[proxy] www.imperva.com← back | site home | direct (HTTPS) ↗ | proxy home | ◑ dark◐ light

What is NTP Amplification | Mitigation Techniques | Imperva

What is an NTP amplification attack?

NTP amplification is a specialized form of distributed denial-of-service (DDoS) attack that exploits the Network Time Protocol (NTP) to overwhelm victims with high volumes of traffic. By abusing the user datagram protocol (UDP) in NTP transactions, attackers can amplify small requests into much larger responses.

NTP-based DDoS attacks often set records for the largest volumetric attacks, surpassing 2 Tbps. As attackers leverage more vulnerable NTP servers, the extensibility of these attacks continues to grow.

Understanding NTP Amplification

NTP is a UDP-based protocol used to synchronize computer clocks on the Internet. Here’s how attackers exploit it to amplify DDoS attacks:

Imperva protects against a NTP amplification attack: 180Gbps and 50 million packets per second

With access to an increasing number of vulnerable, publicly accessible NTP servers, attackers can easily overwhelm victims. The spoofed UDP traffic appears to come from legitimate NTP hosts rather than the actual attack sources.

The History of NTP Amplification Attacks

NTP amplification rose to prominence as a DDoS vector starting in late 2013. Some milestone attacks include:

NTP-based attacks continue to make headlines as amplification techniques evolve, reflecting a growing trend of abusing legitimate protocols and services to carry out DDoS attacks.

Technical Aspects Enabling NTP Amplification

Several technical aspects of NTP enable its exploitation for high-volume traffic amplification:

How to Mitigate NTP Amplification Attacks

Organizations can take various steps to defend against NTP-based DDoS attacks:

Patch NTP Software

Updating NTP server software removes dangerous amplifying commands like monlist. Enabling authentication also prevents anonymous abuse.

Block Unused Protocols

Blocking outbound UDP traffic reduces the external attack surface. Inbound filtering of UDP port 123 prevents reception of NTP.

Limit Access

NTP servers should restrict access to authorized hosts rather than allowing global access. This prevents them being used as DDoS reflectors.

Monitor Traffic

Monitoring tools can detect unusual spikes in outbound NTP traffic that can indicate your systems are being used in an attack.

Cloud-Based DDoS Protection

A cloud-based DDoS protection service, like Imperva DDoS Protection, scrubs attack traffic and can absorb massive volumes without impacting your infrastructure.

Persistent Risk of NTP Amplification

While techniques exist to mitigate NTP-based DDoS attacks, there are still ways for attackers to exploit the protocol:

How Imperva Can Help Mitigate NTP Attacks

Imperva DDoS Protection proxies all incoming traffic to block layer 3/4 and layer 7 attacks, such as NTP amplification attacks, from reaching a customer’s infrastructure.

Imperva secures websites, networks, DNS servers, and individual IPs from the largest and most sophisticated types of DDoS attacks with minimal business disruption. The cloud-based service keeps businesses up and running at high-performance levels, even if they’re under attack.

The high-capacity global network from Imperva scales as needed to absorb the largest attacks that can overwhelm an organization’s web applications.

Imperva DDoS Protection is part of the Imperva Application Security Platform, which also consists of the market-leading web application firewall (WAF), Advanced Bot Protection, API Security, and more.