not run Anti Virus (AV), no supervision • No automatic update mechanism, rarely patched • Wirelessly interconnected • Can result in DoS attack on Internet and RF spectrum • Ideal target
802.11 standard • First broken in 2001, [Fluhrer, SAC '01] • WPA (2003) as an more secure intermediate before WPA2 • WPA2 (2004), secure but not perfect • WPS (2006), facilitate establishment of secure connections • In 2011 Stefan Viehböck found flaws in WPS [VU#723755]
Back Bay: residential, young professional and families, high income 3) Fenway: home to many schools, mostly students, NEU 4) South Boston: Dense residential area, large working class population
are in R-proximity • Coordinates of the strongest signal as the location of AP • Attack can be performed any time during the day • Higher reach of the wireless signal at quiet and idle times
epidemic • Divides population to compartments – Susceptible, Infected, Recovered (SIR) • Captures characteristics of our model • Other alternatives, e.g. SEIR
p 1Stime = 3 3, 6 6, 9 9 hours, p 1Ftime = 10 10 min • Many use default configurations, out of the box ➔ q 1 = 50 50%, u 1 =50 50% • t 1 =100 100%, t 1Stime = 20 20 min • r 1 = 80 80% and s 1 = 10 10% • r 1Stime = r 1Ftime = 60 60 min • s 1Stime = s 1Ftime = 120 120 min
q 1 * r 1 + p 1 * (1-q 1 ) * s 1 ) • %WEP WEP * (t 1 * u 1 * r 1 + t 1 * (1-u 1 ) * s 1 ) ➢ Theoretical average upper bound in a single connected component is 32 32% • R = 50m; 19% to 23%, in 97.1 to 137.5 days • R = 75m; 33% to 35%, in 109.1 to 194.5 days • R = 90m; 34% to 35%, in 62.5 to 189.9 day
vendors • WPS enabled by default without users knowledge • APs not wireless ready , high chance of misconfiguration • Investigate over 540,000 publicly available devices, over 13% use default root passwords [Cui, ACSAC '10 ] • Intrusion Detection System that use flow characteristics of WiFi network, e.g. Kismet • Use of reliable bootstrap architect5ures and malicious code detectors [Arbaugh, ACSAC '02; Adelstein SP '97]
[Cassola, Mobisys '11] • New trend (SDN) and view of the APs [Kim, Comm. Mag. '13] • Easier management and configuration mechanism • Incentive for vendors to maintain APs • Roku, Meraki are good examples of such view
neighbourhoods • WEP is still used, although it's known to be flawed • WPA/WPA2 are “secure” alternatives, not perfect • New enhancement (WPS) made it worst