A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link

A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Milan Stute;Sashank Narain;Alex Mariotto;A. Heinrich;David Kreitschmann;G. Noubir;M. Hollick
Milan Stute;Sashank Narain;Alex Mariotto;A. Heinrich;David Kreitschmann;G. Noubir;M. Hollick
中科院分区:
其他
文献类型:
--
作者:
Milan Stute;Sashank Narain;Alex Mariotto;A. Heinrich;David Kreitschmann;G. Noubir;M. Hollick

文献摘要

相似文献

Apple Wireless Direct Link (AWDL) 是 Apple 生态系统中的关键协议,超过 10 亿 iOS 和 macOS 设备使用该协议进行设备间通信。 AWDL 是 IEEE 802.11 (Wi-Fi) 标准的专有扩展,并与低功耗蓝牙 (BLE) 集成以提供 Apple AirDrop 等服务。我们对 AWDL 及其与 BLE 的集成进行了首次安全和隐私分析。我们发现了多个安全和隐私漏洞,从设计缺陷到实现错误,这些漏洞会导致中间人 (MitM) 攻击(可对通过 AirDrop 传输的文件进行秘密修改)、阻止通信的拒绝服务 (DoS) 攻击、可实现用户识别和长期跟踪、破坏 MAC 地址随机化的隐私泄露,以及可导致所有相邻设备有针对性或同时崩溃的 DoS 攻击。 设备。这些缺陷涵盖 AirDrop 的 BLE 发现机制、AWDL 同步、UI 设计和 Wi-Fi 驱动程序实现。我们的分析基于协议逆向工程和由分析专利支持的代码的结合。我们提供概念验证实施,并证明可以使用低成本(20 美元)micro:bit 设备和现成的 Wi-Fi 卡来发起攻击。我们提出切实有效的对策。虽然在我们负责任的披露后,Apple 能够针对 DoS 攻击漏洞发布修复程序,但其他安全和隐私漏洞需要重新设计其部分服务。
Apple Wireless Direct Link (AWDL) is a key protocol in Apple's ecosystem used by over one billion iOS and macOS devices for device-to-device communications. AWDL is a proprietary extension of the IEEE 802.11 (Wi-Fi) standard and integrates with Bluetooth Low Energy (BLE) for providing services such as Apple AirDrop. We conduct the first security and privacy analysis of AWDL and its integration with BLE. We uncover several security and privacy vulnerabilities ranging from design flaws to implementation bugs leading to a man-in-the-middle (MitM) attack enabling stealthy modification of files transmitted via AirDrop, denial-of-service (DoS) attacks preventing communication, privacy leaks that enable user identification and long-term tracking undermining MAC address randomization, and DoS attacks enabling targeted or simultaneous crashing of all neighboring devices. The flaws span across AirDrop's BLE discovery mechanism, AWDL synchronization, UI design, and Wi-Fi driver implementation. Our analysis is based on a combination of reverse engineering of protocols and code supported by analyzing patents. We provide proof-of-concept implementations and demonstrate that the attacks can be mounted using a low-cost ($20) micro:bit device and an off-the-shelf Wi-Fi card. We propose practical and effective countermeasures. While Apple was able to issue a fix for a DoS attack vulnerability after our responsible disclosure, the other security and privacy vulnerabilities require the redesign of some of their services.