Feeds

Attack of the bandwidth-hogging hackers

Wi-Fi hotspot peril

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

Swiss security researchers have unearthed a flaw in wireless LAN systems that might be used by hackers to drastically increase their share of the available bandwidth at the expense of the other users. The issue should be of particular concern to hotspot operators, according to a team from the computer labs at the Ecole Polytechnique Federale de Lausanne (EPFL).

Appropriate standards (such as 802.11i) have been developed to ensure user security and privacy in hotspots, but this does nothing to prevent users altering the MAC protocol of a machine to increase his share of available bandwidth, according to the Swiss team.

They explain: "The new generation of wireless adapters allow easy modification of previously inaccessible MAC protocol parameters; for example, with a single line of code hackers can reduce the contention window size, realising a considerable redistribution of throughput shares among station competing for wireless bandwidth. Other cheating techniques include the modification of protocol timers, the misuse of collision-avoidance mechanisms such as the Net Allocation Vector, and selective scrambling of other users frames."

Professor Jean-Pierre Hubaux, leader of the three person team from EPFL who investigated the issue, said that although they had demonstrated these attacks in a lab environment they were yet to see reports about this kind of misdeeds in the real world yet. But that is no reason for complacency, he argued.

"Experience has shown that breaches are usually exploited, especially if this is easy to do (as it is the case here). With the increasing programmability of the devices, the risk will increase as well," Prof. Hubaux told El Reg.

"Considering that wireless access to hotspots is a charged service to a shared and scarce resource, it is easy to predict that numerous users will be tempted to cheat using the described techniques, thus discouraging honest users to make use of the service," the Swiss Boffins argue.

The Lab has also designed a (US patent pending) detection system, dubbed Domino, to spot bandwidth-stealing behaviour in wireless LANs. This technology is designed to help any Wi-Fi operator to protect its infrastructure against bandwidth-hogging hackers. EPFL hopes to license its technology to IT suppliers.

EPFL researchers will present their work at the Mobisys mobile system conference in Boston next week. ®

Related stories

New flaw takes Wi-Fi off the air
Wi-Fi group to update WLAN spec
Cisco thwarts WLAN dictionary attack
Wi-Fi Alliance preps WPA 2 security spec

Security for virtualized datacentres

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Blockbuster book lays out the first 20 years of the Smartphone Wars
Symbian's David Wood bares all. Not for the faint hearted
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
This flashlight app requires: Your contacts list, identity, access to your camera...
Who us, dodgy? Vast majority of mobile apps fail privacy test
Apple Watch will CONQUER smartwatch world – analysts
After Applelocalypse, other wristputers will get stuck in
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.