Investigation of WiFi Security Auditing Tools for Evil Twin Attacks and Detection
摘要
The use of public WiFi hotspots is beneficial for both users and service providers, with users able to access free Internet and service providers gaining potential customers. While these days most public WiFi hotspots and home networks have security measures like captive portal and WPA, they are still susceptible to attacks. An attacker can setup an evil twin access point, and an evil portal to capture sensitive user information such as credentials and credit card details. At the same time, while many users may be aware of recommendations not to connect to open public networks, they would lack awareness on how to watch for signs of compromise when the evil twin AP has security in place. There is a need for client-side tools to assist wireless users in identifying and defending themselves against evil twin and evil portal attacks. This paper conducts a comprehensive evaluation of two free WiFi auditing tools Airgeddon and Fluxion using different wireless adapters, and the commercial WiFi Pineapple Tetra. The evaluation covers both technical aspects like their ease-of-use and capabilities for setting up an evil twin AP, and human aspect in terms of signs of evil twin AP on different end-user devices. The results showed that Airgeddon and Fluxion require significant troubleshooting to identify and install suitable adapters, while Pineapple Tetra is more user friendly. In terms of detection, users can watch for signs of multiple APs displayed on some user devices, while automatic solutions can use traffic parameters such as beacon-frame delay and RSSI to distinguish between the legitimate and evil-twin APs.