{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T23:59:14Z","timestamp":1785801554604,"version":"3.56.0"},"reference-count":78,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100005153","name":"China National Funds for Distinguished Young Scientists","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100005153","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179441","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"3162-3177","source":"Crossref","is-referenced-by-count":19,"title":["Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects"],"prefix":"10.1109","author":[{"given":"Xuewei","family":"Feng","sequence":"first","affiliation":[{"name":"Tsinghua University,Department of Computer Science and Technology &amp; BNRist"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Li","sequence":"additional","affiliation":[{"name":"Institute for Network Sciences and Cyberspace &amp; BNRist, Tsinghua University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kun","family":"Sun","sequence":"additional","affiliation":[{"name":"George Mason University,Department of Information Sciences and Technology &amp; CSIS"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuxiang","family":"Yang","sequence":"additional","affiliation":[{"name":"Tsinghua University,Department of Computer Science and Technology &amp; BNRist"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ke","family":"Xu","sequence":"additional","affiliation":[{"name":"Tsinghua University,Department of Computer Science and Technology &amp; BNRist"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1514274.1514286"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45537-X_1"},{"key":"ref3","article-title":"Cracking wep passwords with aircrack-ng","author":"TO"},{"key":"ref4","article-title":"Weakness in passphrase choice in wpa interface","author":"Moskowitz","year":"2003"},{"key":"ref5","first-page":"66","article-title":"A practical message falsification attack on wpa","volume-title":"Proc. JWIS","volume":"54","author":"Ohigashi"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134027"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243807"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00031"},{"key":"ref9","article-title":"Fragment and forge: Breaking wi-fi through frame aggregation and fragmentation","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Vanhoef"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3447993.3448620"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2011.125"},{"key":"ref12","first-page":"322","article-title":"Risk analysis of a fake access point attack against wi-fi network","volume":"9","author":"Alsahlany","year":"2018","journal-title":"International Journal of Scientific & Engineering Research"},{"key":"ref13","article-title":"Understanding evil twin ap attacks and how to prevent them","author":"Orsi","year":"2018"},{"key":"ref14","article-title":"Internet Control Message Protocol","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 792","author":"Postel","year":"1981"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.17487\/rfc4861"},{"key":"ref16","article-title":"Icmp attacks illustrated","author":"Low"},{"key":"ref17","article-title":"Attacks on tcp\/ip protocols","author":"Myers"},{"issue":"6","key":"ref18","article-title":"Router attacks-detection and defense mechanisms","volume":"2","author":"Waichal","year":"2013","journal-title":"International Journal of Scientific & Technology Research"},{"key":"ref19","article-title":"Man in the middle attacks","volume-title":"Blackhat Conference Europe","volume":"1045","author":"Ornaghi"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/378444.378449"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.3"},{"key":"ref22","author":"Du","year":"2019","journal-title":"Computer & Internet Security: A Hands-on Approach"},{"key":"ref23","article-title":"Icmp redirect attacks with scapy","author":"Ivan"},{"key":"ref24","article-title":"Better spoofing of icmp host redirect messages with scapy","author":"Thyer"},{"key":"ref25","article-title":"Icmp redirect attacks in the wild","author":"Ayer"},{"key":"ref26","article-title":"Doubledirect","author":"Zimperium"},{"key":"ref27","doi-asserted-by":"crossref","DOI":"10.17487\/rfc1122","article-title":"Requirements for Internet Hosts - Communication Layers","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 1122","author":"Braden","year":"1989"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3278532.3278559"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/IWQoS49365.2020.9212980"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2022.3145040"},{"key":"ref31","article-title":"v6disc","author":"Miller"},{"key":"ref32","article-title":"The network mapper","author":"Nmap"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.1985.1092530"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2003.1235598"},{"key":"ref35","doi-asserted-by":"crossref","DOI":"10.17487\/rfc3022","article-title":"Traditional IP Network Address Translator (Traditional NAT)","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 3022","author":"Srisuresh","year":"2001"},{"key":"ref36","doi-asserted-by":"crossref","DOI":"10.17487\/rfc5508","article-title":"NAT Behavioral Requirements for ICMP","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 5508","author":"Srisuresh","year":"2009"},{"key":"ref37","article-title":"Packet crafting for python2 and python3","author":"Scapy"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417280"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3486219"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23171"},{"key":"ref41","article-title":"Understanding infrastructure mode in wireless networking","author":"Mitchell"},{"key":"ref42","doi-asserted-by":"crossref","DOI":"10.17487\/rfc1812","article-title":"Requirements for IP Version 4 Routers","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 1812","author":"Baker","year":"1995"},{"key":"ref43","doi-asserted-by":"crossref","DOI":"10.17487\/rfc3013","article-title":"Recommended Internet Service Provider Security Services and Procedures","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 3013","author":"Killalea","year":"2000"},{"key":"ref44","doi-asserted-by":"crossref","DOI":"10.17487\/rfc5210","article-title":"A Source Address Validation Architecture (SAVA) Testbed and Deployment Experience","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 5210","author":"Wu","year":"2008"},{"key":"ref45","doi-asserted-by":"crossref","DOI":"10.17487\/rfc7039","article-title":"Source Address Validation Improvement (SAVI) Framework","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 7039","author":"Wu","year":"2013"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1002\/spy2.49"},{"key":"ref47","article-title":"Arp spoofing protection for linux kernels","volume-title":"Linux"},{"key":"ref48","article-title":"csploit","author":"Materialize"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1186\/1687-1499-2012-89"},{"issue":"2","key":"ref50","first-page":"82","article-title":"Holistic approach to arp poisoning and countermeasures by using practical examples and paradigm","volume":"5","author":"Rahman","year":"2014","journal-title":"International Journal of Advancements in Technology"},{"key":"ref51","article-title":"Network analysis: Investigating icmp redirects (here\u2019s why you should pay attention to icmp redirects in network troubleshooting)","author":"Fortunato"},{"key":"ref52","article-title":"Wireless lan networking"},{"key":"ref53","article-title":"Discover wi-fi security","author":"Alliance"},{"key":"ref54","article-title":"How secure is wi-fi really","author":"Robinson"},{"key":"ref55","article-title":"New attack on wpa\/wpa2 using pmkid","author":"Steube"},{"key":"ref56","first-page":"12","article-title":"A survey on wireless security protocol wpa2","volume-title":"Proceedings of the international conference on security and management (SAM). The Steering Committee of The World Congress in Computer Science, Computer \u2026","author":"Alblwi"},{"key":"ref57","article-title":"Wpa3 specification","author":"Alliance"},{"key":"ref58","article-title":"Type=5, code=1 (or lady in the middle)","author":"Kulas"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417884"},{"key":"ref60","first-page":"209","article-title":"Off-path tcp exploits: Global rate limit considered dangerous","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Cao"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2018.2797081"},{"key":"ref62","first-page":"1581","article-title":"Off-path tcp exploit: How wireless routers can jeopardize your secrets","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Chen"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2021.3115517"},{"key":"ref64","article-title":"Persistent ospf attacks","volume-title":"NDSS, 2012","author":"Nakibly"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664278"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2017.7996829"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/997150.997152"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3211852.3211862"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.23919\/TMA.2019.8784511"},{"key":"ref70","first-page":"2","article-title":"Fragmentation considered vulnerable: Blindly intercepting and discarding fragments","volume-title":"Proceedings of the 5th USENIX conference on Offensive technologies","author":"Gilad"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/2445566.2445568"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2013.6682711"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243790"},{"key":"ref74","first-page":"254","article-title":"Towards adoption of dnssec: Availability and security challenges","volume":"2013","author":"Herzberg","year":"2013","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref75","doi-asserted-by":"crossref","DOI":"10.17487\/rfc1981","article-title":"Path mtu discovery for ip version 6","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 1981","author":"McCann","year":"1996"},{"key":"ref76","doi-asserted-by":"crossref","DOI":"10.17487\/rfc1191","article-title":"Path mtu discovery","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 1191","author":"Mogul","year":"1990"},{"key":"ref77","doi-asserted-by":"crossref","DOI":"10.17487\/RFC8205","article-title":"BGPsec Protocol Specification","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 8205","author":"Lepinski","year":"2017"},{"key":"ref78","doi-asserted-by":"crossref","DOI":"10.17487\/rfc5709","article-title":"OSPFv2 HMAC-SHA Cryptographic Authentication","volume-title":"Internet Requests for Comments, Internet Engineering Task Force, RFC 5709","author":"Bhatia","year":"2009"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179441.pdf?arnumber=10179441","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,21]],"date-time":"2024-07-21T04:18:57Z","timestamp":1721535537000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179441\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":78,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179441","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}