%% You should probably cite draft-ietf-ntp-port-randomization instead of this I-D. @techreport{gont-ntp-port-randomization-00, number = {draft-gont-ntp-port-randomization-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-gont-ntp-port-randomization/00/}, author = {Fernando Gont and Guillermo Gont}, title = {{Port Randomization in the Network Time Protocol Version 4}}, pagetotal = 5, year = 2019, month = apr, day = 16, abstract = {The Network Time Protocol can operate in several modes. Some of these modes are based on the receipt of unsolicited packets, and therefore require the use of a service/well-known port as the local port number. However, in the case of NTP modes where the use of a service/well-known port is not required, employing such well-known/ service port unnecessarily increases the ability of attackers to perform blind/off-path attacks, since knowledge of such port number is typically required for such attacks. This document formally updates RFC5905, recommending the use of port randomization for those modes where use of the NTP service port is not required.}, }