Experts crack 802.11 protocol

University team expose 802.11 as 'totally insecure'.

Written by James Middleton

Scientists at Houston-based Rice University have published a paper on wireless security, concluding that the 802.11 Wireless Encryption Protocol (WEP), which most wireless users currently rely on for security, is "totally insecure".

Adam Stubblefield, John Ioannidis and Aviel Rubin, along with AT&T Labs, this week published a paper on how they used the Fluhrer, Mantin and Shamir attack to break 802.11's WEP at its highest level of 128-bit.

Using only off-the-shelf hardware and software, the researchers claim that the attack was completely passive and undetectable. They used the methodology applied by fellow scientists Fluhrer, Mantin and Shamir, detailed in a paper last month. vnunet.com also explained a similar idea last month.

"With our implementation we were able to recover the 128-bit secret key used in a production network with a passive attack," said the group. The basis of the attack is that the RC4 keystream cipher is implemented improperly, and the attack exploits this design failure. Wireless cards using the 802.11 protocol reset their keystreams every time they are initialised, and then increment them by one for every use.

"This results in a high likelihood that keystreams will be reused, leading to simple cryptanalytic attacks against the cipher, and decryption of message traffic," explained the group. It means that the encryption keys can be predicted.

The team was able to successfully implement the attack in several hours, claiming to have "demonstrated the ultimate break of WEP, which is the recovery of the secret key by observation of traffic".

"Given this attack, we believe that 802.11 networks should be viewed as insecure," the group continued. "We recommend the following for people using such wireless networks: assume that the link layer offers no security; use higher-level security mechanisms such as IPsec and SSH for security instead of relying on WEP; treat all systems that are connected via 802.11 as external.

"Place all access points outside the firewall; assume that anyone within physical range can communicate on the network as a valid user; keep in mind that an adversary may utilise a sophisticated antenna with much longer range than found on a typical 802.11 PC card."

The researchers concluded that it is difficult to get security right. Flaws at every level, including protocol design, implementation and deployment, can render a system completely vulnerable. Once a flawed system is popular enough to become a target, it is usually only a short time before the system is defeated in the field.

Tags:

Further reading

Hacked Wi-Fi security standard faces axe

Wi-Fi Protected Access to replace Wireless Equivalent Privacy security protocol   More...

Europe drags feet on 802.11b

Firms prefer to wait for faster version a, say analysts   More...

Intel demonstrates 802.11a wireless Lan

Future of rival HiperLAN2 now in doubt   More...

College learns the benefits of WLan frequency hopping

Companies will circumvent the insecurity nature of Wired Equivalent Privacy (WEP) protocol by running frequency hopping wireless Lans, according to Black Box.   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement