Security Concepts
Wireless networks introduce unique security challenges due to their reliance on untrusted physical mediums. This section explores core security principles—confidentiality, integrity, and availability—and how they are compromised in wireless environments. Understanding these concepts is critical for both offensive analysis and defensive mitigation.
Confidentiality in Wireless Networks¶
Confidentiality ensures data remains private and accessible only to authorized parties. Wireless networks achieve this through encryption protocols, but vulnerabilities in implementation or configuration can expose sensitive information.
Key Concepts¶
- WEP (Wired Equivalent Privacy): Early encryption with weak RC4 algorithms and static keys, susceptible to IV (Initialization Vector) collisions and dictionary attacks.
- WPA/WPA2 (Wi-Fi Protected Access): Use AES-CCMP encryption with dynamic keys via the four-way handshake. Vulnerable to KRACK (Key Reinstallation Attacks) in WPA2.
- WPA3: Introduces Simultaneous Authentication of Equals (SAE) for stronger pre-shared key (PSK) protection, though vulnerabilities in SAE (e.g., dictionary attacks) persist.
Example: Capturing IVs to Break WEP¶
This command captures packets from a WEP network, enabling IV extraction. Tools likeaircrack-ng can then exploit these IVs to decrypt traffic.
Integrity in Wireless Networks¶
Integrity ensures data remains unaltered during transmission. Wireless protocols use Message Integrity Codes (MICs) to detect tampering, but weaknesses in these mechanisms can allow data modification.
Key Concepts¶
- TKIP (Temporal Key Integrity Protocol): Used in WPA, it includes MICs to prevent packet forgery. However, vulnerabilities like IV collisions can bypass these checks.
- CCMP (Counter Mode Cipher Block Chaining): WPA2’s default encryption mode, which provides stronger integrity guarantees than TKIP.
- EAPOL (Extensible Authentication Protocol over LAN): Ensures secure key exchange during authentication, but misconfigured EAPOL can allow man-in-the-middle (MITM) attacks.
Example: Testing WPA2 Integrity¶
This command tests the integrity of a WPA2 network by attempting to forge packets. Successful forgery indicates vulnerabilities in the MIC implementation.Availability in Wireless Networks¶
Availability ensures the network remains accessible and resistant to denial-of-service (DoS) attacks. Wireless networks are particularly vulnerable due to their broadcast nature and limited bandwidth.
Key Concepts¶
- Deauthentication Attacks: Tools like
aireplay-ngcan flood the network with deauthentication packets, disconnecting clients from the access point (AP). - Rogue APs: Unauthorized access points can consume bandwidth and redirect traffic, causing availability issues.
- Jamming: Physical interference with wireless signals can disrupt communication, though this is less common in modern environments.
Example: Launching a Deauthentication Attack¶
This command sends deauthentication packets to all clients connected to the target AP, effectively disconnecting them.Common Vulnerabilities in Wireless Networks¶
- Weak Encryption: Legacy protocols like WEP and misconfigured WPA2/WPA3 expose data to interception.
- Insecure Authentication: Poorly configured EAP methods (e.g., WPA-PSK with weak passwords) enable brute-force attacks.
- Physical Layer Exploits: Eavesdropping on unencrypted traffic (e.g., via Wireshark) or MITM attacks on unsecured networks.
- Denial-of-Service (DoS): Rogue devices or malicious traffic can overwhelm network resources.
Key takeaways¶
- Encryption is critical: Use WPA3 with strong PSKs or EAP methods to protect confidentiality.
- Integrity checks must be robust: Avoid TKIP in favor of CCMP and monitor for MIC bypasses.
- Mitigate DoS risks: Deploy tools to detect and block rogue APs or deauthentication attacks.
- Regularly update protocols: Stay informed about vulnerabilities like KRACK and patch accordingly.
- Physical security matters: Secure wireless infrastructure against eavesdropping and jamming.