The Experts below are selected from a list of 111 Experts worldwide ranked by ideXlab platform

Douglas Sicker - One of the best experts on this subject based on the ideXlab platform.

  • Passive data link layer 802 11 wireless device driver Fingerprinting
    USENIX Security Symposium, 2006
    Co-Authors: Jason Franklin, Damon Mccoy, Parisa Tabriz, Vicentiu Neagoe, Jamie A Van Randwyk, Douglas Sicker
    Abstract:

    Motivated by the proliferation of wireless-enabled devices and the suspect nature of device driver code, we develop a Passive Fingerprinting technique that identifies the wireless device driver running on an IEEE 802.11 compliant device. This technique is valuable to an attacker wishing to conduct reconnaissance against a potential target so that he may launch a driver-specific exploit. In particular, we develop a unique Fingerprinting technique that accurately and efficiently identifies the wireless driver without modification to or cooperation from a wireless device. We perform an evaluation of this Fingerprinting technique that shows it both quickly and accurately fingerprints wireless device drivers in real world wireless network conditions. Finally, we discuss ways to prevent Fingerprinting that will aid in improving the security of wireless communication for devices that employ 802.11 networking.

  • USENIX Security Symposium - Passive data link layer 802.11 wireless device driver Fingerprinting
    2006
    Co-Authors: Jason Franklin, Damon Mccoy, Parisa Tabriz, Vicentiu Neagoe, Jamie A Van Randwyk, Douglas Sicker
    Abstract:

    Motivated by the proliferation of wireless-enabled devices and the suspect nature of device driver code, we develop a Passive Fingerprinting technique that identifies the wireless device driver running on an IEEE 802.11 compliant device. This technique is valuable to an attacker wishing to conduct reconnaissance against a potential target so that he may launch a driver-specific exploit. In particular, we develop a unique Fingerprinting technique that accurately and efficiently identifies the wireless driver without modification to or cooperation from a wireless device. We perform an evaluation of this Fingerprinting technique that shows it both quickly and accurately fingerprints wireless device drivers in real world wireless network conditions. Finally, we discuss ways to prevent Fingerprinting that will aid in improving the security of wireless communication for devices that employ 802.11 networking.

Andreas Zinnen - One of the best experts on this subject based on the ideXlab platform.

  • GLOBECOM - Clock skew based remote device Fingerprinting demystified
    2012 IEEE Global Communications Conference (GLOBECOM), 2012
    Co-Authors: Fabian Lanze, Andriy Panchenko, Benjamin Braatz, Andreas Zinnen
    Abstract:

    Commonly used identifiers for IEEE 802.11 access points (APs), such as network name (SSID), MAC, or IP address can be easily spoofed. This allows an attacker to fake a real AP and intercept, collect, or alter (potentially even encrypted) data. In this paper, we address the aforementioned problem by studying limits of unique remote physical device identification based on their clock skew—an unavoidable phenomenon that causes clocks to run at marginal but measurably different speed. To this end, we propose an algorithm for Passive Fingerprinting using timestamps regularly sent by APs in beacon frames. The major advantages of our method are that it is online and that we are able to eliminate the influence of clock skew of the measurement device. Hence, fingerprints performed by different devices become comparable. We calculate the precision of our clock skew measurement algorithm and provide a termination criterion for estimation of the clock skew with arbitrary precision. Moreover, conducting a large scale evaluation, we study the stability and uniqueness of clock skew as a means for remote wireless device identification.

  • Clock skew based remote device Fingerprinting demystified
    2012 IEEE Global Communications Conference (GLOBECOM), 2012
    Co-Authors: Fabian Lanze, Andriy Panchenko, Benjamin Braatz, Andreas Zinnen
    Abstract:

    Commonly used identifiers for IEEE 802.11 access points (APs), such as network name (SSID), MAC, or IP address can be easily spoofed. This allows an attacker to fake a real AP and intercept, collect, or alter (potentially even encrypted) data. In this paper, we address the aforementioned problem by studying limits of unique remote physical device identification based on their clock skew - an unavoidable phenomenon that causes clocks to run at marginal but measurably different speed. To this end, we propose an algorithm for Passive Fingerprinting using timestamps regularly sent by APs in beacon frames. The major advantages of our method are that it is online and that we are able to eliminate the influence of clock skew of the measurement device. Hence, fingerprints performed by different devices become comparable. We calculate the precision of our clock skew measurement algorithm and provide a termination criterion for estimation of the clock skew with arbitrary precision. Moreover, conducting a large scale evaluation, we study the stability and uniqueness of clock skew as a means for remote wireless device identification.

Jason Franklin - One of the best experts on this subject based on the ideXlab platform.

  • Passive data link layer 802 11 wireless device driver Fingerprinting
    USENIX Security Symposium, 2006
    Co-Authors: Jason Franklin, Damon Mccoy, Parisa Tabriz, Vicentiu Neagoe, Jamie A Van Randwyk, Douglas Sicker
    Abstract:

    Motivated by the proliferation of wireless-enabled devices and the suspect nature of device driver code, we develop a Passive Fingerprinting technique that identifies the wireless device driver running on an IEEE 802.11 compliant device. This technique is valuable to an attacker wishing to conduct reconnaissance against a potential target so that he may launch a driver-specific exploit. In particular, we develop a unique Fingerprinting technique that accurately and efficiently identifies the wireless driver without modification to or cooperation from a wireless device. We perform an evaluation of this Fingerprinting technique that shows it both quickly and accurately fingerprints wireless device drivers in real world wireless network conditions. Finally, we discuss ways to prevent Fingerprinting that will aid in improving the security of wireless communication for devices that employ 802.11 networking.

  • USENIX Security Symposium - Passive data link layer 802.11 wireless device driver Fingerprinting
    2006
    Co-Authors: Jason Franklin, Damon Mccoy, Parisa Tabriz, Vicentiu Neagoe, Jamie A Van Randwyk, Douglas Sicker
    Abstract:

    Motivated by the proliferation of wireless-enabled devices and the suspect nature of device driver code, we develop a Passive Fingerprinting technique that identifies the wireless device driver running on an IEEE 802.11 compliant device. This technique is valuable to an attacker wishing to conduct reconnaissance against a potential target so that he may launch a driver-specific exploit. In particular, we develop a unique Fingerprinting technique that accurately and efficiently identifies the wireless driver without modification to or cooperation from a wireless device. We perform an evaluation of this Fingerprinting technique that shows it both quickly and accurately fingerprints wireless device drivers in real world wireless network conditions. Finally, we discuss ways to prevent Fingerprinting that will aid in improving the security of wireless communication for devices that employ 802.11 networking.

Fabian Lanze - One of the best experts on this subject based on the ideXlab platform.

  • GLOBECOM - Clock skew based remote device Fingerprinting demystified
    2012 IEEE Global Communications Conference (GLOBECOM), 2012
    Co-Authors: Fabian Lanze, Andriy Panchenko, Benjamin Braatz, Andreas Zinnen
    Abstract:

    Commonly used identifiers for IEEE 802.11 access points (APs), such as network name (SSID), MAC, or IP address can be easily spoofed. This allows an attacker to fake a real AP and intercept, collect, or alter (potentially even encrypted) data. In this paper, we address the aforementioned problem by studying limits of unique remote physical device identification based on their clock skew—an unavoidable phenomenon that causes clocks to run at marginal but measurably different speed. To this end, we propose an algorithm for Passive Fingerprinting using timestamps regularly sent by APs in beacon frames. The major advantages of our method are that it is online and that we are able to eliminate the influence of clock skew of the measurement device. Hence, fingerprints performed by different devices become comparable. We calculate the precision of our clock skew measurement algorithm and provide a termination criterion for estimation of the clock skew with arbitrary precision. Moreover, conducting a large scale evaluation, we study the stability and uniqueness of clock skew as a means for remote wireless device identification.

  • Clock skew based remote device Fingerprinting demystified
    2012 IEEE Global Communications Conference (GLOBECOM), 2012
    Co-Authors: Fabian Lanze, Andriy Panchenko, Benjamin Braatz, Andreas Zinnen
    Abstract:

    Commonly used identifiers for IEEE 802.11 access points (APs), such as network name (SSID), MAC, or IP address can be easily spoofed. This allows an attacker to fake a real AP and intercept, collect, or alter (potentially even encrypted) data. In this paper, we address the aforementioned problem by studying limits of unique remote physical device identification based on their clock skew - an unavoidable phenomenon that causes clocks to run at marginal but measurably different speed. To this end, we propose an algorithm for Passive Fingerprinting using timestamps regularly sent by APs in beacon frames. The major advantages of our method are that it is online and that we are able to eliminate the influence of clock skew of the measurement device. Hence, fingerprints performed by different devices become comparable. We calculate the precision of our clock skew measurement algorithm and provide a termination criterion for estimation of the clock skew with arbitrary precision. Moreover, conducting a large scale evaluation, we study the stability and uniqueness of clock skew as a means for remote wireless device identification.

Jamie A Van Randwyk - One of the best experts on this subject based on the ideXlab platform.

  • Passive data link layer 802 11 wireless device driver Fingerprinting
    USENIX Security Symposium, 2006
    Co-Authors: Jason Franklin, Damon Mccoy, Parisa Tabriz, Vicentiu Neagoe, Jamie A Van Randwyk, Douglas Sicker
    Abstract:

    Motivated by the proliferation of wireless-enabled devices and the suspect nature of device driver code, we develop a Passive Fingerprinting technique that identifies the wireless device driver running on an IEEE 802.11 compliant device. This technique is valuable to an attacker wishing to conduct reconnaissance against a potential target so that he may launch a driver-specific exploit. In particular, we develop a unique Fingerprinting technique that accurately and efficiently identifies the wireless driver without modification to or cooperation from a wireless device. We perform an evaluation of this Fingerprinting technique that shows it both quickly and accurately fingerprints wireless device drivers in real world wireless network conditions. Finally, we discuss ways to prevent Fingerprinting that will aid in improving the security of wireless communication for devices that employ 802.11 networking.

  • USENIX Security Symposium - Passive data link layer 802.11 wireless device driver Fingerprinting
    2006
    Co-Authors: Jason Franklin, Damon Mccoy, Parisa Tabriz, Vicentiu Neagoe, Jamie A Van Randwyk, Douglas Sicker
    Abstract:

    Motivated by the proliferation of wireless-enabled devices and the suspect nature of device driver code, we develop a Passive Fingerprinting technique that identifies the wireless device driver running on an IEEE 802.11 compliant device. This technique is valuable to an attacker wishing to conduct reconnaissance against a potential target so that he may launch a driver-specific exploit. In particular, we develop a unique Fingerprinting technique that accurately and efficiently identifies the wireless driver without modification to or cooperation from a wireless device. We perform an evaluation of this Fingerprinting technique that shows it both quickly and accurately fingerprints wireless device drivers in real world wireless network conditions. Finally, we discuss ways to prevent Fingerprinting that will aid in improving the security of wireless communication for devices that employ 802.11 networking.