This research paper entails an examination of the Enhanced Wi-Fi protocol, focusing on its control command reverse-engineering analysis and subsequent demonstration of a hijacking attack. Our investigation discovered vulnerabilities in the Enhanced Wi-Fi control commands, rendering them susceptible to hijacking attacks. Notably, the study established that even readily available and cost-effective commercial off-the-shelf Wi-Fi routers could be leveraged as effective tools for executing such attacks. To illustrate this vulnerability, a proof-of-concept remote hijacking attack was carried out on a DJI Mini SE drone, whereby we intercepted the control commands to manipulate the drone's flight trajectory. The findings of this research emphasize the critical necessity of implementing robust security measures to safeguard unmanned aerial vehicles against potential hijacking threats. Considering that civilian drones are now used as war weapons, the study underscores the urgent need for further exploration and advancement in the domain of civilian drone security.
翻译:本研究论文对增强型Wi-Fi协议进行了深入剖析,重点聚焦于其控制指令的逆向工程分析及劫持攻击的实证演示。我们的调查揭示了增强型Wi-Fi控制指令中存在的漏洞,使其易受劫持攻击。值得注意的是,研究证实即使是现成且成本低廉的商用现成Wi-Fi路由器,也可被用作实施此类攻击的有效工具。为说明该漏洞,我们对一架DJI Mini SE无人机实施了概念验证式远程劫持攻击,通过截获控制指令成功操控了无人机的飞行轨迹。本研究结果凸显了实施强效安全措施以保护无人驾驶飞行器免受潜在劫持威胁的迫切必要性。鉴于民用无人机现已被用作战争武器,本研究强调亟需在民用无人机安全领域开展更深入的探索与进步。