T-Minus: Space-Cyber Briefing 9.6.26
Ep 723 | 9.6.26

When hackers control the clock.

Transcript

Andy Davis: At a really high level, time is probably the most trusted input in computing, and one of the least defended. So, everyone assumes that time is correct and that all other inputs into software, systems, control flows may potentially be tampered with and therefore have to be validated in some way. And often people don't realize that time, A, can be manipulated and if it is, that it's time that's being manipulated that's resulting in the behavior that they're seeing in either their software or their systems.

Maria Varmazis: Welcome. I'm Maria Varmazis, and you're listening to "T-Minus" Space Cyber Briefing". In this show, we examine the evolution of cybersecurity and the global and orbital infrastructure that powers, protects, and connects our lives. [ Music ] Hi, everyone. Thank you, as always, for joining me. Consider the following. A threat actor doing dastardly things to a key dependency, a single-source of truth that basically all of modern computing and infrastructure runs on. Now, lots of you listening undoubtedly don't have to imagine it. All I need to say is "Heartbleed" and I can hear a bunch of you groaning right back at me. Sorry for that unpleasant reminder. But for today's chat, we are not going to look at TLS, don't worry. Instead, we're going to look at time. And this is a space cyberspace show, so when we talk about time, I mean the kind of thing that you get from positioning navigation and timing satellites, like GPS. So, if you need a brush up on all things GPS, I highly recommend you first take a listen to our two-part GPS explainer if you haven't yet. Those would be Episodes 709 and 710, and don't worry, links are in the show notes for you. Now, a concept that we touched on in the second episode was how positioning and navigation exploits of GPS signals are better known and appreciated, but the timing part of it is both much more important, and much less understood, than it should be. So in today's episode, we're going to dig into that in depth with Andy Davis, Global Research Director at NCC Group. In my discussion with him today, he posits that yes, time is one of the most trusted yet least defended inputs in computing, and that manipulating it can create significant security and reliability impacts. The kinds of operational risks introduced by monkeying with time, it is not sci-fi, it's very real. So, let's get into it.

Andy Davis: Hi, I'm Andy Davis. I'm Global Research Director at NCC Group, which is a pure play cybersecurity consulting firm. And I've been at NCC for around 15 years, about half of that time doing research and half of it running our transport practice, the kind of connected cars, planes, trains, that kind of thing. I've been in this industry for more than 30 years now, really interested in understanding how things work and how I can get things to work in ways that they were designed.

Maria Varmazis: I love that. And that, truly, that is what I think a lot of us got into cybersecurity for, is how do we make it do that thing? Yeah, Andy, thank you so much for joining me today. You and your team got in touch about a really fascinating piece that you wrote. And let's start with maybe what that thesis is, and then we'll get into the details.

Andy Davis: Sure. Well, at a really high level, time is probably the most trusted input in computing and one of the least defended. So, everyone assumes that time is correct and that all other inputs into software, systems, control flows may potentially be tampered with and therefore have to be validated in some way. And the premise of the paper is that there are many different ways of manipulating time. Time should be considered another input that can be manipulated, and you can have all kinds of interesting impacts and controls over systems by manipulating the time that's provided to them. And often people don't realize that time, A, can be manipulated. And if it is, that it's time that's being manipulated that's resulting in the behavior that they're seeing in either their software or their systems.

Maria Varmazis: Okay. I want to dive into all of that. So let's start first with timing. You said there's a bunch of different ways that that can essentially be an input. What are those ways?

Andy Davis: So if you've got a large collection of computers all connected together in a data center, let's say, often you will have a central source of truth for time. Quite often GPS is used, the global positioning system, so you're pointing an antenna up at a GPS satellite. And on all GPS satellites, they have a very accurate time source, a clock that's based on a nuclear reaction that's very, very precise. And timing is incredibly important in the GPS satellite network, because if you didn't have such accurate time, then GPS wouldn't work. The subtle differences in the signals being sent from the different GPS satellites, if they weren't that accurate, your location wouldn't be able to be determined as accurately as it can. So, people use the fact that, you know, GPS satellites are actually accessible from everywhere on earth, and by pointing an antenna at the sky, you can get the current accurate time. So they tend to use that as the kind of single source of truth for a computer network and synchronize via various network timing protocols all the different computers and software that's running on them to that single source. Because it's a radio signal, you may well have heard in military contexts, sometimes adversaries will block the GPS signal --

Maria Varmazis: Yes, yes.

Andy Davis: -- to prevent people, you know, accurately knowing where they are. But you can be more creative than that. You can actually spoof GPS signals. So if I had a software-defined radio, which is a piece of kit that you can buy for less than $1000, probably significantly less than $1000, and pointed my antenna at the receiving antenna on the roof of a data center, I could pretend to be the GPS satellite network and I could inject my own time that could be subtly different or wildly different to the real time. And of course, because all of the computers are trusting that time signal, that information would get propagated and refracted through the network. And so that's a kind of a central place where time could be manipulated. But as I said, the, where the information is propagated from one computer to another using a network time protocol, if somebody has got some kind of level of access to that network and has the ability to spoof their own network time protocol or inject protocol data into that network, they can manipulate the time on the network itself. Now, that's not quite so satisfactory because if you, if you're not manipulating the original kind of source of truth coming from a satellite, it might continue to kind of override any changes you try and make within the network.

Maria Varmazis: Right.

Andy Davis: So that's just two kind of ways where people can manipulate that time. Another place, just quickly to think about, is as our computing infrastructure is becoming more and more virtualized, so instead of lots of physical computers you've got lots of computers that are running hypervisors, that are running virtual computers inside of them. Every layer of virtualization you've got within computing is essentially its own little universe that can run its own little, yes, its own time. So, you know, if you can manipulate how time is propagated to these different virtual worlds where virtual computers are running on, then it's another way of manipulating their understanding of what the current time is.

Maria Varmazis: Yeah, I, and that's really the question that comes up for me is I think in the very abstract, I have a little bit of a sense of, you know, you start manipulating time, bad things will happen. What does happen if you mess with timing? Because that is such a very, very basic, you know, layer of understanding that everything operates on. So, is it just things don't work correctly or things just don't work or does it depend?

Andy Davis: There are some very targeted attacks that you can do. Expiry of things like security certificates is a great example. I mean, just to make it kind of really simple to understand. If you imagine a cinema ticket that expires at midnight tonight, the ticket itself may be genuine, but if somebody changes the clock that checks the ticket, then yesterday's ticket suddenly becomes valid again. And instead of a cinema ticket, it's a security certificate that's providing one system access to another system. And, you know, somebody's decided that on a certain date that expires and should be revoked or should be reset for whatever reason. That's an example of where access control could be bypassed.

Maria Varmazis: Well, time is on our side. Time is the enemy. One thing's for sure, time is. And it is time for us to take a quick break. We'll be right back. [ Music ] We return now to my discussion with Andy Davis, Global Research Director at NCC Group, about why timing is a crucial but underappreciated dependency in modern computing. My next question to him was on the manipulation of timing in attacks against crucial infrastructure, like power grids. What would those kinds of attacks look like?

Andy Davis: Synchronization of systems is often very important, and the way that power generation systems operate sometimes rely on very accurate synchronization between one system and another. And if you can, you know, desynchronize those, you can have a massive impact on the way that the systems operate and can negatively impact the generation of the power, or could potentially, you know, cause outages or even, you know, fires and, you know, really nasty events if systems go out of synchronization that are controlling safety critical elements, critical infrastructure.

Maria Varmazis: Wow. Yeah. I think I really, it's something I really didn't appreciate at all. And I'm still, as I've said, I'm learning so much about this. I guess what do we do from here? How do we make systems more resilient? I perhaps incorrectly had assumed there was a lot of redundancy to protect from this sort of thing, or perhaps that these kinds of risks were so maybe military focused that perhaps the rest of us don't need to worry about this as much. But it sounds like those are false assumptions.

Andy Davis: So with regard to redundancy, people think about the redundancy of their systems rather than necessarily the redundancy of their alternate time sources. When people think about time, they're normally more concerned about how accurate that time is, rather than being concerned about what happens if that time is wrong. So, it's kind of a shift in mindset, really, that we're talking about from an accuracy mindset to an integrity mindset. Because people don't often think about the fact that time could be wrong, and if it was wrong, what impact it might have on their systems. It's all about having multiple time sources that you can compare against. So, for example, you know, I talked about accurate time sources being onboard satellites. In the situation where you've got a large data center with lots of expensive servers in it, it's not that much more expensive to get an accurate time source, you know, independent of the satellite network that you have within your network. So, you know, one of those cesium clocks, that kind of thing, the kind of thing that's actually based onboard the satellites. So you can have multiple time sources and constantly compare between the two and make sure that one isn't being manipulated. If you look at mobile phones, for example, one of the things that they do in this sense is they're constantly getting the accurate time information from the GPS satellites, because all smartphones these days have got GPS in them. But they also have an accurate time source that's sent via the cellular network. And, therefore, they are able to, you know, cross-reference between those two. And if, for example, they suddenly see that the GPS time source changes, they can see that either there's been a problem, you know, some kind of reception problem, or it's being spoofed or manipulated.

Maria Varmazis: Okay. All right. So for an infosec practitioner who's listening to our chat right now, I'm wondering if there's anything, any base assumption that we should be challenging or anything that might surprise them to learn, that you want to highlight.

Andy Davis: I think that the most surprising thing is that when time is either manipulated or strays, you know, it changes as a result of some kind of non-malicious reason. The way that that can be exhibited in behavior of the systems doesn't immediately make you think that something external is affecting it. People wouldn't necessarily jump to the conclusion that, oh, it's time that's caused this. Because, you know, apart from the, you know, targeted type attacks that I talked about, where you manipulate time and bypass the security control, if time drifts, it can have very subtle effects on control systems, let's say. And they could be seen as an intermittent failure or, you know, they could be seen as maybe a component within the system that's just degraded over time the way that it's behaving. So, people might jump to the conclusion that, oh, well, that system might have failed and that's why it's behaving that way, rather than the time source that it's relying on has strayed or stopped or changed, and that's the result. So again, it's a kind of a mindset of don't assume that when you see anomalous behavior in your systems that it's actually the fault of the system. It might be, you know, the time source that's being provided to it that can have those effects. I'd just like to mention an incident that happened back in 2012 called The Leap Second Incident. Now, a leap second is an extra second that occasionally needs to be added to universal coordinated time, UTC, in a coordinated way globally because of the way that the earth's rotation changes over time compared to our universal time. So it's basically a correcting factor, that every number of years they need to add an extra second, which is called a leap second. And back in 2012, when they inserted this leap second, it had a huge amount of effect on major internet services. People like LinkedIn, Mozilla, Reddit, all these big systems that have some reliance on time. Just the manipulation of that time by one second that was done in a controlled way had all kinds of unintended consequences on these systems, and really kind of raise the issue as something that people should be more concerned about. Now, when I've mentioned this to people, they can't remember the 2012 Leap Second Incident, so they forget this stuff quickly.

Maria Varmazis: Yeah, I was going to say, I'm trying to remember that as well, and I'm struggling. Can you refresh my memory a little bit on that one?

Andy Davis: So, I mean, the kind of experiences that the servers had were CPU spikes, lockups, crashes, service outages, because the different ways that software components within them handled the extra second incorrectly. So, that basically goes back to your question earlier about, you know, how should system designers cater for these things. They need to consider time being either actively manipulated or, you know, drifting as an input that needs to be checked, and ensure that the robustness of their system when time does change.

Maria Varmazis: That's fascinating. Honestly, this has been such a really interesting chat. Andy, thank you so much for sharing your expertise with us today. It feels kind of metaphysical to be talking about time in such an abstract and also concrete way at the same time. So, this is super neat. Andy, thank you so much for joining me today. I really appreciate it.

Andy Davis: My pleasure. [ Music ]

Maria Varmazis: And that is "T-minus: Space Cyber Briefing", brought to you by N2K CyberWire. If you like what you heard today, you will also enjoy our newsletter, "Signals in Space". You'll get research and notes pulled together by our producer, Ethan Cook, and me, along with this week's top space cyber news stories. Subscribe by visiting thecyberwire.com/newsletters. We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like our show, and we always hope that you do, please share a rating and review in your podcast app. You could also fill out the survey in the show notes or send an email to us at space@n2k.com. We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at n2k.com. Thank you again for listening to "T-Minus". I am your host, Maria Varmazis. The show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliott Peltzman and Tre Hester, with original music by Elliott Peltzman. Our executive producer is Jennifer Eiben, with content strategy by Ma'ayan Plaut. Peter Kilpe is our publisher. See you next week.