Сейчас загружается
36. Assessing the success of evil twin attacks in WPA3-enterprise networks // IEEE IOTSMS 2025

Tleuberdin S., Satybaldina D., Aidynov T., Issainova A., Magmur Z., Abisheva G.
Assessing the success of evil twin attacks in WPA3-enterprise networks // 2025 12th International Conference on Internet of Things: Systems, Management and Security (IOTSMS). — Lyon, France, 2025. — Pp. 82–86. — DOI: 10.1109/IOTSMS68530.2025.11408581.

Abstract: This work presents an experimental vulnerability evaluation in a WPA3-Enterprise scenario to evaluate the performance of the current WPA3 security methods over different devices and operating systems, including iOS, macOS, Ubuntu, and Windows. We constructed a testing infrastructure with Kali Linux and employed the ALFA AWUS036AXML adapter, in combination with Hostapd and FreeRADIUS software, to setup RADIUS servers and a rogue access point. We evaluated multiple client connection situations to a rogue access point utilizing three device configurations: Safe (compulsory CA certificate verification), Weak (server certificate verification disabled or CA not installed), and Mixed (device trusts the non-valid CA certificate). The experimental results indicated that Evil Twin attacks were effective against clients operating on Ubuntu 24.04.2 and Windows 10, attributable to inadequate certificate verification configurations. We provided guidelines to mitigate risks.

Link / DOI: https://doi.org/10.1109/IOTSMS68530.2025.11408581

Отправить комментарий