Guarding the Wi-Fi 4-Way Handshake against Channel-based MiTM: A Case Study on KRACK Attack
Anand Agrawal, Rajib Ranjan Maiti · 2024
In the rapidly evolving digital age, the security of wireless networks is paramount. In this paper, we present a comprehensive analysis and defense mechanism against Key Reinstallation Attacks (KRACKs) targeting the Wi-Fi Protected Access II (WPA2) protocol suite. WPA2 is vulnerable to KRACK, where an attacker replays a specific set of packets in the 4-way handshake used in WPA2 to install a Pairwise Transient Key (PTK) in both the client and Access Point (AP). We have proposed a scheme to add a channel feature in the packets that are exchanged in the 4-way handshake to guard against channel-based Man-in-The-Middle (MiTM), which is an essential pre-condition for KRACK. In particular, we propose to integrate message 1 (\emphmsg-1 ) and message 3 (\emphmsg-3 ) of handshake with the channel number that has been advertised in the beacon frames. In addition to the predefined parameters in the msg-1 and msg-3, the AP sends an authenticated channel number to the client. On receiving, the client first validates the authenticated channel number and then processes the other parameters in these two messages. This paper details the implementation and evaluation of our solution, demonstrating its effectiveness in thwarting KRACK without compromising network performance or user convenience.