信息网络安全 ›› 2016, Vol. 16 ›› Issue (4): 69-75.doi: 10.3969/j.issn.1671-1122.2016.04.011

• • 上一篇    下一篇

公众环境下无线接入的安全问题研究

李晴, 叶阿勇(), 许力   

  1. 福建师范大学数学与计算机科学学院,福建福州350007
  • 收稿日期:2016-03-03 出版日期:2016-04-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 李晴(1992—),女,福建,硕士研究生,主要研究方向为网络与通信;叶阿勇(1977—),男,福建,副教授,博士,主要研究方向为基于位置的服务、隐私计算、无线定位技术;许力(1970—),男,福建,教授,博士,主要研究方向为网络与信息系统。

  • 基金资助:
    国家自然科学基金海峡联合基金重点项目[U1405255];福建省工业科技重点项目[2014H0018];福州科技计划项目[2015-G-51]

Research on Security Issues of Wireless Access in Public Environment

Qing LI, A-yong YE(), Li XU   

  1. College of Mathematics and Computer Science, Fujian Normal University, Fuzhou Fujian 350007, China
  • Received:2016-03-03 Online:2016-04-20 Published:2020-05-13

摘要:

移动互联网的快速发展和WiFi网络的日益普及,促使人们习惯通过各种WiFi热点接入因特网。然而,公众WiFi热点在提供便利的同时,也增大了网络安全风险。无线信号固有的辐射性、空间信道的开放性,以及公众无线热点本身的不可信等安全隐患,使得无线接入面临严重的安全问题。文章简单介绍了WiFi接入模型,并结合使用Wireshark等软件进行的实验,针对公众WiFi热点本身存在的不可信等问题,分别从数据内容、报文首部、域名系统以及个人隐私等方面,分析了公共环境下无线接入可能造成的网页内容推送时账户和密码明文传输泄露、用户使用浏览器时浏览行为轨迹泄露、网页数据内容被篡改、域名欺骗以及用户个人隐私暴露等安全问题,目的也是提高公众对无线接入的安全意识。

关键词: 公众WiFi, 信息泄露, 协议报文, 域名欺骗, 位置隐私

Abstract:

With the rapid development of mobile internet and the rising popularity of WiFi network, people are used to access the Internet through a variety of WiFi hotspots. However, the public WiFi hotpots not only provide conveniences, but also increase the network security risks. The wireless access is faced with serious problems, considering the radiation of the wireless signals, the openness of the space channels and the incredible public wireless hotpots. The paper briefly introduces the WiFi access model and for the incredible issues of the public WiFi hotpots, analyzes the possible security problems from the aspects of content of data, the message header, the domain system and the personal privacy with the experiments that used Wireshark and other software. These problems include the leakage of accounts and passwords when Web contents are pushed in Plaintext, the leakage of behavior trajectories when users use the browsers, the tampering with the Web contents, domain name deception and the leakage of users’ personal privacies. The paper studies these problems in order to enhance the public security awareness of wireless access.

Key words: public WiFi, information leakage, protocol packet, domain hijacking, location privacy

中图分类号: