{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:28:05Z","timestamp":1785511685842,"version":"3.56.0"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,4,1]],"date-time":"2021-04-01T00:00:00Z","timestamp":1617235200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,4,1]],"date-time":"2021-04-01T00:00:00Z","timestamp":1617235200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The IEEE 1588 precision time protocol (PTP) is very important for many industrial sectors and applications that require time synchronization accuracy between computers down to microsecond and even nanosecond levels. Nevertheless, PTP and its underlying network infrastructure are vulnerable to cyber-attacks, which can stealthily reduce the time synchronization accuracy to unacceptable and even damage-causing levels for individual clocks or an entire network, leading to financial loss or even physical destruction. Existing security protocol extensions only partially address this problem. This paper provides a comprehensive analysis of strategies for advanced persistent threats to PTP infrastructure, possible attacker locations, and the impact on clock and network synchronization in the presence of security protocol extensions, infrastructure redundancy, and protocol redundancy. It distinguishes between attack strategies and attacker types as described in RFC7384, but further distinguishes between the spoofing and time source attack, the simple internal attack, and the advanced internal attack. Some experiments were conducted to demonstrate the impact of PTP attacks. Our analysis shows that a sophisticated attacker has a range of methodologies to compromise a PTP network. Moreover, all PTP infrastructure components can host an attacker, making the comprehensive protection of a PTP network against a malware infiltration, as for example exercised by Stuxnet, a very tedious task.<\/jats:p>","DOI":"10.1186\/s42400-021-00080-y","type":"journal-article","created":{"date-parts":[[2021,3,31]],"date-time":"2021-03-31T23:04:29Z","timestamp":1617231869000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":36,"title":["Precision time protocol attack strategies and their resistance to existing security extensions"],"prefix":"10.1186","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7627-1574","authenticated-orcid":false,"given":"Waleed","family":"Alghamdi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Schukat","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,4,1]]},"reference":[{"key":"80_CR1","doi-asserted-by":"crossref","unstructured":"Alghamdi W, Schukat M (2017) Advanced methodologies to deter internal attacks in PTP time synchronization networks. In: 28th Irish signals and systems conference (ISSC), Killarney, 20-21 June 2017. pp 1-6. IEEE","DOI":"10.1109\/ISSC.2017.7983636"},{"key":"80_CR2","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1109\/MSP.2012.65","volume":"10","author":"E Baize","year":"2012","unstructured":"Baize E (2012) Developing secure products in the age of advanced persistent threats. IEEE Sec & Priv 10:88\u201392. https:\/\/doi.org\/10.1109\/MSP.2012.65","journal-title":"IEEE Sec & Priv"},{"key":"80_CR3","volume-title":"Secure 1588 in HeNB \/ Femtocell application","author":"D Chen","year":"2013","unstructured":"Chen D (2013) Secure 1588 in HeNB \/ Femtocell application. Paper presented at the Time & Sync in Telecoms, Lisbon"},{"key":"80_CR4","first-page":"91","volume":"44","author":"T Chen","year":"2011","unstructured":"Chen T, Abu-Nimeh S (2011) Lessons from stuxnet. Comp 44:91\u201393","journal-title":"Comp"},{"key":"80_CR5","doi-asserted-by":"publisher","first-page":"316","DOI":"10.1016\/j.procs.2019.02.058","volume":"150","author":"DX Cho","year":"2019","unstructured":"Cho DX, Nam HH (2019) A method of monitoring and detecting APT attacks based on unknown domains. Proc Comp Sci 150:316\u2013323","journal-title":"Proc Comp Sci"},{"key":"80_CR6","doi-asserted-by":"crossref","unstructured":"Dadheech K, Choudhary A, Bhatia G (2018, 2018) De-militarized zone: a next level to network security. In: Second international conference on inventive communication and computational technologies (ICICCT), Coimbatore, pp 595\u2013600","DOI":"10.1109\/ICICCT.2018.8473328"},{"key":"80_CR7","doi-asserted-by":"crossref","unstructured":"Dalmas M, Rachadel H, Silvano G, Dutra C (2015, 2015) Improving PTP robustness to the byzantine failure. In: IEEE international symposium on precision clock synchronization for measurement, control, and communication (ISPCS), Beijing, pp 111\u2013114","DOI":"10.1109\/ISPCS.2015.7324693"},{"key":"80_CR8","doi-asserted-by":"publisher","unstructured":"DeCusatis C, Lynch RM, Kluge W, Houston J, Wojciak P, Guendert S (2019) Impact of Cyberattacks on precision time protocol. IEEE Trans Inst Meas\u00a069:2172\u20132181.\u00a0https:\/\/doi.org\/10.1109\/TIM.2019.2918597","DOI":"10.1109\/TIM.2019.2918597"},{"key":"80_CR9","unstructured":"Donoghue KO, Sibold D, Fries S (2017) New security mechanisms for network time synchronization protocols. In: IEEE international symposium on precision clock synchronization for measurement, control, and communication (ISPCS), California, pp 1\u20136"},{"key":"80_CR10","doi-asserted-by":"crossref","unstructured":"Estrela PV, Neus\u00fc\u00df S, Owczarek W (2014, 2014) Using a multi-source NTP watchdog to increase the robustness of PTPv2 in financial industry networks. In: Precision clock synchronization for measurement, control, and communication (ISPCS), IEEE international symposium on, Austin. IEEE, pp 87\u201392","DOI":"10.1109\/ISPCS.2014.6948697"},{"key":"80_CR11","first-page":"1","volume-title":"IEEE 1588 Version 2","author":"GM Garner","year":"2008","unstructured":"Garner GM (2008) IEEE 1588 Version 2, vol 8. ISPCS, Ann Arbor, pp 1\u201389"},{"key":"80_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/IEEESTD.2008.4579760","volume-title":"IEEE Std 1588\u20132008 (Revision of IEEE Std 1588\u20132002)","author":"IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems","year":"2008","unstructured":"IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems (2008) IEEE Std 1588\u20132008 (Revision of IEEE Std 1588\u20132002), pp 1\u2013269. https:\/\/doi.org\/10.1109\/IEEESTD.2008.4579760"},{"key":"80_CR13","first-page":"1","volume-title":"IEEE Std 1588\u20132019 (Revision ofIEEE Std 1588\u20132008)","author":"IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems","year":"2020","unstructured":"IEEE Standard for a Precision Clock Synchronization Protocol for Networked Measurement and Control Systems (2020) IEEE Std 1588\u20132019 (Revision ofIEEE Std 1588\u20132008), pp 1\u2013499"},{"key":"80_CR14","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/IEEESTD.2006.245590","volume-title":"IEEE Std 802.1AE-2006","author":"IEEE Standard for Local and Metropolitan Area Networks: Media Access Control (MAC) Security","year":"2006","unstructured":"IEEE Standard for Local and Metropolitan Area Networks: Media Access Control (MAC) Security (2006) IEEE Std 802.1AE-2006, pp 1\u2013150. https:\/\/doi.org\/10.1109\/IEEESTD.2006.245590"},{"key":"80_CR15","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1109\/TDSC.2017.2748583","volume":"17","author":"E Itkin","year":"2020","unstructured":"Itkin E, Wool A (2020) A security analysis and revised security extension for the precision time protocol. IEEE Trans Dep Sec Com 17:22\u201334. https:\/\/doi.org\/10.1109\/TDSC.2017.2748583","journal-title":"IEEE Trans Dep Sec Com"},{"key":"80_CR16","volume-title":"Industrial network security: securing critical infrastructure networks for smart grid, SCADA, and other industrial control systems","author":"ED Knapp","year":"2015","unstructured":"Knapp ED, Langill JT (2015) Industrial network security: securing critical infrastructure networks for smart grid, SCADA, and other industrial control systems"},{"key":"80_CR17","doi-asserted-by":"crossref","unstructured":"Koskiahde T, Kujala J (2016) PTP monitoring in redundant network. In: IEEE international symposium on precision clock synchronization for measurement, control, and communication (ISPCS), Stockholm, pp 1\u20135","DOI":"10.1109\/ISPCS.2016.7579510"},{"key":"80_CR18","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1109\/MSP.2011.67","volume":"9","author":"R Langner","year":"2011","unstructured":"Langner R (2011) Stuxnet: dissecting a cyberwarfare weapon. IEEE Sec Priv 9:49\u201351","journal-title":"IEEE Sec Priv"},{"key":"80_CR19","doi-asserted-by":"publisher","first-page":"1482","DOI":"10.1109\/26.103043","volume":"39","author":"DL Mills","year":"1991","unstructured":"Mills DL (1991) Internet time synchronization: the network time protocol. IEEE Trans Comm 39:1482\u20131493","journal-title":"IEEE Trans Comm"},{"key":"80_CR20","doi-asserted-by":"crossref","unstructured":"Mizrahi T (2011) Time synchronization security using IPsec and MACsec. In: Proceedings of the International IEEE Symposium on Precision Clock Synchronization for Measurement Control and Communication, Munich, pp 38\u201343","DOI":"10.1109\/ISPCS.2011.6070153"},{"key":"80_CR21","volume-title":"RFC 7384","author":"T Mizrahi","year":"2014","unstructured":"Mizrahi T (2014) Security requirements of time protocols in packet switched networks. In: RFC 7384 https:\/\/tools.ietf.org\/html\/rfc7384"},{"key":"80_CR22","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1109\/TII.2019.2943913","volume":"16","author":"B Moussa","year":"2020","unstructured":"Moussa B, Kassouf M, Hadjidj R, Debbabi M, Assi C (2020) An extension to the precision time protocol (PTP) to enable the detection of cyber attacks. IEEE Trans Ind Info 16:18\u201327. https:\/\/doi.org\/10.1109\/TII.2019.2943913","journal-title":"IEEE Trans Ind Info"},{"key":"80_CR23","doi-asserted-by":"crossref","unstructured":"Neyer J, Gassner L, Marinescu C (2019) Redundant schemes or how to counter the delay attack on time synchronization protocols. In: IEEE international symposium on precision clock synchronization for measurement, control, and communication (ISPCS), Portland, pp 1\u20136","DOI":"10.1109\/ISPCS.2019.8886635"},{"key":"80_CR24","first-page":"1","volume-title":"International IEEE symposium on precision clock synchronization for measurement control and communication (ISPCS)","author":"C \u00d6nal","year":"2012","unstructured":"\u00d6nal C, Kirrmann H (2012) Security improvements for IEEE 1588 annex K: implementation and comparison of authentication codes. In: International IEEE symposium on precision clock synchronization for measurement control and communication (ISPCS). IEEE, San Francisco, pp 1\u20136"},{"key":"80_CR25","volume-title":"Analysis of selective packet delay attack on IEEE 1588 precision time protocol","author":"Y Pathan","year":"2014","unstructured":"Pathan Y, Dalvi A, Pillai A, Patil D, Reed D (2014) Analysis of selective packet delay attack on IEEE 1588 precision time protocol. Technical Report, University of Colorado at Boulder"},{"key":"80_CR26","doi-asserted-by":"publisher","first-page":"3874","DOI":"10.3390\/app10113874","volume":"10","author":"S Quintero-Bonilla","year":"2020","unstructured":"Quintero-Bonilla S, Mart\u00edn del Rey A (2020) A new proposal on the advanced persistent threat: a survey. App Scie 10:3874","journal-title":"App Scie"},{"key":"80_CR27","volume-title":"Improved techniques for time synchronization over WiFi and wireless sensor networks","author":"J Shannon","year":"2013","unstructured":"Shannon J (2013) Improved techniques for time synchronization over WiFi and wireless sensor networks. Dissertation, National University of Ireland, Galway"},{"key":"80_CR28","first-page":"365","volume-title":"IEEE global communications conference (GLOBECOM)","author":"J Shannon","year":"2012","unstructured":"Shannon J, Melvin H, Ruzzelli AG (2012) Dynamic flooding time synchronization protocol for WSNs. In: IEEE global communications conference (GLOBECOM). IEEE, Anaheim, pp 365\u2013371"},{"key":"80_CR29","doi-asserted-by":"crossref","unstructured":"Shereen E, Bitard F, D\u00e1n G, Sel T, Fries S (2019) Next steps in security for time synchronization: experiences from implementing IEEE 1588 v2.1. In: IEEE international symposium on precision clock synchronization for measurement, control, and communication (ISPCS), Portland, pp 1\u20136","DOI":"10.1109\/ISPCS.2019.8886641"},{"key":"80_CR30","doi-asserted-by":"crossref","unstructured":"Shpiner A, Revah Y, Mizrahi T (2013) Multi-path Time Protocols. In: IEEE International Symposium on Precision Clock Synchronization for Measurement, Control and Communication (ISPCS) Proceedings, Lemgo, pp 1\u20136","DOI":"10.1109\/ISPCS.2013.6644754"},{"key":"80_CR31","unstructured":"Stallings W (2006) Cryptography and network security: principles and practices. New Jersey: Pearson Education India"},{"key":"80_CR32","unstructured":"Vacca JR (2017) Computer and information security handbook. San Francisco: Morgan Kaufmann"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00080-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s42400-021-00080-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00080-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,3,31]],"date-time":"2021-03-31T23:05:52Z","timestamp":1617231952000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00080-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,1]]},"references-count":32,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["80"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00080-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,4,1]]},"assertion":[{"value":"11 February 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 February 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 April 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"12"}}