Cleaning the NTP Pool: Detecting and Mitigating NTP-Sourced IPv6 Scanning
This paper identifies and characterizes NTP Pool servers that harvest IPv6 client addresses and uses them for reconnaissance, port scanning, and service enumeration.
This paper is novel because it not only identifies IPv6 address harvesting entities but also characterizes their use of the harvested addresses for malicious activities.
Before reading this…
Applications
- →Network security
- →IPv6 address security
To understand this paper, make sure you know these concepts first:
- Understanding of IPv6 addressesfind papers →
- Familiarity with NTP Poolfind papers →
Abstract
More Like ThisThe ephemeral and random nature of IPv6 client addresses presents a practical challenge to attacks that depend on Internet-wide scanning or reconnaissance -- the adversary must first \emph{find} the client's IPv6 address. While a well-positioned passive adversary can potentially harvest some active IPv6 client addresses, such power is typically reserved for e.g. large CDN or Internet exchange points. In contrast, prior work has shown the feasibility of a low-power entity to easily join the volunteer-based NTP Pool and harvest large quantities of active IPv6 client addresses. In this work, we develop a methodology to not only rigorously identify such IPv6 address harvesting and the entities gathering addresses, but also characterize \emph{what} these entities subsequently do with the addresses. Specifically, we query all NTP Pool servers across the global Internet over the course of one-year using unique IPv6 client addresses, and monitor and correlate any later activity targeting these addresses. In sum, we identify 22 NTP Pool servers, within 4 primary clusters, that are part of larger monitoring infrastructures that utilize the gathered addresses for reconnaissance, port scanning, and service and vulnerability enumeration. To better understand the legal and ethical gray area of such behavior, we both engage with the NTP Pool operators and a cybersecurity insurance firm running one of the harvesting and scanning clusters. The NTP Pool has since integrated our system into their monitoring infrastructure to remove such NTP servers, while the firm changed its operational policy to be more transparent and provide clear opt-out mechanisms.