WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations
WPAxFuzz: выявление уязвимостей в реализациях Wi-Fi
2022-10-20
SCID: 54.1/w5529f75
Discuss with AI
IEEE 802.11Simultaneous Authentication of EqualsWPA3Wi-Fi fuzzingwireless access point vulnerabilities
Figures from the paper
Abstract (AI)
This work attempts to provide a way of scrutinizing the security robustness of Wi-Fi implementations in an automated fashion. To this end, to our knowledge, we contribute the first full-featured and extensible Wi-Fi fuzzer. At the time of writing, the tool, made publicly available as open source, covers the IEEE 802.11 management and control frame types and provides a separate module for the pair of messages of the Simultaneous Authentication of Equals (SAE) authentication and key exchange method. It can be primarily used to detect vulnerabilities potentially existing in wireless Access Points (AP) under the newest Wi-Fi Protected Access 3 (WPA3) certification, but its functionalities can also be exploited against WPA2-compatible APs. Moreover, the fuzzer incorporates: (a) a dual-mode network monitoring module that monitors, in real time, the behavior of the connected AP stations and logs possible service or connection disruptions and (b) an attack tool used to verify any glitches found and automatically craft the corresponding exploit. We present results after testing the fuzzer against an assortment of off-the-shelf APs by different renowned vendors. Adhering to a coordinated disclosure process, we have reported the discovered issues to the affected vendors, already receiving positive feedback from some of them.
Key Findings
1
A dual-mode monitoring module tracks connected access-point stations in real time and logs potential service or connection disruptions.
2
An integrated attack tool validates detected glitches and automatically crafts corresponding exploits; testing across commercial access points uncovered issues reported through coordinated disclosure.
3
The open-source WPAxFuzz covers IEEE 802.11 management and control frames and separately fuzzes SAE authentication and key-exchange messages.
4
The tool primarily targets vulnerabilities in WPA3-certified access points, while also supporting testing of WPA2-compatible access points.
5
The work introduces, to the authors’ knowledge, the first full-featured and extensible fuzzer for automated security testing of Wi-Fi implementations.
Research Object
Wi-Fi implementations, particularly WPA3- and WPA2-compatible wireless Access Points (APs)
Research Subject
Security robustness and vulnerabilities, including service or connection disruptions, in Wi-Fi AP implementations
Publication Details
Publication Date
2022-10-20
Journal
Publisher
ISSN
Cited by
15
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest