Nothing Special   »   [go: up one dir, main page]

skip to main content
Open access

Deep Dive into NTP Pool's Popularity and Mapping

Published: 21 February 2024 Publication History


Time synchronization is of paramount importance on the Internet, with the Network Time Protocol (NTP) serving as the primary synchronization protocol. The NTP Pool, a volunteer-driven initiative launched two decades ago, facilitates connections between clients and NTP servers. Our analysis of root DNS queries reveals that the NTP Pool has consistently been the most popular time service. We further investigate the DNS component (GeoDNS) of the NTP Pool, which is responsible for mapping clients to servers. Our findings indicate that the current algorithm is heavily skewed, leading to the emergence of time monopolies for entire countries. For instance, clients in the US are served by 551 NTP servers, while clients in Cameroon and Nigeria are served by only one and two servers, respectively, out of the 4k+ servers available in the NTP Pool. We examine the underlying assumption behind GeoDNS for these mappings and discover that time servers located far away can still provide accurate clock time information to clients. We have shared our findings with the NTP Pool operators, who acknowledge them and plan to revise their algorithm to enhance security.


Apple. 2021. Apple NTPService.
Roy Arends, Rob Austein, Matt Larson, Dan Massey, and Scott Rose. 2005. DNS Security Introduction and Requirements. RFC 4033. IETF.
Jari Arkko. 2019. Centralised Architectures in Internet Infrastructure. Internet Draft. arch-infrastructure-centralisation-00
Jari Arkko. 2020. The influence of Internet architecture on centralised versus distributed Internet services. Journal of Cyber Policy 5, 1 (2020), 30--45.
Arkko, Jari and Tramme, B. and Nottingham,Mand Huitema, C and Thomson, M. and Tantsura, J. and ten Oever, N. 2019. Considerations on Internet Consolidation and the Internet Architecture. Internet Draft. iab-internet-consolidation-02
Ask Bjørn Hansen. 2021. GeoDNS servers.
Ask Bjørn Hansen. 2023. Minor New Features on the website. the-website/2947/8.
Rushvanth Bhaskar. 2022. A Day in the Life of NTP: Analysis of NTPPool Traffic. Master's thesis. University of Twente and SIDN Labs, Enschede and Arnhem, The Netherlands. Master's thesis.
Stephan Bortzmeyer, Ralph Dolmans, and Paul Hoffman. 2021. DNS Query Name Minimisation to Improve Privacy. RFC 9156. IETF.
Physikalisch Technische Bundesanstalt. 2022. FDCF77 - (Nov. 5 2022). fachabteilungen/abt4/fb-44/ag-442/dissemination-of-legal-time/dcf77.html
Randy Bush and Rob Austein. 2013. The Resource Public Key Infrastructure (RPKI) to Router Protocol. RFC 6810. IETF.
CAIDA. 2022. Index of /datasets/routing/routeviews-prefix2as. routeviews-prefix2as.
Sebastian Castro, Duane Wessels, Marina Fomenkov, and Kimberly Claffy. 2008. A Day at the Root of the Internet. ACM Computer Communication Review 38, 5 (April 2008), 41--46.
Cloudflare. 2021. Cloudflare Time Service.
C. Contavalli, W. van der Gaast, D. Lawrence, and W. Kumari. 2016. Client Subnet in DNS Queries. RFC 7871. IETF.
Jakub Czyz, Michael Kallitsis, Manaf Gharaibeh, Christos Papadopoulos, Michael Bailey, and Manish Karir. 2014. Taming the 800 Pound Gorilla: The Rise and Decline of NTP DDoS Attacks. In Proceedings of the 2014 ACM Conference on Internet Measurement Conference (Vancouver, BC, Canada) (IMC). ACM, 435--448.
Wouter B de Vries, Quirin Scheitle, Moritz Müller, Willem Toorop, Ralph Dolmans, and Roland van Rijswijk-Deij. 2019. A First Look at QNAME Minimization in the Domain Name System. In International Conference on Passive and Active
Omer Deutsch, Neta Rozen Schiff, Danny Dolev, and Michael Schapira. 2018. Preventing (Network) Time Travel with Chronos. In NDSS.
Tim Dierks and Eric Rescorla. 2008. The Transport Layer Security (TLS) Protocol Version 1.2. RFC 5246. IETF. http: //
DNS OARC. 2022. DITL Traces and Analysis.
Ralph Droms. 1997. Dynamic Host Configuration Protocol. RFC 2131. IETF.
Toby Ehrenkranz and Jun Li. 2009. On the state of IP spoofing defense. ACM Transactions on Internet Technology (TOIT) 9, 2 (2009), 1--29.
Daniel Franke, Dieter Sibold, Kristof Teichel, Marcus Dansarie, and Ragnar Sundblad. 2020. Network Time Security for the Network Time Protocol. RFC 8915. IETF.
Richard Gayraud and Benoit Lourdelet. 2010. Network Time Protocol (NTP) Server Option for DHCPv6. RFC 5908. IETF.
Google. 2021. Google Public NTP.
Mohammad Javad Hajikhani, Thomas Kunz, and Howard Schwartz. 2016. A Recursive Method for Clock Synchronization in Asymmetric Packet-Based Networks. IEEE/ACM Transactions on Networking 24, 4 (2016), 2332--2342.
Stewart Hampton. 2018. Five Dangers of Poor Network Timekeeping + Easy and Cost Effective Solutions (Part 2 of 10). (Sept. 5 2018). effective-solutions-to-avoid-networks-fall-out-of-sync-part-2-of-10/
Alden Hilton, Casey Deccio, and Jacob Davis. 2023. Fourteen Years in the Life: A Root Server's Perspective on DNS Resolver Security. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 3171--3186.
Philip Homburg. 2015. NTP Measurements with RIPE Atlas. with-ripe-atlas/.
Nate Hopper. 2022. The Thorny Problem of Keeping the Internet's Time. The New Yorker (Sept. 30 2022). https: //
IEEE. 2002. IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems. IEEE Std. 1588--2002 (2002).
IEEE. 2020. IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems. IEEE Std 1588--2019 (Revision ofIEEE Std 1588--2008) (2020), 1--499.
ITU. 2023. Statistics.
Philipp Jeitner, Haya Shulman, and Michael Waidner. 2020. The Impact of DNS Insecurity on Time. In 2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN). 266--277. 1109/DSN48063.2020.00043
Cecilia Kang and David McCabe. 2020. Lawmakers, United in Their Ire, Lash Out at Big Tech's Leaders. New York Times (July. 29 2020). html
Aqsa Kashaf, Vyas Sekar, and Yuvraj Agarwal. 2020. Analyzing Third Party Service Dependencies in Modern Web Services: Have We Learned from the Mirai-Dyn Incident?. In Proceedings of the ACM Internet Measurement Conference (Virtual Event, USA) (IMC '20). Association for Computing Machinery, New York, NY, USA, 634--647.
Robert Kisteleki. 2023. NTP empty results ('result': ['x': '*']). October/005607.html.
Warren Kumari and Paul Hoffman. 2020. Running a Root Server Local to a Resolver. RFC 8806. IETF. http://tools.ietf. org/rfc/rfc8806.txt
Jonghoon Kwon, Jeonggyu Song, Junbeom Hur, and Adrian Perrig. 2023. Did the Shark Eat the Watchdog in the NTP Pool? Deceiving the NTP Pool's Monitoring System. In 30th USENIX Security Symposium. conference/usenixsecurity23/presentation/kwon
Leslie Lamport. 2019. Time, Clocks, and the Ordering of Events in a Distributed System. Association for Computing Machinery, New York, NY, USA, 179--196.
Ziqian Liu, Bradley Huffaker, Marina Fomenkov, Nevil Brownlee, and Kimberly Claffy. 2007. Two Days in the Life of the DNS Anycast Root Servers. In Proceedings of the International conference on Passive and Active Measurements (PAM). 125--134.
Jonathan Magnusson, Moritz Müller, Anna Brunstrom, and Tobias Pulls. 2023. A Second Look at DNS QNAME Minimization. In Passive and Active Measurement: 24th International Conference, PAM 2023, Virtual Event, March 21--23, 2023, Proceedings. Springer, 496--521.
Aanchal Malhotra, Isaac E Cohen, Erik Brakke, and Sharon Goldberg. 2016. Attacking the Network Time Protocol. In Proceedings of the 23rd Network and Distributed System Security Symposium (NDSS 2016) (San Diego, California).
Aanchal Malhotra and Sharon Goldberg. 2016. Attacking NTP's Authenticated Broadcast Mode. SIGCOMM Comput. Commun. Rev. 46, 2 (may 2016), 12--17.
Aanchal Malhotra, Matthew Van Gundy, Mayank Varia, Haydn Kennedy, Jonathan Gardner, and Sharon Goldberg. 2017. The Security of NTP's Datagram Protocol. In Financial Cryptography and Data Security: 21st International Conference, FC 2017, Sliema, Malta, April 3--7, 2017, Revised Selected Papers 21. Springer, 405--423.
Mark Morowczynski. 2012. Did YourActive Directory Domain Time Just Jump To The Year 2000? https://techcommunity. 2000/ba-p/255873.
Maxmind. 2021. Maxmind.
Microsoft. 2021. Microsoft NTP Service.
David Mills. 2006. Simple Network Time Protocol (SNTP) Version 4 for IPv4, IPv6 and OSI. RFC 4330. IETF. http: //
David Mills, Jim Martin, Jack Burbank, and William Kasch. 2010. Network Time Protocol Version 4: Protocol and Algorithms Specification. RFC 5905. IETF.
Paul Mockapetris. 1987. Domain names - concepts and facilities. RFC 1034. IETF.
Giovane C. M. Moura, Sebastian Castro, Wes Hardaker, Maarten Wullink, and Cristian Hesselman. 2020. Clouding up the Internet: How Centralized is DNS Traffic Becoming?. In Proceedings of the ACM Internet Measurement Conference (Virtual Event, USA) (IMC '20). Association for Computing Machinery, New York, NY, USA, 42--49.
Giovane C. M. Moura, Ricardo deO. Schmidt, John Heidemann,Wouter B. de Vries, Moritz Müller, LanWei, and Christian Hesselman. 2016. Anycast vs. DDoS: Evaluating the November 2015 Root DNS Event. In Proceedings of the ACM Internet Measurement Conference. ACM, Santa Monica, California, USA, 255--270.
Giovane C. M. Moura, John Heidemann, Ricardo de O. Schmidt, and Wes Hardaker. 2019. Cache Me If You Can: Effects of DNS Time-to-Live. In Proceedings of the ACM Internet Measurement Conference. ACM, Amsterdam, the Netherlands, 101--115.
Giovane C. M. Moura, John Heidemann, Moritz Müller, Ricardo de O. Schmidt, and Marco Davids. 2018. When the Dike Breaks: Dissecting DNS Defenses During DDoS. In Proceedings of the ACM Internet Measurement Conference. ACM, Boston, MA, USA, 8--21.
Moritz Müller, Giovane C. M. Moura, Ricardo de O. Schmidt, and John Heidemann. 2017. Recursives in the Wild: Engineering Authoritative DNS Servers. In Proceedings of the ACM Internet Measurement Conference. ACM, London, UK, 489--495.
Network Time Foundation. 2022. Download NTP .
Clifford Neuman, Tom Yu, Sam Hartman, and Kenneth Raeburn. 2005. The Kerberos Network Authentication Service (V5). RFC 4120. IETF.
NIST. 2022. NIST Internet Time Service (ITS). (Nov. 5 2022). time-distribution/internet-time-service-its
M. Nottingham. 2023. Centralization, Decentralization, and Internet Standards. RFC 9518. IETF. rfc9518.txt
NTP Pool. 2021. All Pool Servers.
NTP Pool. 2021. Argentina -
NTP Pool. 2021. statistics for .
NTP Pool. 2021. Statistics for
NTP Pool. 2021. the internet cluster of ntp servers.
NTP Pool. 2021. The NTP Pool for vendors.
NTP Pool. 2022. How do I join
NTP Pool. 2023. Monitoring System - Technical details.
NTP Pool. 2023. NTP Pool Monitoring v2.
Oleg Obleukhov. 2020. Building a more accurate time service at Facebook scale. 18/production-engineering/ntp-service/.
United States Naval Observatory. 2022. Information about NTP, the time backbone of the Internet. (Nov. 5 2022). Network-Time-Protocol-NTP/
Yarin Perry, Neta Rozen-Schiff, and Michael Schapira. 2021. A Devil of a Time: How Vulnerable is NTP to Malicious Timeservers?. In Proceedings of the 28th Network and Distributed System Security Symposium (NDSS 2021) (Virtual Conference).
RIPE NCC. 2021. RIPE Atlas Measurement IDS., where ID is the experiment ID: EnumV4: 32025718, EnumV6: 32058440, ArgV4: 31789516, ArgV4-Emul:31830680, ArgV4-Android: 31992051, DE-Android:31970486, ArgV6:32001506.
RIPE NCC. 2023. RIPE Atlas Measurement IDS., where ID is the experiment ID: Cloudflare: 47865355, Africa: 47867480, Asia:47867358, Europe: 47867632, North America:47867336, South America:47867316:.
RIPE NCC Staff. 2015. RIPE Atlas: A Global Internet Measurement Network. Internet Protocol Journal (IPJ) 18, 3 (Sep 2015), 2--26.
RIPE Network Coordination Centre. 2020. RIPE Atlas.
Root Server Operators. 2021. Root DNS.
Teemu Rytilahti, Dennis Tatang, Janosch Köpper, and Thorsten Holz. 2018. Masters of Time: An Overview of the NTP Ecosystem. In 2018 IEEE European Symposium on Security and Privacy (EuroS P). 122--136. EuroSP.2018.00017
Bruce Schneier. 2018. Censorship in the Age of Large Cloud Providers. 2018/06/censorship_in_the_ag.html
Jeff A. Sherman and Judah Levine. 2016. Usage Analysis of the NIST Internet Time Service. Journal of Research of the National Institute of Standards and Technology 121 (March 2016), 33.
SIDN Labs. 2024. TimeNL.
Internet Society. 2019. Consolidation in the Internet Economy.
Stéphane Bortzmeyer. 2015. DNS Censorship (DNS Lies) As Seen By RIPE Atlas. bortzmeyer/dns-censorship-dns-lies-as-seen-by-ripe-atlas/.
Ubuntu. 2023. Ubuntu NTP Service.
Kevin Vermeulen, Ege Gurmericliler, Italo Cunha, David Choffnes, and Ethan Katz-Bassett. 2022. Internet Scale Reverse Traceroute. In Proceedings of the 22nd ACM Internet Measurement Conference (Nice, France) (IMC '22). Association for Computing Machinery, New York, NY, USA, 694--715.
Adrian von Bidder. 2003. ntp DNS round robin experiment. cShrN7imCJ0.

Cited By

View all
  • (2024)The Multiple Benefits of a Secure Transport for BGPProceedings of the ACM on Networking10.1145/36964062:CoNEXT4(1-23)Online publication date: 25-Nov-2024
  • (2024)Deep Dive into NTP Pool's Popularity and MappingACM SIGMETRICS Performance Evaluation Review10.1145/3673660.365505152:1(9-10)Online publication date: 13-Jun-2024
  • (2024)Byzantine-Secure Relying Party for Resilient RPKIProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security10.1145/3658644.3690368(49-63)Online publication date: 2-Dec-2024
  • Show More Cited By



Please enable JavaScript to view thecomments powered by Disqus.

Information & Contributors


Published In

cover image Proceedings of the ACM on Measurement and Analysis of Computing Systems
Proceedings of the ACM on Measurement and Analysis of Computing Systems  Volume 8, Issue 1
March 2024
494 pages
Issue’s Table of Contents
This work is licensed under a Creative Commons Attribution International 4.0 License.


Association for Computing Machinery

New York, NY, United States

Publication History

Published: 21 February 2024
Published in POMACS Volume 8, Issue 1

Check for updates

Author Tags

  1. client mapping
  2. dns
  3. measurements
  4. ntp
  5. ntp pool


  • Research-article

Funding Sources


Other Metrics

Bibliometrics & Citations


Article Metrics

  • Downloads (Last 12 months)1,595
  • Downloads (Last 6 weeks)215
Reflects downloads up to 13 Feb 2025

Other Metrics


Cited By

View all
  • (2024)The Multiple Benefits of a Secure Transport for BGPProceedings of the ACM on Networking10.1145/36964062:CoNEXT4(1-23)Online publication date: 25-Nov-2024
  • (2024)Deep Dive into NTP Pool's Popularity and MappingACM SIGMETRICS Performance Evaluation Review10.1145/3673660.365505152:1(9-10)Online publication date: 13-Jun-2024
  • (2024)Byzantine-Secure Relying Party for Resilient RPKIProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security10.1145/3658644.3690368(49-63)Online publication date: 2-Dec-2024
  • (2024)Deep Dive into NTP Pool's Popularity and MappingAbstracts of the 2024 ACM SIGMETRICS/IFIP PERFORMANCE Joint International Conference on Measurement and Modeling of Computer Systems10.1145/3652963.3655051(9-10)Online publication date: 10-Jun-2024

View Options

View options


View or Download as a PDF file.



View online with eReader.


Login options

Full Access






Share this Publication link

Share on social media