Preventing (Network) Time Travel with Chronos
Omer Deutsch, Neta Rozen Schiff, Danny Dolev, Michael Schapira
Abstract
The Network Time Protocol (NTP) synchronizes time across computer systems over the Internet. Unfortunately, NTP is highly vulnerable to "time shifting attacks", in which the attacker's goal is to shift forward/backward the local time at an NTP client. This has severe implications for the correctness and safety of time-sensitive applications and for security mechanisms. Importantly, time shifting attacks on NTP are possible even if all NTP communications are encrypted and authenticated. We present Chronos, a new NTP client that achieves good synchronization even in the presence of powerful man-in-the-middle attackers. Chronos is backwards compatible with legacy NTP and involves no changes whatsoever to NTP servers. In addition, Chronos is carefully engineered to minimize communication overhead so as to avoid overloading NTP servers. We evaluate Chronos' security and network efficiency guarantees via a combination of theoretical analyses and experiments with a prototype implementation. Our results indicate that to succeed in shifting time at a Chronos client by over 100ms from the UTC, even a powerful man-in-the-middle attacker requires over 20 years of effort in expectation. Based on work published at [1].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly AttacksRobert Beverly, Erik C. RyeNDSS 2026 · 1 citation
- Cleaning the NTP Pool: Detecting and Mitigating NTP-sourced IPv6 ScanningErik Rye, Robert BeverlyCCS 2026 · 1 citation
- Low-Cost and Robust Global Time SynchronizationMarc Wyss, Marc Frei, Jonghoon Kwon, Adrian PerrigS&P 2025
- Did the Shark Eat the Watchdog in the NTP Pool? Deceiving the NTP Pool's Monitoring SystemJonghoon Kwon, Jeonggyu Song, Junbeom Hur, Adrian PerrigUSENIX Security 2023
- A Devil of a Time: How Vulnerable is NTP to Malicious Timeservers?Yarin Perry, Neta Rozen Schiff, Michael SchapiraNDSS 2021
Builds on2
Related papers
- PTPsec: Securing the Precision Time Protocol Against Time Delay Attacks Using Cyclic Path Asymmetry AnalysisAndreas Finkenzeller, Oliver Butowski, Emanuel Regnath, Mohammad Hamad et al.INFOCOM 2024 · 15 citations
- TimeTravel: Real-time Timing Drift Attack on System Time Using Acoustic WavesJianshuo Liu, Hong Li, Haining Wang, Mengjie Sun et al.USENIX Security 2025
- Keeping Authorities "Honest or Bust" with Decentralized Witness CosigningEwa Syta, Iulia Tamas, Dylan Visher, David Isaac Wolinsky et al.S&P 2016 · 285 citations
- Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing AttacksVik Vanderlinden, Tom van Goethem, Mathy VanhoefNDSS 2026
- Four Attacks and a Proof for TelegramMartin R. Albrecht, Lenka Mareková, Kenneth G. Paterson, Igors StepanovsS&P 2022 · 40 citations
