Analog man-in-the-middle attack against link-based packet source identification

Analog man-in-the-middle attack against link-based packet source identification
复制标题

针对基于链路的数据包源识别的模拟中间人攻击

DOI:
10.1145/2942358.2942361
复制
发表时间:
2016
期刊:
Proceedings of the 17th ACM International Symposium on Mobile Ad Hoc Networking and Computing
影响因子:
--
通讯作者:
Kyu
Kyu
中科院分区:
--
文献类型:
--
作者:
Yu;K. Shin;Kyu

文献摘要

被引文献

相似文献

提出了一种针对现有的无线链接源标识的新型攻击模型,该标识是根据物理层链路签名对数据包来源进行分类的。链接签名被认为是比IP或MAC地址更可靠的指示器,因为通常很难修改/伪造。因此,预计将来是对模仿和DOS攻击的未来身份验证。但是,如果攻击者配备了与身份验证器相同的功能/硬件来处理物理层信号,则在培训阶段,任何附近的无线设备都可以轻松地操纵链接签名。基于这一发现,我们提出了一种攻击模型,称为中型模拟人物(AMITM)攻击,该攻击利用最新的全双工中继技术将半控制的链接签名注入授权数据包并重现注射签名的签名在制造的数据包中。我们的实验评估表明,使用适当的参数设置,有90%的制造数据包被归类为从授权发射器发送的数据包。还提出了对这一新攻击的对策,以使身份验证者通过相同的攻击方法注入链路签名噪声。
A novel attack model is proposed against the existing wireless link-based source identification, which classifies packet sources according to the physical-layer link signatures. A link signature is believed to be a more reliable indicator than an IP or MAC address for identifying packet source, as it is generally harder to modify/forge. It is therefore expected to be a future authentication against impersonation and DoS attacks. However, if an attacker is equipped with the same capability/hardware as the authenticator to process physical-layer signals, a link signature can be easily manipulated by any nearby wireless device during the training phase. Based on this finding, we propose an attack model, called the analog man-in-the-middle (AMITM) attack, which utilizes the latest full-duplex relay technology to inject semi-controlled link signatures into authorized packets and reproduce the injected signature in the fabricated packets. Our experimental evaluation shows that with a proper parameter setting, 90% of fabricated packets are classified as those sent from an authorized transmitter. A countermeasure against this new attack is also proposed for the authenticator to inject link-signature noise by the same attack methodology.