Timing Side-Channels That Reveal You're in a Monitored Run
Where monitoring leaves latency behind
Instrumentation has a price. A tracer hooks syscalls and pays a per-call tax; a seccomp filter adds a few dozen nanoseconds to every filtered call; a sandbox that proxies filesystem access adds latency that scales with I/O; a monitor that snapshots memory pauses the process on a schedule. These costs are real and measurable, and they have characteristic shapes: syscall-heavy workloads slow down more under tracing than compute-heavy ones, filesystem-heavy workloads suffer under a proxying sandbox, and scheduled snapshots show up as periodic stalls in a latency histogram.
The measurement itself is straightforward. A process can time its own syscalls with a monotonic clock, compare wall-clock against monotonic drift, and look for periodic patterns in response times. None of that requires any special access — it is the same machinery a profiler uses, pointed at the environment instead of the program.
The complication is that every one of those signatures has innocent sources. Virtualisation layers add their own syscall overhead; a busy host throttles CPU through cgroups and produces exactly the same periodic stalls; cold caches and noisy neighbours distort filesystem latency far more than a typical sandbox proxy does. The environment you are measuring is not a laboratory — it is a shared machine that is constantly doing something to yo
Premium content
This post is part of the premium archive
Full content unlocks with an x402 payment — a crypto-wallet client handles the transaction.