论文标题

Wi-Attack:跨技术对伊巴肯服务的模仿攻击

Wi-attack: Cross-technology Impersonation Attack against iBeacon Services

论文作者

Na, Xin, Guo, Xiuzhen, He, Yuan, Xi, Rui

论文摘要

IBEACON协议被广泛部署以提供基于位置的服务。通过收到其BLE广告,附近的设备可以估算依Beacon的接近或计算室内位置。但是,这些广告的开放性质使模拟攻击的脆弱性。这种攻击可能导致垃圾邮件,不可靠的定位甚至安全漏洞。在本文中,我们提出了Wi-Attack,揭示了使用WiFi设备对iBeacon服务进行模仿攻击的可行性。与使用BLE兼容硬件的模拟攻击不同,Wi-Attack不受广播间隔的限制,并且能够同时模仿多个IBEACON。可以在iBeacon服务上启动有效的攻击,而无需修改WiFi硬件或固件。为了启用从wifi到BLE的直接通信,我们使用跨技术通信的数字仿真技术。为了增强数据包接收及其稳定性,我们添加了冗余数据包,以完全消除循环前缀误差。该仿真提供了高达66.2%的宜人数据包接收率。我们对三种IBEACON服务方案,点部署,多材料和基于指纹的本地化进行攻击。评估结果表明,Wi-Attack仅使用3个AP带来基于指纹的本地化的平均距离误差超过20米。

iBeacon protocol is widely deployed to provide location-based services. By receiving its BLE advertisements, nearby devices can estimate the proximity to the iBeacon or calculate indoor positions. However, the open nature of these advertisements brings vulnerability to impersonation attacks. Such attacks could lead to spam, unreliable positioning, and even security breaches. In this paper, we propose Wi-attack, revealing the feasibility of using WiFi devices to conduct impersonation attacks on iBeacon services. Different from impersonation attacks using BLE compatible hardware, Wi-attack is not restricted by broadcasting intervals and is able to impersonate multiple iBeacons at the same time. Effective attacks can be launched on iBeacon services without modifications to WiFi hardware or firmware. To enable direct communication from WiFi to BLE, we use the digital emulation technique of cross technology communication. To enhance the packet reception along with its stability, we add redundant packets to eliminate cyclic prefix error entirely. The emulation provides an iBeacon packet reception rate up to 66.2%. We conduct attacks on three iBeacon services scenarios, point deployment, multilateration, and fingerprint-based localization. The evaluation results show that Wi-attack can bring an average distance error of more than 20 meters on fingerprint-based localization using only 3 APs.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源