EDBT 2026 Demo / reviewers in the wild / expert
Mathy Vanhoef
dblp:130/3608
· DBLP profile ↗
37ranked-venue papers
16as first author
20since 2021 · last 2026
0000-0002-8971-9470ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 36 · 15 first-author · 20 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing Attacks
Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
NDSS | 3 |
| 2026 | AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
Xin'an Zhou, Juefei Pu, Zhutian Liu 0002, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy, Mathy Vanhoef |
NDSS | 7 |
| 2026 | Secure Trust On First Use for Enterprise Wi-Fi: Design Guidelines and Linux Implementationabstractstatus: Accepted Rathan Appana, Mathy Vanhoef |
WISEC | 2 |
| 2025 | Saecred: A State-Aware, Over-the-Air Protocol Testing Approach for Discovering Parsing Bugs in SAE Handshake Implementations of COTS Wi-Fi Access PointsabstractWPA3-Personal introduced the stateful Simultane-ous Authentication of Equals (SAE) handshake protocol to achieve forward secrecy and resistance to passphrase guessing attacks during Wi-Fi connection bootstrapping, guarantees that are lacking in WPA2-Personal. However, the initial design of WPA3-Personal with SAE was susceptible to connection downgrade and denial-of-service (DoS) attacks. The current, enhanced version introduces mechanisms to mitigate these vulnerabilities. Enabling these security-enhancing mechanisms, however, results in a variable-structured, context-sensitive packet format that can be challenging to parse and interpret correctly. Misparsing SAE handshake packets can negatively impact Wi-Fi protocol security. To uncover SAE handshake packet misparsing in commercial-off-the-shelf (COTS) Wi-Fi access points (APs), we present Saecred,a packet-structure-guided, SAE-state-aware black-box fuzzer. Saecredreduces the underlying problem of misparsing discovery to a two-dimensional search problem, where the dimensions are the packet structure and the underlying SAE protocol state. It solves this search problem by combining Iterative Deepening Search (IDS) with a context-sensitive grammar-based fuzzing approach, where the latter relies on a Syntax-Guided Synthesis (SyGuS) solver. Saecred'seffectiveness is demonstrated by evaluating it on 6 COTS APs and the widely used open-source hostapd. Our evaluation discovered several instances of 4 classes of bugs. Bugs in two of these classes violate the two fundamental guarantees SAE expects to achieve (i.e., resistance to downgrade and DoS attacks). We reported our findings to the relevant stakeholders, which resulted in patches and security advisories. Muhammad Daniyal Pirwani Dar, Robert Lorch, Aliakbar Sadeghi, Vincenzo Sorcigli, Héloïse Gollier, Cesare Tinelli, Mathy Vanhoef, Omar Chowdhury |
SP | 7 |
| 2025 | Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts
Angelos Beitis, Mathy Vanhoef |
USENIX Security Symposium | 2 |
| 2025 | Confusing Value with Enumeration: Studying the Use of CVEs in Academia
Moritz Schloegel, Daniel Klischies, Simon Koch 0001, David Klein 0001, Lukas Gerlach 0001, Malte Wessels, Leon Trampert, Martin Johns, Mathy Vanhoef, Michael Schwarz 0001, Thorsten Holz, Jo Van Bulck |
USENIX Security Symposium | 9 |
| 2025 | Fragile Frames: Wi-Fi's Fraught Fight Against FragAttacksabstractIn 2021, researchers disclosed vulnerabilities in the IEEE 802.11 standard related to frame fragmentation and aggregation, also known as the FragAttacks. In this paper, we design novel methods to measure whether real-world Wi-Fi networks are still affected by these vulnerabilities. Using our methods, we conducted surveys in three cities at two points in time (2023 and 2025) and found many networks still vulnerable. Concretely, we detected 52691 networks, found that in one city, 30% are still affected by one of the FragAttacks, and that for some ISPs, nearly all their routers are still affected. Motivated by this, we also present a design flaw in the 802.11 standard's defense against one of these vulnerabilities. Siebe Devroe, Héloïse Gollier, Mathy Vanhoef |
WISEC | 3 |
| 2025 | LANShield: Analysing and Protecting Local Network Access on Mobile DevicesabstractHome and workplace networks typically safeguard against external threats but allow internal devices to communicate freely with each other. As a result, malicious code on an internal device can collect sensitive data about other devices or directly attack them. In this paper, we study mobile apps as potential sources of local network attacks, analyse their behaviour, design new defences, and evaluate and bypass existing mitigations. We first focus on Android, where apps with only the Internet permission can access all devices in the Local Area Network (LAN), meaning malicious apps can extract private LAN data, manipulate discovery protocols to obtain a Machine-in-the-Middle (MitM) position, and directly attack devices. To defend against such mobile-based attacks, we define an access model to securely differentiate between LAN and global Internet access. We implement this model on Android by creating LANShield: an app that refines Android's permission model, and can monitor and block LAN access of apps using a virtual network interface. We use LANShield to manually perform tests of 399 Android apps and find, among other observations, that 89 apps unexpectedly access the LAN, and 93 apps scan the network. In contrast to Android, iOS already separates the local and global Internet, but does so based on a proprietary LAN access model. We compare this access model to ours, and present multiple bypasses for an app to circumvent Apple's local network permission. Finally, we reported all our findings to affected vendors, and hope our work will motivate the adoption of stronger permission models on mobile devices. Angelos Beitis, Jeroen Robben, Alexander Matern, Nian Xue, Yongle Chen, Vik Vanderlinden, Mathy Vanhoef |
Proc. Priv. Enhancing Technol. | 9 |
| 2024 | A Security Analysis of WPA3-PK: Implementation and Precomputation Attacks
Mathy Vanhoef, Jeroen Robben |
ACNS (2) | 1 |
| 2024 | Netfuzzlib: Adding First-Class Fuzzing Support to Network Protocol Implementations
Jeroen Robben, Mathy Vanhoef |
ESORICS (2) | 2 |
| 2024 | SSID Confusion: Making Wi-Fi Clients Connect to the Wrong NetworkabstractWhen using protected Wi-Fi protocols such as WPA2 and WPA3, the access point that you connect to is authenticated by the client. This prevents an adversary from creating a rogue clone of the Wi-Fi network, and implies that the name of a network, called SSID, cannot be spoofed. However, in this paper we demonstrate that a client can be tricked into connecting to a different protected Wi-Fi network than the one it intended to connect to. That is, the client's user interface will show a different SSID than the one of the actual network it is connected to. The root cause is a design flaw in the IEEE 802.11 standard, causing the SSID to not always be authenticated. We demonstrate the practical impact of this attack, find that all tested devices are vulnerable to the attack, and propose backwards-compatible defenses as well as updates to the standard. Héloïse Gollier, Mathy Vanhoef |
WISEC | 2 |
| 2023 | Time Will Tell: Exploiting Timing Leaks Using HTTP Response Headers
Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
ESORICS (2) | 3 |
| 2023 | Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
USENIX Security Symposium | 3 |
| 2023 | Bypassing Tunnels: Leaking VPN Client Traffic by Abusing Routing Tables
Nian Xue, Yashaswi Malla, Zihang Xia, Christina Pöpper, Mathy Vanhoef |
USENIX Security Symposium | 5 |
| 2023 | Testing and Improving the Correctness of Wi-Fi Frame InjectionabstractInvestigating the security of Wi-Fi devices often requires writing scripts that send unexpected or malformed frames, to subsequently monitor how the devices respond. Such tests generally use Linux and off-the-self Wi-Fi dongles. Typically, the dongle is put into monitor mode to get access to the raw content of received Wi-Fi frames and to inject, i.e., transmit, customized frames. In this paper, we demonstrate that monitor mode on Linux may, unbeknownst to the user, mistakenly inject Wi-Fi frames or even drop selected frames instead of sending them. We discuss cases where this causes security testing tools to misbehave, making users to believe that a device under test is secure while in reality it is vulnerable to an attack. To remedy this problem, we create a script to test raw frame injection, and we extend the Radiotap standard to gain more control over frame injection. Our extension is now part of the Radiotap standard and has been implemented in Linux. We tested it using commercial Wi-Fi dongles and using openwifi, which is an open implementation of Wi-Fi on top of software-defined radios. With our improved setup, we reproduced tests for the KRACK and FragAttack vulnerabilities, and discovered previously unknown vulnerabilities in three smartphones. Mathy Vanhoef, Xianjun Jiao, Wei Liu 0019, Ingrid Moerman |
WISEC | 1 |
| 2022 | The Closer You Look, The More You Learn: A Grey-box Approach to Protocol State Machine LearningabstractWe propose a new approach to infer state machine models from protocol implementations. Our new tool, StateInspector, learns protocol states by using novel program analyses to combine observations of run-time memory and I/O. It requires no access to source code and only lightweight execution monitoring of the implementation under test. We demonstrate and evaluate StateInspector's effectiveness on numerous TLS and WPA/2 implementations. In the process, we show StateInspector enables deeper state discovery, increased learning efficiency, and more insight compared to existing approaches. Our method led us to discover several concerning deviations from the standards and vulnerabilities in IWD and WolfSSL, both of which were assigned CVEs. Chris McMahon Stone, Sam L. Thomas, Mathy Vanhoef, Nicolas Bailluet, Tom Chothia |
CCS | 3 |
| 2022 | On the Robustness of Wi-Fi Deauthentication CountermeasuresabstractWith the introduction of WPA3 and Wi-Fi 6, an increased usage of Wi-Fi Management Frame Protection (MFP) is expected. Wi-Fi MFP, defined in IEEE 802.11w, protects robust management frames by providing data confidentiality, integrity, origin authenticity, and replay protection. One of its key goals is to prevent deauthentication attacks in which an adversary forcibly disconnects a client from the network. In this paper, we inspect the standard and its implementations for their robustness and protection against deauthentication attacks. In our standard analysis, we inspect the rules for processing robust management frames on their completeness, consistency, and security, leading to the discovery of unspecified cases, contradictory rules, and revealed insecure rules that lead to new denial-of-service vulnerabilities. We then inspect implementations and identify vulnerabilities in clients and access points running on the latest versions of the Linux kernel, hostap, IWD, Apple (i.e., macOS, iOS, iPadOS), Windows, and Android. Altogether, these vulnerabilities allow an adversary to disconnect any client from personal and enterprise networks despite the usage of MFP. Our work highlights that management frame protection is insufficient to prevent deauthentication attacks, and therefore more care is needed to mitigate attacks of this kind. In order to address the identified shortcomings, we worked with industry partners to propose updates to the IEEE 802.11 standard. Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
WISEC | 3 |
| 2021 | Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation
Mathy Vanhoef |
USENIX Security Symposium | 1 |
| 2021 | Let numbers tell the tale: measuring security trends in wi-fi networks and best practicesabstractMotivated by the recent push towards adopting new standards and the discovery of numerous vulnerabilities in both new and old protocols, this paper analyzes the security of Wi-Fi networks. Our analysis is based on publicly available datasets and our own survey covering 250,137 networks across four countries in three continents. We present several key insights, including the continued use of outdated security configurations and vulnerable protocols, the adoption rates of modern protocols, the increasing presence of mesh networks as part of smart city infrastructure, and the vast differences depending on the surveyed geographic region and frequency spectrum. Additionally, we identify and improve upon shortcomings in previous surveys, and recommend best practices for future surveying. In summary, our work provides a more fine-grained understanding on Wi-Fi network security in the real-world. Finally, we publish our tools used for extracting security statistics, and make all anonymized datasets available to other researchers. Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
WISEC | 3 |
| 2021 | A framework to test and fuzz wi-fi devicesabstractOver the years, numerous weaknesses have been identified in the IEEE 802.11 standard and its implementations. In order to present a proof-of-concept or demonstrate their impact in practice, researchers are often required to implement entire procedures or complex features from scratch (e.g., injecting encrypted frames with customized header flags). In this paper, we present a framework that allows researchers to more easily test and fuzz any device (i.e., access points and clients). This framework enables one to, for example, test hypothesis on new weaknesses, implement proof-of-concepts, create testing suites, and automate experiments. Our framework is implemented on top of the hostap user space daemon, and includes a language in which complex test cases can be defined (e.g., instructions to inject a sequence of user-modified frames into the network). Notably, a test case can make use of the hostap control interface, providing access to built-in features (e.g., authentication procedures, retrieval of encryption keys) and allows users to create customized hostap extensions. Domien Schepers, Mathy Vanhoef, Aanjhan Ranganathan |
WISEC | 2 |
| 2020 | Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdabstractThe WPA3 certification aims to secure home networks, while EAP-pwd is used by certain enterprise Wi-Fi networks to authenticate users. Both use the Dragonfly handshake to provide forward secrecy and resistance to dictionary attacks. In this paper, we systematically evaluate Dragonfly's security. First, we audit implementations, and present timing leaks and authentication bypasses in EAP-pwd and WPA3 daemons. We then study Dragonfly's design and discuss downgrade and denial-of-service attacks. Our next and main results are side-channel attacks against Dragonfly's password encoding method (e.g. hash-to-curve). We believe that these side-channel leaks are inherent to Dragonfly. For example, after our initial disclosure, patched software was still affected by a novel side-channel leak. We also analyze the complexity of using the leaked information to brute-force the password. For instance, brute-forcing a dictionary of size 1010requires less than $1 in Amazon EC2 instances. These results are also of general interest due to ongoing standardization efforts on Dragonfly as a TLS handshake, Password-Authenticated Key Exchanges (PAKEs), and hash-to-curve. Finally, we discuss backwards-compatible defenses, and propose protocol fixes that prevent attacks. Our work resulted in a new draft of the protocols incorporating our proposed design changes. Mathy Vanhoef, Eyal Ronen |
SP | 1 |
| 2020 | Timeless Timing Attacks: Exploiting Concurrency to Leak Secrets over Remote Connections
Tom van Goethem, Christina Pöpper, Wouter Joosen, Mathy Vanhoef |
USENIX Security Symposium | 4 |
| 2020 | Protecting wi-fi beacons from outsider forgeriesabstractAll Wi-Fi networks periodically broadcast beacons to announce their presence to nearby clients. These beacons contain various properties of the network, including dynamic information to manage the behavior of clients. We first show that an adversary can forge beacons to carry out various known as well as novel attacks. Motivated by these attacks, we propose a scheme to authenticate beacon frames that is efficient and has low bandwidth overhead. We evaluate the security properties of this scheme, and discuss its current implementation in Linux. By collaborating with industry partners, our scheme also got incorporated into the draft 802.11 standard, increasing the chance of it being implemented by vendors. Mathy Vanhoef, Prasant Adhikari, Christina Pöpper |
WISEC | 1 |
| 2019 | Practical Side-Channel Attacks against WPA-TKIPabstractWe measure the usage of cipher suites in protected Wi-Fi networks, and do this for several distinct geographic areas. Surprisingly, we found that 44.81% of protected networks still support the old WPA-TKIP cipher. Motivated by this, we systematically analyze the security of several implementations of WPA-TKIP, and present novel side-channel attacks against them. The presented attacks bypass existing countermeasures and recover the Michael message authentication key in 1 to 4 minutes. Using this key, an adversary can then decrypt and inject network traffic. In contrast, previous attacks needed 7 to 8 minutes. These results stress the urgent need to stop using WPA-TKIP. Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
AsiaCCS | 3 |
| 2018 | Release the Kraken: New KRACKs in the 802.11 StandardabstractWe improve key reinstallation attacks (KRACKs) against 802.11 by generalizing known attacks, systematically analyzing all handshakes, bypassing 802.11's official countermeasure, auditing (flawed) patches, and enhancing attacks using implementation-specific bugs. Last year it was shown that several handshakes in the 802.11 standard were vulnerable to key reinstallation attacks. These attacks manipulate handshake messages to reinstall an already-in-use key, leading to both nonce reuse and replay attacks. We extend this work in several directions. First, we generalize attacks against the 4-way handshake so they no longer rely on hard-to-win race conditions, and we employ a more practical method to obtain the required man-in-the-middle (MitM) position. Second, we systematically investigate the 802.11 standard for key reinstallation vulnerabilities, and show that the Fast Initial Link Setup (FILS) and Tunneled direct-link setup PeerKey (TPK) handshakes are also vulnerable to key reinstallations. These handshakes increase roaming speed, and enable direct connectivity between clients, respectively. Third, we abuse Wireless Network Management (WNM) power-save features to trigger reinstallations of the group key. Moreover, we bypass (and improve) the official countermeasure of 802.11. In particular, group key reinstallations were still possible by combining EAPOL-Key and WNM-Sleep frames. We also found implementation-specific flaws that facilitate key reinstallations. For example, some devices reuse the ANonce and SNonce in the 4-way handshake, accept replayed message 4's, or improperly install the group key. We conclude that preventing key reinstallations is harder than expected, and believe that (formally) modeling 802.11 would help to better secure both implementations and the standard itself. Mathy Vanhoef, Frank Piessens |
CCS | 1 |
| 2018 | Operating Channel Validation: Preventing Multi-Channel Man-in-the-Middle Attacks Against Protected Wi-Fi NetworksabstractWe present a backwards compatible extension to the 802.11 standard to prevent multi-channel man-in-the-middle attacks. This extension authenticates parameters that define the currently in-use channel. Mathy Vanhoef, Nehru Bhandaru, Thomas Derham, Ido Ouzieli, Frank Piessens |
WISEC | 1 |
| 2017 | Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2abstractWe introduce the key reinstallation attack. This attack abuses design or implementation flaws in cryptographic protocols to reinstall an already-in-use key. This resets the key's associated parameters such as transmit nonces and receive replay counters. Several types of cryptographic Wi-Fi handshakes are affected by the attack. All protected Wi-Fi networks use the 4-way handshake to generate a fresh session key. So far, this 14-year-old handshake has remained free from attacks, and is even proven secure. However, we show that the 4-way handshake is vulnerable to a key reinstallation attack. Here, the adversary tricks a victim into reinstalling an already-in-use key. This is achieved by manipulating and replaying handshake messages. When reinstalling the key, associated parameters such as the incremental transmit packet number (nonce) and receive packet number (replay counter) are reset to their initial value. Our key reinstallation attack also breaks the PeerKey, group key, and Fast BSS Transition (FT) handshake. The impact depends on the handshake being attacked, and the data-confidentiality protocol in use. Simplified, against AES-CCMP an adversary can replay and decrypt (but not forge) packets. This makes it possible to hijack TCP streams and inject malicious data into them. Against WPA-TKIP and GCMP the impact is catastrophic: packets can be replayed, decrypted, and forged. Because GCMP uses the same authentication key in both communication directions, it is especially affected. Finally, we confirmed our findings in practice, and found that every Wi-Fi device is vulnerable to some variant of our attacks. Notably, our attack is exceptionally devastating against Android 6.0: it forces the client into using a predictable all-zero encryption key. Mathy Vanhoef, Frank Piessens |
CCS | 1 |
| 2017 | Discovering Logical Vulnerabilities in the Wi-Fi Handshake Using Model-Based TestingabstractWe use model-based testing techniques to detect logical vulnerabilities in implementations of the Wi-Fi handshake. This reveals new fingerprinting techniques, multiple downgrade attacks, and Denial of Service (DoS) vulnerabilities. Stations use the Wi-Fi handshake to securely connect with wireless networks. In this handshake, mutually supported capabilities are determined, and fresh pairwise keys are negotiated. As a result, a proper implementation of the Wi-Fi handshake is essential in protecting all subsequent traffic. To detect the presence of erroneous behaviour, we propose a model-based technique that generates a set of representative test cases. These tests cover all states of the Wi-Fi handshake, and explore various edge cases in each state. We then treat the implementation under test as a black box, and execute all generated tests. Determining whether a failed test introduces a security weakness is done manually. We tested 12 implementations using this approach, and discovered irregularities in all of them. Our findings include fingerprinting mechanisms, DoS attacks, and downgrade attacks where an adversary can force usage of the insecure WPA-TKIP cipher. Finally, we explain how one of our downgrade attacks highlights incorrect claims made in the 802.11 standard. Mathy Vanhoef, Domien Schepers, Frank Piessens |
AsiaCCS | 1 |
| 2016 | Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery MechanismsabstractWe present several novel techniques to track (unassociated) mobile devices by abusing features of the Wi-Fi standard. This shows that using random MAC addresses, on its own, does not guarantee privacy. First, we show that information elements in probe requests can be used to fingerprint devices. We then combine these fingerprints with incremental sequence numbers, to create a tracking algorithm that does not rely on unique identifiers such as MAC addresses. Based on real-world datasets, we demonstrate that our algorithm can correctly track as much as 50% of devices for at least 20 minutes. We also show that commodity Wi-Fi devices use predictable scrambler seeds. These can be used to improve the performance of our tracking algorithm. Finally, we present two attacks that reveal the real MAC address of a device, even if MAC address randomization is used. In the first one, we create fake hotspots to induce clients to connect using their real MAC address. The second technique relies on the new 802.11u standard, commonly referred to as Hotspot 2.0, where we show that Linux and Windows send Access Network Query Protocol (ANQP) requests using their real MAC address. Mathy Vanhoef, Célestin Matte, Mathieu Cunche, Leonardo S. Cardoso, Frank Piessens |
AsiaCCS | 1 |
| 2016 | All Your Biases Belong to Us: Breaking RC4 in WPA-TKIP and TLS
Mathy Vanhoef, Frank Piessens |
USENIX ATC | 1 |
| 2016 | Request and Conquer: Exposing Cross-Origin Resource Size
Tom van Goethem, Mathy Vanhoef, Frank Piessens, Wouter Joosen |
USENIX Security Symposium | 2 |
| 2016 | Predicting, Decrypting, and Abusing WPA2/802.11 Group Keys
Mathy Vanhoef, Frank Piessens |
USENIX Security Symposium | 1 |
| 2016 | Defeating MAC Address Randomization Through Timing AttacksabstractMAC address randomization is a common privacy protection measure deployed in major operating systems today. It is used to prevent user-tracking with probe requests that are transmitted during IEEE 802.11 network scans. We present an attack to defeat MAC address randomization through observation of the timings of the network scans with an off-the-shelf Wi-Fi interface. This attack relies on a signature based on inter-frame arrival times of probe requests, which is used to group together frames coming from the same device although they use distinct MAC addresses. We propose several distance metrics based on timing and use them together with an incremental learning algorithm in order to group frames. We show that these signatures are consistent over time and can be used as a pseudo-identifier to track devices. Our framework is able to correctly group frames using different MAC addresses but belonging to the same device in up to 75% of the cases. These results show that the timing of 802.11 probe frames can be abused to track individual devices and that address randomization alone is not always enough to protect users against tracking. Célestin Matte, Mathieu Cunche, Franck Rousseau, Mathy Vanhoef |
WISEC | 4 |
| 2015 | All Your Biases Belong to Us: Breaking RC4 in WPA-TKIP and TLS
Mathy Vanhoef, Frank Piessens |
USENIX Security Symposium | 1 |
| 2014 | Advanced Wi-Fi attacks using commodity hardwareabstractWe show that low-layer attacks against Wi-Fi can be implemented using user-modifiable firmware. Hence cheap off-the-shelf Wi-Fi dongles can be used carry out advanced attacks. We demonstrate this by implementing five low-layer attacks using open source Atheros firmware. The first attack consists of unfair channel usage, giving the user a higher throughput while reducing that of others. The second attack defeats countermeasures designed to prevent unfair channel usage. The third attack performs continuous jamming, making the channel unusable for other devices. For the fourth attack we implemented a selective jammer, allowing one to jam specific frames already in the air. The fifth is a novel channel-based Man-in-the-Middle (MitM) attack, enabling reliable manipulation of encrypted traffic. Mathy Vanhoef, Frank Piessens |
ACSAC | 1 |
| 2014 | Stateful Declassification Policies for Event-Driven ProgramsabstractWe propose a novel mechanism for enforcing information flow policies with support for declassification on event-driven programs. Declassification policies consist of two functions. First, a projection function specifies for each confidential event what information in the event can be declassified directly. This generalizes the traditional security labelling of inputs. Second, a stateful release function specifies the aggregate information about all confidential events seen so far that can be declassified. We provide evidence that such declassification policies are useful in the context of Java Script web applications. An enforcement mechanism for our policies is presented and its soundness and precision is proven. Finally, we give evidence of practicality by implementing and evaluating the mechanism in a browser. Mathy Vanhoef, Willem De Groef, Dominique Devriese, Frank Piessens, Tamara Rezk |
CSF | 1 |
| 2013 | Practical verification of WPA-TKIP vulnerabilitiesabstractWe describe three attacks on the Wi-Fi Protected Access Temporal Key Integrity Protocol (WPA-TKIP). The first attack is a Denial of Service attack that can be executed by injecting only two frames every minute. The second attack demonstrates how fragmentation of 802.11 frames can be used to inject an arbitrary amount of packets, and we show that this can be used to perform a portscan on any client. The third attack enables an attacker to reset the internal state of the Michael algorithm. We show that this can be used to efficiently decrypt arbitrary packets sent towards a client. We also report on implementation vulnerabilities discovered in some wireless devices. Finally we demonstrate that our attacks can be executed in realistic environments. Mathy Vanhoef, Frank Piessens |
AsiaCCS | 1 |