CSC416 Network Security

Network SecurityUnit 77 min read

Wireless Security: IEEE 802.11i, Threats, Handshakes & WPA3

Unit 7 of Network Security explores IEEE 802.11i’s security framework (WPA2/WPA3), wireless threats (eavesdropping, rogue APs, DoS), and its four-way handshake. It compares encryption modes (CCMP, TKIP), analyzes real-world attacks (Karmasploit, Evil Twin), and traces mutual authentication in Pathao’s driver-app traffi

Why Wireless Security Matters

Wireless networks (Wi-Fi, Bluetooth, NFC) are everywhere—from Pathao’s driver-to-app communication to Ncell’s 4G towers—but they face unique threats:

  • Eavesdropping: Capturing unencrypted data (e.g., Khalti transactions over public Wi-Fi).
  • Rogue APs: Fake hotspots (e.g., "Free_Nepal_WiFi" in Kathmandu) to steal credentials.
  • DoS Attacks: Jamming signals (e.g., NTC’s 4G outages during protests).

IEEE 802.11i (WPA2/WPA3) was designed to fix these flaws in WEP (weak encryption) and WPA (vulnerable handshakes).


1. Wireless Threats: Real Attacks in Nepal

mindmap
  root((Wireless Threats))
    Passive Attacks
      Eavesdropping["Data sniffing (Wireshark, Airodump-ng)"]
      Traffic Analysis["Timing/pattern analysis (e.g., Daraz order queues)"]
    Active Attacks
      Rogue AP["Fake hotspot (e.g., 'Nepal_Gov_WiFi')"]
      Man-in-the-Middle["ARP spoofing (MITM) on Khalti payments"]
      DoS["Deauthentication floods (disconnects Ncell users)"]
    Cryptographic Attacks
      WEP Cracking["RC4 weak keys (e.g., old café Wi-Fi)"]
      WPA2-PSK Brute Force["Offline dictionary attacks on WPA2" ]

Example: In 2022, a Karmasploit attack tricked users into connecting to a rogue AP at Thamel’s Starbucks, capturing login credentials for eSewa and Khalti.


wifi router with antenna**A typical home router (like those in Pokhara cafés) vulnerable to rogue AP attacks. (Image: Khruner, CC BY-SA 4.0, via Wikimedia Commons)


2. IEEE 802.11i: Fixing WEP/WPA Flaws

Key Improvements Over WEP/WPA

Feature WEP (Broken) WPA (Weak) 802.11i (WPA2/WPA3)
Encryption RC4 (crackable) TKIP (still weak) CCMP (AES-128)
Key Management Static WEP keys Pre-shared keys (PSK) Dynamic keys (PTK/GTK)
Authentication Open or shared key PSK or 802.1X Four-way handshake + SAE (WPA3)
Forward Secrecy ❌ No ❌ No ✅ Yes (WPA3)

Why AES-CCMP?

  • AES-128 encrypts data in 128-bit blocks (unlike WEP’s 64-bit RC4).
  • Counter Mode (CTR) ensures each packet gets a unique key.

How WPA3’s SAE (Simultaneous Authentication) Works

sequenceDiagram
    participant Client as Mobile Device (e.g., Pathao Driver App)
    participant AP as Access Point (e.g., Ncell Hotspot)
    Client->>AP: Connect (EAP-SAE start)
    AP->>Client: Diffie-Hellman (DH) public key
    Client->>AP: DH public key + Commitment
    AP->>Client: Verifier (proof of key)
    Client->>AP: Final key (PTK derived)
    Note over Client,AP: No password sent in plaintext!

Real Example: When a Pathao driver connects to Ncell’s Wi-Fi, SAE ensures their app credentials aren’t stolen via MITM.


3. Four-Way Handshake: Step-by-Step

stateDiagram-v2
    [*] --> Auth: Start
    state Auth {
        [*] --> Pairwise: EAPOL-Start (Client)
        Pairwise --> Auth1: EAPOL (AP sends ANonce)
        Auth1 --> Auth2: EAPOL (Client sends SNonce + MIC)
        Auth2 --> Auth3: EAPOL (AP sends GTK + MIC)
        Auth3 --> [*]: PTK/GTK installed
    }

Worked Example: Khalti’s Wi-Fi Payment

  1. Your phone (Client) sends EAPOL-Start to the café’s AP.
  2. AP replies with ANonce (random number).
  3. Your phone sends SNonce (its random number) + MIC (message integrity code).
  4. AP verifies MIC, sends GTK (group key for all devices) + its MIC.
  5. Both sides derive PTK (pairwise key) for secure data transfer.

Failure Case: If the MIC fails (e.g., MITM attack), the handshake aborts.



4. WPA2 vs. WPA3: What’s New?

Feature WPA2 (802.11i) WPA3 (802.11-2020)
Authentication PSK or 802.1X SAE (Dragonfly Key Exchange)
Resistance to Offline Attacks ❌ Weak (brute-force PSK) ✅ Strong (no password reuse)
Enterprise Security 802.1X + EAP Simultaneous Authentication (SAE)
Forward Secrecy ❌ No ✅ Yes (even if PTK is compromised)
Use Case Most modern devices (e.g., Ncell Wi-Fi) Newer devices (e.g., Google Wi-Fi Nest)

Real Example: Google Wi-Fi uses WPA3-SAE to prevent Krack attacks (which exploit WPA2’s handshake flaws).


5. Wireless Security in Nepal: Case Studies

A. Ncell’s 4G Security

  • Uses WPA2-Enterprise with 802.1X for towers.
  • Problem: Rogue APs in Lalitpur mimic Ncell SSIDs to steal data.
  • Fix: DNSSEC (Unit 8) + MAC filtering (though MAC spoofing bypasses this).

B. Pathao’s Driver-App Traffic

  • Threat: MITM attacks on driver-to-app Wi-Fi (e.g., fake "Pathao_Hotspot").
  • Solution:
    1. WPA3-SAE for driver login.
    2. TLS 1.3 (Unit 4) for payment data.
    3. Device PIN (Unit 3: IDS detects unusual logins).

C. Kathmandu Traffic Cameras (IoT)

  • Threat: Hackers jam NTC’s traffic camera Wi-Fi to alter signals.
  • Solution: WPA3 + AES-256 + physical tamper detection.


6. Common Attacks & Defenses

Attack How It Works Defense (IEEE 802.11i)
Evil Twin Fake AP mimics "Nepal_Gov_WiFi" MAC filtering + WPA3-SAE
Krack Attack Exploits WPA2 handshake flaws Disable WPA2; use WPA3
Replay Attack Repeats old packets (e.g., Khalti TX) Sequence numbers in CCMP
Deauthentication Floods deauth packets (DoS) Rate limiting + IDS (Unit 3)

Worked Example: Stopping a Krack Attack on eSewa

  1. Attacker sends forged Group Key during handshake.
  2. WPA3-SAE detects the mismatch and drops the connection.
  3. IDS (Unit 3) logs the failed handshake as a potential attack.

7. Exam Tip: How to Score Full Marks

  1. Diagrams Are Mandatory:

    • Draw the four-way handshake (sequence diagram) or state machine.
    • Label PTK, GTK, ANonce, SNonce, MIC in your answer.
  2. Compare WPA2 vs. WPA3:

    • Mention SAE, forward secrecy, and resistance to offline attacks.
    • Example: "WPA3’s Dragonfly Key Exchange prevents brute-force attacks seen in WPA2-PSK."
  3. Real-World Tie-Ins:

    • Link Pathao’s driver app to mutual authentication.
    • Link Ncell’s 4G to WPA2-Enterprise + 802.1X.
  4. Common Pitfalls:

    • ❌ Don’t say WEP is "secure" (it’s broken).
    • ❌ Don’t confuse TKIP (WPA) with CCMP (WPA2/WPA3).
    • ❌ Always mention MIC verification in handshakes.
  5. Short-Answer Secrets:

    • Four-way handshake: 4 EAPOL messages → PTK/GTK installation.
    • WPA3 advantage: "No password in plaintext" (SAE).
    • Threats: Rogue AP, Krack, Evil Twin.

Final Visual Summary

flowchart TD
    A["Wireless Threats"] --> B["Eavesdropping<br/>Rogue AP<br/>DoS"]
    B --> C["WEP/WPA Flaws"]
    C --> D["802.11i Fixes<br/>AES-CCMP<br/>Four-Way Handshake"]
    D --> E["WPA2: Enterprise<br/>WPA3: SAE + Forward Secrecy"]
    E --> F["Nepal Use Cases<br/>Ncell 4G<br/>Pathao App<br/>NTC IoT"]

Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 7.

Discussion

Loading…