New AirSnitch Attack Breaks Wi-Fi Encryption, Threatens Worldwide Network Security

New AirSnitch Attack Breaks Wi-Fi Encryption, Threatens Worldwide Network Security

New AirSnitch Attack Breaks Wi-Fi Encryption, Threatens Worldwide Network Security

Wi-Fi has become an integral part of our daily lives, with over 48 billion Wi-Fi-enabled devices shipped since its debut in the late 1990s. However, the history of Wi-Fi has been marred by security landmines, stemming from the inherited confidentiality weaknesses of its networking predecessor, Ethernet, and the ability for anyone nearby to receive the radio signals Wi-Fi relies on.

The Ghost in the Machine

In the early days, public Wi-Fi networks often resembled the Wild West, where ARP spoofing attacks that allowed renegade users to read other users’ traffic were common. The solution was to build cryptographic protections that prevented nearby parties—whether an authorized user on the network or someone near the AP (access point)—from reading or tampering with the traffic of any other user.

New Research Shows Encryption Vulnerabilities

New research has shown that behaviors that occur at the very lowest levels of the network stack make encryption—in any form, not just those that have been broken in the past—incapable of providing client isolation, an encryption-enabled protection promised by all router makers, that is intended to block direct communication between two or more connected clients.

AirSnitch: A Series of Attacks that Capitalize on Encryption Vulnerabilities

The researchers have given the name AirSnitch to a series of attacks that capitalize on the newly discovered weaknesses. Various forms of AirSnitch work across a broad range of routers, including those from Netgear, D-Link, Ubiquity, Cisco, and those running DD-WRT and OpenWrt.

The Threat of AirSnitch

AirSnitch “breaks worldwide Wi-Fi encryption, and it might have the potential to enable advanced cyberattacks,” Xin’an Zhou, the lead author of the research paper, said in an interview. “Advanced attacks can build on our primitives to [perform] cookie stealing, DNS and cache poisoning. Our research physically wiretaps the wire altogether so these sophisticated attacks will work. It’s really a threat to worldwide network security.”

The Lowest Levels of the Networking Stack

The lowest level, Layer-1, encompasses physical devices such as cabling, connected nodes, and all the things that allow them to communicate. The highest level, Layer-7, is where applications such as browsers, email clients, and other Internet software run. Levels 2 through 6 are known as the Data, Link, Network, Transport, Session, and Presentation layers, respectively.

Identity Crisis

Unlike previous Wi-Fi attacks, AirSnitch exploits core features in Layers 1 and 2 and the failure to bind and synchronize a client across these and higher layers, other nodes, and other network names such as SSIDs (Service Set Identifiers). This cross-layer identity desynchronization is the key driver of AirSnitch attacks.

The Most Powerful AirSnitch Attack

The most powerful such attack is a full, bidirectional machine-in-the-middle (MitM) attack, meaning the attacker can view and modify data before it makes its way to the intended recipient. The attacker can be on the same SSID, a separate one, or even a separate network segment tied to the same AP.

Consequences of AirSnitch Attacks

With the ability to intercept all link-layer traffic (that is, the traffic as it passes between Layers 1 and 2), an attacker can perform other attacks on higher layers. The most dire consequence occurs when an Internet connection isn’t encrypted—something that Google recently estimated occurred when as much as 6 percent and 20 percent of pages loaded on Windows and Linux, respectively.

Expert Reaction

HD Moore, a security expert and the founder and CEO of runZero, said: “This work is impressive because unlike other frame injection methods, the attacker controls a bidirectional flow. This research shows that a wireless-connected attacker can subvert client isolation and implement full relay attacks against other clients, similar to old-school ARP spoofing.”

Conclusion

AirSnitch is a serious threat to worldwide network security, and it has the potential to enable advanced cyberattacks. The researchers have shown that encryption vulnerabilities can be exploited to break client isolation, allowing attackers to view and modify data in the clear. It is essential for router makers and network administrators to take immediate action to address these vulnerabilities and protect their networks.

FAQs

Q: What is AirSnitch?

A: AirSnitch is a series of attacks that capitalize on encryption vulnerabilities in Wi-Fi networks.

Q: What are the consequences of AirSnitch attacks?

A: AirSnitch attacks can allow attackers to view and modify data in the clear, steal authentication cookies, passwords, payment card details, and any other sensitive data.

Q: How can I protect my network from AirSnitch attacks?

A: Router makers and network administrators should take immediate action to address the encryption vulnerabilities and protect their networks.