All the latest UK technology news, reviews and analysis

Experts crack 802.11 protocol

by James Middleton

08 Aug 2001

Be the first to comment

  • Tweet this

Scientists at Houston-based Rice University have published a paper on wireless security, concluding that the 802.11 Wireless Encryption Protocol (WEP), which most wireless users currently rely on for security, is "totally insecure".

Adam Stubblefield, John Ioannidis and Aviel Rubin, along with AT&T Labs, this week published a paper on how they used the Fluhrer, Mantin and Shamir attack to break 802.11's WEP at its highest level of 128-bit.

Using only off-the-shelf hardware and software, the researchers claim that the attack was completely passive and undetectable. They used the methodology applied by fellow scientists Fluhrer, Mantin and Shamir, detailed in a paper last month. vnunet.com also explained a similar idea last month.

"With our implementation we were able to recover the 128-bit secret key used in a production network with a passive attack," said the group. The basis of the attack is that the RC4 keystream cipher is implemented improperly, and the attack exploits this design failure. Wireless cards using the 802.11 protocol reset their keystreams every time they are initialised, and then increment them by one for every use.

"This results in a high likelihood that keystreams will be reused, leading to simple cryptanalytic attacks against the cipher, and decryption of message traffic," explained the group. It means that the encryption keys can be predicted.

The team was able to successfully implement the attack in several hours, claiming to have "demonstrated the ultimate break of WEP, which is the recovery of the secret key by observation of traffic".

"Given this attack, we believe that 802.11 networks should be viewed as insecure," the group continued. "We recommend the following for people using such wireless networks: assume that the link layer offers no security; use higher-level security mechanisms such as IPsec and SSH for security instead of relying on WEP; treat all systems that are connected via 802.11 as external.

"Place all access points outside the firewall; assume that anyone within physical range can communicate on the network as a valid user; keep in mind that an adversary may utilise a sophisticated antenna with much longer range than found on a typical 802.11 PC card."

The researchers concluded that it is difficult to get security right. Flaws at every level, including protocol design, implementation and deployment, can render a system completely vulnerable. Once a flawed system is popular enough to become a target, it is usually only a short time before the system is defeated in the field.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

10%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

IT Support Analyst - Active Directory, Windows 7, MS Office

IT Support Analyst - Active Directory, Windows 7, MS...

Helpdesk / Desktop Support Analyst (Windows 7, MAC, Windows Server 2008, LAN)

Helpdesk / Desktop Support Analyst (Windows 7, MAC, Windows...

Infrastructure / Server Support Analyst - 3rd Line, Windows 2008, Exchange 2010, VMware

Infrastructure / Server Support Analyst - 3rd Line, Windows...

Credit Risk Modeller, SAS, London, £50,000

Credit Risk Modeller, SAS, London, £50,000 Title- Credit...

To send to more than one email address, simply separate each address with a comma.