AI 中文总结
该研究提出NICWhisper方法,通过捕获网卡电磁侧信道泄漏识别网络威胁行为,构建对应数据集验证其宏F1达80.67%,可作为传统检测的补充手段。
AI 中文摘要
传统网络威胁检测主要依赖数据包级、流级或主机级遥测数据。本文研究了一种不同的观测面:网卡(Network Interface Card,NIC)活动产生的非预期电磁(Electromagnetic,EM)泄漏,探究这种物理泄漏是否包含足够结构化的信息以用于网络威胁行为识别。我们提出了NICWhisper,该方法可从外部捕获网卡的电磁泄漏,将原始测量数据转换为时频表示,无需检查数据包内容或主机侧运行时状态即可识别网络行为。NICWhisper并非要与基于流量的检测方法竞争,而是利用流量驱动的网卡活动的物理表现,其时间、速率、并发性和突发组织方式自然塑造了所测量的电磁泄漏。我们构建了一个网卡电磁数据集,涵盖不同执行条件下的活跃良性工作负载及七种代表性威胁行为,并系统评估了信号依赖性、执行变化、测量扰动和跨设备迁移能力。NICWhisper在八个行为类别上达到了80.67%的宏F1值,进一步实验表明,所观测到的与行为相关的信息不仅限于简单的信号幅度,还能在一定程度上跨执行条件和网卡硬件迁移。这些结果证实,当无法获取或不希望获取传统流量或主机遥测数据时,网卡电磁泄漏可作为网络安全监控的补充物理观测源。
英文摘要
Conventional network threat detection primarily relies on packet-level, flow-level, or host-level telemetry. This paper investigates a different observation surface: unintended electromagnetic(EM) emissions generated by network interface card(NIC) activity, and asks whether such physical leakage contains sufficiently structured information for network threat-behavior recognition. We present NICWhisper, which externally captures NIC EM emissions, transforms raw measurements into time-frequency representations, and recognizes network behaviors without inspecting packet contents or host-side runtime states. Rather than competing with traffic-based detection, NICWhisper exploits the physical manifestation of traffic-driven NIC activity, whose timing, rate, concurrency, and burst organization naturally shape the measured EM leakage. We construct a NIC EM dataset covering active benign workloads and seven representative threat behaviors under diverse execution conditions, and systematically evaluate signal dependence, execution variation, measurement perturbation, and cross-device transfer. NICWhisper achieves 80.67\% Macro-F1 across eight behavior classes, while further experiments show that the observed behavior-related information extends beyond simple signal magnitude and remains partially transferable across execution conditions and NIC hardware. These results establish NIC EM leakage as a complementary physical observation source for network security monitoring when direct access to conventional traffic or host telemetry is limited or undesirable.