On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly Attacks
Robert Beverly, Erik Rye

TL;DR
This paper provides a comprehensive measurement-based analysis of the NTP Pool's structure, usage, and vulnerabilities, revealing its susceptibility to monopoly attacks and suggesting improvements for robustness.
Contribution
It offers the first detailed, longitudinal measurement study of the NTP Pool, analyzing server independence, configurations, and attack vulnerabilities.
Findings
Only 19.7% of active servers are fully independent.
An informed adversary can mount monopoly attacks in 90% of countries.
The NTP Pool's robustness can be improved through specific measures.
Abstract
Internet services and applications depend critically on the availability and acc uracy of network time. The Network Time Protocol (NTP) is one of the oldest core network protocols and remains the de facto mechanism for clock synchronization across the Internet today. While multiple NTP infrastructures exist, one, the "NTP Pool," presents an attractive attack target for two basic reasons, it is: 1) administratively distributed and based on volunteer servers; and 2) heavily utilized, including by IoT and infrastructure devices worldwide. We %develop measurements to gather the first direct, non-inferential, and comprehensive data on the NTP pool, including: longitudinal server and account membership, server configurations, time quality, aliases, and global query traffic load. We gather complete and granular data over a nine month period to discover over 15k servers (both active and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Time Synchronization Technologies · Advanced Frequency and Time Standards · Wireless Networks and Protocols
