenarios. The columns are the two maps (ground truth and mental map), and two traffic matrices (true source/destination pairs and all intermediary communication hops). The maps and everything besides the communication protocols were kept the same to compare the resulting traffic matrices.

for monitoring agentic behavior for enabling detecting of anomalous and adversarial behavior. Figure 3 illustrates four different scenarios. The first row demonstrates the baseline scenario with an unlimited range policy. In this snapshot the dashboard on the left most map shows the ground truth environment, where dark squares represent a free open space and light squares represent an open

space. To its right is the mental map reconstruction at 92% completion to show what progress within the simulation looks like. The highlighted squares are the target of the respectively colored subagent given by the colored circles. As is expected, the two traffic matrices showing true source/destination pairs looks identical to the all hops matrix, because there is no intermediary communication. This is what a standard operational

technology (OT) network would look like where one source goes to all destinations, and all destinations go back to that source. In this scenario an anomaly can be easy to spot because all other positions besides the first row and column should be zero. In the daisy chaining scenario there is a manhattan distance range limit of 20 squares. This scenario has run to completion and the shutdown order to end the simulation was given by the orchestrator after the mental map reached 100%. The end to end matrix has the same shape as the baseline which is expected because all messages are between the orchestrator and subagents. However, the intermediary matrix diverges because many messages were routed through closer subagents. In this example, the subagents maintain consistent connectivity and communication throughout the run. This is ideal for an agentic swarm as no time is wasted with dropped packets and subagents can continue exploring without also making moves to reconnect in range. In the hierarchical example in the third row, the orchestrator gives more general orders to its direct subordinates. The chain of command in this scenario is the orchestrator to the blue (one) and magenta (two). Blue (one) is in charge of yellow (three) and green (four). Magenta (two) is in charge of pink (five). Blue and Magenta receive orders to explore the left and right regions, respectively, which they divide up among themselves and subordinate subagents. This is visible with the colored highlighted regions which show the territory area of responsibility. Because there is no range limit here, the end to end and hops matrices are identical to each other, but because of the hierarchy are very different from the previous scenarios. Subagents one and two are the only ones interfacing with the orchestrator, collecting updates from subordinates and aggregating into updates for the orchestrator. The higher ranked subagents communicate with their subordinates in the matrix, and a very clear picture of the chain of command is visible here. This is very representative of how many AI agents spin up subagents to accomplish intermediary tasks and in this view would make any deviation from the chain of command apparent. In the final example in the fourth row, daisy chaining with a very low range of 5 squares was introduced. This essentially forced every subagent to return to within 5 squares of the orchestrator to relay the message of new findings and request new orders. This produces a significant amount of dropped packets as subagents attempt communication and are often times unable to deliver the packet even with a chain of them, due to a lack of coordinating. This does provide a useful view on the specific number (dropped packets) that could be minimized when exploring new ways to maintain connectivity in more challenging situations. IV. C ONCLUSION AND F UTURE W ORK Using a combination of DBOS and PostgreSQL to preserve the state and manage agentic workflows, and GraphBLAS to model network traffic, there is now a customizable simulation

to explore agentic communication patterns. There are a multitude of existing scenarios and configurable settings, but in the future, this involves increasing the library of things to simulate. Running experiments with this test bed at a scale of 1000s of runs across 1000s of subagents could provide useful data on agentic behavior. The system could also be used to create an artificial datasets for both normal and anomolous agentic network patterns. Future work may also entail adding this type of network monitoring into current agentic systems, as a way of auditing all communications between agents. Additionally, one could more efficiently store network traffic as the phase between delivered and dropped packets, resulting in a real matrix that holds more information than a traditional network traffic matrix with just delivered packets logged. ACKNOWLEDGMENT The authors wish to acknowledge the following individuals for their contributions and support L. Anderson, W. Arcand, D. Bestor, W. Bergeron, B. Bond, C. Byun, A. Bonn, D. Burrill, V. Gadepally, J. Gottschalk, T. Hardjono, M. Houle, M. Hubbell, M. Jones, P. Luszczek, P. Michaleas, L. Milechin, J. Mullen, C. Leiserson, C. Milner, S. Mohindra, A. Pentland, A. Prout, C. Prothmann, A. Reuther, A. Rosa, D. Rus, D. Ross, J. Ross, M. Sherman, S. Van Broekhoven, M. Weems, J. Wilkinson, C. Yee. R EFERENCES [1] S. Hosseini and H. Seilani, “The role of agentic ai in shaping a smart future: A systematic review,” Array, vol. 26, p. 100399, 2025. [2] H. Su, J. Luo, C. Liu, X. Yang, Y. Zhang, Y. Dong, and J. Zhu, “A survey on autonomy-induced security risks in large model-based agents,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. PP, pp. 1–20, 04 2026. [3] S. Murugesan, “The rise of agentic ai: Implications, concerns, and the path forward,” IEEE Intelligent Systems, vol. 40, no. 2, pp. 8–14, 2025. [4] Z. Deng, Y. Guo, C. Han, W. Ma, J. Xiong, S. Wen, and Y. Xiang, “Ai agents under threat: A survey of key security challenges and future pathways,” ACM Comput. Surv., vol. 57, Feb. 2025. [5] M. Jones, J. Kepner, A. Prout, T. Davis, W. Arcand, D. Bestor, W. Bergeron, C. Byun, V. Gadepally, M. Houle, M. Hubbell, H. Jananthan, A. Klein, L. Milechin, G. Morales, J. Mullen, R. Patel, S. Pisharody, A. Reuther, A. Rosa, S. Samsi, C. Yee, and P. Michaleas, “Deployment of real-time network traffic analysis using graphblas hypersparse matrices and d4m associative arrays,” in 2023 IEEE High Performance Extreme Computing Conference (HPEC), p. 1–8, IEEE, 2023. [6] A. Lakhina, K. Papagiannaki, M. Crovella, C. Diot, E. D. Kolaczyk, and N. Taft, “Structural analysis of network traffic flows,” SIGMETRICS Perform. Eval. Rev., vol. 32, p. 61–72, June 2004. [7] J. Kepner, K. Cho, K. Claffy, V. Gadepally, P. Michaleas, and L. Milechin, “Hypersparse neural network analysis of large-scale internet traffic,” in 2019 IEEE High Performance Extreme Computing Conference (HPEC), pp. 1–11, 2019. [8] T. A. Davis, “Algorithm 1000: Suitesparse:graphblas: Graph algorithms in the language of sparse linear algebra,” ACM Trans. Math. Softw., vol. 45, Dec. 2019. [9] T. Trigg, C. Meiners, S. Pisharody, H. Jananthan, M. Jones, A. Michaleas, T. Davis, E. Welch, W. Arcand, D. Bestor, W. Bergeron, C. Byun, V. Gadepally, M. Houle, M. Hubbell, A. Klein, P. Michaleas, L. Milechin, J. Mullen, A. Prout, A. Reuther, A. Rosa, S. Samsi, D. Stetson, C. Yee, and J. Kepner, “Hypersparse network flow analysis of packets with graphblas,” in 2022 IEEE High Performance Extreme Computing Conference (HPEC), pp. 1–7, 2022.

[10] M. Jones, J. Kepner, D. Andersen, A. Buluç, C. Byun, K. Claffy, T. Davis, W. Arcand, J. Bernays, D. Bestor, W. Bergeron, V. Gadepally, M. Houle, M. Hubbell, H. Jananthan, A. Klein, C. Meiners, L. Milechin, J. Mullen, S. Pisharody, A. Prout, A. Reuther, A. Rosa, S. Samsi, J. Sreekanth, D. Stetson, C. Yee, and P. Michaleas, “Graphblas on the edge: Anonymized high performance streaming of network traffic,” in 2022 IEEE High Performance Extreme Computing Conference (HPEC), pp. 1–8, 2022. [11] M. Pelletier and G. Szarnyas, “Onesparse: Accelerated sparse linear algebra with postgres and suitesparse,” 2024. [12] A. Skiadopoulos, Q. Li, P. Kraft, K. Kaffes, D. Hong, S. Mathew, D. Bestor, M. Cafarella, V. Gadepally, G. Graefe, J. Kepner, C. Kozyrakis, T. Kraska, M. Stonebraker, L. Suresh, and M. Zaharia, “Dbos: a dbmsoriented operating system,” Proc. VLDB Endow., vol. 15, p. 21–30, Sept. 2021. [13] Q. Li, P. Kraft, C. Kozyrakis, M. Zaharia, and M. Stonebraker, “Dbos: three years later: Q. li et al.,” The VLDB Journal, vol. 34, no. 3, p. 37, 2025. [14] M. Stonebraker, X. Zhou, P. Kraft, and Q. Li, “Consistency and correctness in data-oriented workflow systems.,” in CIDR, 2026. [15] S. Lockton, J. Kepner, M. Stonebraker, H. Jananthan, L. Anderson, W. Arcand, D. Bestor, W. Bergeron, A. Bonn, D. Burrill, C. Byun, T. Davis, V. Gadepally, M. Houle, M. Hubbell, M. Jones, P. Luszczek, P. Michaleas, L. Milechin, C. Milner, G. Morales, J. Mullen, M. Pelletier, A. Poliakov, A. Prout, A. Reuther, A. Rosa, C. Yee, and A. Pentland, “Dbos network sensing: A web services approach to collaborative awareness,” in 2025 IEEE High Performance Extreme Computing Conference (HPEC), pp. 1–8, 2025. [16] S. E. Lockton, DBOS Advanced Network Analysis Capability for Collaborative Awareness. PhD thesis, Massachusetts Institute of Technology, 2025.

Record · ID 1108664 · SHA-256 5f6904e8b0f9538c
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.