MEGA Hub

What's Your NIC Whispering? Network Threat Behavior Recognition via NIC Electromagnetic Side-Channel Leakage

Authors

Do you know Hongchao Wang?You can claim authorship or link another user.Do you know Linrui Li?You can claim authorship or link another user.Do you know Yunkai Zou?You can claim authorship or link another user.Do you know Zhenduo Hou?You can claim authorship or link another user.Do you know Yilin Zhang?You can claim authorship or link another user.Do you know Haoyang Pu?You can claim authorship or link another user.Do you know Wen Chen?You can claim authorship or link another user.Do you know Jierui Chen?You can claim authorship or link another user.

Abstract

Conventional network threat detection primarily relies on packet-level, flow-level, or host-level telemetry. This paper investigates a different observation surface: unintended electromagnetic(EM) emissions generated by network interface card(NIC) activity, and asks whether such physical leakage contains sufficiently structured information for network threat-behavior recognition. We present NICWhisper, which externally captures NIC EM emissions, transforms raw measurements into time-frequency representations, and recognizes network behaviors without inspecting packet contents or host-side runtime states. Rather than competing with traffic-based detection, NICWhisper exploits the physical manifestation of traffic-driven NIC activity, whose timing, rate, concurrency, and burst organization naturally shape the measured EM leakage. We construct a NIC EM dataset covering active benign workloads and seven representative threat behaviors under diverse execution conditions, and systematically evaluate signal dependence, execution variation, measurement perturbation, and cross-device transfer. NICWhisper achieves 80.67\% Macro-F1 across eight behavior classes, while further experiments show that the observed behavior-related information extends beyond simple signal magnitude and remains partially transferable across execution conditions and NIC hardware. These results establish NIC EM leakage as a complementary physical observation source for network security monitoring when direct access to conventional traffic or host telemetry is limited or undesirable.

Community

00