Submitted:
28 August 2024
Posted:
29 August 2024
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. State of the Art
2.1. Security Threats at the PHY Layer
- Eavesdropping: The malicious entity aims to intercept confidential information transmitted over the air between the transmitter and receiver resulting in privacy breeches, but also in safety challenge when the information captured can be used for further, maybe off-network, attacks.
- Jamming: The goal is to disrupt over-the-air communication, i.e., reducing the SNR of legitimate transmission by transmitting noise/signal that prevents the receiver from decoding the data, thereby causing a denial of service. Jamming and Eavesdropping can be combined to achieve additional goals, for instance Jamming can force devices to change their transmitter power to maintain a given Signal to Interference plus Noise Ratio (SINR) allowing properly places evesdroppers to collect information on the transmitter position without the need to decrypt the signal. This way a proper combination of techniques can build attacks that cannot be protected with available digital techniques.
- Man-in-the-middle A MITM attack at the PHY layer is based on the interception of the signals and the interposition of a device that mimics the other end of the communication for both parties. In general these attacks require to access also higher layers of the communication and to be able to operate on the victim’s data by modifying the transmitted information. The attacker needs to operate both directions of the communications, by establishing a double fake connection, one for the victim device and the other one with the base station in a cellular context, and AP in a Wi-Fi one or in general the “other” device.
- Wormhole: The wormhole attack, instead is based on the manipulation of signals in order to create a rogue tunnel, i.e., a communication path which is not the natural one between the two devices, but instead forces the actual information to be routed through a different physical path, but without the requirement to decode and re-encode all the layers of the communication. Specifically, the attacker does not manipulate the data transmitted but it only routes it through another path, possibly deceiving some specific information, e.g., the propagation time, or tampering with the analog signal or at most with the MAC layer headers to reach his/her goals.
- Spoofing: In this scenario the attacker manipulates some properties of the signals or of the electromagnetic properties of the environment to deceive the victim in some way. A classical example is GPS spoofing, where the attacker tampers the GPS signal to change the location estimated by the target as desired. Another example is MAC address de-anonymization, obtained by smartly using the information contained in standard Wi-Fi probes, whose final outcome is the violation of users’ privacy and security by allowing tracking and more.
2.2. Integrated Sensing and Communication
3. Countermeasures
3.1. Security Threats at the PHY Layer
3.2. Integrated Sensing and Communication
4. Enabling Legitimate Sensing Use
4.1. Four-Way Handshake for Passive Attacks
4.2. Control of the RSI for Active Attacks
5. Discussion
6. Conclusions
Funding
Conflicts of Interest
References
- Arisdakessian, S.; Wahab, O.A.; Mourad, A.; Otrok, H.; Guizani, M. A Survey on IoT Intrusion Detection: Federated Learning, Game Theory, Social Psychology, and Explainable AI as Future Directions. IEEE Internet of Things Journal 2023, 10, 4059–4092. [Google Scholar] [CrossRef]
- Givehchian, H.; Bhaskar, N.; Herrera, E.R.; Soto, H.R.L.; Dameff, C.; Bharadia, D.; Schulman, A. Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile Devices. IEEE Symposium on Security and Privacy (SP), 2022, pp. 1690–1704.
- Gao, K.; Wang, H.; Lv, H.; Gao, P. Your Locations May Be Lies: Selective-PRS-Spoofing Attacks and Defence on 5G NR Positioning Systems. IEEE Conference on Computer Communications (INFOCOM), 2023, pp. 1–10.
- Bartoletti, Stefania and Bianchi, Giuseppe and Orlando, Danilo and Palamà, Ivan and Blefari-Melazzi, Nicola. Location Security under Reference Signals’ Spoofing Attacks: Threat Model and Bounds. 16th ACM International Conference on Availability, Reliability and Security (ARES), 2021.
- Pecorella, T.; Brilli, L.; Mucchi, L. The Role of Physical Layer Security in IoT: A Novel Perspective. MDPI Information 2016, 7. [Google Scholar] [CrossRef]
- Chetty, K.; Smith, G.; Woodbridge, K. Through-the-Wall Sensing of Personnel Using Passive Bistatic WiFi Radar at Standoff Distances. IEEE Trans. on Geoscience and Remote Sensing 2012, 50, 1218–1226. [Google Scholar] [CrossRef]
- Adib, F.; Katabi, D. See through walls with WiFi! ACM Int. Conf. of the Special Interest Group on Data Communication (SIGCOMM);, 2013; pp. 75–86.
- Wang, X.; Gao, L.; Mao, S. CSI Phase Fingerprinting for Indoor Localization with a Deep Learning Approach. Internet of Things Journal 2016, 3, 1113–1123. [Google Scholar] [CrossRef]
- Di Renzo, M.; Debbah, M.; Phan-Huy, D.; et al. . Smart radio environments empowered by reconfigurable AI meta-surfaces: an idea whose time has come. J Wireless Com Network 2019, 129. [Google Scholar] [CrossRef]
- Abbas, M.; Elhamshary, M.; Rizk, H.; Torki, M.; Youssef, M. WiDeep: WiFi-based Accurate and Robust Indoor Localization System using Deep Learning. IEEE Int. Conf. on Pervasive Computing and Communications (PerCom);, 2019; pp. 1–10.
- Lo Cigno, R.; Gringoli, F.; Cominelli, M.; Ghiro, L. Integrating CSI Sensing in Wireless Networks: Challenges to Privacy and Countermeasures. IEEE Network 2022, 36, 174–180. [Google Scholar] [CrossRef]
- Schumann, R.; Li, F.; Grzegorzek, M. WiFi Sensing with Single-Antenna Devices for Ambient Assisted Living. 8th International Workshop on Sensor-Based Activity Recognition and Artificial Intelligence (iWOAR), 2023.
- Mpitziopoulos, A.; Gavalas, D.; Konstantopoulos, C.; Pantziou, G. A survey on jamming attacks and countermeasures in WSNs. IEEE Communications Surveys & Tutorials 2009, 11, 42–56. [Google Scholar]
- Huo, Y.; Tian, Y.; Ma, L.; Cheng, X.; Jing, T. Jamming Strategies for Physical Layer Security. IEEE Wireless Communications 2018, 25, 148–153. [Google Scholar] [CrossRef]
- Wang, N.; Wang, P.; Alipour-Fanid, A.; Jiao, L.; Zeng, K. Physical-Layer Security of 5G Wireless Networks for IoT: Challenges and Opportunities. IEEE Internet of Things Journal 2019, 6, 8169–8181. [Google Scholar] [CrossRef]
- Meghdadi, M.; Ozdemir, S.; Güler, I. A survey of wormhole-based attacks and their countermeasures in wireless sensor networks. IETE technical review 2014, 28, 89–102. [Google Scholar] [CrossRef]
- Conti, M.; Dragoni, N.; Lesyk, V. A survey of man in the middle attacks. IEEE communications surveys & tutorials 2016, 18, 2027–2051. [Google Scholar]
- Deshmukh-Bhosale, S.; Sonavane, S.S. A Real-Time Intrusion Detection System for Wormhole Attack in the RPL based Internet of Things. Procedia Manufacturing 2019, 32, 840–847, 12th International Conference Interdisciplinarity in Engineering, INTER-ENG2018, 4–5 October 2018, Tirgu Mures,Romania. [Google Scholar] [CrossRef]
- Focarelli, G.; Zanini, S.; Bianchi, G.; Bartoletti, S. Physical Layer Threats to 5G Positioning: Impact on TOA-Based Methods. 2024 IEEE International Conference on Communications Workshops (ICC Workshops), 2024, pp. 1–6.
- Orlando, D.; Bartoletti, S.; Palamà, I.; Bianchi, G.; Blefari-Melazzi, N. Innovative Attack Detection Solutions for Wireless Networks With Application to Location Security. IEEE Transactions on Wireless Communications 2023, 22, 205–219. [Google Scholar] [CrossRef]
- Bartoletti, S.; Bianchi, G.; Blefari-Melazzi, N.; Garlisi, D.; Orlando, D.; Palamà, I.; Modarres Razavi, S. , Chapter 5: Security, Integrity, and Privacy Aspects. In Positioning and Location-based Analytics in 5G and Beyond; Wiley, 2024; pp. 99–123.
- Di Luzio, A.; Mei, A.; Stefa, J. Mind your probes: De-anonymization of large crowds through smartphone WiFi probe requests. 35th IEEE International Conference on Computer Communications (INFOCOM), 2016, pp. 1–9.
- Tsiamitros, N.; Mahapatra, T.; Passalidis, I.; Kailashnath, K.; Pipelidis, G. Pedestrian Flow Identification and Occupancy Prediction for Indoor Areas. Sensors 2023, 23. [Google Scholar] [CrossRef]
- Yang, M.H.; Luo, J.N.; Vijayalakshmi, M.; Shalinie, S.M. Contactless Credit Cards Payment Fraud Protection by Ambient Authentication. Sensors 2022, 22. [Google Scholar] [CrossRef] [PubMed]
- Francillon, A.; Danev, B.; Capkun, S. Relay Attacks on Passive Keyless Entry and Start Systems in Modern Cars. Network and Distributed System Security Symposium (NDSS), 2011, pp. 1–16.
- Sheik, A.T.; Maple, C.; Epiphaniou, G.; Dianati, M. Securing Cloud-Assisted Connected and Autonomous Vehicles: An In-Depth Threat Analysis and Risk Assessment. Sensors 2024, 24. [Google Scholar] [CrossRef] [PubMed]
- Anliker, C.; Camurati, G.; Capkun, S. Time for Change: How Clocks Break UWB Secure Ranging. 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 19–36.
- Wu, K.; Xiao, J.; Yi, Y.; Chen, D.; Luo, X.; Ni, L. CSI-Based Indoor Localization. IEEE Trans. Parallel Distrib. Syst. 2013, 24, 1300–1309. [Google Scholar] [CrossRef]
- Ricciato, Fabio and Sciancalepore, Savio and Gringoli, Francesco and Facchi, Nicolò and Boggia, Gennaro. Position and Velocity Estimation of a Non-Cooperative Source From Asynchronous Packet Arrival Time Measurement. IEEE Trans. on Mobile Computing 2018, 17, 2166–2179. [Google Scholar] [CrossRef]
- Rizk, H.; Elmogy, A.; Yamaguchi, H. A Robust and Accurate Indoor Localization Using Learning-Based Fusion of Wi-Fi RTT and RSSI. Sensors 2022, 22. [Google Scholar] [CrossRef]
- Wang, Y.; Wu, K.; Ni, L.M. WiFall: Device-Free Fall Detection by Wireless Networks. IEEE Trans. on Mobile Computing 2017, 16, 581–594. [Google Scholar] [CrossRef]
- Cai, C.; Deng, L.; Zheng, M.; Li, S. PILC: Passive Indoor Localization Based on Convolutional Neural Networks. IEEE Ubiquitous Positioning, Indoor Navigation and Location-Based Services (UPINLBS);, 2018; pp. 1–6.
- Zheng, Y.; Zhang, Y.; Qian, K.; Zhang, G.; Liu, Y.; Wu, C.; Yang, Z. Zero-Effort Cross-Domain Gesture Recognition with Wi-Fi. Proceedings of the 17th Annual International Conference on Mobile Systems, Applications, and Services. ACM, 2019, MobiSys ’19, p. 313–325.
- Meneghello, F.; Garlisi, D.; Fabbro, N.D.; Tinnirello, I.; Rossi, M. SHARP: Environment and Person Independent Activity Recognition With Commodity IEEE 802.11 Access Points. IEEE Transactions on Mobile Computing 2023, 22, 6160–6175. [Google Scholar] [CrossRef]
- Du, R.; Hua, H.; Xie, H.; Song, X.; Lyu, Z.; Hu, M. ; Narengerile.; Xin, Y.; McCann, S.; Montemurro, M.; Han, T.X.; Xu, J. An Overview on IEEE 802.11bf: WLAN Sensing. IEEE Communications Surveys & Tutorials 2024.
- Kaushik, A.; Singh, R.; Dayarathna, S.; Senanayake, R.; Di Renzo, M.; Dajer, M.; Ji, H.; Kim, Y.; Sciancalepore, V.; Zappone, A.; Shin, W. Toward Integrated Sensing and Communications for 6G: Key Enabling Technologies, Standardization, and Challenges. IEEE Communications Standards Magazine 2024, 8, 52–59. [Google Scholar] [CrossRef]
- 3GPP. NR; Physical channels and modulation. Technical Specification (TS) 38.211, 3rd Generation Partnership Project (3GPP), 2023. 18.0.0.
- Qiao, Y.; Zhang, O.; Zhou, W.; Srinivasan, K.; Arora, A. PhyCloak: Obfuscating Sensing from Communication Signals. 13th USENIX Conf. on Networked Systems Design and Implementation (NSDI’16);, 2016; p. 685–699.
- Cominelli, M.; Kosterhon, F.; Gringoli, F.; Lo Cigno, R.; Asadi, A. IEEE 802.11 CSI randomization to preserve location privacy: An empirical evaluation in different scenarios. Elsevier Computer Networks 2021, 191, 107970. [Google Scholar] [CrossRef]
- Cominelli, M.; Gringoli, F.; Lo Cigno, R. On the properties of device-free multi-point CSI localization and its obfuscation. Elsevier Computer Communications 2022, 189, 67–78. [Google Scholar] [CrossRef]
- Cominelli, M.; Gringoli, F.; Lo Cigno, R. AntiSense: Standard-compliant CSI obfuscation against unauthorized Wi-Fi sensing. Elsevier Computer Communications 2022, 185, 92–103. [Google Scholar] [CrossRef]
- Wang, Y.; Sun, L.; Du, Q.; Elkashlan, M. PriSense: Privacy-Preserving Wireless Sensing for Vital Signs Monitoring. IEEE Wireless Communications Letters 2024. [Google Scholar] [CrossRef]
- Ghiro, L.; Cominelli, M.; Gringoli, F.; Lo Cigno, R. Wi-Fi Localization Obfuscation: An implementation in openwifi. Computer Communications 2023, 205, 1–13. [Google Scholar] [CrossRef]
- Jiao, X.; Liu, W.; Mehari, M.; Aslam, M.; Moerman, I. openwifi: a free and open-source IEEE802.11 SDR implementation on SoC. 2020 IEEE 91st Vehicular Technology Conference (VTC2020-Spring), 2020, pp. 1–2.
- Jiao, X.; Liu, W.; Mehari, M.; Thijs, H.; Muhammad, A. open-source IEEE802.11/Wi-Fi baseband chip/FPGA design, 2023.
- Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) Specifications, 2004. Amendment 6: Medium Access Control (MAC) Security Enhancements.
- Gringoli, F.; Klose, R.; Hollick, M.; Nahla, A. Making Wi-Fi Fit for the Tactile Internet: Low-Latency Wi-Fi Flooding Using Concurrent Transmissions. 2018 IEEE International Conference on Communications Workshops (ICC Workshops), 2018.
| 1 | The openwifi project is an Open Source software and hardware implementation of 802.11n. It is available at: https://github.com/open-sdr/openwifi. |
| 2 | The 802.11bf PAR was approved in Sept. 2020 and has already released drafts and other documents, see https://standards.ieee.org/ieee/802.11bf. The current status of the Task Group work can be found in [35]. |
| 3 |







Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).