Using the Fluhrer, Mantin, and Shamir Attack to Break WEP (2001) [70 citations — 0 self]
http://www.isoc.org/isoc/conferences/ndss/02/proce
http://www.simovits.com/eng/artark/../../archive/b
http://www.cs.rice.edu/~astubble/wep/wep_attack.ps
DBLP
CACHED:
Abstract:
We implemented an attack against WEP, the link-layer security protocol for 802.11 networks. The attack was described in a recent paper by Fluhrer, Mantin, and Shamir. With our implementation, and permission of the network administrator, we were able to recover the 128 bit secret key used in a production network, with a passive attack. The WEP standard uses RC4 IVs improperly, and the attack exploits this design failure. This paper describes the attack, how we implemented it, and some optimizations to make the attack more efficient. We conclude that 802.11 WEP is totally insecure, and we provide some recommendations.
Citations
| 878 | Security Architecture for the Internet Protocol – Kent, Atkinson - 1998 |
| 567 | Applied Cryptography: Protocols, Algorithms, and Source Code – SCHNEIER - 1996 |
| 226 | Intercepting mobile communications: The insecurity of 802.11 – Borisov, Goldberg, et al. - 2001 |
| 125 | SSH—secure login connections over the internet – Ylonen - 1996 |
| 112 | Weaknesses in the key scheduling algorithm of RC4 – Fluhrer, Mantin, et al. - 2001 |
| 16 | of the IEEE Computer Society. Wireless LAN medium access control (MAC) and physical layer (PHY) specifications – C - 1999 |
| 15 | A Standard for the Transmission of IP Datagrams over – Postel, Reynolds - 1988 |
| 11 | The TLS Protocol, Version 1.0. Internet Engineering Task Force – Dierks, Allen - 1999 |
| 2 | medium access control (MAC) and physical layer (PHY) specifications – C - 1999 |

