On the Robustness of Wi-Fi Deauthentication Countermeasures

О робастности средств противодействия деаутентификации в Wi-Fi
Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef
2022-05-07

IEEE 802.11wWi-Fi Management Frame Protectiondeauthentication attacksdenial-of-service vulnerabilitiesrobust management frames
With the introduction of WPA3 and Wi-Fi 6, an increased usage of Wi-Fi Management Frame Protection (MFP) is expected. Wi-Fi MFP, defined in IEEE 802.11w, protects robust management frames by providing data confidentiality, integrity, origin authenticity, and replay protection. One of its key goals is to prevent deauthentication attacks in which an adversary forcibly disconnects a client from the network. In this paper, we inspect the standard and its implementations for their robustness and protection against deauthentication attacks. In our standard analysis, we inspect the rules for processing robust management frames on their completeness, consistency, and security, leading to the discovery of unspecified cases, contradictory rules, and revealed insecure rules that lead to new denial-of-service vulnerabilities. We then inspect implementations and identify vulnerabilities in clients and access points running on the latest versions of the Linux kernel, hostap, IWD, Apple (i.e., macOS, iOS, iPadOS), Windows, and Android. Altogether, these vulnerabilities allow an adversary to disconnect any client from personal and enterprise networks despite the usage of MFP. Our work highlights that management frame protection is insufficient to prevent deauthentication attacks, and therefore more care is needed to mitigate attacks of this kind. In order to address the identified shortcomings, we worked with industry partners to propose updates to the IEEE 802.11 standard.
1
The IEEE 802.11w management-frame-processing rules contain unspecified cases, contradictions, and insecure rules that enable new denial-of-service vulnerabilities.
2
The authors collaborated with industry partners to propose updates to the IEEE 802.11 standard addressing the identified shortcomings.
3
The findings demonstrate that Wi-Fi Management Frame Protection is insufficient by itself to prevent deauthentication attacks.
4
The study identifies deauthentication-related vulnerabilities in clients and access points running current Linux, hostap, IWD, Apple, Windows, and Android implementations.
5
These vulnerabilities allow attackers to disconnect any client from personal and enterprise Wi-Fi networks despite Management Frame Protection being enabled.

Wi-Fi Management Frame Protection (MFP) in IEEE 802.11 and its implementations in Wi-Fi clients and access points

Robustness and security of MFP against deauthentication attacks, including specification flaws, implementation vulnerabilities, and resulting denial-of-service behavior

Publication Details
Publication Date
2022-05-07
Journal
Publisher
ISSN
Cited by
44
Access Type
Author Information
Authors
Domien Schepers
Aanjhan Ranganathan
Mathy Vanhoef
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%