2026-07-28 ワシントン州立大学(WSU)
<関連情報>
- https://news.wsu.edu/press-release/2026/07/28/computer-scientists-design-nosyneighbor-a-cyberattack-to-prevent-cyberattacks/
- https://dl.acm.org/doi/10.1145/3783983
階層型リアルタイムシステムにおけるランダム化に基づく防御の回避について On Evading Randomization-Based Defense in Hierarchical Real-Time Systems
Vijay Banerjee、Sena Hounsinou、Yanyan Zhuang、Monowar Hasan、Gedare Bloom
ACM Transactions on Cyber-Physical Systems Published: 21 April 2026
DOI:https://doi.org/10.1145/3783983

Abstract
Security for real-time systems is increasingly important with the growth of connected real-time systems in safety-critical domains such as automotive, medical, and avionics. A crucial aspect of securing such systems is to understand the attacks that the current techniques cannot effectively safeguard against. Especially relevant are vulnerabilities of real-time systems arising from their rigid temporal guarantees and attacks that exploit such vulnerabilities. Randomization-based defense techniques can reduce side-channel inference, but such techniques are limited due to the strict timing bounds of real-time systems. In this article, we design and analyze NosyNeighbor, an inter-partition side-channel attack that exploits the timing guarantees of real-time systems to infer the timing parameters of a safety-critical task in a hierarchical system. Using an adaptive technique, NosyNeighbor can improve its inference over time and evade randomization-based defense. Experimental results show that NosyNeighbor can infer victim task execution with a precision of roughly 73% under normal system load, and with a recall of about 35% using multiple malicious tasks across partitions. NosyNeighbor is also effective under the common attack model with two malicious tasks in the system, with a precision of 64%.
