SlideShare a Scribd company logo
1 of 26
Download to read offline
SESSION ID:
#RSAC
Michael Calabro
WHAT TIME IS IT?
HOW MANIPULATING "NOW" CAN
CRASH OUR WORLD
HTA-W12
Senior Lead Engineer
Booz Allen Hamilton
Calabro_Michael@bah.com
#RSAC
Why do we need SynchronizaHon?
2
Event ordering
Fairness in Race CondiHons
Security
Event Forensics
#RSAC
Time is Made Up
3
Physicists noted that some materials generate very stable reference
signals at predictable periods (cesium, rubidium)
If you count these periods …
The SI definiHon of a second is the Hme that elapses during
9,192,631,770 cycles of the radiaHon produced by the transiHon
between two levels of the cesium 133 atom.
#RSAC
Time Scales are Agreed Upon and “Local”
4
UTC (USNO) UTC (NIST) Mike Time
#RSAC
Time Accuracy and Precision are DisHnct
5
Precise, Not Accurate
Precise & Accurate
Accurate, Not Precise
#RSAC
The Path of Time Transfer
6
Master Clock
00:00:00.000???
00:00:00.000000 +/- X +/- Y +/- Z
Delays are known or bounded
Time stamps are
transferred from that
source to end applicaHons
Time is
measured
at a source
#RSAC
Time Transfer and Time Sources are Different
7
GPS
NTP PTP
ApplicaHon
LTE
UTC(USNO)
U.S. Air
Force
PTRC
GPS
Rx
GPS
Rx
GPS
Rx
GPS
Rx
GPS
Rx
#RSAC
Financial Business Clock Time Sources
8
MulMple
Technologies,
40%
NTP, 27%
GPS, 6%
PTP, 6%
CDMA, 2%
Other
Technologies,
3%
Did Not Know ,
16%
(FROM 2017 SEC CLOCK SURVEY)
#RSAC
How Time is Transferred via GPS
9
Precise code phase alignment can give < 10 nanoseconds of precision
Distance (m) / Speed of Light (m/s) = Delay (Rule of Thumb: 1 e / ns)
0100110110101011010101110101Path Delay
RX
0100110110101011010101110101
SV Transmits known PN Sequence
GPS receiver generates local
copy and aligns it to transmi`ed
sequence
Precision of alignment
determines precision of Mme
delay calculaMon
#RSAC
GPS is Vulnerable to ManipulaHon
10
Data A`acks Repeaters or
Unsynchronized Spoofers
Code Phase Synchronous
Spoofers
Receivers and their applicaHons do math based
on broadcast parameters. Divide by zeros?
Overflows? Time might go backwards.
Time will jump around. Time may advance more or less quickly … but at
a high level, may appear accurate.
Broadcast by GPS
Algorithms from GPS SPS SpecificaMon
GPS Rx locks on to
dominate signal
GPS Rx locks on to dominate signal and
that signal is very close to the real signal
#RSAC
How GPS Time can be Subtly Spoofed
11
0100110110101011010101110101Path Delay
RX
0100110110101011010101110101
SV Transmits PN Sequence
Rx Generates local copy and
aligns it to transmi`ed
sequence
Precision of alignment
determines precision of Mme
delay calculaMon
Spoofer Near Matched Delay
0100110110101011010101110101
#RSAC
Review So Far
12
Time is “made up”
Time is Measured directly or Transferred
GPS is a common source of Hme across all applicaHons
Timing and SynchronizaHon requirements exist at a variety of levels
across applicaHons
So… What happens when Synch breaks down?
#RSAC
TelecommunicaHons Networks Have the
Strictest Commercial Timing Requirements
13
ApplicaMon/
Technology
Accuracy SpecificaMon
WCDMA MBSFN 12.8 µs [b-3GPP TS 25.346] secHons 7.1A and 7.1B.2.1
LTE-TDD (wide-area) 10 µs [b-3GPP TS 36.133]) secHon 7.4.2
LTE-TDD to CDMA 10 µs [b-TS 3GPP TS 36.133] secHon 7.5.2.1
CDMA2000 3 µs [b-3GPP2 C.S0002] secHon 1.3; [b-3GPP2 C.S0010] secHon 4.2.1.1
WCDMA-TDD 2.5 µs [b-3GPP TS 25.402] secHons 6.1.2 and 6.1.2.1
WiMAX (downlink) 1.428 µs [b-IEEE 802.16] table 6-160, secHon 8.4.13.4
WiMAX (base staHon) 1 µs [b-WMF T23-001], secHon 4.2.2
Primary Reference Time Clock 100 ns [ITU-T G.8272] (Primary Reference Time Clock)
Enhanced PRTC 30 ns [ITU-T G.8272.1] (Enhanced Primary Reference Time Clock)
#RSAC
Power Grid Uses of Time
14
From NASPI-2017-TR-001
#RSAC
EU Finance Requirements in Effect Jan. 2018
15
From COMMISSION DELEGATED REGULATION (EU) 2017/574
#RSAC
Some Scenarios – Financial Front Running
16
T = 0.000
T = 0.001
Buyer buys 1000000 shares of ABC
Seller sells 100000 shares of ABC
T = 0.002
T = 0.00000
T = 0.00010
Seller sells 100000 shares of ABC
T = 0.00035
Buyer buys 1000000 shares of ABC
T = 0.00200
Which ordering of events would you prefer? What if you could change your Hme stamp?
#RSAC
January 25th, 2016 – The Worldwide “Spoof”
#RSAC
A Unique Set of Error CondiHons
18
On January 25th, 2016, during the reHrement of the last IIA satellite,
an error occurring in the GPS system causing many receivers that
used the UTC correcHon broadcast by the satellites to be ~13.7
microseconds deviant from truth
Global effect
Not all satellites broadcast erroneous data
Affected receivers needed to obtain their UTC offset from a bad
satellite – i.e. not all receivers with a common skyview would have
been affected
#RSAC
Suspect a GPS Problem? Call the Coast Guard
19
#RSAC
Effects (caused by an ~12 hour event)
20
Of ~80 NIST clocks monitoring event, only 11% were unaffected
Some high performance precision Hming receivers took 1+ day to
resynchronize to their previous levels of stability
Many precision Hming receivers entered into holdover (starHng a count
down hours to out-of-spec performance)
At least one telecommunicaHons backhaul provider reported that it was
necessary to manually reset affected precision Hming receivers
Some clocks located in telecom systems started to free run with no atomic
discipline or back up
Many organizaHons that should have been affected did not report any
impact (did they even know how close they came to major issues?)
#RSAC
It is Really Hard to Get Away from GPS…
21
Timing Source GPS Dependent Scale Availability Comments
GNSS Yes < 100 ns Global
Not appropriate for all
environments; may be denied
GSM NTIZ Yes ~1s Regional
CDMA2000 Sync Yes 1 ms Regional
LTE R11+ SIB 16 Yes 10 ms
Not widely deployed. 10 ms may
not be sufficiently precise.
Iridium Time
(Satelles)
Yes < 500 ns Global
Paid Service; May have higher
availability than GNSS
eLoran Yes < 100 ns
Europe, Asia,
Middle East
Not available in the US
#RSAC
Upcoming 5G and IoT Sync Requirements
22
Edge of network sync in in TDD LTE is ~ 1 microsecond; 5G proposes
to aggressively push this down – thereby increasing dependency on
synch
SynchronizaHon requirements between cloud processes and events
will become stricter
IoT will need ways to synch local devices
#RSAC
OrganizaHons that are working on this
23
ATIS SynchronizaHon Commi{ee
Resilient NavigaHon & Timing FoundaHon
Network Time FoundaHon
North American Synchrophasor IniHaHve (NASPI)
NaHonal Space-Based PNT Advisory Board and PNT ExecuHve
Commi{ee
#RSAC
Conclusions
24
GPS remains the most convenient source of Hme transfer and is the
only technology capable of meeHng upcoming synchronizaHon
requirements efficiently
2017 and 2018 are seeing many new synchronizaHon applicaHons
being deployed across telecom, finance, transportaHon, and
Sync needs to be done securely and deliberately
Secure SynchronizaHons SoluHons exist today; advocacy is needed at
a naHonal level for an alternaHve system to GPS
#RSAC
Selected References
25
NIST Report on January 2016 Outage
h{ps://}.nist.gov/general/pdf/2886.pdf
SEC Clock Survey
h{ps://www.sec.gov/divisions/marketreg/consolidated-audit-trail-clock-synchronizaHon-assessment-051517.pdf
NASPI
h{ps://www.naspi.org/sites/default/files/reference_documents/ts}_electric_power_system_report_pnnl_26331_march_2017_0.pdf
#RSAC
Apply What You Have Learned Today
26
Next week you should:
IdenHfy synchronizaHon dependent applicaHons within your organizaHon
In the first three months following this presentaHon you should:
Understand where these sync-dependent applicaHons get their Hme from and
their corresponding tolerances for failure
Within six months you should:
Understand how to a{ribute system failures to synchronizaHon outages
“Protect, Toughen, and Augment” your Timing Sources and Sync Methods
Michael Calabro
Calabro_Michael@bah.com

More Related Content

What's hot

PAS planet accuracy simpler
PAS planet accuracy simplerPAS planet accuracy simpler
PAS planet accuracy simplerXiaohua Wen
 
Raw GNSS Measurements under Android : Data Quality Analysis
Raw GNSS Measurements under Android : Data Quality AnalysisRaw GNSS Measurements under Android : Data Quality Analysis
Raw GNSS Measurements under Android : Data Quality AnalysisThe European GNSS Agency (GSA)
 
Introducing the Galileo PVT App:from Assisted GNSS to NeQuick model in Android
Introducing the Galileo PVT App:from Assisted GNSS to NeQuick model in AndroidIntroducing the Galileo PVT App:from Assisted GNSS to NeQuick model in Android
Introducing the Galileo PVT App:from Assisted GNSS to NeQuick model in AndroidThe European GNSS Agency (GSA)
 
In Service Monitoring and Assurance at ITSF 2014
In Service Monitoring and Assurance at ITSF 2014 In Service Monitoring and Assurance at ITSF 2014
In Service Monitoring and Assurance at ITSF 2014 ADVA
 
Precision Time Protocol
Precision Time ProtocolPrecision Time Protocol
Precision Time ProtocolSteven Kreuzer
 
Khi 061 revised dt report
Khi 061 revised dt reportKhi 061 revised dt report
Khi 061 revised dt reportShiraz316
 
Khi 113 revised dt report
Khi 113 revised dt reportKhi 113 revised dt report
Khi 113 revised dt reportShiraz316
 
Sunsight Antenna Alignment intro
Sunsight Antenna Alignment introSunsight Antenna Alignment intro
Sunsight Antenna Alignment introJohn Vetter
 
Frank van diggelen keynote, android gnss measurements update
Frank van diggelen keynote, android gnss measurements updateFrank van diggelen keynote, android gnss measurements update
Frank van diggelen keynote, android gnss measurements updateThe European GNSS Agency (GSA)
 
Khi 151 revised dt report
Khi 151 revised dt reportKhi 151 revised dt report
Khi 151 revised dt reportShiraz316
 
4 U 5 Slides With Notes
4 U 5 Slides With Notes4 U 5 Slides With Notes
4 U 5 Slides With Notesrameraja
 
Location-Aware Rail Asset Management
Location-Aware Rail Asset ManagementLocation-Aware Rail Asset Management
Location-Aware Rail Asset ManagementGeoEnable Limited
 
Precision Time Synchronization
Precision Time SynchronizationPrecision Time Synchronization
Precision Time SynchronizationKrishna Sankar
 
Khi 052 revised dt report
Khi 052 revised dt reportKhi 052 revised dt report
Khi 052 revised dt reportShiraz316
 

What's hot (20)

PAS planet accuracy simpler
PAS planet accuracy simplerPAS planet accuracy simpler
PAS planet accuracy simpler
 
Raw GNSS Measurements under Android : Data Quality Analysis
Raw GNSS Measurements under Android : Data Quality AnalysisRaw GNSS Measurements under Android : Data Quality Analysis
Raw GNSS Measurements under Android : Data Quality Analysis
 
Precision clock synchronization_wp
Precision clock synchronization_wpPrecision clock synchronization_wp
Precision clock synchronization_wp
 
Introducing the Galileo PVT App:from Assisted GNSS to NeQuick model in Android
Introducing the Galileo PVT App:from Assisted GNSS to NeQuick model in AndroidIntroducing the Galileo PVT App:from Assisted GNSS to NeQuick model in Android
Introducing the Galileo PVT App:from Assisted GNSS to NeQuick model in Android
 
In Service Monitoring and Assurance at ITSF 2014
In Service Monitoring and Assurance at ITSF 2014 In Service Monitoring and Assurance at ITSF 2014
In Service Monitoring and Assurance at ITSF 2014
 
Productos k tek 1
Productos k tek 1Productos k tek 1
Productos k tek 1
 
Precision Time Protocol
Precision Time ProtocolPrecision Time Protocol
Precision Time Protocol
 
Khi 061 revised dt report
Khi 061 revised dt reportKhi 061 revised dt report
Khi 061 revised dt report
 
Khi 113 revised dt report
Khi 113 revised dt reportKhi 113 revised dt report
Khi 113 revised dt report
 
Time Synchronisation
Time SynchronisationTime Synchronisation
Time Synchronisation
 
Sunsight Antenna Alignment intro
Sunsight Antenna Alignment introSunsight Antenna Alignment intro
Sunsight Antenna Alignment intro
 
Frank van diggelen keynote, android gnss measurements update
Frank van diggelen keynote, android gnss measurements updateFrank van diggelen keynote, android gnss measurements update
Frank van diggelen keynote, android gnss measurements update
 
Weather meter
Weather meterWeather meter
Weather meter
 
Khi 151 revised dt report
Khi 151 revised dt reportKhi 151 revised dt report
Khi 151 revised dt report
 
Antenna alignment tool
Antenna alignment toolAntenna alignment tool
Antenna alignment tool
 
4 U 5 Slides With Notes
4 U 5 Slides With Notes4 U 5 Slides With Notes
4 U 5 Slides With Notes
 
Location-Aware Rail Asset Management
Location-Aware Rail Asset ManagementLocation-Aware Rail Asset Management
Location-Aware Rail Asset Management
 
Precision Time Synchronization
Precision Time SynchronizationPrecision Time Synchronization
Precision Time Synchronization
 
IEEE1588-v2
IEEE1588-v2IEEE1588-v2
IEEE1588-v2
 
Khi 052 revised dt report
Khi 052 revised dt reportKhi 052 revised dt report
Khi 052 revised dt report
 

Similar to What Time Is It? How Manipulating “Now” Can Crash Our World

6TiSCH @Telecom Bretagne 2015
6TiSCH @Telecom Bretagne 20156TiSCH @Telecom Bretagne 2015
6TiSCH @Telecom Bretagne 2015Pascal Thubert
 
How the fusion of time sensitive networking, time-triggered ethernet and data...
How the fusion of time sensitive networking, time-triggered ethernet and data...How the fusion of time sensitive networking, time-triggered ethernet and data...
How the fusion of time sensitive networking, time-triggered ethernet and data...Real-Time Innovations (RTI)
 
The Poacher and the Gamekeeper: Synchronization Delivery and Assurance
The Poacher and the Gamekeeper: Synchronization Delivery and AssuranceThe Poacher and the Gamekeeper: Synchronization Delivery and Assurance
The Poacher and the Gamekeeper: Synchronization Delivery and AssuranceADVA
 
NextGen Network Synchronization
NextGen Network SynchronizationNextGen Network Synchronization
NextGen Network SynchronizationDhiman Chowdhury
 
Synchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation NetworksSynchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation NetworksADVA
 
Solving synchronization challenges with critical infrastructures
Solving synchronization challenges with critical infrastructuresSolving synchronization challenges with critical infrastructures
Solving synchronization challenges with critical infrastructuresADVA
 
Evolution of Network Synchronization Technologies
Evolution of Network Synchronization TechnologiesEvolution of Network Synchronization Technologies
Evolution of Network Synchronization TechnologiesADVA
 
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...Cisco Canada
 
Introducing GNSS/GPS backup as a service (GBaaS)
Introducing GNSS/GPS backup as a service (GBaaS)Introducing GNSS/GPS backup as a service (GBaaS)
Introducing GNSS/GPS backup as a service (GBaaS)ADVA
 
Timing and synchronization for 5G over optical networks
Timing and synchronization for 5G over optical networksTiming and synchronization for 5G over optical networks
Timing and synchronization for 5G over optical networksADVA
 
MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)
MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)
MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)Art Schanz
 
What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016
What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016
What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016Priyanka Aash
 
Olivier Casabianca
Olivier CasabiancaOlivier Casabianca
Olivier CasabiancaJoost Boers
 
Reducing time errors for GNSS: Time for multiband?
Reducing time errors for GNSS: Time for multiband?Reducing time errors for GNSS: Time for multiband?
Reducing time errors for GNSS: Time for multiband?ADVA
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Canada
 
Options for time-sensitive networking for 5G fronthaul
Options for time-sensitive networking for 5G fronthaulOptions for time-sensitive networking for 5G fronthaul
Options for time-sensitive networking for 5G fronthaulADVA
 

Similar to What Time Is It? How Manipulating “Now” Can Crash Our World (20)

6TiSCH @Telecom Bretagne 2015
6TiSCH @Telecom Bretagne 20156TiSCH @Telecom Bretagne 2015
6TiSCH @Telecom Bretagne 2015
 
How the fusion of time sensitive networking, time-triggered ethernet and data...
How the fusion of time sensitive networking, time-triggered ethernet and data...How the fusion of time sensitive networking, time-triggered ethernet and data...
How the fusion of time sensitive networking, time-triggered ethernet and data...
 
The Poacher and the Gamekeeper: Synchronization Delivery and Assurance
The Poacher and the Gamekeeper: Synchronization Delivery and AssuranceThe Poacher and the Gamekeeper: Synchronization Delivery and Assurance
The Poacher and the Gamekeeper: Synchronization Delivery and Assurance
 
NextGen Network Synchronization
NextGen Network SynchronizationNextGen Network Synchronization
NextGen Network Synchronization
 
Synchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation NetworksSynchronization Protection and Redundancy in Next-Generation Networks
Synchronization Protection and Redundancy in Next-Generation Networks
 
Solving synchronization challenges with critical infrastructures
Solving synchronization challenges with critical infrastructuresSolving synchronization challenges with critical infrastructures
Solving synchronization challenges with critical infrastructures
 
Evolution of Network Synchronization Technologies
Evolution of Network Synchronization TechnologiesEvolution of Network Synchronization Technologies
Evolution of Network Synchronization Technologies
 
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...
 
Presentation1
Presentation1Presentation1
Presentation1
 
sync sources - overview
 sync sources - overview sync sources - overview
sync sources - overview
 
general overview
 general overview general overview
general overview
 
Introducing GNSS/GPS backup as a service (GBaaS)
Introducing GNSS/GPS backup as a service (GBaaS)Introducing GNSS/GPS backup as a service (GBaaS)
Introducing GNSS/GPS backup as a service (GBaaS)
 
Timing and synchronization for 5G over optical networks
Timing and synchronization for 5G over optical networksTiming and synchronization for 5G over optical networks
Timing and synchronization for 5G over optical networks
 
MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)
MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)
MQTC V2.0.1.3 - WMQ & TCP Buffers – Size DOES Matter! (pps)
 
What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016
What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016
What IT Professionals Need to Know about Sniffing Wireless Traffic in 2016
 
Olivier Casabianca
Olivier CasabiancaOlivier Casabianca
Olivier Casabianca
 
Reducing time errors for GNSS: Time for multiband?
Reducing time errors for GNSS: Time for multiband?Reducing time errors for GNSS: Time for multiband?
Reducing time errors for GNSS: Time for multiband?
 
Vsync track c
Vsync   track cVsync   track c
Vsync track c
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
 
Options for time-sensitive networking for 5G fronthaul
Options for time-sensitive networking for 5G fronthaulOptions for time-sensitive networking for 5G fronthaul
Options for time-sensitive networking for 5G fronthaul
 

More from Priyanka Aash

Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsPriyanka Aash
 
Verizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfVerizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfPriyanka Aash
 
Top 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfTop 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfPriyanka Aash
 
Simplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfSimplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfPriyanka Aash
 
Generative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfGenerative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfPriyanka Aash
 
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfEVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfPriyanka Aash
 
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfCyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfPriyanka Aash
 
Cyber Crisis Management.pdf
Cyber Crisis Management.pdfCyber Crisis Management.pdf
Cyber Crisis Management.pdfPriyanka Aash
 
CISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfCISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfPriyanka Aash
 
Chennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfChennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfPriyanka Aash
 
Cloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfCloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfPriyanka Aash
 
Stories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldStories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldPriyanka Aash
 
Lessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksLessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksPriyanka Aash
 
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Priyanka Aash
 
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Priyanka Aash
 
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Priyanka Aash
 
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsCloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsPriyanka Aash
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security GovernancePriyanka Aash
 

More from Priyanka Aash (20)

Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
Verizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdfVerizon Breach Investigation Report (VBIR).pdf
Verizon Breach Investigation Report (VBIR).pdf
 
Top 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdfTop 10 Security Risks .pptx.pdf
Top 10 Security Risks .pptx.pdf
 
Simplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdfSimplifying data privacy and protection.pdf
Simplifying data privacy and protection.pdf
 
Generative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdfGenerative AI and Security (1).pptx.pdf
Generative AI and Security (1).pptx.pdf
 
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdfEVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
EVERY ATTACK INVOLVES EXPLOITATION OF A WEAKNESS.pdf
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdfCyber Truths_Are you Prepared version 1.1.pptx.pdf
Cyber Truths_Are you Prepared version 1.1.pptx.pdf
 
Cyber Crisis Management.pdf
Cyber Crisis Management.pdfCyber Crisis Management.pdf
Cyber Crisis Management.pdf
 
CISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdfCISOPlatform journey.pptx.pdf
CISOPlatform journey.pptx.pdf
 
Chennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdfChennai Chapter.pptx.pdf
Chennai Chapter.pptx.pdf
 
Cloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdfCloud attack vectors_Moshe.pdf
Cloud attack vectors_Moshe.pdf
 
Stories From The Web 3 Battlefield
Stories From The Web 3 BattlefieldStories From The Web 3 Battlefield
Stories From The Web 3 Battlefield
 
Lessons Learned From Ransomware Attacks
Lessons Learned From Ransomware AttacksLessons Learned From Ransomware Attacks
Lessons Learned From Ransomware Attacks
 
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
Emerging New Threats And Top CISO Priorities In 2022 (Chennai)
 
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
Emerging New Threats And Top CISO Priorities In 2022 (Mumbai)
 
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
Emerging New Threats And Top CISO Priorities in 2022 (Bangalore)
 
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow LogsCloud Security: Limitations of Cloud Security Groups and Flow Logs
Cloud Security: Limitations of Cloud Security Groups and Flow Logs
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security Governance
 
Ethical Hacking
Ethical HackingEthical Hacking
Ethical Hacking
 

Recently uploaded

Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 

Recently uploaded (20)

Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 

What Time Is It? How Manipulating “Now” Can Crash Our World

  • 1. SESSION ID: #RSAC Michael Calabro WHAT TIME IS IT? HOW MANIPULATING "NOW" CAN CRASH OUR WORLD HTA-W12 Senior Lead Engineer Booz Allen Hamilton Calabro_Michael@bah.com
  • 2. #RSAC Why do we need SynchronizaHon? 2 Event ordering Fairness in Race CondiHons Security Event Forensics
  • 3. #RSAC Time is Made Up 3 Physicists noted that some materials generate very stable reference signals at predictable periods (cesium, rubidium) If you count these periods … The SI definiHon of a second is the Hme that elapses during 9,192,631,770 cycles of the radiaHon produced by the transiHon between two levels of the cesium 133 atom.
  • 4. #RSAC Time Scales are Agreed Upon and “Local” 4 UTC (USNO) UTC (NIST) Mike Time
  • 5. #RSAC Time Accuracy and Precision are DisHnct 5 Precise, Not Accurate Precise & Accurate Accurate, Not Precise
  • 6. #RSAC The Path of Time Transfer 6 Master Clock 00:00:00.000??? 00:00:00.000000 +/- X +/- Y +/- Z Delays are known or bounded Time stamps are transferred from that source to end applicaHons Time is measured at a source
  • 7. #RSAC Time Transfer and Time Sources are Different 7 GPS NTP PTP ApplicaHon LTE UTC(USNO) U.S. Air Force PTRC GPS Rx GPS Rx GPS Rx GPS Rx GPS Rx
  • 8. #RSAC Financial Business Clock Time Sources 8 MulMple Technologies, 40% NTP, 27% GPS, 6% PTP, 6% CDMA, 2% Other Technologies, 3% Did Not Know , 16% (FROM 2017 SEC CLOCK SURVEY)
  • 9. #RSAC How Time is Transferred via GPS 9 Precise code phase alignment can give < 10 nanoseconds of precision Distance (m) / Speed of Light (m/s) = Delay (Rule of Thumb: 1 e / ns) 0100110110101011010101110101Path Delay RX 0100110110101011010101110101 SV Transmits known PN Sequence GPS receiver generates local copy and aligns it to transmi`ed sequence Precision of alignment determines precision of Mme delay calculaMon
  • 10. #RSAC GPS is Vulnerable to ManipulaHon 10 Data A`acks Repeaters or Unsynchronized Spoofers Code Phase Synchronous Spoofers Receivers and their applicaHons do math based on broadcast parameters. Divide by zeros? Overflows? Time might go backwards. Time will jump around. Time may advance more or less quickly … but at a high level, may appear accurate. Broadcast by GPS Algorithms from GPS SPS SpecificaMon GPS Rx locks on to dominate signal GPS Rx locks on to dominate signal and that signal is very close to the real signal
  • 11. #RSAC How GPS Time can be Subtly Spoofed 11 0100110110101011010101110101Path Delay RX 0100110110101011010101110101 SV Transmits PN Sequence Rx Generates local copy and aligns it to transmi`ed sequence Precision of alignment determines precision of Mme delay calculaMon Spoofer Near Matched Delay 0100110110101011010101110101
  • 12. #RSAC Review So Far 12 Time is “made up” Time is Measured directly or Transferred GPS is a common source of Hme across all applicaHons Timing and SynchronizaHon requirements exist at a variety of levels across applicaHons So… What happens when Synch breaks down?
  • 13. #RSAC TelecommunicaHons Networks Have the Strictest Commercial Timing Requirements 13 ApplicaMon/ Technology Accuracy SpecificaMon WCDMA MBSFN 12.8 µs [b-3GPP TS 25.346] secHons 7.1A and 7.1B.2.1 LTE-TDD (wide-area) 10 µs [b-3GPP TS 36.133]) secHon 7.4.2 LTE-TDD to CDMA 10 µs [b-TS 3GPP TS 36.133] secHon 7.5.2.1 CDMA2000 3 µs [b-3GPP2 C.S0002] secHon 1.3; [b-3GPP2 C.S0010] secHon 4.2.1.1 WCDMA-TDD 2.5 µs [b-3GPP TS 25.402] secHons 6.1.2 and 6.1.2.1 WiMAX (downlink) 1.428 µs [b-IEEE 802.16] table 6-160, secHon 8.4.13.4 WiMAX (base staHon) 1 µs [b-WMF T23-001], secHon 4.2.2 Primary Reference Time Clock 100 ns [ITU-T G.8272] (Primary Reference Time Clock) Enhanced PRTC 30 ns [ITU-T G.8272.1] (Enhanced Primary Reference Time Clock)
  • 14. #RSAC Power Grid Uses of Time 14 From NASPI-2017-TR-001
  • 15. #RSAC EU Finance Requirements in Effect Jan. 2018 15 From COMMISSION DELEGATED REGULATION (EU) 2017/574
  • 16. #RSAC Some Scenarios – Financial Front Running 16 T = 0.000 T = 0.001 Buyer buys 1000000 shares of ABC Seller sells 100000 shares of ABC T = 0.002 T = 0.00000 T = 0.00010 Seller sells 100000 shares of ABC T = 0.00035 Buyer buys 1000000 shares of ABC T = 0.00200 Which ordering of events would you prefer? What if you could change your Hme stamp?
  • 17. #RSAC January 25th, 2016 – The Worldwide “Spoof”
  • 18. #RSAC A Unique Set of Error CondiHons 18 On January 25th, 2016, during the reHrement of the last IIA satellite, an error occurring in the GPS system causing many receivers that used the UTC correcHon broadcast by the satellites to be ~13.7 microseconds deviant from truth Global effect Not all satellites broadcast erroneous data Affected receivers needed to obtain their UTC offset from a bad satellite – i.e. not all receivers with a common skyview would have been affected
  • 19. #RSAC Suspect a GPS Problem? Call the Coast Guard 19
  • 20. #RSAC Effects (caused by an ~12 hour event) 20 Of ~80 NIST clocks monitoring event, only 11% were unaffected Some high performance precision Hming receivers took 1+ day to resynchronize to their previous levels of stability Many precision Hming receivers entered into holdover (starHng a count down hours to out-of-spec performance) At least one telecommunicaHons backhaul provider reported that it was necessary to manually reset affected precision Hming receivers Some clocks located in telecom systems started to free run with no atomic discipline or back up Many organizaHons that should have been affected did not report any impact (did they even know how close they came to major issues?)
  • 21. #RSAC It is Really Hard to Get Away from GPS… 21 Timing Source GPS Dependent Scale Availability Comments GNSS Yes < 100 ns Global Not appropriate for all environments; may be denied GSM NTIZ Yes ~1s Regional CDMA2000 Sync Yes 1 ms Regional LTE R11+ SIB 16 Yes 10 ms Not widely deployed. 10 ms may not be sufficiently precise. Iridium Time (Satelles) Yes < 500 ns Global Paid Service; May have higher availability than GNSS eLoran Yes < 100 ns Europe, Asia, Middle East Not available in the US
  • 22. #RSAC Upcoming 5G and IoT Sync Requirements 22 Edge of network sync in in TDD LTE is ~ 1 microsecond; 5G proposes to aggressively push this down – thereby increasing dependency on synch SynchronizaHon requirements between cloud processes and events will become stricter IoT will need ways to synch local devices
  • 23. #RSAC OrganizaHons that are working on this 23 ATIS SynchronizaHon Commi{ee Resilient NavigaHon & Timing FoundaHon Network Time FoundaHon North American Synchrophasor IniHaHve (NASPI) NaHonal Space-Based PNT Advisory Board and PNT ExecuHve Commi{ee
  • 24. #RSAC Conclusions 24 GPS remains the most convenient source of Hme transfer and is the only technology capable of meeHng upcoming synchronizaHon requirements efficiently 2017 and 2018 are seeing many new synchronizaHon applicaHons being deployed across telecom, finance, transportaHon, and Sync needs to be done securely and deliberately Secure SynchronizaHons SoluHons exist today; advocacy is needed at a naHonal level for an alternaHve system to GPS
  • 25. #RSAC Selected References 25 NIST Report on January 2016 Outage h{ps://}.nist.gov/general/pdf/2886.pdf SEC Clock Survey h{ps://www.sec.gov/divisions/marketreg/consolidated-audit-trail-clock-synchronizaHon-assessment-051517.pdf NASPI h{ps://www.naspi.org/sites/default/files/reference_documents/ts}_electric_power_system_report_pnnl_26331_march_2017_0.pdf
  • 26. #RSAC Apply What You Have Learned Today 26 Next week you should: IdenHfy synchronizaHon dependent applicaHons within your organizaHon In the first three months following this presentaHon you should: Understand where these sync-dependent applicaHons get their Hme from and their corresponding tolerances for failure Within six months you should: Understand how to a{ribute system failures to synchronizaHon outages “Protect, Toughen, and Augment” your Timing Sources and Sync Methods Michael Calabro Calabro_Michael@bah.com