No cover

Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues (Talk, 2023, Real World Crypto 2023)

Talk

Published March 29, 2023 by Real World Crypto 2023.

View on Thinkst Citation

No rating (0 reviews)

Wi-Fi devices routinely queue frames at various layers of the network stack before transmitting, for instance, when the receiver is in sleep mode. In this work, we investigate how Wi-Fi access points manage the security context of queued frames. By exploiting power-save features, we show how to trick access points into leaking frames in plaintext, or encrypted using the group or an all-zero key. We demonstrate resulting attacks against several open-source network stacks. We attribute our findings to the lack of explicit guidance in managing security contexts of buffered frames in the 802.11 standards. The unprotected nature of the power-save bit in a frame’s header, which our work reveals to be a fundamental design flaw, also allows an adversary to force queue frames intended for a specific client resulting in its disconnection and trivially executing a denial-of-service attack. Furthermore, we demonstrate how an attacker can override and control the security …

1 edition

Subjects

  • WiFi
  • Security
  • Computer Science