NTA Monitor

Latest News

Finance industry faces serious IT security issues

23rd June 2008 The finance industry needs to keep its eye on the small change as well as the bigger picture of its security vulnerabilities Read More

Retail sector faces serious IT security issues

23rd June 2008 The retail sector needs to set out its stall and ring the changes in its security vulnerabilities if it is to avoid the potential for hackers to gain unauthorised system access and disrupt service availability Read More

IT managers have more security headaches to deal with

11th May 2008 NTA Monitor's 2008 Annual Security Report has revealed that the average number of vulnerabilities found per test have increased to 21 compared with 19 in 2007 Read More

Solutions not excuses for patch management warns NTA Monitor

23rd April 2008 Patch management is a vital security requirement for any organsation Read More
Date: 30th July 2004
Risk: Informational

Swiss security researchers have unearthed a flaw in wireless LAN systems that might be used by hackers to drastically increase their share of the available bandwidth at the expense of other users. The issue should be of particular concern to hotspot operators, the research team stated.

Appropriate standards (such as 802.11i) have been developed to ensure user security and privacy in hotspots, but this does nothing to prevent users altering the MAC protocol of a machine to increase his share of available bandwidth.

They explain: "The new generation of wireless adapters allow easy modification of previously inaccessible MAC protocol parameters; for example, with a single line of code hackers can reduce the contention window size, realising a considerable redistribution of throughput shares among stations competing for wireless bandwidth. Other cheating techniques include the modification of protocol timers, the misuse of collision-avoidance mechanisms such as the Net Allocation Vector, and selective scrambling of other users' frames."

Professor Jean-Pierre Hubaux, leader of the three person team at EPFL who investigated the issue, said that although they had demonstrated these attacks in a lab environment they were yet to see reports about these kinds of misdeeds in the real world. But that is no reason for complacency, he argued.

"Experience has shown that breaches are usually exploited, especially if this is easy to do (as it is the case here). With the increasing programmability of the devices, the risk will increase as well," Prof. Hubaux told El Reg.

"Considering that wireless access to hotspots is a charged service to a shared and scarce resource, it is easy to predict that numerous users will be tempted to cheat using the described techniques, thus discouraging honest users to make use of the service," the Swiss Boffins argue.

The Lab has also designed a (US patent pending) detection system, dubbed Domino, to spot bandwidth-stealing behaviour in wireless LANs. This technology is designed to help any Wi-Fi operator to protect its infrastructure against bandwidth-hogging hackers.

References