CORTEXA
← Browse
arxivcs.CRcs.NI2026-07-24

Cleaning the NTP Pool: Detecting and Mitigating NTP-Sourced IPv6 Scanning

Erik Rye, Robert Beverly

The ephemeral and random nature of IPv6 client addresses presents a practical challenge to attacks that depend on Internet-wide scanning or reconnaissance -- the adversary must first \emph{find} the client's IPv6 address. While a well-positioned passive adversary can potentially harvest some active IPv6 client addresses, such power is typically reserved for e.g. large CDN or Internet exchange points. In contrast, prior work has shown the feasibility of a low-power entity to easily join the volunteer-based NTP Pool and harvest large quantities of active IPv6 client addresses. In this work, we develop a methodology to not only rigorously identify such IPv6 address harvesting and the entities gathering addresses, but also characterize \emph{what} these entities subsequently do with the addresses. Specifically, we query all NTP Pool servers across the global Internet over the course of one-year using unique IPv6 client addresses, and monitor and correlate any later activity targeting these addresses. In sum, we identify 22 NTP Pool servers, within 4 primary clusters, that are part of larger monitoring infrastructures that utilize the gathered addresses for reconnaissance, port scanning, and service and vulnerability enumeration. To better understand the legal and ethical gray area of such behavior, we both engage with the NTP Pool operators and a cybersecurity insurance firm running one of the harvesting and scanning clusters. The NTP Pool has since integrated our system into their monitoring infrastructure to remove such NTP servers, while the firm changed its operational policy to be more transparent and provide clear opt-out mechanisms.

View free PDFSource page

Related papers

arxivcs.CRcs.DCcs.LGcs.NI2026-07-09

Securing Autonomous Vehicle Systems via Twin-Aware Federated Reinforcement Learning

Zifan Zhang, Minghong Fang, Dianwei Chen, Zhuqing Liu, Prashant Khanduri, Xianfeng Yang, et al.

Federated reinforcement learning (FRL) is crucial for enabling collaborative learning across multiple agents without sharing raw data, thereby enhancing privacy and scalability in the decision-making process within dynamic vehicular environments. However, poisoning attacks pose a…

View free PDFSource page
arxivcs.CRcs.NI2026-07-11

Federated Cybersecurity Testbed as a Service (FCTaaS): A framework to federate cybersecurity testbeds

Josh Dean, Yu-Zheng Lin, John Paul Martin Encinas, Ibrahim Almazyad, Qinxuan Shi, Zhanglong Yang, et al.

Rapid technological change is reshaping society through emerging domains such as autonomous vehicles and smart manufacturing, creating new research challenges in system design, operation, security, and training. Researchers often rely on testbeds to reproduce experimental scenari…

View free PDFSource page
arxivcs.CRcs.NI2026-07-14

Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design Approach

Md. Rahid Parvez, Mikael Soini

IoMT-based remote elderly care systems generate continuous streams of sensitive health data, yet existing security architectures have not simultaneously addressed three interdependent challenges: GDPR-compliant edge-layer pseudonymisation, elderly-specific zero-interaction usabil…

View free PDFSource page
arxivcs.CRcs.AIcs.CYcs.LG2026-07-20

Adversarial Robustness of Phishing Email Detection: A Comparative Study of TF-IDF + Logistic Regression and Fine-Tuned DistilBERT

Tanveer Ahmed, Seyedali Pourmoafil

Phishing emails remain one of the most persistent cybersecurity threats, and machine-learning classifiers are widely used to detect them. Most reported detection accuracies, however, are measured on clean, in-distribution test data rather than on emails deliberately altered to ev…

View free PDFSource page