wep protocol weaknesses and vulnerabilities l.
Skip this Video
Loading SlideShow in 5 Seconds..
WEP Protocol Weaknesses and Vulnerabilities PowerPoint Presentation
Download Presentation
WEP Protocol Weaknesses and Vulnerabilities

Loading in 2 Seconds...

play fullscreen
1 / 18

WEP Protocol Weaknesses and Vulnerabilities - PowerPoint PPT Presentation

  • Uploaded on

WEP Protocol Weaknesses and Vulnerabilities. Riad Lemhachheche Jumnit Hong. OUTLINE. Introduction to WEP Problems with WEP Solutions to WEP 802.1x 802.11i WPA Conclusion. Introduction to WEP. Basically a pseudo random number generator that encrypts data packets.

I am the owner, or an agent authorized to act on behalf of the owner, of the copyrighted work described.
Download Presentation

PowerPoint Slideshow about 'WEP Protocol Weaknesses and Vulnerabilities' - avinoam

An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.

- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript
wep protocol weaknesses and vulnerabilities

WEP Protocol Weaknesses and Vulnerabilities

Riad Lemhachheche

Jumnit Hong

  • Introduction to WEP
  • Problems with WEP
  • Solutions to WEP
    • 802.1x
    • 802.11i
    • WPA
  • Conclusion
introduction to wep
Introduction to WEP
  • Basically a pseudo random number generator that encrypts data packets.
    • Start with generic 802.11 packet
    • Use a secret key plus IV to seed RC4 stream cipher to create pseudo random number
    • Create a CRC-32 of data portion of packet which is then called ICV.
    • Data || ICV XOR Pseudo Random Number = Encrypted portion of WEP Packet
how wep works

Generic 802.11 Packet Frame

Frame Header

Frame Body


Created by Sending Device

Shared before communication begins



Secret Key


Integrity Check Algorithm

RC4 Algorithm

Frame Body


Frame Header


Frame Body



WEP Packet Frame


How WEP Works
problems with wep
Problems with WEP
  • Key Generation
  • ICV Generation
  • Weak Key’s and Weak IV’s
  • WEP Attacks
key generation problems
Key Generation Problems
  • The main problem of WEP is Key Generation.
  • Secret Key is too small, only 40 Bits.
    • Very susceptible to brute force attacks.
  • IV is too small.
    • Only 16 Million different possibilities for every packet.
  • Secret Keys are accessible to user, therefore not secret.
  • Key distribution is done manually.
icv generation problems
ICV Generation Problems
  • The ICV is generated from a cyclic redundancy check (CRC-32)
    • Only a simple arithmetic computation. Can be done easily by anyone.
    • Not cryptographically secure.
  • Easy for attacker to change packet and then change ICV to get response from AP.
weak key s and iv s
Weak Key’s and IV’s
  • Certain keys are more susceptible to showing the relationship between plaintext and ciphertext.
    • There are approx 9000 weak keys out of the 40 bit WEP secret key.
  • Weak IV will correspond to weak Keys.
  • Replay
    • Statistical gathering of certain ciphertext that once sent to server will cause wanted reaction.
  • 802.11 LLC Encapsulation
    • Predictable headers to find ciphertext, plaintext combinations
  • Denial of Service Attacks
    • Flooding the 2.4Ghz frequency with noise.
solutions to wep
Solutions to WEP
  • 802.1x
  • WPA
  • 802.11i
  • All much more secure.
802 1x

IEEE 802.1X is a standard from the IEEE for port-based network access control. The 802.1X authentication process for 802.1X applied to WLAN works as follows:

  • The client access the wireless medium using CSMA/CD and associate with the access point
  • The access point accepts the association and places the client on hold in an unauthenticated ’holding area’. It sends an authentication request to the client. The access to the LAN for the client is still blocked
  • The client provides an identification response with a username or some kind of identifier. It is forwarded by the access point to a RADIUS server
802 1x 2
802.1x (2)
  • The RADIUS server looks up the username from a local database or another authentication server.
  • If the username has been identified by the RADIUS server then the access point starts challenging the client. The way the client is challenged is not specified by the protocol and so depends on the hardware/software implementations. Nevertheless, no secret information, like passwords, are passed over the medium as plaintext.
  • The client initiates a reverse challenge with the RADIUS server to achieve mutual authentication. This protects the network from rogue access points installed by hackers to obtain client authentication data.
  • Once the mutual authentication is performed, a virtual port on the access point is opened up and the client can fully access the network.
wpa wireless protected access
WPA(Wireless Protected Access)

Wi-Fi Protect Access (WPA) has for goal to be an update to WEP weaknesses. It is designed to be:

  • strong,
  • Interoperable & security replacement for WEP
  • software upgradeable for certified Wi-Fi products
  • available quickly.

To fulfill these goals, 2 major enhancements have been made:

  • Improved data encryption
  • User authentication
wpa vs 802 11i
WPA vs. 802.11i

WPA and IEEE 802.11i Comparison

  • WPA will be forward-compatible with the IEEE 802.11i security specification.
  • WPA is a subset of the current 802.11i draft, taking already available pieces of the 802.11i draft such as its implementation of 802.1x and TKIP.

The main pieces of the 802.11i draft that are not included in WPA are :

  • Secure IBSS & Secure fast handoff,
  • Secure de-authentication and disassociation,
  • Enhanced encryption protocols such as AES-CCMP.
802 11i
  • Possibility of two modes to encrypt packets TKIP or CCMP.
  • TKIP uses current WEP and wraps a new packet around the WEP packet. Used to support legacy devices.
  • CCMP uses AES in CBC mode to create MAC and encrypt data packets. New 802.11 encryption standard.

The WEP protocol described in 802.11 is not sufficient at creating cryptographically secure communication between a wireless client and an access point. It will only stop the casual attacker, with virtually no security to protect a network from the professional hacker.

The problems with WEP are as follows:

  • Key Generation and Distribution
  • Weak IV’s and Key’s
  • Predictable Integrity Check algorithm (CRC-32)
  • Freely available tools to break WEP
conclusion 2
Conclusion (2)


  • Modifying WEP by utilizing TKIP enables superior security to that of WEP, but the most secure way to provide cryptographically secure communication is to use well known and studied standard encryption algorithms such as AES. CCMP utilizes AES in cipher-clock-chaining mode to produce a MAC and to encrypt the message. This is the most secure way to transfer confidential information wirelessly. Both CCMP and TKIP are in the new 802.11i standard.
  • WEP only protects against casual attackers and the new 802.11i will provide much needed wireless protection from malicious users.