The Role Of Client Isolation In Protectingwi-Fi Users From Arp Spoofing Attacks
Timur Mirzoev · i-manager s Journal on Information Technology · 2012
WPA is very commonly supported by most AP hardware. In the WPA scenario, a wireless client is provided with a temporary encryption key or 'session key' with which it can communicate securely with the AP and encrypt/decrypt traffic (Cayirci, Rong, 2009) . Once a time limit is reached or the session has ended the key is expired or exchanged for a new one, making any further use of the key invalid (Cayirci, Rong, 2009) . This type of protection prevents an attacker from viewing traffic or capturing a client's key and then using it to impersonate the client. There are other types of security of this nature, but they all have one thing in common: it is necessary for the client to authenticate to the AP in some way with pre-shared authentication information. This study determines if one manufacturer's version of client isolation, Cisco System's Public Secure Packet Forwarding (Cisco, 2010), prevents wireless devices from launching impersonation attacks. The focus of this study is on the wellknown man-in-the-middle IP ARP spoofing attack (Cross, 2008). It is generated using a publically available set of hacking tools known as Cain & Abel (Oxid, 2011). Since Cisco's Aironet access points are widely used throughout ABSTRACT This study investigates the role of the client isolation technology Public Secure Packet Forwarding (PSPF) in defending 802.11 wireless (Wi-Fi) clients, connected to a public wireless access point, from Address Resolution Protocol (ARP) cache poisoning attacks, or ARP spoofing. Exploitation of wireless attack vectors such as these have been on the rise and some have made national and international news. Although client isolation technologies are common place in most wireless access points, they are rarely enabled by default. Since an average user generally has a limited understanding of IP networking concepts, it is rarely enabled during access point configurations. Isolating wireless clients from one another on unencrypted wireless networks is a simple and potentially effective way of protection. The purpose of this research is to determine if a commonly available and easily implementable wireless client isolation security technology, such as PSPF, is an effective method for defending wireless clients against attacks.