USENIX Security2021Top-tier venue
Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation
Mathy Vanhoef
Abstract
In this paper, we present three design flaws in the 802.11 standard that underpins Wi-Fi. One design flaw is in the frame aggregation functionality, and another two are in the frame fragmentation functionality. These design flaws enable an adversary to forge encrypted frames in various ways, which in turn enables exfiltration of sensitive data. We also discovered common implementation flaws related to aggregation and fragmentation, which further worsen the impact of our attacks. Our results affect all protected Wi-Fi networks, ranging from WEP all the way to WPA3, meaning the discovered flaws have been part of Wi-Fi since its release in 1997. In our experiments, all devices were vulnerable to one or more of our attacks, confirming that all Wi-Fi devices are likely affected. Finally, we present a tool to test whether devices are affected by any of the vulnerabilities, and we discuss countermeasures to prevent our attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 283a78ab-1bc6-4d6c-88c7-0071e724915cCited by top-tier papers10
- To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO DevicesSönke Huster, Matthias Hollick, Jiska ClassenS&P 2024 · 8 citations
- AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi NetworksXin'an Zhou, Juefei Pu, Zhutian Liu, Zhiyun Qian et al.NDSS 2026 · 1 citation
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- WCDCAnalyzer: Scalable Security Analysis of Wi-Fi Certified Device Connectivity ProtocolsZilin Shen, Imtiaz Karim, Elisa BertinoNDSS 2026
- Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit QueuesDomien Schepers, Aanjhan Ranganathan, Mathy VanhoefUSENIX Security 2023
Builds on9
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes et al.CCS 2018 · 186 citations
- On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNKarthikeyan Bhargavan, Gaëtan LeurentCCS 2016 · 180 citations
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 146 citations
- Release the Kraken: New KRACKs in the 802.11 StandardMathy Vanhoef, Frank PiessensCCS 2018 · 69 citations
Related papers
- Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel AttackZiqiang Wang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2025
- How to BREAK MU-MIMO Precoding in IEEE 802.11 Wi-Fi NetworksFrancesca Meneghello, Francesco Gringoli, Marco Cominelli, Michele Rossi et al.INFOCOM 2025 · 4 citations
- Predicting, Decrypting, and Abusing WPA2/802.11 Group KeysMathy Vanhoef, Frank PiessensUSENIX Security 2016 · 47 citations
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsXuewei Feng, Qi Li, Kun Sun, Yuxiang Yang et al.S&P 2023
- Non-cooperative wi-fi localization & its privacy implicationsAli Abedi, Deepak VasishtMobiCom 2022 · 30 citations
