Owfuzz: Discovering Wi-Fi Flaws in Modern Devices through Over-The-Air Fuzzing

被引:2
|
作者
Cao, Hongjian [1 ]
Huang, Lin [1 ]
Hu, Shuwei [1 ]
Shi, Shangcheng [2 ]
Liu, Yujia [1 ]
机构
[1] Ant Grp, Beijing, Peoples R China
[2] Ant Grp, Hangzhou, Peoples R China
来源
PROCEEDINGS OF THE 16TH ACM CONFERENCE ON SECURITY AND PRIVACY IN WIRELESS AND MOBILE NETWORKS, WISEC 2023 | 2023年
关键词
802.11; Fuzzing; Wi-Fi Security; Wi-Fi Flaws;
D O I
10.1145/3558482.3590174
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Fuzzing is a practical approach to discovering flaws in the design and implementation of Wi-Fi protocols. However, existing Wi-Fi fuzzers are either vendor- or ecosystem-specific. Besides, they only cover a subset of 802.11 protocols and frame types. The growing complexity of Wi-Fi protocols, which have evolved to Wi-Fi6 and WPA3 already, calls for a free and comprehensive fuzzing tool for modern Wi-Fi devices. In this paper, we present such a fuzzing tool named Owfuzz. Unlike previous works using mostly firmware emulation fuzzing or driver fuzzing, Owfuzz takes the over-the-air fuzzing approach. It can perform fuzzing tests on arbitrary Wi-Fi devices from any vendor and can fuzz all three types of Wi-Fi frames (management, control, and data) defined in all versions of the 802.11 standards. It can be easily extended to support interactive testing of various protocol models. With Owfuzz, we have tested the products of mainstream Wi-Fi chip and device vendors, leading to the discovery of 23 flaws. We have reported most of these flaws to the related vendors with 8 CVE IDs assigned. Moreover, we have open-sourced Owfuzz to the community to facilitate future research.
引用
收藏
页码:263 / 273
页数:11
相关论文
共 17 条
  • [1] Automatic Over-the-Air Provisioning for Wi-Fi Equipped M2M Devices
    Hori, Kenji
    Ogishi, Tomohiko
    Lai, Ming-Yee
    Chee, Dana
    Sinkar, Kaustubh
    PROCEEDINGS OF THE 2013 38TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2013), 2013, : 675 - +
  • [2] Over-the-Air Adversarial Attacks on Deep Learning Wi-Fi Fingerprinting
    Xiao, Fei
    Huang, Yong
    Zuo, Yingying
    Kuang, Wei
    Wang, Wei
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (11) : 9823 - 9835
  • [3] Over-the-Air Runtime Wi-Fi MAC Address Re-randomization
    Jin, Hongyu
    Papadimitratos, Panos
    PROCEEDINGS OF THE 17TH ACM CONFERENCE ON SECURITY AND PRIVACY IN WIRELESS AND MOBILE NETWORKS, WISEC 2024, 2024, : 8 - 13
  • [4] Over-the-Air Performance Results of a Dynamic Spectrum Management Wi-Fi System in TVWS
    Mack, Jane
    Cartmell, John
    2013 NINTH ANNUAL CONFERENCE ON LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY (LISAT 2013), 2013,
  • [5] Poster: Discovering User Relationships Through Smartphone Wi-Fi Probes
    Jiang Tiantian
    Ito, Masaki
    Sezaki, Kaoru
    MOBISYS'16: COMPANION COMPANION PUBLICATION OF THE 14TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS, APPLICATIONS, AND SERVICES, 2016, : 83 - 83
  • [6] Fast, scalable and secure over-the-air bootstrap of Linux operating systems with Wi-Fi ad hoc networks
    André Zúquete
    José Vieira
    Wireless Networks, 2018, 24 : 2043 - 2060
  • [7] Fast, scalable and secure over-the-air bootstrap of Linux operating systems with Wi-Fi ad hoc networks
    Zuquete, Andre
    Vieira, Jose
    WIRELESS NETWORKS, 2018, 24 (06) : 2043 - 2060
  • [8] Indoor Positioning through an Iterative Method in Dense Wi-Fi-Direct Networks with Wi-Fi Direct Devices
    Liu, Llewellyn
    Wong, Wallace
    2015 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS - TAIWAN (ICCE-TW), 2015, : 308 - 309
  • [10] Through-the-Wall Human Behavior Recognition Algorithm with Commercial Wi-Fi Devices
    Yang, Zhenhua
    Yang, Xiaolong
    Zhou, Mu
    Wu, Shiming
    WIRELESS AND SATELLITE SYSTEMS, PT I, 2019, 280 : 209 - 217