Cleaning the NTP Pool: Detecting and Mitigating NTP-sourced IPv6 Scanning
Erik Rye, Robert Beverly
Abstract
The ephemeral and random nature of IPv6 client addresses presents a practical challenge to attacks that depend on Internet-wide scanning or reconnaissance - the adversary must first find the client's IPv6 address. While a well-positioned passive adversary can potentially harvest some active IPv6 client addresses, such power is typically reserved for e.g., large CDNs or Internet exchange points. In contrast, prior work has shown the ease with which a low-power entity can join the volunteer-based NTP Pool and harvest large quantities of active IPv6 client addresses. In this work, we develop a methodology to not only rigorously identify such IPv6 address harvesting and the entities gathering addresses, but also characterize what these entities subsequently do with the addresses. Specifically, we query all NTP Pool servers across the global Internet over the course of one year using unique IPv6 client addresses, and monitor and correlate any later activity targeting these addresses. In sum, we identify 22 NTP Pool servers, within 4 primary clusters, that are part of larger monitoring infrastructures that utilize the gathered addresses for reconnaissance, port scanning, and service and vulnerability enumeration. To better understand the legal and ethical gray area of such behavior, we engage with both the NTP Pool operators and a cybersecurity insurance firm running one of the harvesting and scanning clusters. We are in discussions with the NTP Pool to integrate our system into their monitoring infrastructure to remove such NTP servers, and the cybersecurity insurance firm changed its operational policy to be more transparent and provide clear opt-out mechanisms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bef7bdaa-94f1-4e4b-b5ec-151ed4b17c5aCited by top-tier papers1
Ask how each one uses itBuilds on9
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 100 citations
- Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse ZonesKevin Borgolte, Shuang Hao, Tobias Fiebig, Giovanni VignaS&P 2018 · 48 citations
- IPv6 Hitlists at Scale: Be Careful What You Wish ForErik C. Rye, Dave LevinSIGCOMM 2023 · 38 citations
- Preventing (Network) Time Travel with ChronosOmer Deutsch, Neta Rozen Schiff, Danny Dolev, Michael SchapiraNDSS 2018 · 17 citations
- Where Have All the Firewalls Gone? Security Consequences of Residential IPv6 TransitionErik Rye, Dave Levin, Robert BeverlyCCS 2026 · 2 citations
Related papers
- Glowing in the Dark: Uncovering IPv6 Address Discovery and Scanning Strategies in the WildHammas Bin Tanveer, Rachee Singh, Paul Pearce, Rishab NithyanandUSENIX Security 2023
- On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly AttacksRobert Beverly, Erik C. RyeNDSS 2026 · 1 citation
- Domains Do Change Their Spots: Quantifying Potential Abuse of Residual TrustJohnny So, Najmeh Miramirkhani, Michael Ferdman, Nick NikiforakisS&P 2022 · 15 citations
- Did the Shark Eat the Watchdog in the NTP Pool? Deceiving the NTP Pool's Monitoring SystemJonghoon Kwon, Jeonggyu Song, Junbeom Hur, Adrian PerrigUSENIX Security 2023
- 6Hit: A Reinforcement Learning-based Approach to Target Generation for Internet-wide IPv6 ScanningBingnan Hou, Zhiping Cai, Kui Wu, Jinshu Su et al.INFOCOM 2021 · 75 citations
