Is it your time?
Andrzej Gab
Cybersecurity Director / Senior manager / Expert | CCIE (Sec) | CISSP | CCSP | Maritime | Neurodiversity
This article is also inspired by a man - Tomasz Widomski who has just graduated Cybersecurity Management MBA postgraduate studies at Wojskowa Akademia Techniczna w Warszawie (Military University of Technology in Warsaw, Poland) and shared his work with me just 2 days ago.
I know Tomasz (Tom) more than 20 years since I decided to implement two geo-spread NTP servers delivering GPS-sourced time to computer network of telco company I was working for. Tomasz has been always dedicated to time and time synchronization matter, as long as I know him. We had many talks and discussions on that - as a network engineer and cybersecurity guy, I have always considered time to be an important element in the operation of computer systems, but perhaps not entirely crucial. I guess I treated it a bit like DNS - a kind of side service that helps us operate, but in essence, almost no one notices it - after all, time is always there. Over time, just like with DNS, I began to recognize the growing importance of time and its synchronization. First, in terms of log correlation in SIEM systems, then the unambiguity of timestamps, and most recently in the context of disruptions or jamming of GPS signals.
Tomasz's work titled: "Analysis of the phenomenon of desynchronization as a new cyber weapon destabilizing national infrastructures" excellently expands the theme of time and time synchronization in the context of cybersecurity.
So, in short, why time and its synchronization are important - it is because there exist attacks on time domain:
These attacks could result in many various direct on indirect disruptions destabilizing work of IT, OT or Maritime systems. Why is that? It is because every modern and advanced electronic system is a computer now and it relies on time and very often on time sync. Every manipulation, disruption could result in malfunctioning of the entire system. Let's enumerate some examples:
And here we are coming full circle - time synchronization in a very basic form was used in maritime since 1731 when a sextant was developed and implemented by John Hadley and Thomas Godfrey. To get geo position you needed to have not only a sextant device but also exact time (and a nautical almanac with ABC tables and a map of course). And the correct time was crucial to find yourself on the map. And the other way - you could use a sextant to correct your clock time. That's why maritime can be considered a precursor to time synchronization.
Nowadays, time synchronization is done seamlessly and we rely heavily on it (Another matter is whether it is performed correctly and securely). Our immense reliance on this has been recognized, and current recommendations are to move away from the widespread use of time synchronization relative to GPS as well as unknown public NTP time servers. One of sign of this is Executive Order 13905 by US President titled: "Strengthening National Resilience Through Responsible Use of Positioning, Navigation, and Timing Services (PNT)" and the citation: "Because of the widespread adoption of PNT services, the disruption or manipulation of these services has the potential to adversely affect the national and economic security of the United States. To strengthen national resilience, the Federal Government must foster the responsible use of PNT services by critical infrastructure owners and operators". What does it mean? You, an economy, a company relying on time, time distribution and its synchronization, should take care of it. To have your verified and reliable sources of time. To verify your time and your own time distribution network. My experience is that almost no one does it... Is it your time?
And in the end there are some good projects in the world that are building separate sources and time distribution networks not dependent on satellites and the Internet. In Poland half year ago it has just started the e-Czas (e-Time) project led by G?ówny Urz?d Miar (https://e-czas.gum.gov.pl) and consists of:
领英推荐
The e-Czas Radio 225kHz radio signal covers half of Europe - the other half could be covered by German DCF77 signal.
And the classic for the end of the article, somewhat connected with the subject.
No man is an Island, intire of it selfe; every man is a peece of the Continent, a part of the maine; if a Clod bee washed away by the Sea, Europe is the lesse, as well as if a Promontorie were, as well as if a Mannor of thy friends or of thine own were; any mans death diminishes me, because I am involved in Mankinde; And therefore never send to know for whom the bell tolls; It tolls for thee.
by John Donne, known also from E. Hemingway book titled "For Whom the Bell Tolls".
So - is it your time?
I know that some of my colleagues Tomasz Brol Grzegorz Kaczmarek are involved in time & frequency domain too. Here are my kudos for them.
And once again thank you Tomasz Widomski for sharing your work with me. I hope that people interested in your work may contact you.
Lead Engineer, Maritime Cybersecurity at Royal Caribbean Group | GICSP, CCNA, MCITP | OZ5TEIN
8 个月Good thing that most maritime ICS dont really care about timestamps, but tag the event with its own time at the moment of arrival.
Embedded SW | HAM Radio | Time&Frequency | New Space | Podcasts
8 个月Andrzej Gab thanks for the excellent summary. Indeed, the time is a very interesting beast. We always chase it and we can only loose it. When I was a kid I was always building an electronic clocks. Time was just something I have felt was important. I wasn't really expecting, at the time, it would keep my interest in it for the upcoming decades. Time keeps us organized. Time helps us to localize ourselves. Time is a base for SI measures. Time brings security. Time is our life. How interesting that beast is...
BALTIC SEA & SPACE CLUSTER, President of the Board
8 个月Interesting research