{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:16:48Z","timestamp":1750306608243,"version":"3.41.0"},"reference-count":50,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2015,4,30]],"date-time":"2015-04-30T00:00:00Z","timestamp":1430352000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["CAREER-CNS-844144 and CAREER-CCF-0747042"],"award-info":[{"award-number":["CAREER-CNS-844144 and CAREER-CCF-0747042"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2015,5,21]]},"abstract":"<jats:p>\n            In this article, we illustrate that the boundary of a general-purpose node can be extended into the network by extracting information from network traffic generated by that general-purpose node to infer the state of its hardware components. This information is represented in a\n            <jats:italic>delay signature<\/jats:italic>\n            latent within the network traffic. In contrast, the traditional approach to determine the internal state of a node\u2019s resources meant that a software application with internal processes had to be resident on the node. The aforementioned delay signature is the keystone that provides a correlation between network traffic and the internal state of the source node. We characterize this delay signature by (1) identifying the different types of assembly language instructions that source this delay and (2) describing how architectural techniques, such as instruction pipelining and caching, give rise to this delay signature. In theory, highly utilized nodes (due to multiple threads) will contain excessive context switching and contention for shared resources. One important shared resource is main memory, and excessive use of this resource by applications and internal processes eventually leads to a decrease in cache efficiency that eventually stalls the instruction pipeline. Our results support this theory; specifically, we have observed that excessive context switching in active applications increases the effective memory access time and wastes precious CPU cycles, thus adding additional delay to the execution of load, store, and other instructions. Because the operating system (OS) kernel accesses memory to send network packets, the delay signature is induced into network traffic in situations where user-level utilization is high. We demonstrate this theory in two case studies: (1) resource discovery in cluster grids and (2) network-based detection of bitcoin mining on compromised nodes.\n          <\/jats:p>","DOI":"10.1145\/2700094","type":"journal-article","created":{"date-parts":[[2015,5,1]],"date-time":"2015-05-01T17:49:08Z","timestamp":1430502548000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Using Network Traffic to Infer Hardware State"],"prefix":"10.1145","volume":"14","author":[{"given":"Lanier","family":"Watkins","sequence":"first","affiliation":[{"name":"The Johns Hopkins University Information Security Institute, Laurel, Maryland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William H.","family":"Robinson","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Raheem","family":"Beyah","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, GA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2015,4,30]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Aeroflex Gaisler. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.gaisler.com.  Aeroflex Gaisler. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.gaisler.com."},{"key":"e_1_2_1_2_1","unstructured":"Bitcoin Forum. 2011. Homepage. Retrieved November 1 2011 from https:\/\/bitcointalk.org\/index.php&quest;topic=7219.0.  Bitcoin Forum. 2011. Homepage. Retrieved November 1 2011 from https:\/\/bitcointalk.org\/index.php&quest;topic=7219.0."},{"key":"e_1_2_1_3_1","unstructured":"BitcoinCZ. 2011. Homepage. Retrieved November 1 2011 from http:\/\/mining.bitcoin.cz.  BitcoinCZ. 2011. Homepage. Retrieved November 1 2011 from http:\/\/mining.bitcoin.cz."},{"volume-title":"Understanding Linux Network Internals","author":"Benvenuti C.","key":"e_1_2_1_4_1","unstructured":"C. Benvenuti . 2005. Understanding Linux Network Internals . O\u2019Reilly Publishers , Sebastopol, CA . C. Benvenuti. 2005. Understanding Linux Network Internals. O\u2019Reilly Publishers, Sebastopol, CA."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/PACT.2005.35"},{"key":"e_1_2_1_6_1","unstructured":"S. Chaisiri and P. Uthayopas. 2008. Survey of Resource Discovery in Grid Environments. Retrieved November 1 2011 from http:\/\/javaboom.files.wordpress.com\/2008\/04\/rs&lowbar;grid_survey.pdf.  S. Chaisiri and P. Uthayopas. 2008. Survey of Resource Discovery in Grid Environments. Retrieved November 1 2011 from http:\/\/javaboom.files.wordpress.com\/2008\/04\/rs&lowbar;grid_survey.pdf."},{"key":"e_1_2_1_7_1","unstructured":"Deterlab. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.deterlab.net.  Deterlab. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.deterlab.net."},{"volume-title":"Proceedings of the IEEE International Symposium on Performance Analysis of Systems and Software. IEEE Computer Society.","author":"Foong A.","key":"e_1_2_1_8_1","unstructured":"A. Foong , T. Huff , H. Hum , J. Patwardhan , and G. Regnier . 2003. TCP performance re-visited . In Proceedings of the IEEE International Symposium on Performance Analysis of Systems and Software. IEEE Computer Society. A. Foong, T. Huff, H. Hum, J. Patwardhan, and G. Regnier. 2003. TCP performance re-visited. In Proceedings of the IEEE International Symposium on Performance Analysis of Systems and Software. IEEE Computer Society."},{"volume-title":"TeraGrid 2007 Conference","author":"Gopu A.","key":"e_1_2_1_9_1","unstructured":"A. Gopu , R. Repasky , and S. McCaulay . 2007. Survey of TeraGrid Job Distribution: Toward Specialized Serial Machines as TeraGrid Resources . TeraGrid 2007 Conference . Madison, WI. A. Gopu, R. Repasky, and S. McCaulay. 2007. Survey of TeraGrid Job Distribution: Toward Specialized Serial Machines as TeraGrid Resources. TeraGrid 2007 Conference. Madison, WI."},{"volume-title":"Black Box Methods for Inferring Parallel Applications Properties in Virtual Environments. Dissertation","author":"Gupta A.","key":"e_1_2_1_10_1","unstructured":"A. Gupta . 2008. Black Box Methods for Inferring Parallel Applications Properties in Virtual Environments. Dissertation , Northwestern University . A. Gupta. 2008. Black Box Methods for Inferring Parallel Applications Properties in Virtual Environments. Dissertation, Northwestern University."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/301308.301362"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MASS.2011.60"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCC.2008.19"},{"key":"e_1_2_1_14_1","volume-title":"Anatomy of the Linux Kernel: History and Architectural Decomposition. Retrieved","author":"Jones M.","year":"2011","unstructured":"M. Jones . 2007. Anatomy of the Linux Kernel: History and Architectural Decomposition. Retrieved November 1, 2011 , from http:\/\/www.ibm.com\/developerworks\/linux\/library\/l-linux-kernel\/&quest;S&lowbar;TACT=105AGX59&S&lowbar;&lowbar;CMP=GR&ca=dgr-lnxw01LKernalAnatomy&num;#author1. M. Jones. 2007. Anatomy of the Linux Kernel: History and Architectural Decomposition. Retrieved November 1, 2011, from http:\/\/www.ibm.com\/developerworks\/linux\/library\/l-linux-kernel\/&quest;S&lowbar;TACT=105AGX59&S&lowbar;&lowbar;CMP=GR&ca=dgr-lnxw01LKernalAnatomy&num;#author1."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/605397.605423"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2005.185"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/781498.781506"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/505202.505221"},{"key":"e_1_2_1_19_1","unstructured":"Linux Kernal Map. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.gaisler.com\/doc\/LEON4&lowbar;32-bit&lowbar;processor&lowbar;core.pdf.  Linux Kernal Map. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.gaisler.com\/doc\/LEON4&lowbar;32-bit&lowbar;processor&lowbar;core.pdf."},{"key":"e_1_2_1_20_1","unstructured":"Linux Kernal Map. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.makelinux.net\/kernel&lowbar;map&lowbar;intro.  Linux Kernal Map. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.makelinux.net\/kernel&lowbar;map&lowbar;intro."},{"key":"e_1_2_1_21_1","unstructured":"Mathworks. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.mathworks.com\/matlabcentral\/fileexchange\/6291.  Mathworks. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.mathworks.com\/matlabcentral\/fileexchange\/6291."},{"key":"e_1_2_1_22_1","unstructured":"P. Magnusson Sparc Architecture. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.sics.se\/psm\/sparcstack.html.  P. Magnusson Sparc Architecture. 2011. Homepage. Retrieved November 1 2011 from http:\/\/www.sics.se\/psm\/sparcstack.html."},{"volume-title":"Proceedings of the IEEE International Workshop on Workload Characterization (WWC\u201903)","author":"Makineni S.","key":"e_1_2_1_23_1","unstructured":"S. Makineni and R. Iyer . 2003. Performance characterization of TCP\/IP packet processing in commercial server workloads . In Proceedings of the IEEE International Workshop on Workload Characterization (WWC\u201903) . S. Makineni and R. Iyer. 2003. Performance characterization of TCP\/IP packet processing in commercial server workloads. In Proceedings of the IEEE International Workshop on Workload Characterization (WWC\u201903)."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/106973.106982"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095890.1095892"},{"key":"e_1_2_1_26_1","doi-asserted-by":"crossref","unstructured":"R. Newman and R. Beyah. 2009. On the performance of using covert timing channels for node authentication. Security and Communication Networks Journal 6.  R. Newman and R. Beyah. 2009. On the performance of using covert timing channels for node authentication. Security and Communication Networks Journal 6.","DOI":"10.1002\/sec.87"},{"key":"e_1_2_1_27_1","volume-title":"Bitcoin: A Peer-to-Peer Electronic Cash System. Retrieved","author":"Nakamoto S.","year":"2008","unstructured":"S. Nakamoto . 2008 . Bitcoin: A Peer-to-Peer Electronic Cash System. Retrieved November 1, 2011, from https:\/\/bitcoin.org\/bitcoin.pdf. S. Nakamoto. 2008. Bitcoin: A Peer-to-Peer Electronic Cash System. Retrieved November 1, 2011, from https:\/\/bitcoin.org\/bitcoin.pdf."},{"key":"e_1_2_1_28_1","unstructured":"Norton Antivirus 2002 Email Scanner Buffer Overflow Vulnerability. 2003. Homepage. Retrieved November 1 2011 from http:\/\/www.securityfocus.com\/bid\/6886.  Norton Antivirus 2002 Email Scanner Buffer Overflow Vulnerability. 2003. Homepage. Retrieved November 1 2011 from http:\/\/www.securityfocus.com\/bid\/6886."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/1170137.1170595"},{"key":"e_1_2_1_30_1","doi-asserted-by":"crossref","unstructured":"D. Patterson and J. Hennessy. 1994. Computer Organization & Design: The Hardware\/Software Interface. Morgan Kaufmann San Francisco CA.   D. Patterson and J. Hennessy. 1994. Computer Organization & Design: The Hardware\/Software Interface. Morgan Kaufmann San Francisco CA.","DOI":"10.1016\/B978-1-4832-0775-9.50007-5"},{"volume-title":"How bitcoin brought privacy to electronic transactions","author":"Peck M.","key":"e_1_2_1_31_1","unstructured":"M. Peck . 2012. How bitcoin brought privacy to electronic transactions . IEEE Spectrum Magazine , June. M. Peck. 2012. How bitcoin brought privacy to electronic transactions. IEEE Spectrum Magazine, June."},{"key":"e_1_2_1_32_1","unstructured":"Improving System Cooling Part 2 - Keeping the North Bridge Cool. (August 2003). Retrieved November 1 2011 from http:\/\/www.informit.com\/articles\/article.aspx&quest;p=339028.  Improving System Cooling Part 2 - Keeping the North Bridge Cool. (August 2003). Retrieved November 1 2011 from http:\/\/www.informit.com\/articles\/article.aspx&quest;p=339028."},{"volume-title":"Proceedings of the IEEE Global Communications Conference (GLOBECOM\u201913)","author":"Radhakrishnan S.","key":"e_1_2_1_33_1","unstructured":"S. Radhakrishnan , S. Uluagac , and R. Beyah . 2013. Realizing an 802.11-based covert timing channel using off-the-shelf wireless cards . In Proceedings of the IEEE Global Communications Conference (GLOBECOM\u201913) . S. Radhakrishnan, S. Uluagac, and R. Beyah. 2013. Realizing an 802.11-based covert timing channel using off-the-shelf wireless cards. In Proceedings of the IEEE Global Communications Conference (GLOBECOM\u201913)."},{"volume-title":"ISS Internet Scanner HTTP Banner Text Parsing Buffer Overflow Vulnerability. Homepage. Retrieved","year":"2011","key":"e_1_2_1_34_1","unstructured":"SecurityFocus. 2002. ISS Internet Scanner HTTP Banner Text Parsing Buffer Overflow Vulnerability. Homepage. Retrieved November 1, 2011 , from http:\/\/www.securityfocus.com\/bid\/5738. SecurityFocus. 2002. ISS Internet Scanner HTTP Banner Text Parsing Buffer Overflow Vulnerability. Homepage. Retrieved November 1, 2011, from http:\/\/www.securityfocus.com\/bid\/5738."},{"key":"e_1_2_1_35_1","unstructured":"Symantec Client Security and Symantec AntiVirus Elevation of Privilege. 2006. Homepage. Retrieved November 1 2011 from http:\/\/www.symantec.com\/avcenter\/security\/Content\/2006.05.25.html.  Symantec Client Security and Symantec AntiVirus Elevation of Privilege. 2006. Homepage. Retrieved November 1 2011 from http:\/\/www.symantec.com\/avcenter\/security\/Content\/2006.05.25.html."},{"volume-title":"Secure Integrated Circuits and Systems: Introduction to Side-Channel Attacks","author":"Standaert F.","key":"e_1_2_1_36_1","unstructured":"F. Standaert . 2010. Secure Integrated Circuits and Systems: Introduction to Side-Channel Attacks . Springer , New York , 27--42. F. Standaert. 2010. Secure Integrated Circuits and Systems: Introduction to Side-Channel Attacks. Springer, New York, 27--42."},{"key":"e_1_2_1_37_1","unstructured":"R. Stevens B. Fenner and A. Rudoff. 2003. Unix Network Programming Vol. 1: The Sockets Networking API (3rd. ed.). Addison-Wesley Professional.   R. Stevens B. Fenner and A. Rudoff. 2003. Unix Network Programming Vol. 1: The Sockets Networking API (3rd. ed.). Addison-Wesley Professional."},{"volume-title":"The Protocols","author":"Stevens W.","key":"e_1_2_1_38_1","unstructured":"W. Stevens . 1994. TCP\/ IP Illustrated : The Protocols . Addison-Wesley Professional . W. Stevens. 1994. TCP\/IP Illustrated: The Protocols. Addison-Wesley Professional."},{"volume-title":"Proceedings of the 18th International Parallel and Distributed Processing Symposium.","author":"Storie S.","key":"e_1_2_1_39_1","unstructured":"S. Storie and M. Sosonkina . 2004. Packet probing as network load detection for scientific applications at run-time . In Proceedings of the 18th International Parallel and Distributed Processing Symposium. S. Storie and M. Sosonkina. 2004. Packet probing as network load detection for scientific applications at run-time. In Proceedings of the 18th International Parallel and Distributed Processing Symposium."},{"volume-title":"Security Response Blog. Retrieved","year":"2011","key":"e_1_2_1_40_1","unstructured":"Symantec. 2011. Security Response Blog. Retrieved November 1, 2011 , from http:\/\/www.symantec.com\/connect\/blogs\/bitcoin-botnet-mining. Symantec. 2011. Security Response Blog. Retrieved November 1, 2011, from http:\/\/www.symantec.com\/connect\/blogs\/bitcoin-botnet-mining."},{"volume-title":"Proceedings of World Academy of Science, Engineering and Technology, Dec 17","author":"Sharma A.","key":"e_1_2_1_41_1","unstructured":"A. Sharma and S. Bawa . 2006. An improved resource discovery approach using P2P model for condor: A grid middleware . In Proceedings of World Academy of Science, Engineering and Technology, Dec 17 . A. Sharma and S. Bawa. 2006. An improved resource discovery approach using P2P model for condor: A grid middleware. In Proceedings of World Academy of Science, Engineering and Technology, Dec 17."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/223982.224449"},{"key":"e_1_2_1_43_1","unstructured":"TORQUE. (November 2011). Retrieved November 1 2011 from http:\/\/www.clusterresources.com\/pages\/products\/torque-resource-manager.php.  TORQUE. (November 2011). Retrieved November 1 2011 from http:\/\/www.clusterresources.com\/pages\/products\/torque-resource-manager.php."},{"volume-title":"Homepage Retrieved","year":"2011","key":"e_1_2_1_44_1","unstructured":"TeraGrid. 2011. Homepage Retrieved November 1, 2011 , from http:\/\/teragrid.org. TeraGrid. 2011. Homepage Retrieved November 1, 2011, from http:\/\/teragrid.org."},{"volume-title":"Proceedings of the IEEE International Conference on Communications (ICC\u201908)","author":"Watkins L.","key":"e_1_2_1_45_1","unstructured":"L. Watkins , C. Corbet , and R. Beyah . 2008. Passive identification of under utilized CPUs in high performance cluster grid networks . In Proceedings of the IEEE International Conference on Communications (ICC\u201908) . L. Watkins, C. Corbet, and R. Beyah. 2008. Passive identification of under utilized CPUs in high performance cluster grid networks. In Proceedings of the IEEE International Conference on Communications (ICC\u201908)."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2011.89"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2010.1012.0326"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS.2005.270"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1477942.1477953"},{"volume-title":"Proceedings of the IEEE International Conference on Computer Design.","author":"Yung R.","key":"e_1_2_1_50_1","unstructured":"R. Yung and N. Wilhelm . 1995. Caching processor general registers . In Proceedings of the IEEE International Conference on Computer Design. R. Yung and N. Wilhelm. 1995. Caching processor general registers. In Proceedings of the IEEE International Conference on Computer Design."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2700094","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2700094","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:17:00Z","timestamp":1750227420000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2700094"}},"subtitle":["A Kernel-Level Investigation"],"short-title":[],"issued":{"date-parts":[[2015,4,30]]},"references-count":50,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2015,5,21]]}},"alternative-id":["10.1145\/2700094"],"URL":"https:\/\/doi.org\/10.1145\/2700094","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2015,4,30]]},"assertion":[{"value":"2013-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2014-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2015-04-30","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}