遇见数据集

Masters Of Time: An Overview Of The Ntp Ecosystem - (Datasets)

收藏
Zenodo2020-09-20 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

Datasets of the published paper: "Masters of Time: An Overview of the NTP Ecosystem".<br> The paper was published at IEEE Eu­ropean Sym­po­si­um on Se­cu­ri­ty and Pri­va­cy (Euro S&amp;P), London, United Kingdom, April 2018. Abstract The Net­work Time Pro­to­col (NTP) is cur­rent­ly the most com­mon­ly used ap­proach to ke­eping the clocks of com­pu­ting de­vices ac­cu­ra­te. It ope­ra­tes in the back­ground of many sys­tems; howe­ver, it is often im­portant be­cau­se if NTP fails in pro­vi­ding the cor­rect time, mul­ti­ple ap­p­li­ca­ti­ons such as se­cu­ri­ty pro­to­cols like TLS can fail. De­s­pi­te its cru­ci­al prac­tical role, only a li­mi­ted num­ber of me­a­su­re­ment stu­dies have fo­cu­sed on the NTP eco­sys­tem. In this paper, we re­port the re­sults of an in-depth lon­gi­tudinal study of the ser­vices pro­vi­ded by the NTP Pool Pro­ject, which enables volun­te­ers to offer their NTP ser­vices to other In­ter­net users in a straight­for­ward man­ner. We sup­ple­ment these ob­ser­va­tions with an ana­ly­sis of other rea­di­ly avail­able NTP ser­vers, such as those of­fe­red by OS ven­dors or those that can be fre­e­ly found on the In­ter­net. The ana­ly­sis in­di­ca­tes a re­li­an­ce on a small set of ser­vers that are (at least in­di­rect­ly) re­s­pon­si­ble for pro­vi­ding the time for the In­ter­net. Fur­thermore, this paper con­s­i­ders the im­pact of se­ver­al in­ci­dents that the aut­hors ob­ser­ved bet­ween De­cem­ber 2016 and April 2017. To com­ple­ment this study, we also per­form an ana­ly­sis of mul­ti­ple geo­gra­phi­cal re­gi­ons from the ope­ra­tor’s per­spec­tive, span­ning a pe­ri­od of 5 months. A co­ar­se-grained ca­te­go­riza­t­i­on of cli­ent re­quests al­lows us to ca­te­go­ri­ze 95 per­cent of our in­co­ming traf­fic as NTP- and SNTP-li­ke traf­fic (the lat­ter being a sim­pler, but more er­ror-pro­ne, form of NTP); we ob­ser­ve that up to 75 per­cent of all re­quests ori­gi­na­ted from SNTP-like cli­ents. With this in mind, we con­s­i­der what kind of harm a rogue ser­ver ad­mi­nis­tra­tor could cause to users.

本数据集对应已发表论文"Masters of Time: An Overview of the NTP Ecosystem"(《时间掌控者:网络时间协议生态系统概览》)。该论文发表于2018年4月英国伦敦举办的IEEE欧洲安全与隐私研讨会(IEEE European Symposium on Security and Privacy,缩写Euro S&P)。 摘要 网络时间协议(Network Time Protocol,NTP)是当前保障计算设备时钟精度最通用的授时方案,其运行于多数系统的后台。尽管NTP至关重要,一旦其无法提供准确时间,包括传输层安全(Transport Layer Security,TLS)在内的诸多安全协议类应用都将失效,但目前针对NTP生态系统的实测研究仍较为有限。 本文针对网络时间协议池项目(NTP Pool Project)提供的服务展开了深入的纵向研究,该项目允许志愿者以简便方式为其他互联网用户提供NTP服务。本研究还对其他可公开获取的NTP服务器进行了分析作为补充,例如操作系统厂商提供的服务器或互联网上可自由获取的服务器。分析结果显示,当前互联网授时服务高度依赖少数(至少是间接)提供时间服务的服务器集群。此外,本文还探讨了研究团队在2016年12月至2017年4月期间观测到的多起事件所带来的影响。 为进一步完善本研究,研究团队还从运营方视角对覆盖5个月时长的多个地理区域进行了分析。通过对客户端请求进行粗粒度分类,研究团队将95%的入站流量归类为类NTP与类简单网络时间协议(Simple Network Time Protocol,SNTP)流量——后者是一种更简洁但容错性更差的NTP变体;观测数据显示,高达75%的请求均来自类SNTP客户端。基于上述发现,本文还探讨了恶意服务器管理员可能对用户造成的各类危害。

提供机构:
Zenodo
创建时间:
2018-04-23
二维码
社区交流群
二维码
科研交流群
商业服务