AUDIT@eduroam: A Security Auditing Tool for the eduroam Infrastructure

  • Fabiano Losilla de Carvalho IFPB / UFSCar
  • Luciana Pereira Oliveira IFPB
  • Erick Lazaro Melo UFSCar

Resumo


The eduroam federation enables global academic mobility through IEEE 802.1X and RADIUS standards. However, non-compliance with RFC 7593 leaves user credentials vulnerable. To address this, AUDIT@eduroam introduces a three-stage automated framework: (1) data acquisition, (2) static client-side analysis of CAT profiles, and (3) dynamic server-side verification via RADIUS logs. Validation across 148 IdPs over three execution cycles revealed that theoretical compliance (39.86%) drops to just 2.70% in dynamic tests, with 81.08%-83.11% of institutions failing due to expired certificates and identity exposure. These findings underscore a state of insecurity within the infrastructure, highlighting the need for continuous, automated monitoring of the network.

Referências

Ahmed, F., Li, X., Niu, Y., Zhang, C., Wei, L., and Gu, C. (2020). Uniroam: An anonymous and accountable authentication scheme for cross-domain access. In 2020 International Conference on Networking and Network Applications (NaNA), pages 198–205.

Batista, L. M., Gomes, H., and Almeida, J. R. (2024). A study of security issues of eduroam networks in portugal. In 13th Symposium on Languages, Applications and Technologies (SLATE 2024), pages 14:1–14:14. Schloss Dagstuhl – Leibniz-Zentrum für Informatik.

Batista, L. M., Gomes, H., and Almeida, J. R. (2025). Challenges and solutions for eduroam network security. Procedia Computer Science, 256:150–157. CENTERIS - International Conference on ENTERprise Information Systems / ProjMAN - International Conference on Project MANagement / HCist - International Conference on Health and Social Care Information Systems and Technologies.

Caballero, A., Garcia-Valverde, T., Pereniguez, F., and Botia, J. A. (2016). Activity recommendation in intelligent campus environments based on the eduroam federation. Journal of Ambient Intelligence and Smart Environments, 8(1):35–46.

Daldoul, Y. and Berrima, M. (2025). A robust certificate management system to prevent evil twin attacks in ieee 802.11 networks. International Journal of Information Technology, 17(6):3589–3599.

Dekkar, L. and Fiore, S. (2021). Africaconnect3: Connecting africa to unlimited possibilities. In IST-Africa 2021 Conference Proceedings. IST-Africa Institute and IIMC.

Ferraiolo, H. and Regenscheid, A. (2024). Cryptographic algorithms and key sizes for personal identity verification. Technical Report NIST Special Publication (SP) 800-78-5, National Institute of Standards and Technology (NIST), Gaithersburg, MD.

GEANT (2009). Report on introduction of monitoring system and diagnostics tools. Deliverable GN2-09-008v2, GEANT Association. Accessed: 2024-05-22.

Goto, H. (2025). Offline attribute sharing methods for authentication traffic reduction and functionality enhancement of wireless lan roaming systems. In 2025 IEEE 49th Annual Computers, Software, and Applications Conference (COMPSAC), pages 2224–2229.

GÉANT (2011). Configuration assistant tool. [link]. Acessado em: 15 mar. 2026.

Júnior, C. A. J., da Rocha, L. F., Torres, R., and Silva, E. F. (2024). Monitoramento da última milha do eduroam com wifimon. In Anais do XIV Workshop de Gestão de Identidades Digitais (WGID). Sociedade Brasileira de Computação (SBC).

Lima, M. L. G., Campos, P. H. L., and Matias, P. (2021). Módulo de autenticação via eduroam para o pluggable authentication modules. In Anais do XI Workshop de Gestão de Identidades Digitais (WGID). SBC.

Mazhar, H., Kaiser, M., Smith, M., and Adams, C. (2021). All your credentials are belong to us: On insecure WPA2-Enterprise configurations. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS). Acessado em: 26 mar. 2026.

McKay, K. A. and Cooper, D. A. (2019). Guidelines for the selection, configuration, and use of transport layer security (tls) implementations. Technical Report NIST Special Publication (SP) 800-52 Rev. 2, National Institute of Standards and Technology, Gaithersburg, MD.

Okabe, Y., Nakamura, M., and Goto, H. (2024). Dynamic vlan assignment for local users under external idp management in radius-based wi-fi roaming. In 2024 International Conference on Information Networking (ICOIN), pages 484–489.

Oliveira, L. A. and Silva, E. F. (2024). Evaluation of eap usage for authenticating eduroam users in 5g networks. arXiv preprint arXiv:2402.10889.

Orús Comabella, G. (2025). Autenticació segura en xarxes acadèmiques: Desplegament d’un servidor radius per eduroam. Master’s thesis, Universitat Autònoma de Barcelona.

Palamà, I., Amici, A., Bellicini, G., Gringoli, F., Pedretti, F., and Bianchi, G. (2023). Attacks and vulnerabilities of wi-fi enterprise networks: User security awareness assessment through credential stealing attack experiments. Computer Communications, 212:129–140.

Palamà, I., Amici, A., Gringoli, F., and Bianchi, G. (2022). “careful with that roam, edu”: experimental analysis of eduroam credential stealing attacks. In 2022 17th Wireless On-Demand Network Systems and Services Conference (WONS), pages 1–7.

Petrosyan, A. S., Petrosyan, G. S., Tadevosyan, R. N., and Arsalanian, K. K. (2019). Identity infrastructure boost concept for eduroam service. Mathematical Problems of Computer Science, 52:61–65.

Rieckers, J.-F. (2021). Passive security analysis of current TLS implementations and configurations in the eduroam EAP-TLS environment. Bachelor’s thesis, Universität Bremen, Bremen, Alemanha. Acessado em: 26 mar. 2026.

Torres, R., Silva, E. F., and Júnior, C. A. d. J. (2025). Desenvolvimento de um App eduroam na RNP. In Anais Estendidos do SBSeg 2025: WGID.

Turner, P. and Woodward, A. (2006). Securing a wireless network with EAP-TLS: Perception and realities of its implementation. In Proceedings of the 4th Australian Information Security Management Conference. Edith Cowan University. Acessado em: 26 mar. 2026.

Wang, K., Zheng, Y., Zhang, Q., Bai, G., Qin, M., Zhang, D., and Dong, J. S. (2022). Assessing certificate validation user interfaces of wpa supplicants. In Proceedings of the 28th Annual International Conference on Mobile Computing And Networking, MobiCom ’22, page 501–513, New York, NY, USA. Association for Computing Machinery.

Wierenga, K., Winter, S., and Wolniewicz, T. (2015). The eduroam Architecture for Network Roaming. RFC 7593.

Yang, X., Goto, H., and Suganuma, T. (2025). Route selection optimization for multi-hop radius proxies in wlan roaming systems. In 2025 IEEE 49th Annual Computers, Software, and Applications Conference (COMPSAC), pages 1553–1558.
Publicado
01/09/2026
CARVALHO, Fabiano Losilla de; OLIVEIRA, Luciana Pereira; MELO, Erick Lazaro. AUDIT@eduroam: A Security Auditing Tool for the eduroam Infrastructure. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 191-206. DOI: https://doi.org/10.5753/sbseg.2026.26509.

Artigos mais lidos do(s) mesmo(s) autor(es)