Wi-Fi access denial of service attack to smartphones
Erich Dondyk, Louis Rivera, Cliff Changchun Zou · International Journal of Security and Networks · 2013
This paper presents a novel denial–of–service attack targeted at popular smartphones. This type of attack, which we call a Denial–of–Convenience (DoC) attack, prevents non–technical savvy victims from utilising data services by exploiting the Wi–Fi connectivity protocol of smartphones. By setting up a fake Wi–Fi access point without internet access, an attacker can prompt a smartphone to automatically terminate a valid mobile broadband connection. Thus, preventing the targeted smartphone from having internet access unless the victim is capable of identifying the attack and manually disable the Wi–Fi features. We demonstrate that most popular smartphones, including Android and iPhone phones, are vulnerable to DoC attacks. To address this attack we propose, implement, and evaluate a novel validation protocol that uses the cellular network to send a secret key phrase to an internet validation server. Then, attempts to retrieve it via the newly established Wi–Fi channel to validate the Wi–Fi access point.