TY - GEN
T1 - City-Hunter: Hunting Smartphones in Urban Areas
AU - LIU, Xuefeng
AU - WEN, Jiaqi
AU - TANG, Shaojie
AU - CAO, Jiannong
AU - SHEN, Jiaxing
PY - 2017
Y1 - 2017
N2 - The security issue of public WiFi is gaining more and more concern. By listening to probe requests, an adversary can obtain the SSID list of the APs to which a smartphone previously connected, and utilizes this information to trick the smartphone into associating to it. However, with the enhancement of security level, most smartphones now do not proactively disclose their SSID lists, making these attacks obsolete. In this paper, we propose City-Hunter, an attacker that can lure nearby smartphones without knowing their SSID information. City-Hunter establishes and maintains an SSID database by integrating both offline and online information. Meanwhile, it smartly chooses some SSIDs to hit a smartphone according to the past record and freshness. We evaluate the performance of City-Hunter in different public places. The results demonstrate that City-Hunter is able to successfully hit 12% ∼ 18% smartphones without knowing their SSID information, which is about 4 ∼ 8 times improvement compared to the similar attacks like KARMA and MANA.
AB - The security issue of public WiFi is gaining more and more concern. By listening to probe requests, an adversary can obtain the SSID list of the APs to which a smartphone previously connected, and utilizes this information to trick the smartphone into associating to it. However, with the enhancement of security level, most smartphones now do not proactively disclose their SSID lists, making these attacks obsolete. In this paper, we propose City-Hunter, an attacker that can lure nearby smartphones without knowing their SSID information. City-Hunter establishes and maintains an SSID database by integrating both offline and online information. Meanwhile, it smartly chooses some SSIDs to hit a smartphone according to the past record and freshness. We evaluate the performance of City-Hunter in different public places. The results demonstrate that City-Hunter is able to successfully hit 12% ∼ 18% smartphones without knowing their SSID information, which is about 4 ∼ 8 times improvement compared to the similar attacks like KARMA and MANA.
UR - http://www.scopus.com/inward/record.url?scp=85027246447&partnerID=8YFLogxK
U2 - 10.1109/ICDCS.2017.148
DO - 10.1109/ICDCS.2017.148
M3 - Conference paper (refereed)
AN - SCOPUS:85027246447
T3 - International Conference on Distributed Computing Systems
SP - 162
EP - 171
BT - 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS)
A2 - LEE, Kisung
A2 - LIU, Ling
PB - IEEE
T2 - 37th IEEE International Conference on Distributed Computing Systems, ICDCS 2017
Y2 - 5 June 2017 through 8 June 2017
ER -