EDBT 2026 Demo / reviewers in the wild / expert
Domien Schepers
dblp:198/6828
· DBLP profile ↗
10ranked-venue papers
7as first author
6since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 7 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
USENIX Security Symposium | 1 |
| 2022 | On the Robustness of Wi-Fi Deauthentication CountermeasuresabstractWith the introduction of WPA3 and Wi-Fi 6, an increased usage of Wi-Fi Management Frame Protection (MFP) is expected. Wi-Fi MFP, defined in IEEE 802.11w, protects robust management frames by providing data confidentiality, integrity, origin authenticity, and replay protection. One of its key goals is to prevent deauthentication attacks in which an adversary forcibly disconnects a client from the network. In this paper, we inspect the standard and its implementations for their robustness and protection against deauthentication attacks. In our standard analysis, we inspect the rules for processing robust management frames on their completeness, consistency, and security, leading to the discovery of unspecified cases, contradictory rules, and revealed insecure rules that lead to new denial-of-service vulnerabilities. We then inspect implementations and identify vulnerabilities in clients and access points running on the latest versions of the Linux kernel, hostap, IWD, Apple (i.e., macOS, iOS, iPadOS), Windows, and Android. Altogether, these vulnerabilities allow an adversary to disconnect any client from personal and enterprise networks despite the usage of MFP. Our work highlights that management frame protection is insufficient to prevent deauthentication attacks, and therefore more care is needed to mitigate attacks of this kind. In order to address the identified shortcomings, we worked with industry partners to propose updates to the IEEE 802.11 standard. Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
WISEC | 1 |
| 2022 | Privacy-Preserving Positioning in Wi-Fi Fine Timing MeasurementabstractAbstract With the standardization of Wi-Fi Fine Timing Measurement (Wi-Fi FTM; IEEE 802.11mc), the IEEE introduced indoor positioning for Wi-Fi networks. To date, Wi-Fi FTM is the most widely supported Wi-Fi distance measurement and positioning system. In this paper, we perform the first privacy analysis of Wi-Fi FTM and evaluate devices from a wide variety of vendors. We find the protocol inherently leaks location-sensitive information. Most notably, we present techniques that allow any client to be localized and tracked by a solely passive adversary. We identify flaws inWi-Fi FTM MAC address randomization and present techniques to fingerprint stations with firmware-specific granularity further leaking client identity. We address these shortcomings and present a privacy-preserving passive positioning system that leverages existing Wi-Fi FTM infrastructure and requires no hardware changes. Due to the absence of any client-side transmission, our design hides the very existence of a client and as a side-effect improves overall scalability without compromising on accuracy. Finally, we present privacy-enhancing recommendations for the current and next-generation protocols such as Wi-Fi Next Generation Positioning (Wi-Fi NGP; IEEE 802.11az). Domien Schepers, Aanjhan Ranganathan |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | Let numbers tell the tale: measuring security trends in wi-fi networks and best practicesabstractMotivated by the recent push towards adopting new standards and the discovery of numerous vulnerabilities in both new and old protocols, this paper analyzes the security of Wi-Fi networks. Our analysis is based on publicly available datasets and our own survey covering 250,137 networks across four countries in three continents. We present several key insights, including the continued use of outdated security configurations and vulnerable protocols, the adoption rates of modern protocols, the increasing presence of mesh networks as part of smart city infrastructure, and the vast differences depending on the surveyed geographic region and frequency spectrum. Additionally, we identify and improve upon shortcomings in previous surveys, and recommend best practices for future surveying. In summary, our work provides a more fine-grained understanding on Wi-Fi network security in the real-world. Finally, we publish our tools used for extracting security statistics, and make all anonymized datasets available to other researchers. Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
WISEC | 1 |
| 2021 | Here, there, and everywhere: security analysis of wi-fi fine timing measurementabstractToday, an increasing number of applications rely on location and proximity information to deliver services. With the introduction of Wi-Fi Fine Timing Measurement (FTM) in the IEEE 802.11-2016 standard, Wi-Fi derived location and proximity information will play a key role in many safety- and security-critical applications. For example, Wi-Fi FTM is adopted in Wi-Fi Aware where it enables geo-fencing and mobile identification. In this paper, we perform the first security analysis of Wi-Fi FTM and analyze its security guarantees across the logical and physical layers. We find various weaknesses that enable an attacker to introduce distance reductions and enlargements to any arbitrary attacker-chosen value, requiring commodity hardware only. We perform an evaluation using commercial access points, smartphones, and off-the-shelf Wi-Fi cards, and show that an attacker can manipulate distances with meter-level precision. Furthermore, we highlight the distance manipulation attacks which are independent of any higher-layer cryptographic protection, exposing fundamental limitations to achieving secure distance measurements in the current standard. Finally, we present security recommendations for the design and implementation of Wi-Fi FTM and next-generation positioning protocols. Domien Schepers, Mridula Singh, Aanjhan Ranganathan |
WISEC | 1 |
| 2021 | A framework to test and fuzz wi-fi devicesabstractOver the years, numerous weaknesses have been identified in the IEEE 802.11 standard and its implementations. In order to present a proof-of-concept or demonstrate their impact in practice, researchers are often required to implement entire procedures or complex features from scratch (e.g., injecting encrypted frames with customized header flags). In this paper, we present a framework that allows researchers to more easily test and fuzz any device (i.e., access points and clients). This framework enables one to, for example, test hypothesis on new weaknesses, implement proof-of-concepts, create testing suites, and automate experiments. Our framework is implemented on top of the hostap user space daemon, and includes a language in which complex test cases can be defined (e.g., instructions to inject a sequence of user-modified frames into the network). Notably, a test case can make use of the hostap control interface, providing access to built-in features (e.g., authentication procedures, retrieval of encryption keys) and allows users to create customized hostap extensions. Domien Schepers, Mathy Vanhoef, Aanjhan Ranganathan |
WISEC | 1 |
| 2019 | Practical Side-Channel Attacks against WPA-TKIPabstractWe measure the usage of cipher suites in protected Wi-Fi networks, and do this for several distinct geographic areas. Surprisingly, we found that 44.81% of protected networks still support the old WPA-TKIP cipher. Motivated by this, we systematically analyze the security of several implementations of WPA-TKIP, and present novel side-channel attacks against them. The presented attacks bypass existing countermeasures and recover the Michael message authentication key in 1 to 4 minutes. Using this key, an adversary can then decrypt and inject network traffic. In contrast, previous attacks needed 7 to 8 minutes. These results stress the urgent need to stop using WPA-TKIP. Domien Schepers, Aanjhan Ranganathan, Mathy Vanhoef |
AsiaCCS | 1 |
| 2019 | Wireless Attacks on Aircraft Instrument Landing Systems
Harshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara Noubir |
USENIX Security Symposium | 2 |
| 2019 | Wireless attacks on aircraft landing systems: demoabstractModern aircraft heavily rely on several wireless technologies for communications, control, and navigation. In this work, we demonstrate the vulnerability of aircraft instrument landing systems to wireless attacks. We show that it is possible to fully and in finegrain control the course deviation indicator, as displayed by the ILS receiver, in real-time, and demonstrate it on aviation-grade ILS receivers. We develop a tightly-controlled closed-loop ILS spoofer that autonomously adjusts the adversary's transmitted signals based on the aircraft's GPS location to cause an undetected off-runway landing. We demonstrate the integrated attack on an FAA certified flight-simulator (X-Plane)'s AI-based auto-land feature and show success rate with offset touchdowns of 18 meters to over 50 meters. Harshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara Noubir |
WiSec | 2 |
| 2017 | Discovering Logical Vulnerabilities in the Wi-Fi Handshake Using Model-Based TestingabstractWe use model-based testing techniques to detect logical vulnerabilities in implementations of the Wi-Fi handshake. This reveals new fingerprinting techniques, multiple downgrade attacks, and Denial of Service (DoS) vulnerabilities. Stations use the Wi-Fi handshake to securely connect with wireless networks. In this handshake, mutually supported capabilities are determined, and fresh pairwise keys are negotiated. As a result, a proper implementation of the Wi-Fi handshake is essential in protecting all subsequent traffic. To detect the presence of erroneous behaviour, we propose a model-based technique that generates a set of representative test cases. These tests cover all states of the Wi-Fi handshake, and explore various edge cases in each state. We then treat the implementation under test as a black box, and execute all generated tests. Determining whether a failed test introduces a security weakness is done manually. We tested 12 implementations using this approach, and discovered irregularities in all of them. Our findings include fingerprinting mechanisms, DoS attacks, and downgrade attacks where an adversary can force usage of the insecure WPA-TKIP cipher. Finally, we explain how one of our downgrade attacks highlights incorrect claims made in the 802.11 standard. Mathy Vanhoef, Domien Schepers, Frank Piessens |
AsiaCCS | 2 |