Pitfalls of Provably Secure Systems in Internet The Case of Chronos-NTP

10/16/2020
by   Philipp Jeitner, et al.
0

The critical role that Network Time Protocol (NTP) plays in the Internet led to multiple efforts to secure it against time-shifting attacks. A recent proposal for enhancing the security of NTP with Chronos against on-path attackers seems the most promising one and is on a standardisation track of the IETF. In this work we demonstrate off-path attacks against Chronos enhanced NTP clients. The weak link is a central security feature of Chronos: The server pool generation mechanism using DNS. We show that the insecurity of DNS allows to subvert the security of Chronos making the time-shifting attacks against Chronos-NTP even easier than attacks against plain NTP.

READ FULL TEXT

page 1

page 2

page 3

research
10/19/2020

Secure Consensus Generation with Distributed DoH

Many applications and protocols depend on the ability to generate a pool...
research
05/21/2022

SERVFAIL: The Unintended Consequences of Algorithm Agility in DNSSEC

Cryptographic algorithm agility is an important property for DNSSEC: it ...
research
04/03/2018

Blockchain-based TLS Notary Service

The Transport Layer Security (TLS) protocol is a de facto standard of se...
research
10/19/2020

The Impact of DNS Insecurity on Time

We demonstrate the first practical off-path time shifting attacks agains...
research
11/27/2017

Composable Security Against Collective Attacks of a Modified BB84 QKD Protocol with Information only in One Basis

Quantum Cryptography uses the counter-intuitive properties of Quantum Me...
research
01/02/2023

Honeypot Implementation in a Cloud Environment

In this age of digitalization, Internet services face more attacks than ...
research
10/26/2020

Easing the Conscience with OPC UA: An Internet-Wide Study on Insecure Deployments

Due to increasing digitalization, formerly isolated industrial networks,...

Please sign up or login with your details

Forgot password? Click here to reset