Attack Techniques and Countermeasures against Kr00k using CSA
Shogo Nakajima, Taketo Inoue, Yoshiaki Shiraishi, Masakatu Morii · 2022
Encryption of communication is essential for secure data exchange in wireless LANs. Kr00k was proposed as a new attack method for wireless LANs in 2020. This attack method can decrypt packets using the specifications of the encryption keys employed for communication. However, assuming an actual real-time environment, the probability of a successful attack is infinitesimally low and has no practical impact because the situation in which the packets are accumulated in the transmission buffer is instantaneous. Therefore, we propose a new attack method that can decrypt packets in a real environment by combining a signal called the channel switch announcement. Because this attack is difficult to recognize, it is possible to intercept information continuously for a long period. We succeeded in disabling the encryption of a large number of packets and forcing them to communicate as ciphertext that can be restored to plaintext. In particular, this is a very dangerous attack because it can identify important information, such as IP addresses, leading to damage from hacking and DDoS attacks. This study aims to demonstrate countermeasures against this attack and encourage the public to take countermeasures against it.