Cybersecurity researchers have discovered a fundamental security flaw in the design of the IEEE 802.11 WiFi protocol standard, allowing attackers to trick access points into leaking network frames in plaintext form.
WiFi frames are data containers consisting of a header, data payload, and trailer, which include information such as the source and destination MAC address, control, and management data.
These frames are ordered in queues and transmitted in a controlled matter to avoid collisions and to maximize data exchange performance by monitoring the busy/idle states of the receiving points.
The IEEE 802.11 standard includes power-save mechanisms that allow WiFi devices to conserve power by buffering or queuing frames destined for sleeping devices.
When a client station (receiving device) enters sleep mode, it sends a frame to the access point with a header that contains the power-saving bit, so all frames destined for it are queued.
The standard, however, does not provide explicit guidance on managing the security of these queued frames and does not set limitations like how long the frames can stay in this state.
Once the client station wakes up, the access point dequeues the buffered frames, applies encryption, and transmits them to the destination.
An attacker can spoof the MAC address of a device on the network and send power-saving frames to access points, forcing them to start queuing frames destined for the target. Then, the attacker transmits a wake-up frame to retrieve the frame stack.
However, the attacker can change the security context of the frames by sending authentication and association frames to the access point, thus forcing it to transmit the frames in plaintext form or encrypt them with an attacker-provided key.
Cisco acknowledges flaw
The first vendor to acknowledge the impact of the WiFi protocol flaw is Cisco, admitting that the attacks outlined in the paper may be successful against Cisco Wireless Access Point products and Cisco Meraki products with wireless capabilities.
However, Cisco believes says that the retrieved frames are unlikely to jeopardize the overall security of a properly secured network.
Visit Our Website : https://networking-events.sciencefather.com/awards/
Nomination Link : https://x-i.me/prinom
Registration Link : https://x-i.me/prireg2
Contact us : network@sciencefather.com
Instagram : https://x-i.me/net23m
Pinterest : https://x-i.me/net23p
Linked in : https://x-i.me/net23l
#network #protocols #networkingbestpractices #routing #scheduling #internet
#servers #networkspeed #topology #firewall #tcp #dhcp #cas #networking
#networkengineering #networksecurity #networkefficiency #networkreliability
#networkperformance #networkresilience #networkingstandards #networkavailability
No comments:
Post a Comment