HomeSecurityThe first attack on the Internet's synchronization system (NTP servers) is a "serious threat"

The first attack on the Internet's synchronization system (NTP servers) is a "serious threat"

Since 09.01.2014 we have published about an unprecedented hacking technique used in an attack on League of Legends.

We are republishing Cloudflare 's analysis that attempts to explain the new technique.

The ability of servers that synchronize time on the Internet to return more data than they received from the computers that requested the time was exploited by attackers, Cloudflare explains. 

change-internet-time-serverA technique that could render popular online services inaccessible was deployed on a large scale on Monday, the BBC reports. Cloudflare, a provider of online hosting and security services, announced that it had recorded the largest attack on the Internet's computer synchronization system, flooding the (unknown) target with data.

The technique involves the so-called Network Time Protocol, the protocol for synchronizing the time of computers connected via the Internet, that is, tens of millions of computers. The target of the "largest NTP attack" remains unknown, according to Cloudflare, although it is located in Europe. It is a distributed denial-of-service (DDoS) attack that sent data with a power much greater than that of what is considered to be the largest cyberattack of all time. Cloudflare recorded 400 Gigabits per second, when the Spamhaus attack in 2013 was 100Gigabits weaker. The method described by the company involves requests to thousands of NTP servers for time synchronization from "masquerading" servers that used a fake identity to forward the NTP server's response to a single target, uploading much more data to its back. The result was the target accepting an incredible amount of data and ultimately, being destroyed.
Cloudflare CEO Matthew Prince attributed the attack to security flaws in the NTP protocol, which were developed when cyberattacks were not even a possibility (1985), and, in the role of Cassandra, predicted on Twitter that this attack would be the beginning of many troubles. It is noteworthy that the possibility of exploiting the NTP protocol flaws has been discussed for months.
tweets

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS