0% found this document useful (0 votes)
23 views20 pages

NetSec-Wireless Network Attacks & Defences

This document discusses wireless network attacks and defenses. It describes different types of wireless networks including WPAN (Bluetooth), WLAN (802.11 standards), WMAN (WiMax) and WWAN. It outlines vulnerabilities in wireless networks like shared media, signal blockage, lack of boundaries and fixed points. Common wireless network attacks are also summarized such as reconnaissance, access attacks and denial of service attacks. Specific attacks on Bluetooth and 802.11 wireless networks are then covered in more detail. The document concludes by explaining the weaknesses in the original Wired Equivalent Privacy (WEP) encryption standard for 802.11 networks.

Uploaded by

RuRuele Ru
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views20 pages

NetSec-Wireless Network Attacks & Defences

This document discusses wireless network attacks and defenses. It describes different types of wireless networks including WPAN (Bluetooth), WLAN (802.11 standards), WMAN (WiMax) and WWAN. It outlines vulnerabilities in wireless networks like shared media, signal blockage, lack of boundaries and fixed points. Common wireless network attacks are also summarized such as reconnaissance, access attacks and denial of service attacks. Specific attacks on Bluetooth and 802.11 wireless networks are then covered in more detail. The document concludes by explaining the weaknesses in the original Wired Equivalent Privacy (WEP) encryption standard for 802.11 networks.

Uploaded by

RuRuele Ru
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Wireless Network Attacks &

Defenses
Contents
• Wireless Technologies
• Type of Wireless Networks
• Wireless Networks Vulnerabilities

• WPAN – Bluetooth
• WLAN – 802.11
• WWAN - WiMAX

2
Wireless Technologies
i. Infrared communication
• Line-of-sight
ii. Terrestrial microwave
• Line-of-sight
iii. Radio waves
• High-frequency and low-frequency radio technology

3
Types of Wireless Networks
WPAN WLAN WMAN WWAN
Wireless Wireless Local Wireless Wireless
Personal Area Area Network Metropolitan Wide Area
Network Area Network Network
Coverage  > 10m  Building  City  Cities
 Groups of  Countries
buildings
 Campus
Ownership  Personal  Implementer  Service  Service
provider provider

Technology  Bluetooth  IEEE 802.11  WiMax  Satelite


 WiFi  4G / 5G

4
Wireless Network Vulnerabilities
1. Shared media
• Packets are sent in shared media, accessible to all
• Packets can be sniffed, hijacked, inserted
2. Signal Blockage
• Electromagnetic waves can be blocked by metals, water
• Bandwidth can be interfered and jammed
3. No definite boarders
• Packets can be sniffed, hijacked, inserted from anywhere that
signals can be detected
4. No fixed points
• Hard to pin point attacker’s location

5
Types of Wireless Network Attacks
1. Reconnaissance Attacks
• Packet sniffers, Ping sweeps, Port scans
2. Access Attacks
• Password attack, Trust exploitation, Man-in-the-middle attack
3. Denial of Service Attacks
• Single-Message DoS attacks, Flooding DoS attacks, Distributed
DoS attacks
• Signal jamming

6
WPAN - Bluetooth
• Bluetooth
• is a Radio Frequency (RF) specification
• for short-range, point-to-point and point-to-multipoint
• for voice and data transfer
• Perfect for mobile devices
1. Small
2. low power
3. low cost
4. good performance
• Bluetooth is useful for cable replacement, data and voice access
points, and ad hoc networks

7
Bluetooth Attacks
1. Bluejacking
• An attacker sends unsolicited messages to Bluetooth enabled devices,
more annoying than harmful
2. Bluesnarfing
• Attack that access unauthorised information from a wireless
device through Bluetooth connection and steals data stored in
the device
3. Bluebugging
• Attacker connects to target device without knowledge of owner
and executes commands on the device
4. Blueborne
• Attack conducted by exploiting a stack buffer overflow flaw,
hijacking Bluetooth connections and gaining control of target 8
device’s embedded content and functions
WLAN – 802.11
• The IEEE 802.11 WLAN standard defines how Radio Frequencies in
the unlicensed ISM frequency bands is used for the physical layer
and the MAC sublayer of wireless links
• Various implementation of the IEEE 802.11 standard have been
developed over the years

Backwards
Standard Maximum Speed Frequency
Compatible
802.11a 54 Mbps 5 GHz No
802.11b 11 Mbps 2.4 GHz No
802.11g 54 Mbps 2.4 GHz 802.11b
802.11n 600 Mbps 2.4 GHz or 5 GHz 802.11b/g
802.11ac 1.3 Gbps 2.4 GHz and 5.5 GHz 802.11b/g/n

802.11ad 7 Gbps 2.4 GHz, 5 GHz and 60 GHz 802.11b/g/n/ac 9


WLAN Attacks
1. WAR Driving / WAR Walking
• Access Point / wireless network discovery
• Wireless location mapping
2. Wireless Protocol Analyser
• Captured wireless traffic are captured to decode and analyse
contents of packets
• Wireless network interface card adapters can operate in one of
six modes: master (AP), managed (Client), repeater, mesh, ad-
hoc, or monitor (Also called Radio Frequency Monitor RFMON)
3. RF Interference attacks
• Use equipment to flood RF spectrum with enough interference to
impact network
10
WLAN Attacks
4. Evil Twin
• An AP setup to mimic an authorised AP so that user’s device connect to
evil twin instead
5. Rogue Access Points
• A rogue access point is an unauthorised wireless access point that
has been installed on a secure network without explicit
authorization from a local network administrator, allowing
attackers to bypass network firewall security
• Use monitoring tools to locate rogue access points

SSID = ABC SSID = ABC

Rouge AP 11
Evil Twin
Wired Equivalent Privacy (WEP)
• Wired Equivalent Privacy (WEP)
• provides confidentiality to wireless transmission
• relies on a secret key that is shared between a wireless client device and
the access point (AP)
• A WEP key is an alphanumeric character string that is used for encrypting
and decrypting any packet transmitted
• WEP Encryption:
• Integrity Check Value (ICV) is a cyclic redundancy check (CRC) value
calculated for plaintext
• Initialization Vector (IV) is a 24-bit randomly generated value each time a
packet is encrypted
• IV and the shared Secret Key are combined to ‘seed’ a random keystream
that is combined through exclusive OR (XOR) with the plaintext to form
the Cipher text for the packet 12
• IV is added to the front of the Cypher Text (“Prepended”) for receiver to
decrypt message
Wired Equivalent Privacy (WEP)
Encrypt
Plaintext Plaintext ICV

CRC
XOR Ciphertext
* Same IV produces same Keystream

IV Secret key RC4 Keystream *IV is unencrypted

IV Ciphertext

Decrypt
Ciphertext

XOR Plaintext ICV


IV Secret key RC4 Keystream 13
Plaintext : 11010011 Ciphertext : 01110101
Keystream : 10100110 Keystream : 10100110
Ciphertext : 01110101 Plaintext : 11010011
WEP Weakness
1. Encryption key length is too short (64-bit or 128-bit)
2. Initialization Vector (IV) is too short (24-bit)
3. WEP implementation produces a detectable pattern that
attackers can break
• 24 bit IV creates only about 16 thousand possible values (2^24)
• Reuse of same IV (called a collision) allows attacker to launch keystream
or IV attack as the same IV and secret key will always create the same
keystream
• Keystream attack is the method of determining the keystream by
analyzing 2 packets created from the same IV

14
WEP Weakness
• IV collision occurs when the same IV is used in 2 different packets,
resulting in same keystream
Plaintext1: 11010011 Plaintext2: 00101101
Keystream: 10100110 Same Keystream: 10100110
Ciphertext1: 01110101 Ciphertext2: 10001011
• If Keystream is the same, the following happens:
Plaintext1: 11010011 Ciphertext1: 01110101
Plaintext2: 00101101 Ciphertext2: 10001011
11111110 Value matches 11111110
• If attacker knows keystream is the same and he know Plaintext 1,
he is able to derive Plaintext 2 using XOR of the 2 Cyphertexts

Ciphertext1: 01110101 Plaintext1: 11010011


Ciphertext2: 10001011 11111110
15
11111110 00101101
(Plaintext2)
• Plaintext1 like certain fields and headers are known
• Attacker can capture encrypted ARP requests and re-play them to generate more ARP response
Cracking WEP Secret Key
• AirSnort can be used for cracking WEP
• It operates by passively monitoring transmissions and
computing the encryption key when enough packets have
been gathered
• It requires approx. 5-10 million encrypted packets to be
gathered, in which it can guess the encryption password in
under a second

•Hacker passively listens and


captures enough packets to
break WEP key
•Attack possible due to the 16
limited space in the 24-bit IV
Other WLAN Security Solutions
1. WPA (Wi-Fi Protected Access)
• Replace WEP encryption key with Temporal Key Integrity Protocol
(TKIP) which creates per-packet keys to prevent collision
• Unlike WEP, preshared keys (PSK) are not used for encryption but
used as the starting point for generating encryption keys
• Replaces CRC with Message Integrity Check (MIC) which provides
integrity check and optional client authentication
2. WPA2 (Wi-Fi Protected Access 2)
• Uses the Advanced Encryption Standard (AES) instead of RC4
cipher
• Available key length of 128, 192 and 256 bits

17
WWAN - WiMAX
• WiMAX
WiMAX tower
• Worldwide Interoperability
for Microwave Access
• Speed
• Downlink 144 Mbps /
Uplink 35 Mbps
• Wireless
• Easier to extend to
suburban and rural areas
• Broad coverage
• Much wider coverage than
WiFi hotspots
WiMAX receiver
18
WWAN - WiMAX
• WiMAX tower
• Similar in concept to a cell-phone tower
• Provides coverage to very large area - 8,000 km2
• A WiMAX receiver
• Receiver and antenna could be an external device or can be built
into a laptop like what WiFi access
• Range
• 50 km radius from base station
• Speed
• 70 megabits per second
• Line-of-sight not needed between user and base station
• WiMAX operates similar to WiFi but at higher speeds, over greater
19
distances and for a greater number of users
WiMAX Security Issues
1. A flaw in the authentication mechanism used by WiMAX's privacy
and key management (PKM) protocol makes WiMAX networks
susceptible to man-in-the-middle attacks
2. Management frames are not encrypted, allowing an attacker to
collect information about subscribers and other potentially
sensitive network characteristics
3. Attacker can use legacy management frames to forcibly disconnect
legitimate stations
4. Physical layer denial of service attacks

20

You might also like