Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»WIFI»New WiKI-Eve attack can steal numeric passwords over WiFi
WIFI

New WiKI-Eve attack can steal numeric passwords over WiFi

5gantennas.orgBy 5gantennas.orgSeptember 11, 2023No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


A new attack called “WiKI-Eve” can intercept clear text transmissions from smartphones connected to modern WiFi routers, estimate individual numeric keystrokes with up to 90% accuracy, and steal numeric passwords. Masu.

WiKI-Eve utilizes Beamforming Feedback Information (BFI), a feature introduced in WiFi 5 (802.11ac) in 2013. This allows the device to send feedback about its location to the router, allowing the router to send its signal more accurately.


The problem with BFI is that the information exchange involves data in plain text format. This means that this data can be easily intercepted and used without the need for hardware hacking or cracking encryption keys.

WiKI-Eve attack overview (arxiv.org)

This security gap was discovered by a team of university researchers from China and Singapore who tested the potential secrets obtained from these communications.

Researchers found that it was fairly easy to identify numeric keystrokes 90% of the time, crack six-digit numeric passwords with 85% accuracy, and crack complex app passwords with about 66% accuracy. I discovered that.

This attack only works for numeric passwords, but NordPass research showed that 16 of the top 20 passwords use only numeric characters.

WiKI-Eve attack

The WiKI-Eve attack is designed to intercept WiFi signals while entering passwords, making it a real-time attack that must be performed while the target is actively using the smartphone and trying to access certain applications. is.

Changes in BFI signal due to finger movements and taps (arxiv.org)

Some preparation is required because the attacker must identify the target using an identity indicator on the network, such as a MAC address.

“In practice, Eve can obtain this information in advance by performing visual and traffic monitoring simultaneously. By correlating user behavior with network traffic originating from various MAC addresses, Eve can ‘s physical device to the digital traffic, thereby allowing us to determine Bob’s MAC address,” the researchers explain.

In the main phase of the attack, the attacker uses a traffic monitoring tool such as Wireshark to capture the victim’s BFI time series while entering the password.

Every time a user presses a key, it impacts the WiFi antenna behind the screen and generates a unique WiFi signal.

“Although these only consider part of the downlink CSI on the AP side, the fact that on-screen inputs directly impact the Wi-Fi antenna (and therefore the channel) directly behind the screen (see Figure 1) ) allows the BFI to contain sufficient information about the AP side keystrokes,” the paper says.

However, the paper highlights that the boundaries between keystrokes can be blurred by the recorded BFI series, so we developed an algorithm to parse and recover the available data.

Neural models that analyze captured data (arxiv.org)

To tackle the challenge of filtering out factors that interfere with results, such as typing style, typing speed, and adjacent keystrokes, the researchers are using machine learning called a “1-D convolutional neural network.”

The system is trained to consistently recognize keystrokes regardless of typing style through a “domain adaptation” concept consisting of a feature extractor, keystroke classifier, and domain discriminator.

WiKI-Eve ML Framework Training (arxiv.org)

Finally, we apply a “gradient reversal layer” (GRL) to suppress domain-specific features, allowing the model to learn keystroke representations that are consistent across domains.

WiKI-Eve attack procedure (arxiv.org)

attack result

Researchers experimented with WiKI-Eve using a laptop and WireShark, but smartphones could also be used as attack devices, although the number of supported WiFi protocols may be more limited. I pointed out that there is.

The captured data were analyzed using Matlab and Python, and the segmentation parameters were set to the indicated values ​​for best results.

Twenty participants connected to the same WiFi access point but used different phone models. They entered different passwords with a combination of active background apps, entered different input speeds, and measurements were taken from six different locations.

Experimental results show that WiKI-Eve’s keystroke classification accuracy is stable at 88.9% when using sparse recovery algorithm and domain adaptation.

Overall accuracy of WiKI-Eve compared to CSI target model (arxiv.org)

For 6-digit numeric passwords, WiKI-Eve was able to guess the password with an 85% success rate in less than 100 attempts, and remained consistently above 75% in all test environments.

However, the distance between the attacker and the access point is important for this performance. Increasing that distance from 1 meter to 10 meters reduced guess success by 23%.

Effect of distance on guessing performance (arxiv.org)

The researchers also conducted an experiment to emulate a realistic attack scenario to retrieve WeChat Pay user passwords and found that WiKI-Eve correctly guessed the password 65.8% of the time. .

The model consistently predicted the correct password within the top five guesses in more than 50% of the 50 tests conducted. This means that an attacker has a 50% chance of gaining access before reaching his security threshold of 5 incorrect password attempts, beyond which the app will be locked. .

Attacks on WeChat passwords (arxiv.org)

In conclusion, this paper shows that an attacker can infer secrets without hacking the access point simply by using network traffic monitoring tools and machine learning frameworks.

This will require increased security for WiFi access points and smartphone apps, including keyboard randomization, data traffic encryption, signal obfuscation, CSI scrambling, and WiFi channel scrambling.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHow fast is 5G? What you need to know about 5G speeds
Next Article EE becomes the first UK to call mobile phones over 5G network – VoNR
5gantennas.org
  • Website

Related Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

Best WiFi deal: Save $200 on the Starlink Standard Kit AX

August 29, 2024

Sonos Roam 2 review | Good Housekeeping UK

August 29, 2024
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

IDTechEx discusses driving the integration of antenna packaging technology for 5G and 6G

By 5gantennas.orgFebruary 27, 2024

boston, February 27, 2024 /PRNewswire/ — Once limited to military, satellite, and automotive radar applications,…

China’s important role in 6G

March 4, 2024

Golden Band and the Future of 6G (Leader Forum)

February 19, 2024

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

What can 5G do for packaging production?

November 29, 2023

5G could cause problems for US airlines, here’s why

June 28, 2023

Nokia and stc conduct O-RAN based 5G private wireless network trials

March 11, 2024
© 2025 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.