Pretražite po imenu i prezimenu autora, mentora, urednika, prevoditelja

Napredna pretraga

Pregled bibliografske jedinice broj: 1079027

On WPA2-Enterprise Privacy in High Education and Science


Perković, T.; Dagelić, A.; Bugarić, M.; Čagalj, M.
On WPA2-Enterprise Privacy in High Education and Science // Security and Communication Networks, 2020 (2020), 1-11 doi:10.1155/2020/3731529 (međunarodna recenzija, članak, znanstveni)


CROSBI ID: 1079027 Za ispravke kontaktirajte CROSBI podršku putem web obrasca

Naslov
On WPA2-Enterprise Privacy in High Education and Science

Autori
Perković, T. ; Dagelić, A. ; Bugarić, M. ; Čagalj, M.

Izvornik
Security and Communication Networks (1939-0114) 2020 (2020); 1-11

Vrsta, podvrsta i kategorija rada
Radovi u časopisima, članak, znanstveni

Ključne riječi
wpa2-enterprise, location privacy, device deanonymization, eduroam

Sažetak
A plethora of organizations, companies, and foremost universities and educational institutions are using WPA2-Enterprise protocol to allow their end-users to connect to provided Wi-Fi networks. When both the provider’s and the end-user’s devices are configured properly, it is considered one of the safest Wi-Fi connection protocols with the added benefits of having a unique password for every Wi-Fi user. However, a known evil twin attack can be performed to steal users’ Wi-Fi login credentials, if the devices are not configured correctly. Considering the widespread use of Wi-Fi-enabled smartphones and rising concerns regarding users’ privacy, we focus on the privacy aspects of WPA2-Enterprise vulnerabilities mainly on the widespread Eduroam network. We show that device deanonymization is a concerning liability of many Eduroam networks. More than 87% of 1650 devices collected during a two-month test on our university are vulnerable to MAC address deanonymization attack. Furthermore, by analyzing the Eduroam Configuration Assistant Tool of 1066 different institutions around the world, 67% of exported Eduroam profiles having the Wi-Fi device reveal the user’s identity in the clear, thus linking the users with the device’s MAC address. Indeed, the analysis of the configuration profiles has been confirmed by performing the deanonymization attack on a large-scale international music festival in our country, where 70% of the devices have been vulnerable. Additionally, we showcase the psychological aspects of secure Eduroam users, where some are willing to modify secure configuration profiles to gain aspects to certain blocked features. As a result, the attacker is granted with user credentials and IMSI number and provided with access to all Eduroam-related services.

Izvorni jezik
Engleski

Znanstvena područja
Računarstvo



POVEZANOST RADA


Ustanove:
Fakultet elektrotehnike, strojarstva i brodogradnje, Split

Profili:

Avatar Url Ante Dagelić (autor)

Avatar Url Mario Čagalj (autor)

Avatar Url Toni Perković (autor)

Avatar Url Marin Bugarić (autor)

Citiraj ovu publikaciju

Perković, T.; Dagelić, A.; Bugarić, M.; Čagalj, M.
On WPA2-Enterprise Privacy in High Education and Science // Security and Communication Networks, 2020 (2020), 1-11 doi:10.1155/2020/3731529 (međunarodna recenzija, članak, znanstveni)
Perković, T., Dagelić, A., Bugarić, M. & Čagalj, M. (2020) On WPA2-Enterprise Privacy in High Education and Science. Security and Communication Networks, 2020, 1-11 doi:10.1155/2020/3731529.
@article{article, year = {2020}, pages = {1-11}, DOI = {10.1155/2020/3731529}, keywords = {wpa2-enterprise, location privacy, device deanonymization, eduroam}, journal = {Security and Communication Networks}, doi = {10.1155/2020/3731529}, volume = {2020}, issn = {1939-0114}, title = {On WPA2-Enterprise Privacy in High Education and Science}, keyword = {wpa2-enterprise, location privacy, device deanonymization, eduroam} }
@article{article, year = {2020}, pages = {1-11}, DOI = {10.1155/2020/3731529}, keywords = {wpa2-enterprise, location privacy, device deanonymization, eduroam}, journal = {Security and Communication Networks}, doi = {10.1155/2020/3731529}, volume = {2020}, issn = {1939-0114}, title = {On WPA2-Enterprise Privacy in High Education and Science}, keyword = {wpa2-enterprise, location privacy, device deanonymization, eduroam} }

Časopis indeksira:


  • Current Contents Connect (CCC)
  • Web of Science Core Collection (WoSCC)
    • Science Citation Index Expanded (SCI-EXP)
    • SCI-EXP, SSCI i/ili A&HCI


Citati





    Contrast
    Increase Font
    Decrease Font
    Dyslexic Font