Cloud Nine Connectivity: Security Analysis of In-Flight Wi-Fi Paywall Systems

  • Abdullah Al Ishtiaq
  • , Raja Hasnain Anwar
  • , Yasra Chandio
  • , Fatima Muhammad Anwar
  • , Syed Rafiul Hussain
  • , Muhammad Taqi Raza

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

In-flight Wi-Fi provides high-speed Internet connectivity to travelers at 30,000 feet at premium fees. In this paper, we present the first systematic study of the architecture and security policies of in-flight Wi-Fi paywall systems using network tomography analysis. We discover that attackers can exploit the inherent architectural shortcomings of airborne networks to create covert channels and conceal data packets within certain ''always-Allowed'' traffic for free Internet access. Moreover, broken device authentication policies in these systems allow unlimited complimentary Internet connectivity. Finally, insecure ARP policies allow attackers to steal paid users' bandwidth to access the free Internet even faster. We validate these issues in practice over two major in-flight Wi-Fi providers using common protocols, e.g., UDP, DNS, etc. We also find that the root causes of these issues stem from different design choices in the architectures of these systems and propose countermeasures to address these flaws and prevent similar attacks.

Original languageEnglish (US)
Title of host publicationWiSec 2025 - Proceedings of the 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks
PublisherAssociation for Computing Machinery, Inc
Pages76-87
Number of pages12
ISBN (Electronic)9798400715303
DOIs
StatePublished - Jun 30 2025
Event18th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2025 - Arlington, United States
Duration: Jun 30 2025Jul 3 2025

Publication series

NameWiSec 2025 - Proceedings of the 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks

Conference

Conference18th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2025
Country/TerritoryUnited States
CityArlington
Period6/30/257/3/25

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Information Systems
  • Software
  • Safety Research
  • Computer Science Applications

Fingerprint

Dive into the research topics of 'Cloud Nine Connectivity: Security Analysis of In-Flight Wi-Fi Paywall Systems'. Together they form a unique fingerprint.

Cite this