Warflying in a Cessna

Matt Thomassen, Sean McKeever

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

This talk, "Warflying in a Cessna," presented by Sean McKeever and Matt Thomassen at DEF CON 32, delves into the intriguing concept of collecting wireless access point data from the air. Drawing inspiration from traditional war driving and war dialing, the speakers explored the unique advantages of an aerial perspective for surveying Wi-Fi networks. Their research, born from a casual conversation in November 2019 and navigating the challenges of 2020, sought to revive a topic that had seen little attention in the security community for two decades: the efficacy and implications of war flying.

Watch on YouTube

Visual summary for Warflying in a Cessna by Matt Thomassen, Sean McKeever
Visual summary for Warflying in a Cessna by Matt Thomassen, Sean McKeever

Key moments

  1. 0:50 The unexpected idea: A plane and Wi-Fi
  2. 1:18 Defining 'Warflying': Scanning Wi-Fi from the air
  3. 2:00 The Cessna 182: Our aerial Wi-Fi collection platform
  4. 3:10 Why warfly? Unlocking line of sight advantages
  5. 4:20 Aviation safety first: Aviate, Navigate, Communicate
  6. 5:30 First data collection attempt: A critical learning error
  7. 6:15 Solo warflying procedure: Automated phone data collection
  8. 8:20 Summary of test flights and data collection efforts

Warflying in a Cessna

Speakers: Matt Thomassen, Commercial Multi-Engine Pilot & A&P Mechanic; Sean McKeever, Senior Security Researcher

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=anrgU7LjN1A

Overview

This talk, "Warflying in a Cessna," presented by Sean McKeever and Matt Thomassen at DEF CON 32, delves into the intriguing concept of collecting wireless access point data from the air. Drawing inspiration from traditional war driving and war dialing, the speakers explored the unique advantages of an aerial perspective for surveying Wi-Fi networks. Their research, born from a casual conversation in November 2019 and navigating the challenges of 2020, sought to revive a topic that had seen little attention in the security community for two decades: the efficacy and implications of war flying.

The core premise of their work centers on the fundamental physics of radio frequency (RF) propagation. By elevating a scanning device to several thousand feet above ground level in a general aviation aircraft, specifically a Cessna 182, the researchers aimed to overcome the significant line-of-sight limitations that hinder ground-based Wi-Fi reconnaissance. This novel approach allowed them to quickly cover vast geographical areas and potentially detect wireless networks that would be invisible from street level due to obstructions like buildings, terrain, and vegetation.

The talk is significant for several reasons. Firstly, it reignites a previously explored but largely abandoned avenue of security research, prompting a re-evaluation of aerial network reconnaissance capabilities. Secondly, it highlights the practical considerations and safety protocols paramount when combining aviation with security research, emphasizing the "aviating, navigating, communicating" hierarchy in flight. Finally, it serves as a foundational exploration into how an elevated vantage point can drastically alter the scope and scale of network discovery, offering new perspectives for both offensive and defensive security strategies in a world increasingly reliant on ubiquitous wireless connectivity.

Background

▶ Watch: The unexpected idea: A plane and Wi-Fi (0:50)

The concept of "war" activities in cybersecurity has a rich history, beginning with war dialing in the 1980s, where attackers used modems to systematically dial phone numbers in search of vulnerable computer systems. This evolved into war driving with the advent of Wi-Fi, involving individuals driving around with Wi-Fi scanners (often laptops with specialized antennas) to map out wireless access points and identify unsecured networks. Tools like Wiggle (Wigle.net), mentioned by the speakers, have become central to this community, aggregating vast databases of Wi-Fi networks globally.

The primary motivation behind war driving, and by extension war flying, is to understand the prevalence and configuration of wireless networks within a given area. This can range from identifying open Wi-Fi networks that could be exploited for unauthorized access to mapping the physical footprint of an organization's wireless infrastructure. However, ground-based war driving is inherently limited by line of sight. Wi-Fi signals, operating in the 2.4 GHz and 5 GHz bands, are highly susceptible to attenuation and obstruction by physical barriers such as buildings, trees, and terrain. This means that a war driver on the ground might only detect access points within a relatively small, unobstructed radius.

Matt Thomassen and Sean McKeever identified this line-of-sight constraint as the critical bottleneck that war flying could potentially overcome. By raising a scanner to altitudes of 1,500 to 2,500 feet above ground, the effective range and visibility of Wi-Fi signals increase dramatically. The speakers noted that while a paper on collecting wireless access point data from the air was published approximately 20 years ago, there has been "not a lot of discussion or work on the topic since then." This observation provided a compelling impetus for their research: to re-explore the practicalities, findings, and implications of aerial Wi-Fi scanning in the contemporary security landscape, particularly given the pervasive nature of Wi-Fi networks today. Their work sought to answer whether the theoretical advantages of elevated line of sight translated into practical, scalable data collection.

Key Findings

▶ Watch: The Cessna 182: Our aerial Wi-Fi collection platform (2:00)

The "Warflying in a Cessna" talk presented several key findings, primarily revolving around the feasibility, safety, and initial data collection challenges and successes of aerial Wi-Fi scanning. The speakers underscored the significant advantage gained by leveraging line of sight from an aircraft, explaining that radio frequencies, particularly those used by Wi-Fi, are heavily impacted by terrestrial interference from objects, vegetation, and buildings. Elevating the scanning device effectively "raises one end of the radio conversation," potentially enabling detection over much greater distances and with fewer obstructions.

One immediate and crucial finding concerned the safety protocols essential for such an endeavor. The speakers heavily emphasized the aviation mantra: "aviating, navigating, and communicating." The pilot's primary responsibility is always to "aviate" – keep the airplane flying safely. Only once safe flight is assured should "navigate" (knowing where you are and where you're going) be considered, and finally "communicate" (talking on the radio). This hierarchy directly impacted their methodology, dictating that scanning equipment must not distract the pilot, especially during critical phases of flight like taxi, takeoff, approach, landing, and low-level maneuvering. This led to the conclusion that war flying is "best done as a team sport," with one person piloting and another managing the scanning equipment.

However, a significant finding related to solo operation emerged from Matt Thomassen's second flight. He demonstrated that safe solo war flying is indeed possible under specific conditions. His procedure involved initiating the Wiggle application on a Google Pixel phone during pre-flight checks, before engine start, then leaving it untouched throughout the flight. Data collection was only reviewed after the airplane was safely shut down. This method successfully mitigated the distraction risk, allowing Matt to focus solely on piloting while still gathering data over an unpopulated "northeast practice area." This demonstrated a pragmatic approach to integrate security research with strict aviation safety.

Regarding data collection itself, the initial attempts revealed a critical limitation: the difficulty in precisely pinpointing the location of detected access points. The first flight's data analysis showed "the same distance for every single device," indicating an issue likely related to the Wiggle app's default behavior or the rapid movement of the aircraft. When flying at 150 miles per hour and altitudes between 1,500 and 2,500 feet above ground, the scanning device would detect an access point for a period, but the exact moment and corresponding precise GPS coordinate of the access point itself remained elusive. The result was a "blob" of detection rather than a precise point, making it impossible to say "oh, that's Sean's house down there." The speakers concluded that more precise geolocation, or triangulation, would likely require multiple passes over the same area from different angles to refine the data, a challenge for future research.

Despite these initial localization challenges, the overarching finding was the feasibility and potential of war flying. The ability to collect Wi-Fi data from an aircraft, even with current limitations, opens up new possibilities for large-scale network mapping and understanding RF propagation in complex environments. The speakers successfully demonstrated that aerial Wi-Fi reconnaissance is not just a theoretical concept but a practical method, albeit one that demands careful planning, adherence to safety protocols, and further refinement in data analysis techniques.

Technical Deep Dive

▶ Watch: Aviation safety first: Aviate, Navigate, Communicate (4:20)

The technical execution of the "Warflying in a Cessna" project involved a straightforward yet effective combination of readily available tools and a standard general aviation aircraft, coupled with rigorous adherence to aviation safety principles.

The primary platform for their aerial reconnaissance was a Cessna 182 aircraft. The speakers described it as a "four-seat airplane" with a "high wing," a crucial feature providing "a little better visibility to the ground" compared to low-wing aircraft. This enhanced visibility is paramount for both flight safety and the efficacy of aerial scanning. The aircraft was powered by a "200-230 horsepower engine," allowing it to cruise comfortably at "around 150 miles an hour." With "six hours of fuel," or approximately "5 hours with reserve," the Cessna 182 offered substantial endurance, enabling extended flight paths and coverage of large geographical areas without needing frequent refueling. This combination of speed, range, and visibility made it an ideal choice for their exploratory war flying missions.

For Wi-Fi scanning, the researchers utilized a Google Pixel smartphone running the Wiggle application. Wiggle (Wigle.net) is a popular open-source tool and online database for collecting and mapping wireless networks (Wi-Fi, Bluetooth, cellular towers). It uses the phone's internal Wi-Fi radio and GPS receiver to scan for access points, record their Service Set Identifiers (SSIDs), Basic Service Set Identifiers (BSSIDs/MAC addresses), signal strength (RSSI), encryption types, and GPS coordinates. The simplicity of using a standard smartphone with a readily available app minimized the need for specialized, bulky, or custom-built equipment in the confined space of a small aircraft. Sean McKeever, an Apple user, had to borrow his girlfriend's Android-based Google Pixel, highlighting the platform-specific nature of certain scanning tools.

The data collection methodology involved a series of test flights. For the initial flights, the phone was simply "held in my lap" by the non-piloting researcher. Flight parameters were consistently maintained:

  • Altitude: Primarily between 1,500 to 2,500 feet Above Ground Level (AGL). For specific passes, this translated to 2,500 feet Above Sea Level (MSL) (which is 1,500 feet AGL) and 3,500 feet MSL (which is 2,500 feet AGL). Operating at these altitudes allowed for a broad line of sight while remaining within typical general aviation operating envelopes.
  • Speed: Approximately 150 miles per hour, matching the aircraft's comfortable cruising speed. This speed allowed for efficient coverage of territory.

A critical aspect of the technical deep dive was the safety protocol established, particularly for solo flights. Matt Thomassen's solo procedure for collecting data involved:

  1. Pre-flight initiation: Starting the Wiggle app on the Google Pixel during pre-flight checks, before the aircraft engine was started.
  2. Hands-off operation: Once Wiggle was activated, the phone was left untouched and unattended throughout the flight. This ensured no distraction to the pilot.
  3. Post-flight data review: Only after the aircraft was safely shut down and secured was the collected Wiggle data accessed and reviewed.

This systematic approach directly addressed the paramount safety concern of pilot distraction, demonstrating a responsible integration of security research with aviation operations. The speakers also acknowledged the cooperation of air traffic control, specifically "Pontiac Tower and Detroit Approach," who worked with them despite "having no idea what we were doing up there," underscoring the importance of clear communication and adherence to aviation regulations.

The initial data analysis revealed a limitation: the inexactness of access point location. The rapid movement of the aircraft combined with the phone's scanning interval resulted in "a blob for each one," meaning researchers knew where they started and stopped detecting a signal, but not the precise location of the access point. This challenge points to the need for more sophisticated geolocation techniques such as multilateration or signal strength mapping over multiple passes to achieve higher precision in future war flying endeavors. Despite this, the ability to rapidly identify large numbers of access points over a broad area, even with approximate locations, confirmed the fundamental efficacy of the war flying methodology.

Demo / Proof of Concept

▶ Watch: First data collection attempt: A critical learning error (5:30)

The practical demonstration and proof of concept for war flying were conducted through a series of test flights over a well-known area in Michigan. The speakers specifically detailed their first flight, which served as a primary proof of concept for aerial Wi-Fi data collection.

This initial flight involved three distinct passes down Woodward Avenue, a historically significant roadway in Michigan renowned for the Woodward Dream Cruise and identified as Michigan Highway 1. Choosing this location provided a familiar and populated urban/suburban corridor for their initial data gathering efforts.

The flight profile for these passes was as follows:

  • Two passes were conducted at an altitude of 2,500 feet above sea level (MSL), which translated to approximately 1,500 feet above ground level (AGL) over the terrain.
  • One pass was conducted at a higher altitude of 3,500 feet MSL, equating to roughly 2,500 feet AGL.

During these passes, the single Google Pixel phone running the Wiggle application was actively scanning for Wi-Fi access points. The phone was simply "held in my lap" by the non-piloting speaker, Sean McKeever, while Matt Thomassen piloted the Cessna 182 at its cruising speed of approximately 150 miles per hour.

The data collected during these flights, while not presented in granular detail during the talk, was visualized through maps. The speakers showed a map illustrating "the various air spaces that we were operating in" and highlighted their actual flight path with "orange yellow squiggles." A more relatable "road map" was also shown, depicting "the circles you can see on the right side that would be our our laps around Woodward." This visual representation confirmed the successful execution of the flight plan and the active collection of data along the designated route.

While the "demo" was not a live, interactive demonstration of tools, the presentation of the flight path maps and the discussion of data collection parameters served as a clear proof of concept. It validated the ability to conduct aerial Wi-Fi scanning using off-the-shelf equipment from a general aviation aircraft. The primary limitation encountered, as discussed in "Key Findings," was the "very in-exact" nature of pinpointing specific access point locations from a single pass. The rapid speed and altitude meant they could only identify a "blob" indicating where an access point was detected, rather than its precise coordinates. The speakers suggested that "if we can see them more than once over multiple flights, we could maybe pinpoint it a little better," pointing towards future refinements in the methodology for more accurate geolocation. This exploratory phase successfully demonstrated that war flying is possible and what its initial challenges are, setting the stage for further research.

Defensive Implications

▶ Watch: Summary of test flights and data collection efforts (8:20)

While the "Warflying in a Cessna" talk was primarily an exploratory and proof-of-concept endeavor, focusing on the feasibility and challenges of aerial Wi-Fi scanning, the underlying implications for network security professionals are significant. The very act of demonstrating the ability to rapidly map Wi-Fi networks from the air highlights potential vulnerabilities and necessitates a re-evaluation of defensive strategies.

The most direct defensive implication stems from the enhanced line of sight achieved through war flying. Traditional ground-based war driving is limited by physical obstructions, meaning organizations might feel a false sense of security for networks not easily detectable from public roads. However, an aerial perspective can expose networks that are otherwise "hidden" from ground-level observation. This includes Wi-Fi access points on higher floors of buildings, those serving remote facilities, or even unintentionally broadcasting internal networks that were assumed to be localized. Defenders should recognize that their wireless footprint might be significantly larger and more visible to an airborne adversary than previously thought.

This capability implies that organizations need to adopt a "top-down" perspective when assessing their wireless security posture. It's no longer sufficient to only perform ground-level surveys. Instead, security teams should consider:

  1. Comprehensive Wireless Audits: Conduct regular, thorough wireless audits that account for potential aerial visibility. This might involve using specialized tools to estimate signal propagation from high-altitude perspectives or, ideally, conducting their own simulated war flying exercises.
  2. Physical Security of Access Points: Ensure that access points are deployed with an understanding of their broadcast range, both horizontally and vertically. While an access point on the 10th floor might not be reachable from the street, it could be easily detectable from an aircraft at 2,000 feet. This reinforces the need to secure all corporate SSIDs, even those intended for internal use only, with strong encryption (e.g., WPA3) and robust authentication.
  3. Minimizing Unintentional Broadcasts: Review Wi-Fi configurations to minimize unintentional broadcasts of sensitive SSIDs. This includes disabling guest networks when not in use and ensuring that management interfaces are not exposed wirelessly. While SSID hiding offers minimal security, understanding its limitations in an aerial context is important.
  4. Network Segmentation and Least Privilege: Even if an access point is detected from the air, robust network segmentation can limit the damage an attacker could inflict. If an attacker gains access to a Wi-Fi network, ensuring it's segmented from critical internal resources, and that users on that network operate with the principle of least privilege, reduces the attack surface.
  5. Awareness of Open/Weakly Secured Networks: The ease with which war flying can identify open or weakly secured networks (e.g., WEP, WPA-Personal with weak passphrases) means that such networks become immediate targets. Organizations should actively monitor for and eliminate these vulnerabilities within their operational areas.
  6. Geolocation Challenges for Attackers: While war flying offers broad detection, the speakers highlighted the difficulty in precisely pinpointing access point locations from a single pass. This limitation provides a small defensive buffer, as attackers would still need to conduct more precise ground-based reconnaissance or multiple aerial passes to accurately locate a target for physical exploitation. However, the initial detection still provides valuable reconnaissance for an adversary.

In essence, the "Warflying in a Cessna" talk serves as a call to action for defenders to broaden their threat model to include aerial reconnaissance. It underscores that the physical boundaries and obstructions that typically limit ground-based adversaries are significantly diminished when an attacker operates from the sky, making comprehensive wireless security more critical than ever.

Key Takeaways

  • War flying offers significant line-of-sight advantages over traditional war driving, enabling detection of Wi-Fi access points from greater distances and over vast areas due to reduced terrestrial interference.
  • Aviation safety is paramount: The "aviating, navigating, communicating" hierarchy dictates that flying the aircraft safely must always be the pilot's top priority, requiring careful planning to avoid distraction from scanning equipment.
  • Solo war flying is feasible with strict protocols: By initiating scanning (e.g., Wiggle on a Google Pixel) before flight and leaving it undisturbed until after landing, a single pilot can safely collect Wi-Fi data without compromising flight safety.
  • Initial data collection provides broad coverage but lacks precision: While war flying can quickly identify many access points over a large area (e.g., Woodward Avenue at 1,500-2,500 ft AGL), pinpointing their exact ground location from a single pass remains a challenge, often resulting in "blob" data rather than precise coordinates.
  • General aviation aircraft are suitable platforms: A standard Cessna 182 (four-seat, high-wing, 200-230 HP, 150 mph cruise, 5-6 hours endurance) provides an effective and accessible platform for this type of research.
  • War flying reignites overlooked research: This project re-explores a topic largely untouched for two decades, highlighting the potential for new insights into wireless network reconnaissance and security from an aerial perspective.

About the Speaker(s)

Sean McKeever is a Senior Security Researcher based in Metro Detroit. Beyond his professional work in security, he is also an enthusiast who "raises cars," indicating a passion for automotive culture. His involvement in the war flying project stemmed from a desire to explore security topics outside of his typical work constraints.

Matt Thomassen also hails from Metro Detroit and works in security, though he notes his day job has "pretty much nothing whatsoever to do with war flying." He is a highly accomplished aviator, holding a commercial multi-engine pilot license with an instrument rating. Additionally, he is a licensed airframe and power plant mechanic, demonstrating a deep and comprehensive understanding of aircraft operations and maintenance. His extensive aviation expertise was foundational to the feasibility and safety of the war flying research.

All talks from DEF CON 32 Creator Stage