Operating Channel Validation: Preventing Multi-Channel Man-in-the-Middle Attacks Against Protected Wi-Fi Networks

Operating Channel Validation: Preventing Multi-Channel Man-in-the-Middle Attacks Against Protected Wi-Fi Networks
复制标题

操作通道验证:防止针对受保护 Wi-Fi 网络的多通道中间人攻击

DOI:
--
复制
发表时间:
2018
期刊:
Wireless Network Security
影响因子:
--
通讯作者:
Frank Piessens
Frank Piessens
中科院分区:
--
文献类型:
--
作者:
M. Vanhoef;Nehru Bhandaru;T. Derham;I. Ouzieli;Frank Piessens

文献摘要

被引文献

相似文献

我们提出了 802.11 标准的向后兼容扩展,以防止多通道中间人攻击。此扩展对定义当前使用的通道的参数进行身份验证。最近针对 WPA2 的攻击(例如大多数密钥重新安装攻击)需要在客户端和接入点 (AP) 之间设置中间人 (MitM) 位置。特别是,它们都采用多通道技术来获取 MitM 位置。在这种技术中,攻击者通过将真实 AP 发送的所有帧复制到不同的通道来充当合法 AP。同时,攻击者充当合法客户端,将客户端发送的所有帧复制到真实AP的通道中。当在两个通道之间复制帧时,攻击者可以可靠地操纵(加密)流量。我们建议对 802.11 标准进行扩展,以防止此类多通道 MitM 攻击,从而使利用受保护的 Wi-Fi 网络的未来弱点变得更加困难,甚至几乎不可行。此外,我们提出了一种方法来安全地验证已连接到网络时可能发生的动态通道切换。最后,我们在 Linux 上为客户端和 AP 实现了扩展原型,以确认实际可行性。
We present a backwards compatible extension to the 802.11 standard to prevent multi-channel man-in-the-middle attacks. This extension authenticates parameters that define the currently in-use channel. Recent attacks against WPA2, such as most key reinstallation attacks, require a man-in-the-middle (MitM) position between the client and Access Point (AP). In particular, they all employ a multi-channel technique to obtain the MitM position. In this technique, the adversary acts as a legitimate AP by copying all frames sent by a real AP to a different channel. At the same time, the adversary acts as a legitimate client by copying all frames sent by the client to the channel of the real AP. When copying frames between both channels, the adversary can reliably manipulate (encrypted) traffic. We propose an extension to the 802.11 standard to prevent such multi-channel MitM attacks, making exploitation of future weaknesses in protected Wi-Fi networks harder, to practically infeasible. Additionally, we propose a method to securely verify dynamic channel switches that may occur while already connected to a network. Finally, we implemented a prototype of our extension on Linux for both the client and AP to confirm practical feasibility.