研究者が「NosyNeighbor」を開発しサイバー攻撃防御に応用(Computer scientists design NosyNeighbor — a cyberattack to prevent cyberattacks)

2026-07-28 ワシントン州立大学(WSU)

ワシントン州立大学(WSU)の研究チームは、クラウド環境で利用者の情報漏えいを防ぐため、新たな防御技術「NosyNeighbor」を開発した。研究成果は、情報セキュリティ分野の国際会議で発表された。クラウドでは複数の利用者が同じサーバー資源を共有するため、CPUキャッシュなどの共有資源を悪用するサイドチャネル攻撃によって、暗号鍵や機密データが盗み取られる危険性がある。NosyNeighborは、この攻撃手法を逆に利用し、防御側が意図的に共有資源へアクセスしてノイズを発生させることで、攻撃者が取得するタイミング情報を乱し、情報の推定を困難にする仕組みである。実験では、性能低下を最小限に抑えながらサイドチャネル攻撃の精度を大幅に低下させられることを確認した。専用ハードウェアを必要とせず、既存のクラウド環境へ比較的容易に導入できる点も特徴である。本研究は、クラウドコンピューティングや仮想化環境におけるデータ保護を強化し、安全性と運用効率を両立する新たなセキュリティ対策として期待される。

<関連情報>

階層型リアルタイムシステムにおけるランダム化に基づく防御の回避について On Evading Randomization-Based Defense in Hierarchical Real-Time Systems

Vijay Banerjee、Sena Hounsinou、Yanyan Zhuang、Monowar Hasan、Gedare Bloom
ACM Transactions on Cyber-Physical Systems  Published: 21 April 2026
DOI:https://doi.org/10.1145/3783983

研究者が「NosyNeighbor」を開発しサイバー攻撃防御に応用(Computer scientists design NosyNeighbor — a cyberattack to prevent cyberattacks)

Abstract

Security for real-time systems is increasingly important with the growth of connected real-time systems in safety-critical domains such as automotive, medical, and avionics. A crucial aspect of securing such systems is to understand the attacks that the current techniques cannot effectively safeguard against. Especially relevant are vulnerabilities of real-time systems arising from their rigid temporal guarantees and attacks that exploit such vulnerabilities. Randomization-based defense techniques can reduce side-channel inference, but such techniques are limited due to the strict timing bounds of real-time systems. In this article, we design and analyze NosyNeighbor, an inter-partition side-channel attack that exploits the timing guarantees of real-time systems to infer the timing parameters of a safety-critical task in a hierarchical system. Using an adaptive technique, NosyNeighbor can improve its inference over time and evade randomization-based defense. Experimental results show that NosyNeighbor can infer victim task execution with a precision of roughly 73% under normal system load, and with a recall of about 35% using multiple malicious tasks across partitions. NosyNeighbor is also effective under the common attack model with two malicious tasks in the system, with a precision of 64%.

1604情報ネットワーク
ad
ad
Follow
ad
タイトルとURLをコピーしました