DocumentCode :
653827
Title :
Wireless spreading of WiFi APs infections using WPS flaws: An epidemiological and experimental study
Author :
Sanatinia, Amirali ; Narain, Sanjai ; Noubir, Guevara
Author_Institution :
Coll. of Comput. & Inf. Sci., Northeastern Univ., Boston, MA, USA
fYear :
2013
fDate :
14-16 Oct. 2013
Firstpage :
430
Lastpage :
437
Abstract :
WiFi Access Points (APs) are ideal targets of attack. They have access to home internal networks which allows an adversary to easily carry out man-in-the-middle attacks and spread infections wirelessly. They can also be used to launch massive denial of service attacks that target the physical infrastructure as well as the RF spectrum (both WiFi and cellular). While Wired Equivalent Privacy (WEP) vulnerabilities are common knowledge, the flaws of the WiFi Protected Setup (WPS) protocol are less known. In this paper, we use an epidemiological approach, combined with experimental war-driving measurements to investigate the speed of infections spreading in four neighborhoods of Boston, MA, USA, with distinct population and demographics. Our analysis and experimental data indicate that such attacks are feasible. While the graph of WEP APs and WPS APs may not be fully connected, the combined graph of WEP-WPS APs is fully connected, making large scale spreading of infections feasible. Due to the unique characteristics of WPS, the absence of automated firmware upgrades and mechanisms to safely configure and administer APs; these attacks pose a significant threat that require serious attention and countermeasures to provide safe management of APs and their policies.
Keywords :
access protocols; cellular radio; computer network security; data privacy; firmware; wireless LAN; Boston; USA; WEP; WPS flaws; WPS protocol; WiFi AP infections; WiFi protected setup protocol; access points; automated firmware; cellular radio; denial of service attacks; epidemiological study; home internal networks; man-in-the-middle attacks; war-driving measurements; wired equivalent privacy; Computational modeling; Educational institutions; IEEE 802.11 Standards; Protocols; Sociology; Statistics; Wireless communication;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications and Network Security (CNS), 2013 IEEE Conference on
Conference_Location :
National Harbor, MD
Type :
conf
DOI :
10.1109/CNS.2013.6682757
Filename :
6682757
Link To Document :
بازگشت