UNMASKING WI-FI MISUSE: FORENSIC STRATEGIES FOR IEEE 802.11 NETWORKS

Выявление неправомерного использования Wi‑Fi: криминалистические стратегии для сетей IEEE 802.11
Ujjwal Sharma, Samruddhi Mangesh Kalekar
2026-01-16

IEEE 802.11 networksMAC address randomizationProtected Management FramesWi-Fi forensicswireless evidence acquisition
IEEE 802.11 is the dominant technology for wireless local area networking across consumer, enterprise, and embedded domains.Contemporary deployments incorporate WPA3, Protected Management Frames (PMF), and increasingly strict privacy controls such as MAC address randomization-factors that complicate attribution and evidence collection compared to legacy WLANs.This paper foregrounds these modern constraints and presents a practitioner-oriented methodology for acquiring, preserving, and analyzing wireless evidence that remains forensically sound and legally defensible.We synthesize live and post-event techniques, discuss capture strategies and tooling, enumerate device-specific artifacts, and provide a comparative analysis of legacy vs. modern WLAN forensics.Our framing builds on prior work that systematized Wi-Fi misuse categories and evidence sources, extending it for today's encrypted and privacy-preserving environments [4]-[6].
1
A comparative analysis distinguishes forensic challenges and evidence sources in legacy versus modern WLAN environments.
2
Modern IEEE 802.11 deployments using WPA3, Protected Management Frames, and MAC address randomization complicate attribution and wireless evidence collection compared with legacy WLANs.
3
The methodology integrates live and post-event forensic techniques, capture strategies, tooling, and device-specific artifact analysis.
4
The paper presents a practitioner-oriented methodology for acquiring, preserving, and analyzing wireless evidence in a forensically sound and legally defensible manner.
5
The work extends prior classifications of Wi-Fi misuse and evidence sources to encrypted and privacy-preserving wireless networks.

Modern IEEE 802.11 wireless local area networks, including WPA3-, PMF-, and MAC-randomization-enabled deployments

Forensically sound and legally defensible acquisition, preservation, attribution, and analysis of wireless evidence under encryption and privacy constraints

Publication Details
Publication Date
2026-01-16
Journal
Publisher
ISSN
Cited by
2
Access Type
Author Information
Authors
Ujjwal Sharma
Samruddhi Mangesh Kalekar
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%