Logo del repository
  1. Home
 
Opzioni

Evil twins and WPA2 Enterprise: A coming security disaster?

Bartoli, Alberto
•
Medvet, Eric
•
Onesti, Filippo
2018
  • journal article

Periodico
COMPUTERS & SECURITY
Abstract
WPA2 Enterprise is a suite of protocols for secure communication in a wireless local network and has become an essential component of virtually every enterprise. In many practical deployments of this technology, a device that authenticates with username and password is at risk of leaking credentials to fraudulent access points claiming to be the enterprise network (evil twins) that may be placed virtually anywhere. While this kind of vulnerability is well known to practitioners, we believe these issues deserve a fresh look because the current technological landscape has magnified the corresponding risks. Convergence of organizations toward single sign-on architectures in which a single set of credentials unlock access to all services of the organizations, coupled with the huge diffusion of wifi-enabled personal devices which often contain enterprise credentials and that connect to wifi networks automatically, have made attacks aimed at stealing network credentials particularly attractive to attackers and hard to detect. In this paper we intend to draw the attention of the research and technological community on this important yet, in our opinion, widely underestimated risk. We also suggest a direction for investigating practical solutions able to offer stronger security without requiring any overhaul of existing protocols.
DOI
10.1016/j.cose.2017.12.011
WOS
WOS:000428098500001
Archivio
http://hdl.handle.net/11368/2915044
info:eu-repo/semantics/altIdentifier/scopus/2-s2.0-85040256358
https://www.sciencedirect.com/science/article/pii/S0167404817302808#
Diritti
open access
license:creative commons
license:digital rights management non definito
license uri:http://creativecommons.org/licenses/by-nc-nd/3.0/it/
FVG url
https://arts.units.it/bitstream/11368/2915044/1/2018-CS-EvilTwinsSecurityDisaster.pdf
Soggetti
  • Authentication

  • Wifi

  • Smartphone

  • Hacking

  • Password

Scopus© citazioni
21
Data di acquisizione
Jun 7, 2022
Vedi dettagli
Web of Science© citazioni
21
Data di acquisizione
Mar 27, 2024
google-scholar
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your nstitution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Realizzato con Software DSpace-CRIS - Estensione mantenuta e ottimizzata da 4Science

  • Impostazioni dei cookie
  • Informativa sulla privacy
  • Accordo con l'utente finale
  • Invia il tuo Feedback