We (academic security researchers) have been studying the prevalence and characteristics of NTP Pool-enabled IPv6 “backscanning.” In short, there are NTP servers participating in the pool that provide valid time, but harvest the IPv6 addresses of NTP clients; these clients are then subsequently scanned for open services, vulnerabilities, etc. This is done because client IPv6 addresses are random, hard-to-guess, and ephemeral.
We are not the first to observe this phenomenon. There was discussion about it back in 2016. However, IPv6 adoption and scanning tactics have changed significantly since 2016. Our recent work (see [1]) investigates NTP Pool backscanning in detail.
We have been in discussion with pool maintainers Ask and Steven about the possibility of continually monitoring and mitigating this type of backscanning. We’d like to get a better feel for the wider NTP server operator community’s thoughts and solicit input on this topic.
If you would like to contribute input, we would very much appreciate your feedback on this (anonymous) survey: https://docs.google.com/forms/d/e/1FAIpQLSciJue4z9KJ8A5DecJhR8brlaFnsfMzCe_ObvRwVjFPVxsC-Q/viewform?usp=publish-editor
Thanks,
Rob Beverly, Erik Rye (SDSU/JHU)