A Systematic Threat Analysis and Practical Attacks on Automated Frequency Coordination Systems
Yilu Dong, Tianchang Yang, Arupjyoti Bhuyan, Syed Rafiul Hussain
Abstract
The 6 GHz band, traditionally reserved for mission-critical incumbent systems such as public safety communications, utility infrastructure, and fixed satellite services, has recently been opened for Wi-Fi devices. This expansion introduces a critical coexistence challenge of ensuring that unlicensed Wi-Fi Access Points (APs) do not interfere with incumbent operations. To manage this risk, regulators mandated the use of Automated Frequency Coordination (AFC) systems that assign spectrum access to Wi-Fi APs based on their locations. In this work, we present the first systematic security analysis of AFC systems. In particular, we analyze the trust assumptions of AFC systems and uncover design lapses and deployment mishaps in this model. Our analysis reveals that the AFC's dependence on unauthenticated data sources, including GNSS/GPS and Wi-Fi-based localization (for location), DNS (for service discovery), and NTP (for time synchronization), creates practical off-path attack vectors that allow adversaries to manipulate control-plane parameters without breaking cryptographic protections between APs and AFC servers. For example, using inexpensive, off-the-shelf software-defined radios, an off-path adversary can spoof the GPS signals received by an AP, falsifying its reported location to either disable 6 GHz transmissions or cause harmful interference with incumbent services. We validate these vectors empirically on commercial APs from four major vendors and evaluate four commercial and one open-source AFC servers to measure real-world impact. We also propose potential mitigations and analyze the trade-offs between usability and security to formulate our recommendations to harden AFC deployments and 6 GHz APs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c3a53ea5-211f-41f5-851b-93d5d51e140eBuilds on10
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 100 citations
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai et al.USENIX Security 2024 · 33 citations
- Stars Can Tell: A Robust Method to Defend against GPS Spoofing Attacks using Off-the-shelf ChipsetShinan Liu, Xiang Cheng, Hanchao Yang, Yuanchao Shu et al.USENIX Security 2021 · 29 citations
Related papers
- Efficient Wideband Spectrum Sensing Using MEMS Acoustic ResonatorsJunfeng Guan, Jitian Zhang, Ruochen Lu, Hyungjoo Seo et al.NSDI 2021 · 14 citations
- Safeguarding WiFi 7 and Beyond: Tackling Protocol-Aware Jamming in Multi-AP CoordinationMunmun Talukder, Jiang (Linda) XieINFOCOM 2025 · 1 citation
- Coexistence of Wi-Fi 6E and 5G NR-U: Can We Do Better in the 6 GHz Bands?Gaurang Naik, Jung-Min Jerry ParkINFOCOM 2021 · 44 citations
- Surveilling the Masses with Wi-Fi-Based Positioning SystemsErik C. Rye, Dave LevinS&P 2024 · 5 citations
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders et al.S&P 2018 · 135 citations
