Combating Nationwide WiFi Security Threats

Zhenhua Li,Yafei Dai,Guihai Chen,Yunhao Liu
DOI: https://doi.org/10.1007/978-981-19-6982-9_8
2023-01-01
Abstract:Carrying over 75% of the last-mile mobile Internet traffic, WiFi has inevitably become an enticing target for various security threats. In this work, we characterize a wide variety of real-world WiFi threats at an unprecedented scale, involving 19M WiFi APs mostly located in China, by deploying a crowdsourced security checking system on 14M mobile devices in the wild. Leveraging the collected data, we reveal the landscape of nationwide WiFi threats for the first time. We find that the prevalence, riskiness, and breakdown of WiFi threats deviate significantly from common understandings and prior studies. In particular, we detect attacks at around 4% of all WiFi APs, uncover that most WiFi attacks are driven by an underground economy, and provide strong evidence of web analytics platforms being the bottleneck of its monetization chain. Furthermore, we provide insightful guidance for defending against WiFi attacks at scale, and some of our efforts have already yielded real-world impacteffectively disrupted the WiFi attack ecosystem.
What problem does this paper attempt to address?