Miroslav observed unexplained NTP request bursts coming from clients in Germany. The duration of the bursts varied, but was often ~140 seconds. During a burst hundreds to thousand of clients might each send ~200 NTP requests.
So far no NTP server disruptions have been seen, but it is worrisome.
Based on our tcpdump analysis we currently suspect some type of IP-aware appliance: It could be some network related phenomenon.
The behavior may extend past Germany, we’re still analyzing.
Has anyone observed similar behavior? Packet captures would be welcome.
I’m seeing similar traffic patterns on my server in Germany. But they are not a new phenomenon - they have been there ever since I first monitored my NTP server traffic in Germany, at least half a year ago. Nevertheless they are worth investigating.
IIRC there was an german heating manufactor some time ago which also “abused” the pool.
Ahh quick search: How to NOT use the NTP Pool
Maybe they doing it again
Nice article, thanks. The NTP client described in this article has a different signature, NTP requests every 7 seconds. The abusive clients I mentioned could be IoT devices.
The only capture filter on it was the IP range. I didn’t expect much traffic, since I’m not in a zone that will likely receive much traffic from that range.