DH
D.J. Hill
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
1 records found
1
The Modern Abuse of Network Time Protocol in Denial of Service Attacks
A honeypot-based observation of real-world DRDoS attacks
Distributed Reflective Denial of Service (DRDoS) attacks leveraging the Network Time Protocol (NTP) continue to threaten network infrastructure. Previous research has been done on this topic, but needs to be reevaluated often due to the high-paced changes in cybersecurity. To capture modern adversarial tactics, this study deployed an experimental network framework consisting of 16 emulated, rate-limited NTP honeypots to log real-world attacker telemetry. Logged data was analysed based on location and target, the sequence of requests, and frequency of attack. Ultimately, this work contributes a safe, open-source honeypot framework, establishes a modern empirical baseline of the NTP DRDoS threat landscape, and underscores the critical need for renewed longitudinal research into evolving adversarial tactics.
...
Distributed Reflective Denial of Service (DRDoS) attacks leveraging the Network Time Protocol (NTP) continue to threaten network infrastructure. Previous research has been done on this topic, but needs to be reevaluated often due to the high-paced changes in cybersecurity. To capture modern adversarial tactics, this study deployed an experimental network framework consisting of 16 emulated, rate-limited NTP honeypots to log real-world attacker telemetry. Logged data was analysed based on location and target, the sequence of requests, and frequency of attack. Ultimately, this work contributes a safe, open-source honeypot framework, establishes a modern empirical baseline of the NTP DRDoS threat landscape, and underscores the critical need for renewed longitudinal research into evolving adversarial tactics.