(In)Secure Configuration Practices of WPA2 Enterprise Supplicants
AI-generated Key Points
- Study focuses on (in)secure configuration practices of WPA2 Enterprise supplicants in enterprise wireless networks
- Investigates awareness of risks associated with incorrectly configuring WiFi-enabled devices before connecting to the network
- Key requirement of WPA2 Enterprise is correctly configured supplicants to prevent attacks and stealing network credentials
- Data gathered through survey among 1000 users and review of 310 network configuration guides provided by administrators
- Results indicate systematic violation of key requirement, suggesting it is no longer realistic
- Only 29 out of 69 institutions published guides describing secure configurations
- Majority published at least one guide leading to insecure or partly secure configuration
- Technicians cannot be relied upon to configure supplicants securely
- Emphasizes need for improved awareness and education regarding secure configuration practices in enterprise wireless networks
- Provides valuable insights into current state of (in)secure configuration practices in WPA2 Enterprise supplicants
Authors: Alberto Bartoli, Eric Medvet, Andrea De Lorenzo, Fabiano Tarlao
Abstract: WPA2 Enterprise is a fundamental technology for secure communication in enterprise wireless networks. A key requirement of this technology is that WiFi-enabled devices (i.e., supplicants) be correctly configured before connecting to the enterprise wireless network. Supplicants that are not configured correctly may fall prey of attacks aimed at stealing the network credentials very easily. Such credentials have an enormous value because they usually unlock access to all enterprise services. In this work we investigate whether users and technicians are aware of these important and widespread risks. We conducted two extensive analyses: a survey among approximately 1000 users about how they configured their WiFi devices for enterprise network access; and, a review of approximately 310 network configuration guides made available by enterprise network administrators. The results provide strong indications that the key requirement of WPA2 Enterprise is violated systematically and thus can no longer be considered realistic.
Ask questions about this paper to our AI assistant
You can also chat with multiple papers at once here.
Assess the quality of the AI-generated content by voting
Score: 0
Why do we need votes?
Votes are used to determine whether we need to re-run our summarizing tools. If the count reaches -10, our tools can be restarted.
The previous summary was created more than a year ago and can be re-run (if necessary) by clicking on the Run button below.
Similar papers summarized with our AI tools
Navigate through even more similar papers through a
tree representationLook for similar papers (in beta version)
By clicking on the button above, our algorithm will scan all papers in our database to find the closest based on the contents of the full papers and not just on metadata. Please note that it only works for papers that we have generated summaries for and you can rerun it from time to time to get a more accurate result while our database grows.
Disclaimer: The AI-based summarization tool and virtual assistant provided on this website may not always provide accurate and complete summaries or responses. We encourage you to carefully review and evaluate the generated content to ensure its quality and relevance to your needs.