Round Trip Time: A Benign Signal or an Indirect Window into Datacenter Workloads?
This paper investigates a network side-channel vulnerability in multi-tenant datacenter fabrics caused by shared congestion behavior, achieving up to 97.3% run-level accuracy in workload inference.
Introduces a new network side-channel vulnerability in multi-tenant datacenter fabrics and proposes a framework for workload inference using indirect RTT observations
Keywords
Before reading this…
Applications
- →Datacenter security
- →Network security
To understand this paper, make sure you know these concepts first:
- Understanding of multi-tenant datacenter networksfind papers →
- Familiarity with network side-channel vulnerabilitiesfind papers →
Abstract
More Like ThisMulti-tenant datacenter networks increasingly rely on shared leaf-spine fabrics, where traffic from multiple tenants traverses common network resources. While logical isolation mechanisms prevent direct access between tenants, shared congestion dynamics may still expose indirect information about co-located workloads through observable latency variations. In this paper, we investigate a network side-channel vulnerability arising from shared congestion behavior in multi-tenant datacenter fabrics using RTT observations collected along overlapping network paths. We develop a framework to explore how workload-induced latency variations contain sufficiently distinguishable signatures to enable workload inference under realistic deployment conditions. Our evaluations show that indirect RTT observations can reveal meaningful workload information, achieving up to 97.3\% run-level accuracy under cross-path evaluation when workload-induced congestion is sufficiently observable. The findings suggest that logical network isolation alone may be insufficient to prevent information leakage through shared congestion dynamics in modern datacenter infrastructures.