New AirSnitch Attack Breaks Wi-Fi Encryption, Threatens Worldwide Network Security
Wi-Fi has become an integral part of our daily lives, with over 48 billion Wi-Fi-enabled devices shipped since its debut in the late 1990s. However, the history of Wi-Fi has been marred by security landmines, stemming from the inherited confidentiality weaknesses of its networking predecessor, Ethernet, and the ability for anyone nearby to receive the radio signals Wi-Fi relies on.
The Ghost in the Machine
In the early days, public Wi-Fi networks often resembled the Wild West, where ARP spoofing attacks that allowed renegade users to read other users’ traffic were common. The solution was to build cryptographic protections that prevented nearby parties—whether an authorized user on the network or someone near the AP (access point)—from reading or tampering with the traffic of any other user.
New Research Shows Encryption Vulnerabilities
New research has shown that behaviors that occur at the very lowest levels of the network stack make encryption—in any form, not just those that have been broken in the past—incapable of providing client isolation, an encryption-enabled protection promised by all router makers, that is intended to block direct communication between two or more connected clients.
AirSnitch: A Series of Attacks that Capitalize on Encryption Vulnerabilities
The researchers have given the name AirSnitch to a series of attacks that capitalize on the newly discovered weaknesses. Various forms of AirSnitch work across a broad range of routers, including those from Netgear, D-Link, Ubiquity, Cisco, and those running DD-WRT and OpenWrt.
The Threat of AirSnitch
AirSnitch “breaks worldwide Wi-Fi encryption, and it might have the potential to enable advanced cyberattacks,” Xin’an Zhou, the lead author of the research paper, said in an interview. “Advanced attacks can build on our primitives to [perform] cookie stealing, DNS and cache poisoning. Our research physically wiretaps the wire altogether so these sophisticated attacks will work. It’s really a threat to worldwide network security.”
The Lowest Levels of the Networking Stack
The lowest level, Layer-1, encompasses physical devices such as cabling, connected nodes, and all the things that allow them to communicate. The highest level, Layer-7, is where applications such as browsers, email clients, and other Internet software run. Levels 2 through 6 are known as the Data, Link, Network, Transport, Session, and Presentation layers, respectively.
Identity Crisis
Unlike previous Wi-Fi attacks, AirSnitch exploits core features in Layers 1 and 2 and the failure to bind and synchronize a client across these and higher layers, other nodes, and other network names such as SSIDs (Service Set Identifiers). This cross-layer identity desynchronization is the key driver of AirSnitch attacks.
The Most Powerful AirSnitch Attack
The most powerful such attack is a full, bidirectional machine-in-the-middle (MitM) attack, meaning the attacker can view and modify data before it makes its way to the intended recipient. The attacker can be on the same SSID, a separate one, or even a separate network segment tied to the same AP.
Consequences of AirSnitch Attacks
With the ability to intercept all link-layer traffic (that is, the traffic as it passes between Layers 1 and 2), an attacker can perform other attacks on higher layers. The most dire consequence occurs when an Internet connection isn’t encrypted—something that Google recently estimated occurred when as much as 6 percent and 20 percent of pages loaded on Windows and Linux, respectively.
Expert Reaction
HD Moore, a security expert and the founder and CEO of runZero, said: “This work is impressive because unlike other frame injection methods, the attacker controls a bidirectional flow. This research shows that a wireless-connected attacker can subvert client isolation and implement full relay attacks against other clients, similar to old-school ARP spoofing.”
Conclusion
AirSnitch is a serious threat to worldwide network security, and it has the potential to enable advanced cyberattacks. The researchers have shown that encryption vulnerabilities can be exploited to break client isolation, allowing attackers to view and modify data in the clear. It is essential for router makers and network administrators to take immediate action to address these vulnerabilities and protect their networks.
FAQs
Q: What is AirSnitch?
A: AirSnitch is a series of attacks that capitalize on encryption vulnerabilities in Wi-Fi networks.
Q: What are the consequences of AirSnitch attacks?
A: AirSnitch attacks can allow attackers to view and modify data in the clear, steal authentication cookies, passwords, payment card details, and any other sensitive data.
Q: How can I protect my network from AirSnitch attacks?
A: Router makers and network administrators should take immediate action to address the encryption vulnerabilities and protect their networks.







