Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef
摘要
Wi-Fi devices routinely queue frames at various layers of the network stack before transmitting, for instance, when the receiver is in sleep mode. In this work, we investigate how Wi-Fi access points manage the security context of queued frames. By exploiting power-save features, we show how to trick access points into leaking frames in plaintext, or encrypted using the group or an all-zero key. We demonstrate resulting attacks against several open-source network stacks. We attribute our findings to the lack of explicit guidance in managing security contexts of buffered frames in the 802.11 standards. The unprotected nature of the power-save bit in a frame's header, which our work reveals to be a fundamental design flaw, also allows an adversary to force queue frames intended for a specific client resulting in its disconnection and trivially executing a denial-of-service attack. Furthermore, we demonstrate how an attacker can override and control the security context of frames that are yet to be queued. This exploits a design flaw in hotspot-like networks and allows the attacker to force an access point to encrypt yet to be queued frames using an adversary-chosen key, thereby bypassing Wi-Fi encryption entirely. Our attacks have a widespread impact as they affect various devices and operating systems (Linux, FreeBSD, iOS, and Android) and because they can be used to hijack TCP connections or intercept client and web traffic. Overall, we highlight the need for transparency in handling security context across the network stack layers and the challenges in doing so.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-FiS. Mahmudul Hasan, Che Wei Tu, Md. Endadul Hoque, Omar Chowdhury 等CHI 2025 · 被引用 2 次
- AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi NetworksXin'an Zhou, Juefei Pu, Zhutian Liu, Zhiyun Qian 等NDSS 2026 · 被引用 1 次
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- WCDCAnalyzer: Scalable Security Analysis of Wi-Fi Certified Device Connectivity ProtocolsZilin Shen, Imtiaz Karim, Elisa BertinoNDSS 2026
- Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel AttackZiqiang Wang, Xuewei Feng, Qi Li, Kun Sun 等NDSS 2025
它引用的顶会 Paper9
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 被引用 437 次
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem 等NDSS 2018 · 被引用 399 次
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 被引用 146 次
- Release the Kraken: New KRACKs in the 802.11 StandardMathy Vanhoef, Frank PiessensCCS 2018 · 被引用 69 次
相关 Paper
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 被引用 48 次
- Predicting, Decrypting, and Abusing WPA2/802.11 Group KeysMathy Vanhoef, Frank PiessensUSENIX Security 2016 · 被引用 47 次
- Off-Path TCP Exploit: How Wireless Routers Can Jeopardize Your SecretsWeiteng Chen, Zhiyun QianUSENIX Security 2018 · 被引用 35 次
- How to BREAK MU-MIMO Precoding in IEEE 802.11 Wi-Fi NetworksFrancesca Meneghello, Francesco Gringoli, Marco Cominelli, Michele Rossi 等INFOCOM 2025 · 被引用 4 次
- A Formal Analysis of IEEE 802.11's WPA2: Countering the Kracks Caused by Cracking the CountersCas Cremers, Benjamin Kiesl, Niklas MedingerUSENIX Security 2020
