Parallel active dictionary attack on IEEE 802.11 enterprise networks

Parallel active dictionary attack on IEEE 802.11 enterprise networks
复制标题

针对 IEEE 802.11 企业网络的并行主动字典攻击

DOI:
10.1109/milcom.2016.7795337
复制
发表时间:
2016
期刊:
MILCOM 2016 - 2016 IEEE Military Communications Conference
影响因子:
--
通讯作者:
C. Zou
C. Zou
中科院分区:
--
文献类型:
--
作者:
Omar Nakhila;C. Zou

文献摘要

被引文献

相似文献

802.11无线局域网(WLAN)面临的最大挑战之一是提供与有线局域网(LAN)等效的安全性。Wi-Fi Protected Access II(WPA-II),也称为IEEE 802.11i标准,是企业无线网络的当前安全机制。IEEE 802.11i标准依赖于IEEE 802.1X标准来认证和生成用于保护无线网络流量的主加密密钥。在WPA-II企业网络中,在接入点(AP)和授权无线客户端之间的身份验证阶段捕获无线帧不会危及WLAN的安全性。但是,攻击者可以通过猜测用于访问无线网络的凭据来应用主动字典攻击。在这种情况下,攻击者直接与身份验证服务器(AS)通信。这种攻击的主要缺点是攻击者可以实现的密码猜测试验的强度较低,因此安全社区通常不会关注这种攻击。本文提出了一种新的攻击方案,可以增加对WPA-II企业的猜测试验强度。新方案基于使用一个无线接口卡创建多个虚拟无线客户端(VWC),每个VWC作为独立的无线客户端与认证服务器通信。我们已经开发了一个工作原型,我们的实验表明,该方案可以提高主动字典猜测速度超过1700%,相比传统的单无线客户端攻击。
One of the greatest challenges facing 802.11 wireless local area network (WLAN) is to provide equivalent security to wired local area network (LAN). Wi-Fi Protected Access II (WPA-II), also referred to as IEEE 802.11i standard, is the current security mechanism for enterprise wireless networks. IEEE 802.11i standard depends upon IEEE 802.1X standard to authenticate and generate the main cryptographic key used to secure wireless network traffic. In a WPA-II enterprise network, capturing wireless frames during the authentication phase between the Access Point (AP) and an authorized wireless client will not compromise the security of the WLAN. However, an attacker can apply active dictionary attack by guessing the credentials used to access the wireless network. In this case, the attacker communicates directly with the Authentication Server (AS). The main downside of this attack is the low intensity of password guessing trials that the attacker can achieve, thus security community usually does not pay attention to such an attack. In this paper, we present a new attack scheme that can increase the intensity of guessing trials against WPA-II enterprise. The new scheme is based on using one wireless interface card to create multiple virtual wireless clients (VWCs), each VWC communicates with the Authentication Server as a standalone wireless client. We have developed a working prototype and our experiments show that the proposed scheme can improve the active dictionary guessing speed by more than 1700% compared to the traditional single wireless client attack.