Search papers, labs, and topics across Lattice.
This paper introduces NICWhisper, a novel approach to network threat detection that leverages unintended electromagnetic emissions from network interface cards (NICs) to recognize network behaviors without analyzing packet contents. By transforming raw electromagnetic measurements into time-frequency representations, the method achieves an impressive 80.67% Macro-F1 score across eight behavior classes, demonstrating the potential of physical leakage as a structured information source for threat recognition. The findings suggest that NIC EM emissions can serve as a complementary observation surface for network security, particularly in scenarios where traditional telemetry is inaccessible or undesirable.
NICWhisper reveals that electromagnetic emissions from network interface cards can effectively identify network threats, achieving over 80% accuracy without analyzing packet data.
Conventional network threat detection primarily relies on packet-level, flow-level, or host-level telemetry. This paper investigates a different observation surface: unintended electromagnetic(EM) emissions generated by network interface card(NIC) activity, and asks whether such physical leakage contains sufficiently structured information for network threat-behavior recognition. We present NICWhisper, which externally captures NIC EM emissions, transforms raw measurements into time-frequency representations, and recognizes network behaviors without inspecting packet contents or host-side runtime states. Rather than competing with traffic-based detection, NICWhisper exploits the physical manifestation of traffic-driven NIC activity, whose timing, rate, concurrency, and burst organization naturally shape the measured EM leakage. We construct a NIC EM dataset covering active benign workloads and seven representative threat behaviors under diverse execution conditions, and systematically evaluate signal dependence, execution variation, measurement perturbation, and cross-device transfer. NICWhisper achieves 80.67\% Macro-F1 across eight behavior classes, while further experiments show that the observed behavior-related information extends beyond simple signal magnitude and remains partially transferable across execution conditions and NIC hardware. These results establish NIC EM leakage as a complementary physical observation source for network security monitoring when direct access to conventional traffic or host telemetry is limited or undesirable.