{"id":"https://openalex.org/W4225092406","doi":"https://doi.org/10.23919/wons54113.2022.9764586","title":"\u201cCareful with that Roam, Edu\u201d: experimental analysis of Eduroam credential stealing attacks","display_name":"\u201cCareful with that Roam, Edu\u201d: experimental analysis of Eduroam credential stealing attacks","publication_year":2022,"publication_date":"2022-03-30","ids":{"openalex":"https://openalex.org/W4225092406","doi":"https://doi.org/10.23919/wons54113.2022.9764586"},"language":"en","primary_location":{"id":"doi:10.23919/wons54113.2022.9764586","is_oa":false,"landing_page_url":"https://doi.org/10.23919/wons54113.2022.9764586","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 17th Wireless On-Demand Network Systems and Services Conference (WONS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5025702435","display_name":"Ivan Palam\u00e0","orcid":"https://orcid.org/0000-0002-7001-7743"},"institutions":[{"id":"https://openalex.org/I116067653","display_name":"University of Rome Tor Vergata","ror":"https://ror.org/02p77k626","country_code":"IT","type":"education","lineage":["https://openalex.org/I116067653"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Ivan Palama","raw_affiliation_strings":["University of Rome,CNIT,Tor Vergata","CNIT, University of Rome, Tor Vergata"],"affiliations":[{"raw_affiliation_string":"University of Rome,CNIT,Tor Vergata","institution_ids":["https://openalex.org/I116067653"]},{"raw_affiliation_string":"CNIT, University of Rome, Tor Vergata","institution_ids":["https://openalex.org/I116067653"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102742583","display_name":"Alessandro Amici","orcid":"https://orcid.org/0000-0002-9637-8352"},"institutions":[{"id":"https://openalex.org/I116067653","display_name":"University of Rome Tor Vergata","ror":"https://ror.org/02p77k626","country_code":"IT","type":"education","lineage":["https://openalex.org/I116067653"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Alessandro Amici","raw_affiliation_strings":["University of Rome,Tor Vergata","University of Rome, Tor Vergata"],"affiliations":[{"raw_affiliation_string":"University of Rome,Tor Vergata","institution_ids":["https://openalex.org/I116067653"]},{"raw_affiliation_string":"University of Rome, Tor Vergata","institution_ids":["https://openalex.org/I116067653"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034071044","display_name":"Francesco Gringoli","orcid":"https://orcid.org/0000-0003-2621-582X"},"institutions":[{"id":"https://openalex.org/I30667456","display_name":"Brescia University","ror":"https://ror.org/015ahgd08","country_code":"US","type":"education","lineage":["https://openalex.org/I30667456"]},{"id":"https://openalex.org/I79940851","display_name":"University of Brescia","ror":"https://ror.org/02q2d2610","country_code":"IT","type":"education","lineage":["https://openalex.org/I79940851"]}],"countries":["IT","US"],"is_corresponding":false,"raw_author_name":"Francesco Gringoli","raw_affiliation_strings":["University of Brescia,CNIT","CNIT, University of Brescia"],"affiliations":[{"raw_affiliation_string":"University of Brescia,CNIT","institution_ids":["https://openalex.org/I30667456","https://openalex.org/I79940851"]},{"raw_affiliation_string":"CNIT, University of Brescia","institution_ids":["https://openalex.org/I79940851"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5007176500","display_name":"Giuseppe Bianchi","orcid":"https://orcid.org/0000-0001-7277-7423"},"institutions":[{"id":"https://openalex.org/I116067653","display_name":"University of Rome Tor Vergata","ror":"https://ror.org/02p77k626","country_code":"IT","type":"education","lineage":["https://openalex.org/I116067653"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Giuseppe Bianchi","raw_affiliation_strings":["University of Rome,CNIT,Tor Vergata","CNIT, University of Rome, Tor Vergata"],"affiliations":[{"raw_affiliation_string":"University of Rome,CNIT,Tor Vergata","institution_ids":["https://openalex.org/I116067653"]},{"raw_affiliation_string":"CNIT, University of Rome, Tor Vergata","institution_ids":["https://openalex.org/I116067653"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5025702435"],"corresponding_institution_ids":["https://openalex.org/I116067653"],"apc_list":null,"apc_paid":null,"fwci":0.2651,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.59171325,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10651","display_name":"IPv6, Mobility, Handover, Networks, Security","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11158","display_name":"Wireless Networks and Protocols","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/credential","display_name":"Credential","score":0.9490071535110474},{"id":"https://openalex.org/keywords/roaming","display_name":"Roaming","score":0.8569451570510864},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7693099975585938},{"id":"https://openalex.org/keywords/certificate","display_name":"Certificate","score":0.6884442567825317},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.623429000377655},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6231865286827087},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.5413195490837097},{"id":"https://openalex.org/keywords/kerberos","display_name":"Kerberos","score":0.4984719753265381},{"id":"https://openalex.org/keywords/service","display_name":"Service (business)","score":0.46395343542099},{"id":"https://openalex.org/keywords/work","display_name":"Work (physics)","score":0.4504214823246002},{"id":"https://openalex.org/keywords/password","display_name":"Password","score":0.43158233165740967},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.41779381036758423},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.34008121490478516},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.19928684830665588},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.1937425434589386},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.1910741925239563}],"concepts":[{"id":"https://openalex.org/C2777810591","wikidata":"https://www.wikidata.org/wiki/Q16861606","display_name":"Credential","level":2,"score":0.9490071535110474},{"id":"https://openalex.org/C194498986","wikidata":"https://www.wikidata.org/wiki/Q680016","display_name":"Roaming","level":2,"score":0.8569451570510864},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7693099975585938},{"id":"https://openalex.org/C96865113","wikidata":"https://www.wikidata.org/wiki/Q2946816","display_name":"Certificate","level":2,"score":0.6884442567825317},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.623429000377655},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6231865286827087},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.5413195490837097},{"id":"https://openalex.org/C32455479","wikidata":"https://www.wikidata.org/wiki/Q506053","display_name":"Kerberos","level":3,"score":0.4984719753265381},{"id":"https://openalex.org/C2780378061","wikidata":"https://www.wikidata.org/wiki/Q25351891","display_name":"Service (business)","level":2,"score":0.46395343542099},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.4504214823246002},{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.43158233165740967},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.41779381036758423},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.34008121490478516},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.19928684830665588},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.1937425434589386},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.1910741925239563},{"id":"https://openalex.org/C78519656","wikidata":"https://www.wikidata.org/wiki/Q101333","display_name":"Mechanical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.23919/wons54113.2022.9764586","is_oa":false,"landing_page_url":"https://doi.org/10.23919/wons54113.2022.9764586","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 17th Wireless On-Demand Network Systems and Services Conference (WONS)","raw_type":"proceedings-article"},{"id":"pmh:oai:iris.unibs.it:11379/576084","is_oa":false,"landing_page_url":"https://hdl.handle.net/11379/576084","pdf_url":null,"source":{"id":"https://openalex.org/S4306400804","display_name":"Institutional Research Information System (Universit\u00e0 degli Studi di Brescia)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I66752286","host_organization_name":"University of Milano-Bicocca","host_organization_lineage":["https://openalex.org/I66752286"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/4","score":0.4399999976158142,"display_name":"Quality Education"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":10,"referenced_works":["https://openalex.org/W2002443910","https://openalex.org/W2182096981","https://openalex.org/W2291494244","https://openalex.org/W2310384642","https://openalex.org/W2782130228","https://openalex.org/W2958921429","https://openalex.org/W2963121010","https://openalex.org/W3083019178","https://openalex.org/W4253159079","https://openalex.org/W4255216674"],"related_works":["https://openalex.org/W2394359997","https://openalex.org/W2739313573","https://openalex.org/W2031148862","https://openalex.org/W1540917895","https://openalex.org/W1983288955","https://openalex.org/W2372879518","https://openalex.org/W2101816580","https://openalex.org/W2350950651","https://openalex.org/W2492219852","https://openalex.org/W4285327239"],"abstract_inverted_index":{"Eduroam,":[0,47],"which":[1],"stands":[2],"for":[3,81,179],"education":[4,21],"roaming,":[5],"is":[6,101,189],"a":[7,51,57,63,105,153,190],"world-wide":[8],"Wi-Fi":[9,194],"access":[10,37],"and":[11,20,34,79,96,186],"roaming":[12],"service":[13],"largely":[14],"exploited":[15],"by":[16,32],"the":[17,27,43,125,130,184],"international":[18],"research":[19],"community.":[22],"Eduroam\u2019s":[23],"authentication":[24,195],"relies":[25],"on":[26,56,92],"same":[28],"long-term":[29],"credentials":[30,118],"used":[31],"students":[33],"professors":[35],"to":[36,151,162,175,182],"critical":[38],"education/research":[39],"services.":[40],"To":[41],"assess":[42],"real-world":[44],"security":[45],"of":[46,124,129,193],"we":[48,86,116],"i)":[49,156],"implemented":[50],"credential":[52],"stealing":[53],"attack":[54,108],"based":[55],"rogue":[58],"Eduroam":[59,131,159],"setup,":[60],"ii)":[61,166],"ran":[62],"controlled":[64],"experiment":[65],"with":[66,104],"37":[67],"relatively":[68,199],"skilled":[69,200],"real":[70],"world":[71],"users":[72],"(mainly":[73],"electrical":[74],"or":[75],"computer":[76],"engineering":[77],"students),":[78],"iii)":[80,187],"four":[82],"heterogeneous":[83],"selected":[84],"devices,":[85],"investigated":[87],"their":[88,114],"more":[89,120],"detailed":[90],"dependence":[91],"different":[93],"WPA-enterprise":[94],"configurations":[95,160],"certificate":[97],"settings.":[98],"The":[99],"aftermath":[100],"that,":[102],"even":[103,197],"completely":[106],"passive":[107],"(users":[109],"were":[110],"keeping":[111],"devices":[112],"in":[113,134,144,171,198],"pocket),":[115],"stole":[117],"from":[119],"than":[121],"one":[122],"third":[123],"participants.":[126],"While":[127],"most":[128,157],"vulnerabilities":[132],"employed":[133],"this":[135],"work":[136,149],"should":[137],"be":[138,163],"considered":[139],"somewhat":[140],"known":[141],"(being":[142],"disclosed":[143],"former":[145],"technical":[146],"papers),":[147],"our":[148,172],"appears":[150],"raise":[152],"threefold":[154],"concern:":[155],"pragmatic":[158],"appear":[161],"grossly":[164],"insecure;":[165],"no":[167],"Apple\u2019s":[168],"iPhone":[169],"felt":[170],"attack,":[173],"owing":[174],"its":[176],"reduced":[177],"possibility":[178],"an":[180],"user":[181],"misconfigure":[183],"terminal;":[185],"there":[188],"limited":[191],"awareness":[192],"threats":[196],"end":[201],"users.":[202]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2022-04-30T00:00:00"}
