Héloïse Gollier

dblp:375/5812 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0002-1522-0906ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Saecred: A State-Aware, Over-the-Air Protocol Testing Approach for Discovering Parsing Bugs in SAE Handshake Implementations of COTS Wi-Fi Access Points
abstract
WPA3-Personal introduced the stateful Simultane-ous Authentication of Equals (SAE) handshake protocol to achieve forward secrecy and resistance to passphrase guessing attacks during Wi-Fi connection bootstrapping, guarantees that are lacking in WPA2-Personal. However, the initial design of WPA3-Personal with SAE was susceptible to connection downgrade and denial-of-service (DoS) attacks. The current, enhanced version introduces mechanisms to mitigate these vulnerabilities. Enabling these security-enhancing mechanisms, however, results in a variable-structured, context-sensitive packet format that can be challenging to parse and interpret correctly. Misparsing SAE handshake packets can negatively impact Wi-Fi protocol security. To uncover SAE handshake packet misparsing in commercial-off-the-shelf (COTS) Wi-Fi access points (APs), we present Saecred,a packet-structure-guided, SAE-state-aware black-box fuzzer. Saecredreduces the underlying problem of misparsing discovery to a two-dimensional search problem, where the dimensions are the packet structure and the underlying SAE protocol state. It solves this search problem by combining Iterative Deepening Search (IDS) with a context-sensitive grammar-based fuzzing approach, where the latter relies on a Syntax-Guided Synthesis (SyGuS) solver. Saecred'seffectiveness is demonstrated by evaluating it on 6 COTS APs and the widely used open-source hostapd. Our evaluation discovered several instances of 4 classes of bugs. Bugs in two of these classes violate the two fundamental guarantees SAE expects to achieve (i.e., resistance to downgrade and DoS attacks). We reported our findings to the relevant stakeholders, which resulted in patches and security advisories.
Muhammad Daniyal Pirwani Dar, Robert Lorch, Aliakbar Sadeghi, Vincenzo Sorcigli, Héloïse Gollier, Cesare Tinelli, Mathy Vanhoef, Omar Chowdhury
SP5
2025 Fragile Frames: Wi-Fi's Fraught Fight Against FragAttacks
abstract
In 2021, researchers disclosed vulnerabilities in the IEEE 802.11 standard related to frame fragmentation and aggregation, also known as the FragAttacks. In this paper, we design novel methods to measure whether real-world Wi-Fi networks are still affected by these vulnerabilities. Using our methods, we conducted surveys in three cities at two points in time (2023 and 2025) and found many networks still vulnerable. Concretely, we detected 52691 networks, found that in one city, 30% are still affected by one of the FragAttacks, and that for some ISPs, nearly all their routers are still affected. Motivated by this, we also present a design flaw in the 802.11 standard's defense against one of these vulnerabilities.
Siebe Devroe, Héloïse Gollier, Mathy Vanhoef
WISEC2
2024 SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network
abstract
When using protected Wi-Fi protocols such as WPA2 and WPA3, the access point that you connect to is authenticated by the client. This prevents an adversary from creating a rogue clone of the Wi-Fi network, and implies that the name of a network, called SSID, cannot be spoofed. However, in this paper we demonstrate that a client can be tricked into connecting to a different protected Wi-Fi network than the one it intended to connect to. That is, the client's user interface will show a different SSID than the one of the actual network it is connected to. The root cause is a design flaw in the IEEE 802.11 standard, causing the SSID to not always be authenticated. We demonstrate the practical impact of this attack, find that all tested devices are vulnerable to the attack, and propose backwards-compatible defenses as well as updates to the standard.
Héloïse Gollier, Mathy Vanhoef
WISEC1