WLAN and IEEE 802.11 Security



Similar documents
Wireless Networks. Welcome to Wireless

Your Wireless Network has No Clothes

Network Security. Security of Wireless Local Area Networks. Chapter 15. Network Security (WS 2002): 15 Wireless LAN Security 1 Dr.-Ing G.

Security (WEP, WPA\WPA2) 19/05/2009. Giulio Rossetti Unipi

Security+ Guide to Network Security Fundamentals, Third Edition. Chapter 6. Wireless Network Security

Security in Wireless Local Area Network

12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust

A Security Analysis of the Wireless Networks (IEEE )

The Basics of Wireless Local Area Networks

Lecture Objectives. Lecture 8 Mobile Networks: Security in Wireless LANs and Mobile Networks. Agenda. References

Key Hopping A Security Enhancement Scheme for IEEE WEP Standards

WIRELESS SECURITY. Information Security in Systems & Networks Public Development Program. Sanjay Goel University at Albany, SUNY Fall 2006

Security in IEEE WLANs

Wireless Security Overview. Ann Geyer Partner, Tunitas Group Chair, Mobile Healthcare Alliance

Wireless LAN Security I: WEP Overview and Tools

COMPARISON OF WIRELESS SECURITY PROTOCOLS (WEP AND WPA2)

WEP Overview 1/2. and encryption mechanisms Now deprecated. Shared key Open key (the client will authenticate always) Shared key authentication

CSC574: Computer and Network Security

Wireless Threats To Corporate Security A Presentation for ISACA UK Northern Chapter

SSI. Commons Wireless Protocols WEP and WPA2. Bertil Maria Pires Marques. Dez Dez

Wireless LAN Security Mechanisms

802.11b and associated network security risks for the home user

All vulnerabilities that exist in conventional wired networks apply and likely easier Theft, tampering of devices

WIRELESS NETWORKING SECURITY

PwC. Outline. The case for wireless networking. Access points and network cards. Introduction: OSI layers and 802 structure

How To Secure Wireless Networks

Introduction to WiFi Security. Frank Sweetser WPI Network Operations and Security

INFORMATION TECHNOLOGY MANAGEMENT COMMITTEE LIVINGSTON, NJ ITMC TECH TIP ROB COONCE, MARCH 2008

Wireless security. Any station within range of the RF receives data Two security mechanism

Analysis of Security Issues and Their Solutions in Wireless LAN 1 Shenam Chugh, 2 Dr.Kamal

Chapter 6 CDMA/802.11i

EVOLUTION OF WIRELESS LAN SECURITY ARCHITECTURE TO IEEE i (WPA2)

Wireless LANs vs. Wireless WANs

CS 356 Lecture 29 Wireless Security. Spring 2013

Journal of Mobile, Embedded and Distributed Systems, vol. I, no. 1, 2009 ISSN

THE IMPORTANCE OF CRYPTOGRAPHY STANDARD IN WIRELESS LOCAL AREA NETWORKING

Wireless LAN Security: Securing Your Access Point

Wireless Local Area Networking (WLAN) Security Assessment And Countermeasures

WLAN Attacks. Wireless LAN Attacks and Protection Tools. (Section 3 contd.) Traffic Analysis. Passive Attacks. War Driving. War Driving contd.

Network Security. Security of Wireless Local Area Networks. Chapter 15. Network Security (WS 2003): 15 Wireless LAN Security 1. Dr.-Ing G.

CS549: Cryptography and Network Security

The next generation of knowledge and expertise Wireless Security Basics

Abstract. 1. IEEE a a b b c g 2. HiperLAN/2. 3. Bluetooth. 4. HomeRF.

Overview. Summary of Key Findings. Tech Note PCI Wireless Guideline

Wireless Security: Token, WEP, Cellular

Ebonyi State University Abakaliki 2 Department of Computer Science. Our Saviour Institute of Science and Technology 3 Department of Computer Science

Security Awareness. Wireless Network Security

WLAN Security Why Your Firewall, VPN, and IEEE i Aren t Enough to Protect Your Network

How To Secure Your Network With 802.1X (Ipo) On A Pc Or Mac Or Macbook Or Ipo On A Microsoft Mac Or Ipow On A Network With A Password Protected By A Keyed Key (Ipow)

Chapter 2 Wireless Networking Basics

Vulnerabilities of Wireless Security protocols (WEP and WPA2)

WI-FI SECURITY: A LITERATURE REVIEW OF SECURITY IN WIRELESS NETWORK

chap18.wireless Network Security

Key Management (Distribution and Certification) (1)

A COMPARITIVE ANALYSIS OF WIRELESS SECURITY PROTOCOLS (WEP and WPA2)

Chapter 2 Configuring Your Wireless Network and Security Settings

Wireless Local Area. Network Security

Industrial Communication. Securing Industrial Wireless

Agenda. Wireless LAN Security. TCP/IP Protocol Suite (Internet Model) Security for TCP/IP. Agenda. Car Security Story

Chapter 7 Low-Speed Wireless Local Area Networks

Linux Access Point and IPSec Bridge

Chapter 3 Safeguarding Your Network

WiFi Security: WEP, WPA, and WPA2

Recommended Wireless Local Area Network Architecture

Security in Wireless and Mobile Networks

CS5490/6490: Network Security- Lecture Notes - November 9 th 2015

Cisco Aironet Wireless Bridges FAQ

WHITE PAPER. WEP Cloaking for Legacy Encryption Protection

Network Security Best Practices

A SURVEY OF WIRELESS NETWORK SECURITY PROTOCOLS

Authentication in WLAN

Wiereless LAN

DESIGNING AND DEPLOYING SECURE WIRELESS LANS. Karl McDermott Cisco Systems Ireland

Applying of Security Mechanisms to Low Layers of OSI/ISO Network Model

HANDBOOK 8 NETWORK SECURITY Version 1.0

CS 336/536 Computer Network Security. Summer Term Wi-Fi Protected Access (WPA) compiled by Anthony Barnard


54M/150M/300Mbps USB WIRELESS ADAPTER. User s Manual Version 2.0

WiFi. Is for Wireless Fidelity Or IEEE Standard By Greg Goldman. WiFi 1

How To Protect A Wireless Lan From A Rogue Access Point

WIRELESS NETWORK SECURITY

The Misuse of RC4 in Microsoft Word and Excel

ECE 4893: Internetwork Security Lab 10: Wireless Security

Wireless Ethernet LAN (WLAN) General a/802.11b/802.11g FAQ

Wireless Network Policy

IEEE Wireless LAN Security Overview

Security Requirements for Wireless Networks and their Satisfaction in IEEE b and Bluetooth

54M/150M/300Mbps USB WIRELESS ADAPTER. User s Manual Version 1.8

WIRELESS SECURITY IN (WI-FI ) NETWORKS

WLAN - Good Security Principles. WLAN - Good Security Principles. Example of War Driving in Hong Kong* WLAN - Good Security Principles

White paper. Testing for Wi-Fi Protected Access (WPA) in WLAN Access Points.

Transcription:

WLAN and IEEE 802.11 Security

Agenda Intro to WLAN Security mechanisms in IEEE 802.11 Attacks on 802.11 Summary

Wireless LAN Technologies WLAN technologies are becoming increasingly popular, and promise to be the platform for many future applications: Home Entertainment Networking Example WLAN/WPAN Technologies: IEEE 802.11 Bluetooth WLAN End User Forecast (millions)

Bluetooth Cable replacement Self-forming PANs (Personal Area Networks) Freq: 2.4 GHz band Power 1mw to 100 mw Mode : FHSS Range: 40-50 Feet Data Rate: Approx 400 Kbps Security better than Wi-Fi but not MUCH of a concern. We will not focus on Bluetooth security in this talk.

IEEE 802.11 Wireless Networks Speeds of upto 54 Mb/s Operating Range: 10-100m indoors, 300m outdoors Power Output Limited to 1 Watt in U.S. Frequency Hopping (FHSS), Direct Sequence & Infrared (IrDA) ( Networks are NOT compatible with each other) Uses unlicensed 2.4/5 GHz band (2.402-2.480,5 GHz) Provide wireless Ethernet for wired networks

WLAN Components

More about WLAN Modes of Operation Ad Hoc mode (Independent Basic Service Set - IBSS) Infrastructure mode (Basic Service Set - BSS)

Ad-Hoc mode Client A Client B Client C Laptop users wishing to share files could set up an ad-hoc network using 802.11 compatible NICs and share files without need for external media.

Infrastructure mode In this mode the clients communicate via a central station called Access Point (AP) which acts as an ethernet bridge and forwards the communication onto the appropriate network, either the wired or the wireless network. Client A Access point Client B

WLAN Security Problem!! There is no physical link between the nodes of a wireless network, the nodes transmit over the air and hence anyone within the radio range can eavesdrop on the communication. So conventional security measures that apply to a wired network do not work in this case. Internal network protected Wireless Access Point Valid User Access Only

IEEE 802.11 Basic Security Mechanisms Service Set Identifier (SSID) MAC Address filtering Wired Equivalent Privacy (WEP) protocol 802.11 products are shipped by the vendors with all security mechanisms disabled!!

Service Set Identifier (SSID) and their limits! Limits access by identifying the service area covered by the access points. AP periodically broadcasts SSID in a beacon. End station listens to these broadcasts and chooses an AP to associate with based upon its SSID. Use of SSID weak form of security as beacon management frames on 802.11 WLAN are always sent in the clear. A hacker can use analysis tools (eg. AirMagnet, Netstumbler, AiroPeek) to identify SSID. Some vendors use default SSIDs which are pretty well known (eg. CISCO uses tsunami)

MAC Address Filtering The system administrator can specify a list of MAC addresses that can communicate through an access point. Advantage : Provides a little stronger security than SSID Disadvantages : Increases Administrative overhead Reduces Scalability Determined hackers can still break it

Wired Equivalent Privacy (WEP) Designed to provide confidentiality to a wireless network similar to that of standard LANs. WEP is essentially the RC4 symmetric key cryptographic algorithm (same key for encrypting and decrypting). Transmitting station concatenates 40 bit key with a 24 bit Initialization Vector (IV) to produce pseudorandom key stream. Plaintext is XORed with the pseudorandom key stream to produce ciphertext. Ciphertext is concatenated with IV and transmitted over the Wireless Medium. Receiving station reads the IV, concatenates it with the secret key to produce local copy of the pseudorandom key stream. Received ciphertext is XORed with the key stream generated to get back the plaintext.

WEP has its cost!

WEP vulnerability to attack WEP has been broken! Walker (Oct 2000), Borisov et. al. (Jan 2001), Fluhrer-Mantin -Shamir (Aug 2001). Unsafe at any key size : Testing reveals WEP encapsulation remains insecure whether its key length is 1 bit or 1000 or any other size. More about this at: http://grouper.ieee.org/groups/802/11/documents/documentholder/0-362.zip

WEP Overview WEP relies on a shared key K between communicating parties 1. Checksum: For a message M, we calculate c(m). The plaintext is P={M,c(M)} 2. Encryption: The plaintext is encrypted using RC4. RC4 requires an initialization vector (IV) v, and the key K. Output is a stream of bits called the keystream. Encryption is XOR with P. C = P RC4(v, K) 3. Transmission: The IV and the ciphertext C are transmitted. Message CRC v RC4(v,K) Ciphertext Transmit

WEP Security Goals WEP had three main security goals: Confidentiality: Prevent eavesdropping Access Control: Prevent inappropriate use of 802.11 network, such as facilitate dropping of not-authorized packets Data Integrity: Ensure that messages are not altered or tampered with in transit The basic WEP standard uses a 40-bit key (with 24bit IV) Additionally, many implementations allow for 104-bit key (with 24bit IV) None of the three goals are provided in WEP due to serious security design flaws and the fact that it is easy to eavesdrop on WLAN

WEP (Vernam( Vernam) ) Key Stream Reuse Vernam-style stream ciphers are susceptible to attacks when same IV and key are reused: C C C 1 2 1 = P = 1 P 2 C RC4(v, K) 2 RC4(v, K) = P = P 1 1 RC4(v, K) P P 2 Particularly weak to known plaintext attack: If P 1 is known, then P 2 is easy to find (as is RC4). This might occur when contextual information gives P 1 (e.g. applicationlevel or network-level information reveals information) Even so, there are techniques to recover P 1 and P 2 when just (P 1 XOR P 2 ) is known (frequency analysis, crib dragging) Example, look for two texts that XOR to same value 2 RC4(v, K)

WEP s Proposed Fix WEP s engineers were aware (it seems??) of this weakness and required a per-packet IV strategy to vary key stream generation Problems: Keys, K, typically stay fixed and so eventual reuse of IV means eventual repetition of keystream!! IVs are transmitted in the clear, so its trivial to detect IV reuse Many cards set IV to 0 at startup and increment IV sequentially from there Even so, the IV is only 24 bits! Calculation: Suppose you send 1500 byte packets at 5Mbps, then 2 24 possible IVs will be used up in 11.2 hours! Even worse: we should expect to see atleast one collision after 5000 packets are sent! Thus, we will see the same IV again and again

WEP Decryption Dictionaries Once a plaintext is known for an IV collision, the adversary can obtain the key stream for that specific IV! The adversary can gather the keystream for each IV collision he observes As he does so, it becomes progressively easier to decrypt future messages (and he will get improved context information!) The adversary can build a dictionary of (IV, keystream) This dictionary attack is effective regardless of keysize as it only depends on IV size!

WEP Weakness in Message Authentication The checksum used by WEP is CRC-32, which is not a cryptographic checksum (MAC) Purpose of checksum is to see if noise modified the message, not to prevent malicious and intelligent modifications Property of CRC: The checksum is a linear function of the message c(x y) = c(x) c(y) This property allows one to make controlled modifications to a ciphertext without disrupting the checksum: Suppose ciphertext C is: We can make a new ciphertext C that corresponds to an M of our choosing Then we can spoof the source by: A B: {v,c } C = RC4(v, K) {M,c(M)}

WEP: Spoofing the Source Our goal: Produce an M =M+δ, and a corresponding checksum that will pass checksum test. (Hence, we will need to make a plaintext P ={M,c(M )} and a corresponding ciphertext C ) Start by choosing our own δ value, and calculate checksum. Observe: C' = C { δ,c( δ)} = RC4(v, K) {M,c(M)} { δ,c( δ)} = RC4(v, K) {M δ,c(m) c( δ)} = RC4(v, K) {M',c(M δ)} = RC4(v, K) {M',c(M')} Thus, we have produced a new plaintext of our choosing and made a corresponding ciphertext C Does not require knowledge of M, actually, we can choose δ to flip bits!

WEP Message Injection (No Access Control!) Property: The WEP checksum is an unkeyed function of the message. If attacker can obtain an entire plaintext corresponding to a frame, he will then be able to inject arbitrary traffic into the network (for same IV): 1. Get RC4(v,K) 2. For any message M form C' = RC4(v, K) {M',c(M')} Why did this work? c(m) only depended on M and not on any key!!! (Note: An adversary can easily masquerade as an AP since there are no mechanisms to prevent IV reuse at the AP-level!)

Other Security Problems of 802.11 Easy Access "Rogue" Access Points Unauthorized Use of Service Traffic Analysis and Eavesdropping Higher Level Attacks

Drive By Hacking ipaq Notebook Less than 1500ft * Access Port Switch Main Corporate Backbone Server Server Server PalmPilot Mobile Phone If the distance from the Access Point to the street outside is 1500 feet or less, then a Intruder could also get access while sitting outside

War-driving expeditions In one 30-minute journey using the Pringles can antenna, witnessed by BBC News Online, the security company I-SEC managed to find and gain information about almost 60 wireless networks.

War Chalking Practice of marking a series of symbols on sidewalks and walls to indicate nearby wireless access. That way, other computer users can pop open their laptops and connect to the Internet wirelessly.

What are the major security risks to 802.11b? Insertion Attacks (Intrusions!) Interception and monitoring wireless traffic Misconfiguration Jamming Client to Client Attacks (Intrusions also!)

Packet Sniffing

Jamming (Denial of Service) Broadcast radio signals at the same frequency as the wireless Ethernet transmitters - 2.4 GHz To jam, you just need to broadcast a radio signal at the same frequency but at a higher power. Waveform Generators Microwave

Replay Attack Good guy Alice Authorized WEP Communications Good guy Bob Eavesdrop and Record Play back selections Bad guy Eve

Measures to strengthen WLAN security Recommendations Wireless LAN related Configuration Enable WEP, use 128bit key* Using the encryption technologies Disable SSID Broadcasts Change default Access Point Name Choose complex admin password Apply Filtering Use MAC (hardware) address to restrict access The Use of 802.1x Enable firewall function

Major Papers on 802.11 Security Intercepting Mobile Communications: The Insecurity of 802.11(Borisov, Goldberg, and Wagner 2001) Your 802.11 Wireless Network Has No Clothes (Arbaugh, Shankar, and Wan 2001) Weaknesses in the Key Scheduling Algorithm of RC4(Fluhrer, Mantin, and Shamir 2001) The IEEE 802.11b Security Problem, Part 1 (Joseph Williams,2001 IEEE) An IEEE 802.11 Wireless LAN Security White Paper (Jason S. King, 2001)