• DocumentCode
    1505812
  • Title

    The Insecurity of Wireless Networks

  • Author

    Sheldon, Frederick T. ; Weber, John Mark ; Yoo, Seong-Moo ; Pan, W.David

  • Author_Institution
    Oak Ridge National Laboratory
  • Volume
    10
  • Issue
    4
  • fYear
    2012
  • Firstpage
    54
  • Lastpage
    61
  • Abstract
    Wi-Fi is the standard protocol for wireless networks used extensively in US critical infrastructures. Since the Wired Equivalency Privacy (WEP) security protocol was broken, the Wi-Fi Protected Access (WPA) protocol has been considered the secure alternative compatible with hardware developed for WEP. However, in November 2008, researchers developed an attack on WPA, allowing forgery of Address Resolution Protocol (ARP) packets. Subsequent enhancements have enabled ARP poisoning, cryptosystem denial of service, and man-in-the-middle attacks. Open source systems and methods (OSSM) have long been used to secure networks against such attacks. This article reviews OSSMs and the results of experimental attacks on WPA. These experiments re-created current attacks in a laboratory setting, recording both wired and wireless traffic. The article discusses methods of intrusion detection and prevention in the context of cyberphysical protection of critical Internet infrastructure. The basis for this research is a specialized (and undoubtedly incomplete) taxonomy of Wi-Fi attacks and their adaptations to existing countermeasures and protocol revisions. Ultimately, this article aims to provide a clearer picture of how and why wireless protection protocols and encryption must achieve a more scientific basis for detecting and preventing such attacks.
  • Keywords
    Communication system security; Encryption; IEEE 802.11 Standards; Network security; Phase shift keying; Wireless communication; Wireless networks; IEEE 802.11; Internet-based attacks on privacy and confidentiality; Wi-Fi protected access; attack experimentation; computer security; critical Internet infrastructure; intrusion detection and prevention;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2012.60
  • Filename
    6193090