WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations

WPAxFuzz: выявление уязвимостей в реализациях Wi-Fi
Vyron Kampourakis, Efstratios Chatzoglou, Georgios Kambourakis, Apostolos Dolmes, Christos Zaroliagis
2022-10-20

IEEE 802.11Simultaneous Authentication of EqualsWPA3Wi-Fi fuzzingwireless access point vulnerabilities
This work attempts to provide a way of scrutinizing the security robustness of Wi-Fi implementations in an automated fashion. To this end, to our knowledge, we contribute the first full-featured and extensible Wi-Fi fuzzer. At the time of writing, the tool, made publicly available as open source, covers the IEEE 802.11 management and control frame types and provides a separate module for the pair of messages of the Simultaneous Authentication of Equals (SAE) authentication and key exchange method. It can be primarily used to detect vulnerabilities potentially existing in wireless Access Points (AP) under the newest Wi-Fi Protected Access 3 (WPA3) certification, but its functionalities can also be exploited against WPA2-compatible APs. Moreover, the fuzzer incorporates: (a) a dual-mode network monitoring module that monitors, in real time, the behavior of the connected AP stations and logs possible service or connection disruptions and (b) an attack tool used to verify any glitches found and automatically craft the corresponding exploit. We present results after testing the fuzzer against an assortment of off-the-shelf APs by different renowned vendors. Adhering to a coordinated disclosure process, we have reported the discovered issues to the affected vendors, already receiving positive feedback from some of them.
1
A dual-mode monitoring module tracks connected access-point stations in real time and logs potential service or connection disruptions.
2
An integrated attack tool validates detected glitches and automatically crafts corresponding exploits; testing across commercial access points uncovered issues reported through coordinated disclosure.
3
The open-source WPAxFuzz covers IEEE 802.11 management and control frames and separately fuzzes SAE authentication and key-exchange messages.
4
The tool primarily targets vulnerabilities in WPA3-certified access points, while also supporting testing of WPA2-compatible access points.
5
The work introduces, to the authors’ knowledge, the first full-featured and extensible fuzzer for automated security testing of Wi-Fi implementations.

Wi-Fi implementations, particularly WPA3- and WPA2-compatible wireless Access Points (APs)

Security robustness and vulnerabilities, including service or connection disruptions, in Wi-Fi AP implementations

Publication Details
Publication Date
2022-10-20
Journal
Publisher
ISSN
Cited by
15
Access Type
Author Information
Authors
Vyron Kampourakis
Efstratios Chatzoglou
Georgios Kambourakis
Apostolos Dolmes
Christos Zaroliagis
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%