SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Don't use WEP, say German security researchers

Don't use WEP, say German security researchers

By:  Peter Sayer  On: 03 Apr 2007 For: IDG News Service (Paris Bureau) Creator

The Wi-Fi security protocol WEP should not be relied on to protect sensitive material, according to three German security researchers who have discovered a faster way to crack it. They plan to demonstrate their findings at a security conference in Hamburg this weekend.

The Wi-Fi security protocol WEP should not be relied on to protect sensitive material, according to three German security researchers who have discovered a faster way to crack it. They plan to demonstrate their findings at a security conference in Hamburg this weekend.

Mathematicians showed as long ago as 2001 that the RC4 key scheduling algorithm underlying the WEP (Wired Equivalent Privacy) protocol was flawed, but attacks on it required the interception of around 4 million packets of data in order to calculate the full WEP security key. Further flaws found in the algorithm have brought the time taken to find the key down to a matter of minutes, but that's not necessarily fast enough to break into systems that change their security keys every five minutes.

Now it takes just 3 seconds to extract a 104-bit WEP key from intercepted data using a 1.7GHz Pentium M processor. The necessary data can be captured in less than a minute, and the attack requires so much less computing power than previous attacks that it could even be performed in real time by someone walking through an office.

Anyone using Wi-Fi to transmit data they want to keep private, whether it's banking details or just e-mail, should consider switching from WEP to a more robust encryption protocol, the researchers said.

"We think this can even be done with some PDAs or mobile phones, if they are equipped with wireless LAN hardware," said Erik Tews, a researcher in the computer science department at Darmstadt University of Technology in Darmstadt, Germany.

Tews, along with colleagues Ralf-Philipp Weinmann and Andrei Pyshkin, published a paper about the attack showing that their method needs far less data to find a key than previous attacks: just 40,000 packets are needed for a 50 percent chance of success, while 85,000 packets give a 95 percent chance of success, they said.

Although stronger encryption methods have come along since the first flaws in WEP were discovered over six years ago, the new attack is still relevant, the researchers said. Many networks still rely on WEP for security: 59 percent of the 15,000 Wi-Fi networks surveyed in a large German city in September 2006 used it, with only 18 percent using the newer WPA (Wi-Fi Protected Access) protocol to encrypt traffic. A survey of 490 networks in a smaller German city last month found 46 percent still using WEP, and 27 percent using WPA. In both surveys, over a fifth of networks used no encryption at all, the researchers said in their paper.

Businesses can still protect their networks from the attack, even if they use old Wi-Fi hardware incapable of handling the newer WPA encryption.

For one thing, the researchers said, their attack is active: in order to gather enough of the right kind of data, they send out ARP (Address Resolution Protocol) requests, prompting computers on the network under attack to reply with unencrypted packets of an easily recognizable length. This should be enough to alert an IDS (intrusion detection system) to the attack, they say.


Sign up for our Newsletters












Print |  Views: 1109   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Peter Sayer Peter Sayer Peter Sayer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more... more

Related Content

Adobe patches Flash vulnerabilities for three platforms
Adobe patches Flash vulnerabilities for three platformsThe software maker has patched the bug that put users at risk merely by viewing malicious Shockwave Flash files. Other updates addressed risks of clickjacking and denial of service
Security attacks rise
Security attacks riseA recent Canada-wide survey reveals that not only are security attacks on the rise, but when it comes to network and denial-of-service (DoS) attacks, one-third of Canadian enterprises were hit from the inside. The survey findings were revealed late last month at a CA Identity and Access Management (IAM) symposium held in Toronto.
Cyber-crime strides in lockstep with security
Cyber-crime strides in lockstep with securityInformation Security made great strides last year. Sadly, so did cyber-crime. In the U.S. – according to a recent FBI study – almost 90 per cent of firms experienced computer attacks last year despite the use of security software. So what happened in 2005?
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali
VIDEO: How to deal with Conficker
conficker, which has infected more than 10 million pcs so far, is easy to repel with common security practices, according to info-tech research group.see our video interview with james quin of info-tech research group to find out who you can protect your network and figure out whether your
blog comments powered by Disqus