0% found this document useful (0 votes)
17 views9 pages

Wi-Fi Security Protocols and Attacks Guide

The document discusses the vulnerabilities and security protocols of Wi-Fi networks, highlighting the risks associated with public Wi-Fi and various types of wireless network attacks. It covers security protocols like WEP, WPA, WPA2, and WPA3, detailing their strengths and weaknesses. Additionally, it provides recommendations for securing personal and public Wi-Fi connections to mitigate potential threats.

Uploaded by

Rafgs 88
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views9 pages

Wi-Fi Security Protocols and Attacks Guide

The document discusses the vulnerabilities and security protocols of Wi-Fi networks, highlighting the risks associated with public Wi-Fi and various types of wireless network attacks. It covers security protocols like WEP, WPA, WPA2, and WPA3, detailing their strengths and weaknesses. Additionally, it provides recommendations for securing personal and public Wi-Fi connections to mitigate potential threats.

Uploaded by

Rafgs 88
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

h

h
h
h
h

PA192 Secure Hardware Based Desing

Laboratory Task No. 1


Atacking on WIFI
h
Author:
Rafael Grande Salido (545705)

h
Professor:
Zdeněk Matěj
h
h

h
h
PA192 - Laboratory Task No. 1

Índice
Chapters Page

1. Introducction: The Problems With WiFi Networks 1

2. Wi-Fi Security Protocols 1


2.1. Wired Equivalend Privacy (WEP) . . . . . . . . . . . . . . . . . . . . . 1
2.2. Wi-Fi Protected Access (WPA) . . . . . . . . . . . . . . . . . . . . . . 2
2.3. WPA2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
2.4. WPA3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3

3. Types of Wireless Network Attacks 4


3.1. Fake Wi-Fi Access Points and Man-in-the-Middle (MitM) attacks . . . 4
3.2. Packet Sniffing Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
3.3. Brute Force Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5

4. Advices and Recommendations 6


4.1. On your personal Wi-Fi . . . . . . . . . . . . . . . . . . . . . . . . . . 6
4.2. To connect to public Wi-Fi networks . . . . . . . . . . . . . . . . . . . 6

5. References 7

i
PA192 - Laboratory Task No. 1

1. Introducction: The Problems With WiFi Net-


works
Wi-Fi networks have become an integral part of our daily lives, offering us the con-
venience of wireless connectivity. However, within the realm of Wi-Fi, challenges and
vulnerabilities persist. While all Wi-Fi networks, even our private ones, are susceptible
to potential attacks, the most dangerous ones are the public free Wi-Fi networks.

These public networks are very frequenly target for malicious actors, attracting a
lot of attacks. Connecting to an insecure network, whether public or private, can have
far-reaching consequences. Hackers have the potential to obtain passwords, access sen-
sitive personal data, such as financial and medical information.

We are going to see the most important security protocols on wireless networks,
the most common types of attacks and some recommendation and possible solutions to
make our wireless connection safer.

2. Wi-Fi Security Protocols

2.1. Wired Equivalend Privacy (WEP)


WEP (Wired Equivalent Privacy) is a wireless security protocol. It was one of the
earliest protocols developed to encrypt wireless data transmissions. However, it had
significant security shortcomings.

WEP employed the RC4 encryption algorithm and CRC-32 (Cyclic Redundancy
Check) for data integrity. Initially, it used a 64-bit key, which consisted of a 40-bit
user-defined password concatenated with a 24-bit initialization vector to create the
encryption key. There was also a 128-bit variant of WEP that provided a longer key,
making it more secure.

One of the most critical issues with WEP was the reuse of the initialization vectors.
When these vectors were reused, it significantly weakened the encryption, making it re-
latively easy for attackers to crack the encryption and gain unauthorized access to the
network. This inherent vulnerability led to widespread security concerns and ultimately

1
PA192 - Laboratory Task No. 1

rendered WEP an insecure choice for wireless security.

The insecurity of WEP was widely recognized, and by 2005, it had become evident
that it could not provide adequate protection for wireless networks. The FBI, along
with various security researchers, demonstrated how easily attackers could compromise
the security of WEP-protected networks. As a result, WEP was deprecated, and more
secure encryption methods, such as WPA (Wi-Fi Protected Access).

2.2. Wi-Fi Protected Access (WPA)


WPA (Wi-Fi Protected Access) is a wireless security protocol introduced as an
improvement over its predecessor, WEP, it was developed to enhance the security of
wireless networks and provide better protection for data transmission.

WPA adopted more robust encryption mechanisms, such as TKIP (Temporal Key
Integrity Protocol). These encryption method provided stronger protection for data in
transit.

One of the notable improvements in WPA was the introduction of dynamic encry-
ption keys. WPA regularly changed encryption keys, making it significantly more cha-
llenging for attackers to decipher the transmitted data. This dynamic key exchange was
a fundamental security enhancement over the static keys used in WEP.

WPA also introduced a stronger message integrity check, making it more resistant
to data tampering or injection attacks. It used a more secure initialization vector and
addressed the critical initialization vector reuse issue found in WEP.

WPA was not without its vulnerabilities, and in response to emerging threats, WPA2
was introduced in 2004, further enhancing wireless network security.

2.3. WPA2
WPA2 replaced TKIP and the RC4 encryption used in WEP and WPA with two
more robust alternatives for encryption and authentication. Firstly, it introduced the
Advanced Encryption Standard (AES), and secondly, it employed the Counter Mode

2
PA192 - Laboratory Task No. 1

with Cipher Block Chaining Message Authentication Code Protocol (CCMP). Addi-
tionally, it allowed for the configuration of WPA2 with TKIP to maintain backward
compatibility.

This protocol is significantly more secure and resistant to attacks compared to WEP
and WPA. However, it is not entirely without issues. One of its vulnerabilities is known
as ’Hole196,’ which relates to the implementation of the Group Temporal Key (GTK).
While the protocol uses a random system to block attacks, some manufacturers use
random number generators that make these numbers quite predictable, rendering the
protocol vulnerable.

We can also consider the issue of weak passwords. If a user changes the default pass-
word to something simpler and easier to remember, it can leave networks vulnerable to
brute-force attacks using dictionary-based methods. Due to all these problems, a new
version of the WPA protocol has been created, WPA3, which aims to address these
issues.

2.4. WPA3
In January 2018, the Wi-Fi Alliance introduced WPA3 as a replacement for WPA2,
aiming to enhance the security of Wi-Fi networks.

WPA3-Personal offers improved password-based authentication, making it more se-


cure even with simpler passwords. It uses Simultaneous Authentication of Equals (SAE)
to protect against offline dictionary attacks. This approach allows users to create mo-
re easily memorable passwords while ensuring that network connections remain user-
friendly and data traffic stays secure, even if a password is compromised.

WPA3-Enterprise takes security to the next level, building on WPA2-Enterprise by


requiring Protected Management Frames for all WPA3 connections. It enforces robust
security with various Extensible Authentication Protocol (EAP) methods, minimum
128-bit AES-CCMP for authenticated encryption, 256-bit HMAC-SHA256 for key de-
rivation, and 128-bit BIP-CMAC-128 for management frame protection. An optional
192-bit mode provides even stronger security, utilizing advanced cryptographic tools
and protocols to safeguard sensitive data.

3
PA192 - Laboratory Task No. 1

WPA3 enhances security on open Wi-Fi networks. It offers unauthenticated data


encryption, safeguarding user data while maintaining network convenience. This tech-
nology is interoperable with legacy networks and eliminates the need for public passph-
rases. It’s a valuable addition to Wi-Fi security, benefiting both users and network
providers.

3. Types of Wireless Network Attacks

3.1. Fake Wi-Fi Access Points and Man-in-the-Middle (MitM)


attacks
A Fake Wi-Fi Access Point, is a deceptive network created by malicious actors to
mimic legitimate, trusted Wi-Fi networks. These attackers set up a rogue access point
with a name (SSID) that closely resembles a well-known network like a public Wi-Fi
hotspot from a airport, a cafe or an hotel. Once connected, the attacker gains unautho-
rized access to the user’s device and can intercept internet traffic, capturing sensitive
data or login credentials.

On the other hand, Man-in-the-Middle (MitM) Attacks represent a larger category


of security threats that involve an attacker positioning themselves between two com-
municating parties. The attacker intercepts their communication, potentially altering
the data exchanged. MitM attacks can occur in various contexts, not limited to Wi-Fi.
In the case of Wi-Fi, an attacker executes a MitM attack by placing themselves in the
middle of the communication between a user and their target network or destination.
The attacker can spy on the communication, capture sensitive information, and poten-
tially modify the data.

Fake access points ranks as prevalent wireless network due to their simplicity, mi-
nimal technical expertise required, and high success rates. Research has revealed that
over a third of WiFi hotspot users tend to be complacent, neglecting security measures
when connecting to WiFi hotspots and frequently opting for unsecured networks.

4
PA192 - Laboratory Task No. 1

3.2. Packet Sniffing Attacks


Packet sniffing attacks, also known as packet analysis or network sniffing attacks,
involve the interception and examination of data packets as they go across a network.
These attacks can be conducted for legitimate network monitoring and troubleshooting
purposes by administrators but can also be exploited by malicious actors for unautho-
rized surveillance and data theft.

In a packet sniffing attack, specialized software or hardware tools called packet snif-
fers or network analyzers capture and inspect data packets being transmitted within a
network. These packets contain valuable information such as source and destination IP
addresses, content, and the communication protocols being used. Attackers can use the-
se tools to intercept sensitive data. This unauthorized access can lead to the exposure
of confidential information, including login credentials, personal data, or even sensitive
business communications.

It’s not a major issue if the data is well-encrypted; however, many public Wi-Fi
networks do not utilize secure encryption or, in some cases, have no encryption at all.
This situation makes it easy for attackers to gain access to the data.

3.3. Brute Force Attacks


A brute force attack on a Wi-Fi network is an attempt by an attacker to gain
unauthorized access by systematically trying an extensive number of possible passwords
or encryption keys. This method can be combined with dictionary attacks, where the
attacker utilizes a predefined list of common or likely passwords, significantly increa-
sing the efficiency of the attack. The attacker’s approach relies on determination and
computational power to repeatedly guess and test various password combinations until
the correct one is discovered.

In this type of attack, automated software or scripts are often employed to generate
a substantial list of potential passwords. These passwords, combined with those from a
dictionary file, are systematically and rapidly tested against the target Wi-Fi network.
The attacker aims to find the correct combination that grants access.

Brute force attacks on Wi-Fi networks, particularly when combined with dictionary

5
PA192 - Laboratory Task No. 1

attacks, can be time-consuming and resource-intensive, especially when network secu-


rity measures are robust. To mitigate such attacks, security practices like using complex
and difficult-to-guess Wi-Fi passwords, implementing account lockouts after multiple
failed login attempts, and employing measures that limit the number of login attempts
are recommended to strengthen network security.

4. Advices and Recommendations

4.1. On your personal Wi-Fi


To secure your Wi-Fi network, change the SSID to a unique name, avoiding personal
information, and use strong, complex passwords for router access. Opt for long, mixed-
character passwords to deter unauthorized access. Consider adopting WPA3, a more
robust security protocol, to enhance encryption and authentication, making it harder
for attackers to compromise your network. These steps significantly improve the security
of your home Wi-Fi, reducing the risk of breaches and unauthorized access.

4.2. To connect to public Wi-Fi networks


To enhance your network security on public Wi-Fi networks, it’s crucial to take a
few additional measures. Firstly, configure your devices not to automatically connect
to this type of networks. This prevents unintended connections to potentially unsafe
networks, offering you better control over your connections.

Additionally, always ensure that the websites you visit use HTTPS, indicated by a
padlock symbol in the browser’s address bar. HTTPS encrypts the data transmitted bet-
ween your device and the website, safeguarding your information from eavesdropping.
Some websites might lack this encryption, so remain cautious when sharing sensitive
data on them.

Moreover, it’s essential to sign out of your accounts and disconnect from Wi-Fi net-
works once you’re done using them. Leaving yourself logged in or connected can pose
security risks.

For an added layer of protection, consider using a reputable Virtual Private Net-
work (VPN), preferably a paid one. A VPN encrypts your internet connection, making

6
PA192 - Laboratory Task No. 1

it difficult for anyone to intercept your data. However, exercise caution when selecting a
VPN service, as not all are created equal. Research and choose a trusted, well-reviewed
VPN provider to ensure your online privacy and security.

These practices collectively bolster your network security and online privacy, redu-
cing the chances of falling victim to cyber threats.

5. References
Xataka. (2022). Caos en la seguridad WiFi: un repaso a las vulnerabilidades de
WEP, WPA y WPA2. [Link]
un-repaso-a-las-vulnerabilidades-de-wep-wap-y-wap2

Xataka. (2022). Por qué es peligroso conectarse a Wifis públicas y qué debes hacer
para protegerte. [Link]
a-wifis-publicas-y-que-debes-hacer-para-protegerte

Xataka. (2020). ¿En qué se diferencia la seguridad WiFi WPA3 de WPA2?. [Link]
se-diferencia-seguridad-wifi-wpa3-wpa2

WebTitan. (n.d.). Most Common Wireless Network Attacks. [Link]


common-wireless-network-attacks/

Wi-Fi Alliance. (2020). Security. [Link]

You might also like