Researchers Unveil NosyNeighbor: A Stealthy Side-Channel Attack Targeting Time-Critical Systems
A team of researchers from Washington State University (WSU), the University of Colorado Colorado Springs, and Metro State University has developed NosyNeighbor, a novel side-channel attack designed to exploit vulnerabilities in time- and safety-critical computing systems. The attack, detailed in a recent publication in ACM Transactions on Cyber-Physical Systems, demonstrates how malicious actors could infer internal operations of partitioned systems such as those used in aviation, medical devices, and automotive safety without directly compromising software or algorithms.
Led by Monowar Hasan, an assistant professor at WSU’s School of Electrical Engineering & Computer Science, the project adopts an adversarial perspective to identify weaknesses in systems where multiple vendor-supplied components operate under strict timing constraints. Unlike traditional attacks, NosyNeighbor operates externally, leveraging secondary data such as task execution times to deduce the behavior of other partitions within the system. In testing, the attack achieved a 73% accuracy rate in inferring active tasks, a precision sufficient to pose significant risks to safety-critical functions.
The research highlights the growing threat to modern cyber-physical systems, which increasingly rely on multi-vendor, containerized architectures. By exploiting timing discrepancies, NosyNeighbor could enable attackers to disable critical modules such as an autonomous vehicle’s braking system or an aircraft’s navigation controls with potentially catastrophic consequences. The findings underscore the need for enhanced defenses in systems where even millisecond delays can lead to failure.
The work was supported by a National Science Foundation CAREER Award and builds on Hasan’s broader research into mitigating information leakage in time-sensitive environments. Former WSU postdoctoral researcher Vijay Banjaree, now at Argonne National Laboratory, co-led the study.
Washington State University TPRM report: https://www.rankiteo.com/company/washington-state-university
Metro State University TPRM report: https://www.rankiteo.com/company/metropolitan-sewer-district-of-greater-cincinnati
"id": "wasmet1785277752",
"linkid": "washington-state-university, metropolitan-sewer-district-of-greater-cincinnati",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Education/Research',
'location': 'Washington, USA',
'name': 'Washington State University (WSU)',
'type': 'Academic/Research Institution'},
{'industry': 'Education/Research',
'location': 'Colorado, USA',
'name': 'University of Colorado Colorado Springs',
'type': 'Academic/Research Institution'},
{'industry': 'Education/Research',
'location': 'Colorado, USA',
'name': 'Metro State University',
'type': 'Academic/Research Institution'}],
'attack_vector': 'Timing discrepancies in partitioned systems',
'description': 'Researchers from Washington State University, the University '
'of Colorado Colorado Springs, and Metro State University '
'developed NosyNeighbor, a novel side-channel attack that '
'exploits vulnerabilities in time- and safety-critical '
'computing systems. The attack infers internal operations of '
'partitioned systems (e.g., aviation, medical devices, '
'automotive safety) by leveraging secondary data such as task '
'execution times, achieving a 73% accuracy rate in inferring '
'active tasks without directly compromising software or '
'algorithms.',
'impact': {'operational_impact': 'Potential disabling of critical modules '
'(e.g., autonomous vehicle braking systems, '
'aircraft navigation controls)',
'systems_affected': 'Time- and safety-critical computing systems '
'(e.g., aviation, medical devices, automotive '
'safety)'},
'investigation_status': 'Research completed and published',
'lessons_learned': 'The attack highlights the growing threat to modern '
'cyber-physical systems relying on multi-vendor, '
'containerized architectures and the need for enhanced '
'defenses in time-sensitive environments where even '
'millisecond delays can lead to failure.',
'motivation': 'Research and vulnerability disclosure',
'post_incident_analysis': {'corrective_actions': 'Research into mitigating '
'information leakage in '
'time-sensitive environments '
'(ongoing).',
'root_causes': 'Vulnerabilities in partitioned '
'systems with strict timing '
'constraints, enabling external '
'inference of internal operations '
'via timing discrepancies.'},
'recommendations': 'Develop and implement enhanced defenses for time- and '
'safety-critical systems to mitigate side-channel attacks '
'exploiting timing discrepancies.',
'references': [{'source': 'ACM Transactions on Cyber-Physical Systems'},
{'source': 'Washington State University News'}],
'response': {'communication_strategy': 'Publication in ACM Transactions on '
'Cyber-Physical Systems'},
'threat_actor': 'Researchers (Monowar Hasan, Vijay Banjaree, et al.)',
'title': 'NosyNeighbor: A Stealthy Side-Channel Attack Targeting '
'Time-Critical Systems',
'type': 'Side-Channel Attack',
'vulnerability_exploited': 'Weaknesses in multi-vendor, containerized '
'architectures with strict timing constraints'}