Cybersecurity Experts Develop NosyNeighbor Defense

WSU

PULLMAN, Wash. - Protecting sensitive, precision-timed computing systems requires understanding the nature of cyberthreats.

So researchers from Washington State University teamed up with experts at the University of Colorado Colorado Springs and Metro State University to design an attack - dubbed NosyNeighbor - that lurks on the sidelines of time- and safety-critical computer systems, "infers" what's happening inside and adapts its malicious approach.

In initial testing, NosyNeighbor evaded common cyberdefenses, showing promise as a potential tool for building protections into systems that operate airplane navigation, medical devices like pacemakers, and anti-lock brake systems in cars, among other uses.

Closeup of Monowar Hasan.
Monowar Hasan

"If we know those vulnerabilities, then we can better prepare to defend against them," said Monowar Hasan, co-author of a new publication on the work and an assistant professor in WSU's School of Electrical Engineering & Computer Science. "It's always good to think from an adversarial point of view, so we know what the worst may be. When I teach in cybersecurity courses, I always say to students: 'Think like an attacker. If we're given a computer system, how can we break it, so that we better know how to defend it?'"

The work on NosyNeighbor was published in the journal ACM Transactions on Cyber-Physical Systems, one of the leading journals in the field. This work was led by Vijay Banjaree, a former postdoctoral researcher at WSU, who recently joined Argonne National Laboratory.

The project grows out of Hasan's research into the detection and mitigation of information leakage in time-critical cyber-physical systems, work that is supported by a National Science Foundation CAREER Award.

The new publication is focused on developing protections for "partitioned" time-critical systems - computing systems that operate with separate, connected units that each handle different stages of an overall task. In such a system, each partition must perform its task within strict time constraints; even a few milliseconds of delay means failure.

"It's kind of containerized, in the sense that different components from different vendors are designed individually, and then packaged together and deployed for production," Hasan said. "In an avionics system you have different submodules - engine control, passenger cockpit infotainment, flight control, navigation, and so on. How can we ensure all of those components are trusted and they can operate in a coherent manner? This is even critical for modern systems as they are becoming more complex and have significant multi-vendor dependency, which also increases supply-chain cyber-risks."

Hasan's team designed a side-channel attack, which does not try to disrupt the software or algorithms of a system, but operates outside the system and draws inferences from certain kinds of secondary information. NosyNeighbor successfully launched malicious attacks using inferences about the time a task took to run in certain partitions.

Crucially, Nosy Neighbor could use inferences drawn from one partition to determine actions in other partitions. Experimental results show that NosyNeighbor could infer the task being executed with a precision of roughly 73% under normal system operations. That's precise enough to be a real safety risk - an adversary only needs one shot to disrupt a safety-critical system.

"If we run those individual software tasks in different partitions, it is possible that malicious software from one partition can infer the behavior of other partitions," he said. "This could have severe consequences. Because if an attacker knows a certain task is running at a certain time, they can disable that service. That would be a very serious safety concern - for instance, if a braking module of an autonomous car is disabled by an adversary at an intersection."

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.