|
Warning: The download time has expired please click on the item to try again.
ABSTRACT
The 802.11 standard for wireless networks includes a Wired Equivalent Privacy (WEP) protocol, used to protect link-layer communications from eavesdropping and other attacks. We have discovered several serious security flaws in the protocol, stemming from mis-application of cryptographic primitives. The flaws lead to a number of practical attacks that demonstrate that WEP fails to achieve its security goals. In this paper, we discuss in detail each of the flaws, the underlying security principle violations, and the ensuing attacks.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
W. A. Arbaugh. An inductive chosen plaintext attack against WEP/WEP2. IEEE Document 802.11-01/230, May 2001.
|
| |
2
|
W. A. Arbaugh, N. Shankar, and Y. J. Wan. Your 802.11 wireless network has no clothes. http://www.cs.umd.edu/~waa/wireless.pdf, Mar. 2001.
|
| |
3
|
A. Beck. Netscape's export SSL broken by 120 workstations and one student. HPCwire, Aug. 22 1995.
|
| |
4
|
S. M. Bellovin. Problem areas for the IP security protocols. In 6th USENIX Security Symposium, San Jose, California, July 1996. USENIX.
|
| |
5
|
B. Braden, D. Borman, and C. Partridge. Computing the internet checksum. Internet Request for Comments RFC 1071, Internet Engineering Task Force, Sept. 1988.
|
| |
6
|
Core SDI. crc32 compensation attack against ssh-1.5. http://www.core-sdi. com/soft/ssh/attack.txt, July 1998.
|
| |
7
|
E. Dawson and L. Nielsen. Automated cryptanalysis of XOR plaintext strings. Cryptologia, (2):165-181, Apr. 1996.
|
| |
8
|
D. Doligez. SSL challenge virtual press conference. http://pauillac.inria.fr/~doligez /ssl/press-conf.html, 1995.
|
| |
9
|
R. Jueneman, S. Matyas, and C. Meyer. Message authentication. IEEE Communications Magazine, 23(9):29-40, Sept. 1985.
|
| |
10
|
S. Kent and R. Atkinson. Security architecture for the Internet Protocol. Internet Request for Comment RFC 2401, Internet Engineering Task Force, Nov. 1998.
|
| |
11
|
P. Kocher. Cryptanalysis of Diffie-Hellman, RSA, DSS, and other cryptosystems using timing attacks. In D. Coppersmith, editor, Advances in cryptology, CRYPTO '95: 15th Annual International Cryptology Conference, Santa Barbara, California, USA, August 27-31, 1995: proceedings, pages 171-183. Springer-Verlag, 1995.
|
| |
12
|
|
| |
13
|
H. Krawczyk, M. Bellare, and R. Canetti. HMAC: Keyed-hashing for message authentication. RFC 2104, Feb. 1997.
|
| |
14
|
T. Mallory and A. Kullberg. Incremental updating of the internet checksum. Internet Request for Comments RFC 1141, Internet Engineering Task Force, Jan. 1990.
|
| |
15
|
L. M. S. C. of the IEEE Computer Society. Wireless LAN medium access control (MAC) and physical layer (PHY) specifications. IEEE Standard 802.11, 1999 Edition, 1999.
|
| |
16
|
R. L. Rivest. The RC4 Encryption Algorithm. RSA Data Security, Inc., Mar. 12, 1992. (Proprietary).
|
| |
17
|
|
 |
18
|
|
| |
19
|
D. Simon, B. Aboba, and T. Moore. IEEE 802.11 security and 802.1X. IEEE Document 802.11-00/034r1, Mar. 2000.
|
| |
20
|
|
| |
21
|
|
| |
22
|
W. Tutte. FISH and I, 1998. A transcript of Tutte's June 19, 1998 lecture at the University of Waterloo.
|
| |
23
|
D. Wagner and B. Schneier. Analysis of the SSL 3.0 protocol. In Proceedings of the 2nd USENIX Workshop on Electronic Commerce (EC-96), pages 29-40, Berkeley, Nov. 18-21 1996. USENIX Association.
|
| |
24
|
J. R. Walker. Unsafe at any key size; an analysis of the WEP encapsulation. IEEE Document 802.11-00/362, Oct. 2000.
|
CITED BY 84
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Jiejun Kong , Shirshanka Das , Edward Tsai , Mario Gerla, ESCORT: a decentralized and localized access control system for mobile wireless access to secured domains, Proceedings of the 2003 ACM workshop on Wireless security, September 19-19, 2003, San Diego, CA, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Andrei Oliveira da Silva , Paulo Henrique de Souza Schneider , Fabricio D'Avila Cabral , Ana Cristina Benso da Silva , João Batista de Oliveira , Eduardo Augusto Bezerra, Towards service and user discovery on wireless networks, Proceedings of the second international workshop on Mobility management & wireless access protocols, October 01-01, 2004, Philadelphia, PA, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
D. F. Bantz , C. Bisdikian , D. Challener , J. P. Karidis , S. Mastrianni , A. Mohindra , D. G. Shea , M. Vanover, Autonomic personal computing, IBM Systems Journal, v.42 n.1, p.165-176, January 2003
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Changhua He , Mukund Sundararajan , Anupam Datta , Ante Derek , John C. Mitchell, A modular correctness proof of IEEE 802.11i and TLS, Proceedings of the 12th ACM conference on Computer and communications security, November 07-11, 2005, Alexandria, VA, USA
|
|
|
|
|
|
|
|
|
R. Bagrodia , S. Bhattacharyya , F. Cheng , S. Gerding , G. Glazer , R. Guy , Z. Ji , J. Lin , T. Phan , E. Skow , M. Varshney , G. Zorpas, iMASH: interactive mobile application session handoff, Proceedings of the 1st international conference on Mobile systems, applications and services, p.259-272, May 05-08, 2003, San Francisco, California
|
|
|
|
|
|
|
|
|
|
|
|
Yang Xiao , Chaitanya Bandela , Xiaojiang (James) Du , Yi Pan , Edilbert Kamal Dass, Security mechanisms, attacks and security enhancements for the IEEE 802.11 WLANs, International Journal of Wireless and Mobile Computing, v.1 n.3/4, p.276-288, February 2006
|
|
|
|
|
|
P. Akritidis , W. Y. Chin , V. T. Lam , S. Sidiroglou , K. G. Anagnostakis, Proximity breeds danger: emerging threats in metro-area wireless networks, Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, p.1-16, August 06-10, 2007, Boston, MA
|
|
|
Ben Greenstein , Ramakrishna Gummadi , Jeffrey Pang , Mike Y. Chen , Tadayoshi Kohno , Srinivasan Seshan , David Wetherall, Can Ferris Bueller still have his day off? protecting privacy in the wireless era, Proceedings of the 11th USENIX workshop on Hot topics in operating systems, p.1-6, May 07-09, 2007, San Diego, CA
|
|
|
|
|
|
|
|
|
Joshua Mason , Kathryn Watkins , Jason Eisner , Adam Stubblefield, A natural language approach to automated cryptanalysis of two-time pads, Proceedings of the 13th ACM conference on Computer and communications security, October 30-November 03, 2006, Alexandria, Virginia, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Ivan Cibrario Bertolotti , Luca Durante , Paolo Maggi , Riccardo Sisto , Adriano Valenzano, Improving the security of industrial networks by means of formal verification, Computer Standards & Interfaces, v.29 n.3, p.387-397, March, 2007
|
|
|
Suman Kundu , J. Mukherjee , A. K. Majumdar , B. Majumdar , Sirsendu Sekhar Ray, Algorithms and heuristics for efficient medical information display in PDA, Computers in Biology and Medicine, v.37 n.9, p.1272-1282, September, 2007
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Kevin Richardson , John A. Hamilton, Jr. , Martin C. Carlisle, A performance analysis of the spring protocol through simulation, Proceedings of the 2007 spring simulation multiconference, p.356-361, March 25-29, 2007, Norfolk, Virginia
|
|
|
|
|
|
Loh Chin Choong Desmond , Cho Chia Yuan , Tan Chung Pheng , Ri Seng Lee, Identifying unique devices through wireless fingerprinting, Proceedings of the first ACM conference on Wireless network security, March 31-April 02, 2008, Alexandria, VA, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Sarah M. Diesburg , Christopher R. Meyers , David M. Lary , An-I Andy Wang, When cryptography meets storage, Proceedings of the 4th ACM international workshop on Storage security and survivability, October 31-31, 2008, Alexandria, Virginia, USA
|
|
|
|
|
|
|
|
|
|
|
|
Liran Ma , Amin Y. Teymorian , Xiuzhen Cheng , Min Song, RAP: protecting commodity wi-fi networks from rogue access points, The Fourth International Conference on Heterogeneous Networking for Quality, Reliability, Security and Robustness & Workshops, August 14-17, 2007, Vancouver, Canada
|
|