Network Time Protocol (NTP)

The protocol hosts use to synchronise their clocks with reference time sources over a network, which log correlation, Kerberos and certificate checks all depend on.

Network Time Protocol synchronises the clocks of computers and network devices with reference time sources. The current version, NTPv4, is specified in RFC 5905 and runs over UDP on well-known port 123. Time is distributed through a hierarchy of strata: a stratum 1 server is attached directly to a reference clock such as a GPS receiver, and each level below synchronises from the level above.

Accurate time is a security dependency rather than a convenience. Kerberos rejects authentication requests when client and server clocks drift too far apart, certificates are checked against validity dates, and a SIEM can only reconstruct an incident if the timestamps in logs from different systems line up. An attacker who can shift a system’s clock can therefore disrupt authentication or undermine evidence. It has also been abused for amplification attacks, in which small spoofed queries to misconfigured servers produce much larger replies aimed at a victim. Controls include trusted internal time sources, restricting who may query them, and authenticated time such as Network Time Security (RFC 8915).

Exam relevance: a scenario in which logs from several systems cannot be put in order, or Kerberos authentication fails for no obvious reason, is likely to point to clock synchronisation. Candidates are expected to recognise NTP as part of the evidence chain and as a possible amplification vector.