Masters Of Time: An Overview Of The Ntp Ecosystem - (Datasets)
收藏资源简介:
Datasets of the published paper: "Masters of Time: An Overview of the NTP Ecosystem".<br> The paper was published at IEEE European Symposium on Security and Privacy (Euro S&P), London, United Kingdom, April 2018. Abstract The Network Time Protocol (NTP) is currently the most commonly used approach to keeping the clocks of computing devices accurate. It operates in the background of many systems; however, it is often important because if NTP fails in providing the correct time, multiple applications such as security protocols like TLS can fail. Despite its crucial practical role, only a limited number of measurement studies have focused on the NTP ecosystem. In this paper, we report the results of an in-depth longitudinal study of the services provided by the NTP Pool Project, which enables volunteers to offer their NTP services to other Internet users in a straightforward manner. We supplement these observations with an analysis of other readily available NTP servers, such as those offered by OS vendors or those that can be freely found on the Internet. The analysis indicates a reliance on a small set of servers that are (at least indirectly) responsible for providing the time for the Internet. Furthermore, this paper considers the impact of several incidents that the authors observed between December 2016 and April 2017. To complement this study, we also perform an analysis of multiple geographical regions from the operator’s perspective, spanning a period of 5 months. A coarse-grained categorization of client requests allows us to categorize 95 percent of our incoming traffic as NTP- and SNTP-like traffic (the latter being a simpler, but more error-prone, form of NTP); we observe that up to 75 percent of all requests originated from SNTP-like clients. With this in mind, we consider what kind of harm a rogue server administrator could cause to users.
本数据集对应已发表论文"Masters of Time: An Overview of the NTP Ecosystem"(《时间掌控者:网络时间协议生态系统概览》)。该论文发表于2018年4月英国伦敦举办的IEEE欧洲安全与隐私研讨会(IEEE European Symposium on Security and Privacy,缩写Euro S&P)。 摘要 网络时间协议(Network Time Protocol,NTP)是当前保障计算设备时钟精度最通用的授时方案,其运行于多数系统的后台。尽管NTP至关重要,一旦其无法提供准确时间,包括传输层安全(Transport Layer Security,TLS)在内的诸多安全协议类应用都将失效,但目前针对NTP生态系统的实测研究仍较为有限。 本文针对网络时间协议池项目(NTP Pool Project)提供的服务展开了深入的纵向研究,该项目允许志愿者以简便方式为其他互联网用户提供NTP服务。本研究还对其他可公开获取的NTP服务器进行了分析作为补充,例如操作系统厂商提供的服务器或互联网上可自由获取的服务器。分析结果显示,当前互联网授时服务高度依赖少数(至少是间接)提供时间服务的服务器集群。此外,本文还探讨了研究团队在2016年12月至2017年4月期间观测到的多起事件所带来的影响。 为进一步完善本研究,研究团队还从运营方视角对覆盖5个月时长的多个地理区域进行了分析。通过对客户端请求进行粗粒度分类,研究团队将95%的入站流量归类为类NTP与类简单网络时间协议(Simple Network Time Protocol,SNTP)流量——后者是一种更简洁但容错性更差的NTP变体;观测数据显示,高达75%的请求均来自类SNTP客户端。基于上述发现,本文还探讨了恶意服务器管理员可能对用户造成的各类危害。



