Wi-Fi Virus Outbreak? Researchers Say It's Possible

A Wi-Fi attack could take over 20,000 wireless routers in New York City within a two-week period, according to researchers.

Fri, January 04, 2008 — IDG News Service (San Francisco Bureau) — Criminals looking to target unsecured wireless routers could create an attack that could piggyback across thousands of Wi-Fi networks in urban areas like Chicago or New York City, according to researchers at Indiana University.

The researchers estimate that a Wi-Fi attack could take over 20,000 wireless routers in New York City within a two-week period, with most of the infections occurring within the first day.

"The issue is that most of these routers are installed out of the box very insecurely," said Steven Myers, an assistant professor at Indiana University, who published the paper in November, along with researchers from the Institute for Scientific Interchange in Torino, Italy,

The researchers theorize that attack would work by guessing administrative passwords and then instructing the routers to install new worm-like firmware which would in turn cause the infected router to attack other devices in its range.

Because there are so many closely connected Wi-Fi networks in most urban areas, the attack could hop from router to router for many miles in some cities.

The team used what is known as the Susceptible Infected Removed (SIR) model to track the growth of this attack. This methodology is typically used to estimate things like influenza outbreaks, but it has also been used to predict things like computer virus infections, Myers said.

Although the researchers did not develop any attack code that would be used to carry out this infection, they believe it would be possible to write code that guessed default passwords by first entering the default administrative passwords that shipped with the router, and then by trying a list of one million commonly used passwords, one after the other. They believe that 36 percent of passwords can be guessed using this technique.

Even some routers that use encryption could be cracked, if they use the popular WEP (Wired Equivalent Privacy) algorithm, which security experts have been able to crack for years now. Routers that were encrypted using the more-secure WPA (Wi-Fi Protected Access) standard were considered impossible to infect, Myers said.

Myers' model is based on data compiled from the Wireless Geographic Logging Engine (WiGLE), a volunteer-run effort to map Wi-Fi networks around the world, which has over 10 million networks in its database.

Using this data, they were able to map out large networks of made out of Wi-Fi routers that were each no more than 45 meters (49 yards) from the network -- in other words, close enough for an infection to spread. The largest such network in New York included 36,807 systems; in Boston it was 15,899; and in Chicago: 50,084.

Loading...
 
SPONSORED LINKS
 

Fulfill Your Remote Access Strategy for Mobile Users

Check Point Endpoint Security - Unifying Essential Components

Data Protection: Challenges for the Traveling User

Leading university calls on Nokia for mobile unified communications.

Unified Communications & Collaboration: Game-Changing Business Results

Explore Fixed-Mobile Convergence

Learn how to leverage virtualization for a 74% savings in TCO.

Find out how you can affordably consolidate applications with VMware.

Discover what you need to consider when evaluating virtualization.

Save with 0% Lease Offer on HP Servers and Storage

How RFID Improves Data Center Efficiency

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

Improve Web-Enabled SAP Performance

Gartner on Data Deduplication Cost Savings

Data Protection Options Explained

Ponemon Study: How Much Does a Data Breach "Cost"?

5 Steps to Successful IT Consolidation

Effective Security with a Continuous Approach to ISO 27001 Compliance

Expand High-Performance Computing (HPC) Capabilities

Power the Platform of Choice for Virtualization in the Enterprise

Effective Security with a Continuous Approach to ISO 27001 Compliance

Boost your top- and bottom- lines.

Best Intel Info for IT Pros/Intel Premier IT Professional Program: Stay up to date with roadmaps, technologies & best practices

Make Hidden Trends, Inter-Relationships and Influences Visible.

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Revolutionizing Endpoint Security with a Single Agent

MAKING MOBILITY WORK: Wide-area data services enable today's global enterprise

Mobility is Growing: Survey Shows Why CIOs are Concerned

Put Enterprise Communications on Autopilot

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Find out why IDC thinks virtualization is changing operating environments.

Explore the impact virtualization can have on your bottom-line.

ESG Research on Server and Storage Virtualization

Data Center ROI with RFID Asset Tracking

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Determine the ROI of Web Application Acceleration Managed Services

Achieve a 50:1 Data Deduplication Ratio

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Optimizing Infrastructure Control

File Integrity Monitoring: Secure Your Virtual and Physical IT Environments

High-performance computing is no longer just for Big Business

Optimizing Infrastructure Control

Configuration Assessment: Choosing the Right Solution

Learn what it takes to build a holistic digital collaboration platform

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

 
 
RESOURCE CENTER