Cybersecurity Research

NosyNeighbor: the experimental cyberattack designed to strengthen the security of critical systems

Why would a group of researchers spend years designing a cyberattack? The answer is straightforward: to prevent others from using it first.

A team of researchers from Washington State University, the University of Colorado Colorado Springs and Metro State University has developed NosyNeighbor, an experimental attack technique whose goal is not to compromise real systems, but to demonstrate a vulnerability that had not previously been studied in depth.

The attack is not the end goal — it is a tool for uncovering weaknesses and developing countermeasures. This is exactly the same approach used when researchers create an exploit to demonstrate a Windows vulnerability: they do it not to harm users, but so that Microsoft can fix the issue before someone else exploits it.

What vulnerability did they want to demonstrate, and how did they find it?

Many critical systems — in avionics, automotive and medical devices, for example — are divided into isolated partitions to prevent a failure in one area from affecting the whole system.

The researchers' question was straightforward: is it possible to find out what is happening inside one of those partitions without directly accessing it? The answer is yes.

Rather than attempting to break the system's isolation, NosyNeighbor uses a side-channel attack: it analyses small variations in execution times to infer which tasks are running. It is like guessing what a neighbour is doing without entering their home — purely from the clues that come through from outside.

What makes it novel is that the attack learns as it goes. At each phase it adapts its behaviour to improve the accuracy of its inferences. The result:

73% accuracy in identifying the running task
3 universities involved in the research
0 direct access required to the target system

Why does it matter?

Knowing the exact moment a critical task executes does not compromise a system on its own, but it can enable subsequent attacks that are far more precise and effective.

"Apparently harmless timing information can become a valuable source of intelligence for an attacker."

Thinking like an attacker to build better defences

The goal of NosyNeighbor is not to create a new threat, but to uncover weaknesses before cybercriminals do.

The researchers developed an experimental attack model to show that some protection mechanisms still have limitations against adaptive attackers. Understanding those limitations makes it possible to design better defences and strengthen critical systems before those vulnerabilities can be exploited.

Academic source

Banerjee, V., Hounsinou, S., Zhuang, Y., Hasan, M., and Bloom, G. (2026). "On Evading Randomization-Based Defense in Hierarchical Real-Time Systems". ACM Transactions on Cyber-Physical Systems, 10(2), Article 22. DOI: 10.1145/3783983

Cloud Levante · Cybersecurity Are your critical systems prepared for this type of threat?

At Cloud Levante we assess your infrastructure's security posture against advanced attack vectors, including side-channel attacks. No commitment required.

Request a review