Characterizing Wi-Fi Man-In-the-Middle Attacks
Andy Amoordon, Christophe Gransart, Virginie Deniau · 2020
Wi-Fi networks are widely deployed and used privately or professionally. However, many tools exist to implement Man-in-The-Middle attacks, on these networks, to intercept data. If certain Wi-Fi networks are protected, we all by negligence or compellingly use unprotected or poorly protected Wi-Fi networks, making it possible for attackers to collect sensitive information that can further be used for more virulent attacks. In this context, our research work aims to develop detection techniques, for Man-in-The-Middle attacks against Wi-Fi networks, by analyzing the Electromagnetic activity, i.e. the physical layer of the OSI model. We want to identify combinations or sequences of signals which can be indicative of the presence of such attacks. In this paper, we recall the Wi-Fi standards and their existing levels of protection. We describe in detail the steps involved in the implementation of Man-in-The-Middle attacks on public, private and enterprise Wi-Fi networks. Finally, from this detailed description, we identify the characteristics of the signals, sent by fake access points, which could allow us to devise a detection strategy.