NTP,Security,Authentication,an computer NTP Security: Authentication and Trusted Time References


----------------------------------------------------------Permission is granted for the below article to forward,reprint, distribute, use for ezine, newsletter, website,offer as free bonus or part of a product for sale as longas no changes a Gone are those times when the companies and the organisations didn't need a hi-tech system to handle them. Owing to the considerable increase in the business sector and thus, an enormous increase in the complexity of the organisational struc


NTP(Network Time Protocol) synchronises networks to a single time source usingtimestamps to represent the current time of the day, this is essential for timesensitive transactions and many system applications such as email.NTP istherefore vulnerable to security threats, whether from a malicious hacker whowants to alter the timestamp to commit fraud or a DDoS attack (DistributedDenial of Service - normally caused by malicious malware that floods a serverwith traffic) that blocks server access.However,being one of the Internet’s oldest protocols and having been developed for over25 years, NTP is equipped with its own security measures in the form ofauthentication.Authenticationverifies that each timestamp has come from the intended time reference byanalysing a set of agreed encryption keys that are sent along with the timeinformation. NTP, using Message Digest encryption (MD5) to un-encrypt the key,analyses it and confirms whether it has come from the trusted time source byverifying it against a set of trusted keys.Trustedauthentication keys are listed in the NTP server configuration file (ntp.conf)and are normally stored in the ntp.keys file. The key file is normally verylarge but trusted keys tell the NTP server which set of subset of keys iscurrently active and which are not. Different subsets can be activated withoutediting the ntp.keys file using the trusted-keys config command.Authenticationis therefore highly important in protecting a NTP server from malicious attack;however there are many time references were authentication can’t be trusted.Microsoft,who has installed a version of NTP in their operating systems since Windows2000, strongly recommends that a hardware source is used as a timing referenceas Internet sources can’t be authenticated.NTP isvital in keeping networks synchronised but equally important is keeping systemssecure. Whilst network administrators spend thousands in anti-viral/malwaresoftware many fail to spot the vulnerability in their time servers.Many networkadministrators still entrust Internet sources for their time reference. Whilstmany do provide a good source for UTC time (Coordinated Universal Time - theinternational standard of time), such as nist.gov, the lack of authenticationmeans the network is open to abuse.Othersources of UTC time are more secure and can be utilized with relatively lowcost equipment. The easiest method is to use a specialist NTP GPS time serverthat can connect to a GPS antenna and receive an authenticated timestamp bysatellite.GPS timeservers can provide accuracy to UTC time to within a few nanoseconds as long asthe antenna has a good view of the sky. They are relatively cheap and thesignal is authenticated providing a secure time reference.Alternativelythere are several national broadcasts that transmit a time reference. In the UKthis is broadcast by the National Physics Laboratory (NPL) in Cumbria. Similarsystems operate in Germany, France and the US. Whilst this signal isauthenticated, these radio transmissions are vulnerable to interference and havea finite range.Authenticationfor NTP has been developed to prevent malicious tampering with systemsynchronisation just as firewalls have been developed to protect networks fromattack but as with any system of security it only works if it is utilised.

NTP,Security,Authentication,an

computer

Equipment Rental Software – Features And Cost

Equipment rental management software is an essential thing these days for any equipment rental company.A well-developed equipment rental software provides you with a variety of features that can really help you maintain and organise your cus ...

computer

5 Big Reasons Why I Migrated From Angularjs To React

I have 5 main reasons for my angularjs to react migration. No, it's not a comparison on which is better. A comparison between apples and oranges would make no point. React is a library, and angular is a framework. Both can do stuff in their ...

computer

How to troubleshoot McAfee error 2318?

Security software means McAfee! For many computer users, McAfee antivirus is the only choice for security software as it provides all the features and tools which are necessary for device and data protection. This robust antivirus merely sho ...

computer

Manage Multiple Counter With AlignBooks Point of Sale

Fulfilling your businesss needs which can grow your firm is our aim. AlignBooks is better known for providing a strong pillar to newly started or midway businesss. Those companies who dont want to fall back with irregularity manage the inven ...

computer

How to Autoplay Embedded YouTube Videos

Source: How to Autoplay Embedded YouTube VideosEmbedding a video or audio enables the users to share their videos with any of their preferred sites or any social networking platforms. They can do so by copying the embedded link of the parti ...

computer

3 Major Mistakes to Avoid in Retail Business

Truth be told, nearly half of the retail businesses survive longer than four years and which can be something to ponder for a newbie before stepping into the industry. However, this being said, it is also true that you can excel in the indus ...

computer

Start Your Own Computer Repair Business

1. Know your street value. In the early 90's, running a PC repair business centered around selling parts and products, with service on the side. Today, it's about selling hours. If you run a business, you need to consider the X3 rule. That m ...

computer

How Establishments Show Up in Restaurant Searches

The revolutionary rise of technology has made things easy-peasy for consumers in the restaurant industry. Unlike the old days, the availability of innumerable platforms has made it possible for diners to choose from various searching options ...

computer

GuildWars 2 :

The last expansion pack for Guild Wars 2 was Path of Fire, which was released in 2017 and brings you a new enemy-Balthazar, the evil god of war. Although this doesn't sound like another expansion pack currently in production, some fans ma ...

computer

Customer Support at the time of COVID-19 Pandemic

COVID-19 is the worst crisis of our time as we observe social distancing protocols being imposed all around the world. While these measures are a step in effectively managing the COVID-19 pandemic, Hospitality and Retail businesses are confr ...

computer

How to Choose a Contract Management Solution (CLM)?

Contract life cycle management (CLM) systems can simplify and automate contract creation, negotiation, execution and storage. They are an intelligent alternative to the tedious hand tools formerly used for these tasks, which lacked visibili ...

computer

Contacting Google Live Person to Resolve Your Issues

Users are fond of all the Google supported products and look forward to the best services. Also, Google as a whole has never disappointed its users and helped them at every point with its commendable services. Also, being a customer-oriente ...

computer

how to uninstall discord

How to Uninstall Discord in Windows 10? has supported open source technologies, our tool is secure and safe to use. To uninstall a discord from your windows, you'll use this method which is given below.USING THIRD PARTY TOOLS1. Firstly, you ...