CHAOS: Exploiting Station Time Synchronization in 802.11 Networks

Sirus Shahini

Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · WiFi and Bluetooth Security

Overview

This talk, titled "CHAOS: Exploiting Station Time Synchronization in 802.11 Networks," presented by Sirus Shahini, unveils a novel and highly stealthy covert channel strategy that leverages a fundamental, low-level functionality of Wi-Fi networks: the Timing Synchronization Function (TSF). The research demonstrates how inherent, natural fluctuations in the TSF, typically considered noise, can be precisely modulated to establish a secret communication channel that is both remarkably fast and reliable. This work challenges long-held assumptions about the security of foundational Wi-Fi protocols and highlights a significant design issue within the 802.11 standard.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to CHAOS: Exploiting Wi-Fi time synchronization
  2. 0:50 Beacon frames and TSF: Crucial for network time synchronization
  3. 2:40 Unveiling TSF noise: The hidden exploitation opportunity
  4. 4:40 Why TSF noise is ideal: Periodic, high-resolution characteristics
  5. 5:50 CHAOS communication model: Modulating TSF noise for covert data

CHAOS: Exploiting Station Time Synchronization in 802.11 Networks

Speakers: Sirus Shahini

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=kxoFy8OVLKE

Overview

This talk, titled "CHAOS: Exploiting Station Time Synchronization in 802.11 Networks," presented by Sirus Shahini, unveils a novel and highly stealthy covert channel strategy that leverages a fundamental, low-level functionality of Wi-Fi networks: the Timing Synchronization Function (TSF). The research demonstrates how inherent, natural fluctuations in the TSF, typically considered noise, can be precisely modulated to establish a secret communication channel that is both remarkably fast and reliable. This work challenges long-held assumptions about the security of foundational Wi-Fi protocols and highlights a significant design issue within the 802.11 standard.

The significance of CHAOS lies in its ability to facilitate undetectable communication by exploiting existing network traffic rather than injecting new frames or altering firmware in an easily discernible way. This makes it an exceptionally difficult threat to detect or prevent using current network monitoring techniques. The research not only details the technical underpinnings of this exploitation but also explores the profound implications for network security, suggesting that a fundamental re-evaluation of Wi-Fi synchronization protocols may be necessary to address such vulnerabilities.

The findings presented are crucial for security researchers, network architects, and anyone involved in designing or securing wireless communication systems. By exposing a critical, previously overlooked side effect of the TSF, CHAOS underscores the potential for sophisticated adversaries to exfiltrate data or establish command-and-control channels in environments where even the most robust network defenses are deployed. Its reliance on existing, benign network behavior makes it a formidable challenge for conventional detection mechanisms.

Background

▶ Watch: Introduction to CHAOS: Exploiting Wi-Fi time synchronization (0:00)

Modern Wi-Fi networks, operating under the 802.11 standard in infrastructure mode, rely on a constant exchange of various radio frames between stations (access points and clients). These frames are broadly categorized into management, control, data, and extension frames. Among these, beacon frames (type 00, subtype 100) serve several critical purposes. They announce the presence of a network, provide essential network parameters for client association (such as encryption details), and, most importantly, facilitate time synchronization across all connected stations.

The Timing Synchronization Function (TSF) is a high-precision, independent internal clock that must be consistently synchronized across all stations. This synchronization is vital for the proper functioning of the physical layer, enabling power management, signal scheduling, and other low-level radio routines. The 802.11 standard mandates that this synchronization occurs via beacon frames. The access point's firmware periodically transmits beacon frames, each containing the current TSF clock value, allowing other stations to synchronize. The interval between consecutive beacon transmissions is defined as the Target Beacon Transmission Time (TBT), specified as 100 time units, or 102,400 microseconds. This translates to approximately 10 beacons per second per access point.

While the standard prescribes a precise interval, the reality of real-world environments introduces a degree of imprecision. This imprecision, termed TSF noise by the speaker, arises from various factors, including interference from other radio sources, the busy state of the medium when a beacon is scheduled for transmission, or even subtle physical barriers like ambient temperature fluctuations affecting the crystal oscillator's nominal frequency. These factors cause the TSF counter to count slightly faster or slower, introducing minor, seemingly random fluctuations in the reported TSF values. Crucially, this TSF noise does not typically cause functional problems, as the sheer volume of beacons (10 per second) ensures adequate synchronization for normal network operations. However, this research identifies these natural, persistent fluctuations as an unaddressed design issue, creating a fertile ground for exploitation.

Key Findings

▶ Watch: Beacon frames and TSF: Crucial for network time synchronization (0:50)

The central discovery of the CHAOS research is that the seemingly innocuous TSF noise, an inherent byproduct of real-world Wi-Fi operations, possesses unique characteristics that enable the establishment of a remarkably effective timing-based covert channel. This noise, which always exists in 802.11 networks, can be leveraged to embed secret data without introducing new frames or altering existing frames in a way that is easily detectable by standard network monitoring tools.

A critical characteristic identified is the periodic transmission nature of beacon frames, which are generated approximately 10 times per second by any healthy access point. This ensures a constant, high-frequency stream of potential data carriers without requiring any active manipulation or tricking of the access point. Furthermore, the resolution of this natural noise precisely matches the resolution of the 64-bit TSF counter timestamp found in the MAC layer of beacon frames (microseconds). This high-resolution match significantly enhances the precision of timing measurements, which is fundamental for building a stable and high-capacity covert channel.

By exploiting these characteristics, CHAOS demonstrates that a fraction of the background TSF noise can be subtly modulated to embed a separate layer of secret data. This modulation is designed to be discoverable only by a receiver that is aware of the covert channel and possesses the correct configuration set. The resulting channel achieves a surprisingly high data transmission rate for a timing-based covert channel, capable of conveying hundreds of bits per second. This capacity is considered significant and unusual, especially given the stealthy nature of the communication. The research also highlights that the system requires no special equipment or firmware modifications, being capable of running on a low-powered computer like a Raspberry Pi device, making it highly accessible for adversaries.

Technical Deep Dive

▶ Watch: Unveiling TSF noise: The hidden exploitation opportunity (2:40)

The CHAOS system operates by subtly modulating the natural TSF noise present in 802.11 beacon frames to embed secret data. This modulation is achieved without introducing any new network traffic or altering the fundamental structure of beacon frames, rendering the covert channel highly stealthy.

At its core, CHAOS establishes a one-way broadcast channel from a single physical transmitter to any number of receivers. The transmitter does not need to know the receivers' identities. The system's operation hinges on a predefined configuration set shared between the transmitter and aware receivers. This configuration set includes several crucial parameters:

  1. Access Point Grouping: The transmitter targets a set of access points, dividing them into two distinct groups:
  • Tap access points (Tap APs): These are the access points whose TSF noise will be actively modulated to carry the secret data.
  • Cap access points (Cap APs): These access points are used for statistical adaptation to the ambient environment noise, helping to ensure the modulated output blends in with benign TSF noise.
  1. Delay Step: This is an arbitrary value within a specific range. It is used to translate the raw, continuous TSF noise measurements into discrete numerical values, forming the "TSF component of state sequences." This discretization is essential for mapping noise levels to specific data bits.
  1. Tap Rotation Key: This key is used to dynamically change the membership status of defined access points within the Tap and Cap sets. This rotation strategy is critical for the system's stealth, as it prevents the noise characteristics of any single access point from consistently deviating in a detectable manner.

Based on this configuration set, each member (transmitter and receiver) generates a secret permutation space. This space is then used to convert the discretized state sequences (derived from TSF noise) into data bits. Two primary permutation components are utilized:

  1. Beacon Order: Given the density and frequency of beacon transmissions (approximately 10 beacons per second), they do not follow a specific, predictable order in terms of their exact arrival times or the precise TSF values they contain beyond the TBT interval. CHAOS leverages the order of beacons within a specific "purse" (a batch of beacon transmissions) as the first permutation component. This order carries a specific meaning for the channel.
  1. Magnitude of TSF Noise (Delay Level): For each defined Tap access point, the magnitude of its TSF noise, represented as a delay level calculated at runtime based on the configured delay step, forms the second permutation component. This is where the actual modulation occurs, with specific noise magnitudes encoding specific data.

These two permutation components (beacon order and noise magnitude/delay level) are then combined and uniquely mapped to a member within the secret permutation space. This mapping translates the observed TSF noise patterns into a bitstream at the receiver.

From an adversary's perspective, the network environment remains unchanged before and during CHAOS transmission. No new frames are added, and the observed traffic consists only of the usual background TSF noise that is always present. However, for a receiver equipped with the correct configuration set, this noise now carries meaningful, secret data.

A crucial aspect of CHAOS's stealth is the Tap rotation strategy. The researchers observed that benign TSF noise in the environment typically follows a normal or semi-normal distribution. To prevent detection, the CHAOS output is designed to mimic these natural statistical patterns. The Tap rotation key allows for dynamic adjustment of how aggressively this noise adaptation strategy is enforced, ensuring that the modulated noise distribution closely resembles the benign environmental TSF noise. This significantly increases the cost of adversarial measurements and makes it extremely difficult to distinguish the CHAOS-modulated noise from natural fluctuations.

To enhance reliability, the system incorporates RX burst synchronization. This mechanism addresses the issue of missed frames, which can occur even with the best hardware. Even if some beacon frames are lost during transmission or reception, RX burst synchronization enables the receiver to accurately recover the correct payload from the background noise, ensuring robust communication.

The entire system is designed to operate without specialized hardware or firmware modifications. It can be deployed on readily available, low-powered computing devices, such as a Raspberry Pi device, making it highly practical for a wide range of covert applications. The example configuration discussed involved using six access points and 216 delay levels, which can create a massive sample space of approximately 73,000 trillion members, enabling the conveyance of hundreds of bits per second.

Demo / Proof of Concept

▶ Watch: Why TSF noise is ideal: Periodic, high-resolution characteristics (4:40)

While the talk itself did not feature a live, explicit demonstration, Sirus Shahini mentioned that a blog post was published just before the conference, serving as complementary material. This blog post provides "proof of concept examples" that illustrate "how chaos actually works in action." The speaker encourages attendees and readers to consult this resource for a more hands-on understanding of the system's practical implementation and operational dynamics. The paper also details comprehensive examples of the system's behavior and the effectiveness of the Tap rotation strategy in adapting the modulated noise distribution to match benign environmental noise patterns.

Defensive Implications

▶ Watch: CHAOS communication model: Modulating TSF noise for covert data (5:50)

The CHAOS research highlights a profound and inherent vulnerability within the 802.11 protocol's Timing Synchronization Function (TSF). The exploitation of TSF noise is fundamentally a design issue, meaning it stems from the protocol's mandated synchronization strategy rather than a software bug or misconfiguration. This makes traditional mitigation approaches exceedingly difficult.

According to the speaker, this vulnerability is "not something that can be affected by users or even can be disabled at the firmware level." The current synchronization protocol is deeply embedded in the way Wi-Fi networks function. Therefore, simple patches or user-level adjustments are insufficient. The only guaranteed way to address this covert channel and prevent its exploitation would be to implement a "completely new synchronization strategy at the protocol level." This would entail a radical departure from the existing TSF mechanism, requiring significant changes to the 802.11 standard and potentially impacting hardware compatibility.

While some "hacky ways" might offer partial mitigation to a certain extent, they cannot fundamentally stop the exploitation. Even if a new protocol-level synchronization strategy were developed, its deployment would require widespread firmware updates across all Wi-Fi devices, which is a monumental task. The speaker clarified that if a manufacturer were to release a comprehensive patch for a home access point that incorporates a radically different synchronization protocol, then, in principle, it could be patched. However, this is not a simple firmware patch but a complete overhaul of a core network function.

Beyond covert channel communication, the research also points out that the TSF has other inherent issues that enable different forms of exploitation. These include traffic analysis and correlation attacks, which are comprehensively discussed in the accompanying paper, with examples provided for how they could be applied to networks like Tor. This suggests that the TSF's design weaknesses extend beyond covert communication, posing broader risks to privacy and network anonymity.

Key Takeaways

  • TSF Noise Exploitation: The natural, persistent fluctuations in Wi-Fi's Timing Synchronization Function (TSF), known as TSF noise, can be reliably modulated to create a fast and stealthy covert channel.
  • High Stealth and Capacity: CHAOS operates by leveraging existing beacon frames without adding new traffic or altering frames visibly, making it extremely difficult to detect. It achieves "hundreds of bits per second," a significant rate for a timing-based covert channel.
  • Fundamental Design Flaw: The vulnerability is not a bug but an inherent design issue within the 802.11 protocol's synchronization mechanism, making it pervasive across all Wi-Fi networks.
  • Challenging Mitigation: Effective mitigation requires a "completely new synchronization strategy at the protocol level," as simple firmware patches or user-level controls are insufficient to stop the exploit.
  • Accessible Implementation: The system can be deployed on low-powered, off-the-shelf hardware like a Raspberry Pi device, lowering the barrier to entry for potential adversaries.
  • Broader Implications: TSF vulnerabilities extend beyond covert channels, also enabling traffic analysis and correlation attacks, posing wider security and privacy risks.

About the Speaker(s)

The talk "CHAOS: Exploiting Station Time Synchronization in 802.11 Networks" was presented by Sirus Shahini. He noted that he was presenting with Robert Richie, implying a collaborative effort on the research. While specific titles and company affiliations for both individuals were not explicitly detailed in the provided transcript or metadata, Sirus Shahini led the presentation, demonstrating deep expertise in wireless network protocols and security research. His work focuses on uncovering and exploiting low-level functionalities within standard communication protocols to understand their security implications.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Genuine protocol-layer research that reframes TSF noise — previously treated as benign jitter — as a viable, high-capacity covert channel. The attack surface is inherent to 802.11 infrastructure mode, requires no firmware mods, runs on a Raspberry Pi, and has no clean patch path short of a protocol redesign. That's a real contribution.

Heather Calloway (CISO) — WEAK

Technically credible research into a real design-level flaw in 802.11 TSF — the covert channel mechanism is novel and the stealth characteristics are genuinely interesting. But this talk stops at the discovery and offers no actionable path for defenders, operators, or policymakers, and the defensive section amounts to 'you can't fix it without rewriting the standard.'

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025