• DocumentCode
    1724851
  • Title

    Denial of convenience attack to smartphones using a fake Wi-Fi access point

  • Author

    Dondyk, E. ; Zou, Cliff C.

  • Author_Institution
    Coll. of Eng. & Comput. Sci, Univ. of Central Florida, Orlando, FL, USA
  • fYear
    2013
  • Firstpage
    164
  • Lastpage
    170
  • Abstract
    In this paper, we present a novel denial-of-service attack targeted at popular smartphones that are used by normal users who are not technology savvy. This type of attack, which we call a denial-of-convenience attack, prevents non-technical savvy victims from utilizing data services by exploiting the connectivity management protocol of smartphones when encountered with a Wi-Fi access point. By setting up a fake Wi-Fi access point without Internet access (using a simple device such as a laptop computer), an attacker can prompt a smartphone with enabled Wi-Fi features to automatically terminate a valid mobile broadband connection and connect to this fake Wi-Fi access point. This, as a result, prevents the targeted smartphone from having any type of Internet connection unless the victim is capable of identifying the attack and manually disabling the Wi-Fi features. We demonstrate that most popular smartphones, including iPhone and Android phones, are vulnerable to denial-of-convenience attacks. To address this attack, we propose implementing a novel Internet-access validation protocol that uses the cellular network to send a secret key phrase to an Internet validation server. Then, it attempts to retrieve this secret key phrase via the newly established Wi-Fi channel to validate the Wi-Fi access point. We have fully developed and evaluated the attacks as well as the defense prototypes that run on Android phones.
  • Keywords
    protocols; smart phones; telecommunication security; wireless LAN; Android phones; Internet-access validation protocol; WiFi features; connectivity management protocol; defense prototypes; denial of convenience attack; denial-of-service attack; fake Wi-Fi access point; iPhone; non-technical savvy victims; smartphones; Broadband communication; IEEE 802.11 Standards; Internet; Mobile communication; Protocols; Servers; Smart phones; Android; denial-of-service; iPhone; mobile platforms;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Consumer Communications and Networking Conference (CCNC), 2013 IEEE
  • Conference_Location
    Las Vegas, NV
  • Print_ISBN
    978-1-4673-3131-9
  • Type

    conf

  • DOI
    10.1109/CCNC.2013.6488441
  • Filename
    6488441