Smashing WEP in a Passive Attack
Smashing WEP in a Passive Attack
复制标题
DOI:
10.1007/978-3-662-43933-3_9
复制
发表时间:
2013-03
期刊:
影响因子:
--
通讯作者:
Pouyan Sepehrdad;Petr Susil;S. Vaudenay;Martin Vuagnoux
中科院分区:
文献类型:
--
作者:
Pouyan Sepehrdad;Petr Susil;S. Vaudenay;Martin Vuagnoux
In this paper, we report extremely fast and optimised active and passive attacks against the old IEEE 802.11 wireless communication protocol WEP. This was achieved through a huge amount of theoretical and experimental analysis (capturing WiFi packets), refinement and optimisation of all the former known attacks and methodologies against RC4 stream cipher in WEP mode. We support all our claims by providing an implementation of this attack as a publicly available patch on Aircrack-ng. Our new attacks improve its success probability drastically. We adapt our theoretical analysis in Eurocrypt 2011 to real-world scenarios and we perform a slight adjustment to match the empirical observations. Our active attack, based on ARP injection, requirespackets to gain success probability ofagainst a-bit WEP key, using Aircrack-ng in non-interactive mode. It runs in less thans on an off-the-shelf PC. Using the same number of packets, Aicrack-ng yields aroundsuccess rate. Furthermore, we describe very fast passive only attacks by just eavesdropping TCP/IPv4 packets in a WiFi communication. Our passive attack requirespackets. This ismuch less than the number of packetsAircrack-ng requires inactive mode(around), which is a huge improvement. We believe that our analysis brings on further insight to the security of RC4.