Warflying in a Cessna, Part II

Matthew Thomassen (Security Architect), Sean McKeever

RF Village @ DEF CON 33 · Day 1 · RF Village

Overview

In "Warflying in a Cessna, Part II: Upping Our Game," Matthew Thomassen, a security architect and commercial pilot, alongside his colleague Sean McKeever, a cybersecurity researcher and architect, presented an update on their ongoing project to map wireless access points from a small aircraft. This talk, delivered at RF Village, builds upon their initial presentation at DEF CON, delving deeper into the methodologies, equipment, and lessons learned from their aerial Wi-Fi reconnaissance efforts. The project aims to explore the capabilities and limitations of collecting Wi-Fi data from an elevated perspective, specifically around 1500 feet above ground level, a unique vantage point that minimizes ground-level obstructions prevalent in traditional war driving.

Watch on YouTube

Visual summary for Warflying in a Cessna, Part II by Matthew Thomassen, Sean McKeever
Visual summary for Warflying in a Cessna, Part II by Matthew Thomassen, Sean McKeever

Key moments

  1. 0:00 Introduction to warflying and the project
  2. 2:45 Emphasizing pilot safety: "Fly the airplane!"
  3. 3:20 Why a Cessna 172 for warflying
  4. 4:20 The core problem: measuring equipment performance
  5. 6:10 Discovering and acquiring the Wi-Fi Coconut
  6. 7:30 Testing the first antenna: a whip antenna
  7. 8:40 Panel antenna test and a crucial mounting mistake

Warflying in a Cessna, Part II

Speakers: Matthew Thomassen (Security Architect); Sean McKeever

Conference: RF Village

YouTube: https://www.youtube.com/watch?v=KwI2daso3ug

Overview

In "Warflying in a Cessna, Part II: Upping Our Game," Matthew Thomassen, a security architect and commercial pilot, alongside his colleague Sean McKeever, a cybersecurity researcher and architect, presented an update on their ongoing project to map wireless access points from a small aircraft. This talk, delivered at RF Village, builds upon their initial presentation at DEF CON, delving deeper into the methodologies, equipment, and lessons learned from their aerial Wi-Fi reconnaissance efforts. The project aims to explore the capabilities and limitations of collecting Wi-Fi data from an elevated perspective, specifically around 1500 feet above ground level, a unique vantage point that minimizes ground-level obstructions prevalent in traditional war driving.

The significance of warflying lies in its potential to provide a broader, less obstructed view of wireless infrastructure, offering insights into network density, coverage patterns, and the prevalence of different Wi-Fi technologies across geographical areas. By flying above common obstructions like buildings and terrain, Thomassen and McKeever seek to understand what wireless signals are truly visible, and how far they propagate. This research is crucial for understanding the real-world footprint of Wi-Fi networks, which has implications for security, urban planning, and radio frequency spectrum analysis. This second installment details their "upped game," focusing on refined data collection techniques, advanced equipment, and comprehensive data visualization, moving beyond initial validation to more quantitative analysis of their findings.

Background

▶ Watch: Introduction to warflying and the project (0:00)

The concept of "warflying" is a natural evolution of earlier reconnaissance techniques like wardialing (scanning phone numbers for modems) and wardriving (mapping Wi-Fi networks from a moving vehicle). The fundamental premise remains the same: systematically collect data about wireless access points over a wide area. However, warflying introduces a critical difference: elevation. By operating a small aircraft, typically a Cessna 172, at an altitude of approximately 1500 feet above ground, the team aimed to overcome the significant line-of-sight limitations that plague ground-based wardriving. Wi-Fi signals, particularly in the 2.4 GHz and 5 GHz bands, are highly susceptible to obstruction by buildings, trees, and terrain. Flying higher allows for a clearer path to access points, theoretically extending detection ranges and revealing networks that might be invisible from the ground.

The initial phase of their project, presented at DEF CON, primarily focused on validating the feasibility of warflying and confirming that Wi-Fi signals could indeed be detected from an aircraft. The challenge for "Part II" was to move beyond mere detection to a more quantitative understanding: how much data could they collect, how effectively could their equipment perform, and what new insights could be gleaned about wireless network distribution.

A core technical challenge in Wi-Fi scanning is the nature of beacon packets. Wireless access points (APs) typically broadcast a beacon packet every 102.4 milliseconds (approximately one-tenth of a second) on a specific channel. To reliably detect these beacons, a receiver needs to be within radio range and tuned to the correct frequency at the precise moment the packet is transmitted. The 2.4 GHz Wi-Fi band alone has 14 channels (with 11 commonly used in the US). This presents a dilemma: either use a single radio that rapidly cycles through all channels (channel hopping), which introduces lag and potential missed beacons, or employ multiple radios, each dedicated to a specific channel, to ensure continuous monitoring. This problem, extensively documented by projects like Kismet, highlights the need for specialized hardware to achieve comprehensive Wi-Fi data collection.

Their choice of aircraft, a Cessna 172, is a standard small, high-wing, aluminum-constructed plane, flying at about 120 mph (176 feet per second). The high-wing design minimizes signal obstruction from the wings, but the aluminum fuselage was anticipated to significantly block signals from the opposite side of the aircraft, a hypothesis they sought to confirm. Safety, as emphasized by Thomassen, is paramount, with the primary rule being "fly the airplane," making warflying best suited as a team sport to manage both piloting and data collection tasks.

Key Findings

▶ Watch: Why a Cessna 172 for warflying (3:20)

The warflying project yielded several significant findings that refine the understanding of aerial Wi-Fi reconnaissance:

  1. Phone Usability for Warflying: Contrary to expectations that specialized, high-gain equipment would be essential, the project demonstrated that even a standard smartphone running the WIGLE app is a viable tool for collecting Wi-Fi data from an airplane. While not as performant as dedicated hardware, phones can still detect a substantial number of access points, making warflying accessible to pilots with minimal specialized setup. This finding encourages broader participation in collecting aerial Wi-Fi data.
  1. Significant Fuselage Blocking: The aluminum fuselage of the Cessna 172 acts as a substantial radio frequency shield, severely blocking Wi-Fi signals from the side of the aircraft opposite to the antenna. This was strongly validated by comparative visualizations showing almost zero overlap in detections between a phone on one side and a specialized antenna on the other, confirming that antenna placement directly influences which networks are detected.
  1. Criticality of Antenna Orientation: The orientation and type of antenna profoundly impact detection performance. The whip antenna, despite its omnidirectional pattern, generally outperformed the panel antenna in total detections, which was initially surprising. This suggests that while panel antennas offer directional gain, their optimal orientation (e.g., pointing downwards) needs careful consideration, especially from 1500 feet, to effectively capture ground-based signals. The initial mounting of the panel antenna "backwards" (pointing into the aircraft) also highlighted the importance of correct installation.
  1. Warflying vs. Wardriving Trade-offs: Direct comparisons between warflying and wardriving the same route with identical equipment (Wi-Fi Coconut, whip antenna, Kismet) reaffirmed previous conclusions: wardriving detects more access points overall, but warflying detects them faster. This implies that warflying is more efficient for rapid, wide-area surveys, while wardriving offers greater density of detection along a specific path due to closer proximity to APs.
  1. Prevalence of 5 GHz Wi-Fi: An unexpected but crucial finding was the high prevalence of 5 GHz Wi-Fi networks. Initially, the team focused on 2.4 GHz, assuming it would be sufficient. However, upon realizing the phone was collecting 5 GHz data, they discovered approximately five times as many access points operating on the 5 GHz band compared to 2.4 GHz. This indicates a significant shift in network deployment towards the higher frequency band, which has implications for signal propagation and detection range due to its shorter wavelength and greater susceptibility to obstruction.
  1. Mysterious 00D97 MAC Addresses: The project consistently identified a large number of access points with MAC addresses starting with 00:00:D9:XX:XX:XX that appeared at maximum detection distances. The nature or origin of these devices remains unknown but their widespread presence and strong signals make them a notable anomaly in the collected data.

Technical Deep Dive

▶ Watch: The core problem: measuring equipment performance (4:20)

The technical core of the warflying project revolves around overcoming the inherent challenges of Wi-Fi signal detection from a moving platform at altitude, leveraging specialized hardware and sophisticated data processing.

Wi-Fi Beacon Detection Mechanics

As detailed, Wi-Fi access points broadcast beacon packets approximately every 102.4 milliseconds. These beacons announce the AP's presence, SSID, and capabilities. The primary hurdle for efficient detection, especially across the 14 channels of the 2.4 GHz band (and even more for 5 GHz), is ensuring a receiver is tuned to the correct channel at the precise moment a beacon is transmitted. Traditional single-radio scanners perform channel hopping, rapidly cycling through frequencies. However, this introduces latency, meaning many beacons can be missed, leading to incomplete data.

The Wi-Fi Coconut

To address the channel hopping limitation, the team adopted the Wi-Fi Coconut. This specialized device is a multi-radio solution, uniquely equipped with 14 dedicated 2.4 GHz Wi-Fi radios. Each radio is continuously tuned to a specific Wi-Fi channel, allowing for simultaneous, real-time monitoring of all 2.4 GHz channels without any lag. This design drastically increases the probability of capturing every beacon packet within range. The particular Coconut used in the project was a rare, modified version featuring an external antenna port, which was crucial for testing various antenna types beyond its internal antennas.

The Coconut was integrated into the data collection setup via a USBC connection for both power and data. It was connected to a laptop running Kismet, a powerful network detector, sniffer, and intrusion detection system. Kismet was configured with the war drive overlay to process and log the detected Wi-Fi data, including MAC addresses, SSIDs, signal strength, and timestamped GPS coordinates provided by an external GPS receiver.

Antennas and Placement

Three primary antenna types were considered and tested:

  1. Whip Antenna: This omnidirectional antenna, longer than a quarter-wave, was mounted vertically near the windshield in the front right seat. Its expected radiation pattern is a "donut" shape, offering 360-degree horizontal coverage with a null directly above and below. This vertical orientation was chosen assuming most access points also use vertical polarization.
  1. Panel Antenna: Designed for directional gain, this antenna's radiation pattern is primarily straight out from its face. It was also taped in the front right seat. A notable mistake during initial testing was its backward mounting, causing the primary lobe to point into the aircraft rather than outward. Despite this, some reception was still achieved off the back lobe, and the effective reception was still outward, albeit attenuated. The directional nature of the panel antenna was intended to focus reception towards the ground as the airplane banked during turns.
  1. Yagi Antenna: A highly directional antenna, a Yagi was acquired but unfortunately could not be made to work with the Coconut in time for the presentation. Its narrow, focused beam would offer the highest gain for pinpointing distant signals, but also requires precise aiming.

A critical observation regarding antenna placement was the significant signal blocking caused by the aluminum fuselage of the Cessna 172. This metallic structure acts as a Faraday cage, attenuating signals originating from the opposite side of the aircraft, reinforcing the need for external antennas or strategic internal placement. The speaker also highlighted the extreme difficulties and safety/legal hurdles (FAA regulations, 150 mph wind resistance, potential for FOD) associated with mounting antennas outside the aircraft.

Data Collection and Processing

Data was collected using Kismet on a laptop connected to the Wi-Fi Coconut, with GPS data from a separate receiver mounted on the glare shield. The raw data was then exported into WIGLE CSV files, a common format for wardriving data, which facilitated analysis and visualization.

Matthew Thomassen developed custom Python scripts to process these CSV files and generate visualizations. Key metrics extracted and analyzed included:

  • Total Points: The total number of Wi-Fi beacons detected.
  • Unique MACs: The number of distinct access points identified.
  • Max per Minute: A density metric indicating how many unique MAC addresses were detected within a minute, highlighting the efficiency of data collection.
  • Detection Categories: A novel metric categorizing access points by how many times they were detected (1, 2, 3, 4, or 5+ detections), providing insight into the duration of visibility for a given AP as the aircraft moved at 176 ft/sec.
  • Max Distance Between Detections: While not the actual distance to the AP, this metric showed the maximum lateral spread of detections for a single MAC address, indicating how far the aircraft traveled while still "seeing" a particular AP. For some access points, this distance exceeded 2 miles, implying they were detected from at least 1 mile away.

Aircraft Considerations

The Cessna 172 provided a stable platform but also introduced challenges. Its cruising speed of 120 mph (176 ft/sec) meant rapid movement over target areas, necessitating efficient detection. The high-wing configuration was advantageous as it minimized wing obstruction of ground-based signals. However, the aluminum fuselage was a major impediment, acting as a shield. The flight altitude of 1500 feet was chosen to balance line-of-sight advantages with regulatory and safety considerations for small aircraft.

Demo / Proof of Concept

▶ Watch: Testing the first antenna: a whip antenna (7:30)

The presentation included several compelling demonstrations and visualizations of the collected data, illustrating the project's progress and findings.

The team started with basic linear flights, collecting data along straight paths. To move towards a two-dimensional mapping capability, they experimented with right-handed turns. By banking the airplane to the right, the panel antenna (mounted on the right side) was angled downwards, allowing it to "sweep" an area. The visualizations clearly showed these turns "filling in" the map, indicating that the same access points were being detected from different angles, which is crucial for more accurate triangulation and location estimation. Further experiments involved flying circles over specific areas, such as Lake Orion, Michigan, to systematically attempt to fill in detection maps.

A key demonstration involved a grid pattern flight over the northern suburbs of Metro Detroit. This pattern consisted of approximately 10-mile east-west legs with 1-mile north-south spacing between them. Two runs were performed, one with the panel antenna and one with the whip antenna, both connected to the Wi-Fi Coconut. These were then compared against data collected simultaneously by a phone. The visualizations for these grid patterns highlighted:

  • Coverage: The extent of detected Wi-Fi networks across the grid.
  • Overlap: A custom visualization used blue dots for data set one, yellow dots for data set two, and green dots for points seen in both data sets. This proved highly effective in comparing antenna performance and the impact of the fuselage. For instance, comparing the Coconut runs to the phone run showed almost no green dots, strongly confirming the fuselage's blocking effect on signals from the opposite side of the aircraft.

A direct comparison of warflying versus wardriving was also demonstrated. Sean McKeever performed a wardrive along Woodward Avenue in Metro Detroit using his Honda Civic, equipped with the identical laptop, Kismet, Wi-Fi Coconut, and whip antenna used in the warflights. The visualization showed the direct overlap and differences. As previously noted, wardriving picked up more total access points, but warflying collected them faster over a wider area. An interesting observation was that when comparing a warflight with the panel antenna to a wardrive with the whip antenna, there was almost no overlap, suggesting the panel antenna's directional gain from altitude was picking up entirely different, farther-away access points.

Finally, the speaker shared an impromptu "warflight" from an airliner. While traveling to DEF CON, he used his phone (in airplane mode, but with GPS and Wi-Fi enabled) from a window seat to collect data. Although he needed to filter out the airliner's own Wi-Fi, he successfully demonstrated that warflying is possible from a commercial airliner, albeit with limited data collection, adding an accessible dimension to the project.

Defensive Implications

▶ Watch: Panel antenna test and a crucial mounting mistake (8:40)

The warflying project offers several crucial insights for network defenders, homeowners, and organizations concerned about the visibility and security of their wireless networks:

  1. Antenna Placement is Paramount: The strong evidence of fuselage blocking highlights that the physical placement of Wi-Fi access points and their antennas significantly impacts their detectable footprint. For organizations needing to minimize their external RF signature, strategic internal placement, away from windows or external walls, could reduce aerial visibility. Conversely, for those aiming for maximum coverage (e.g., public Wi-Fi), conscious antenna choices and outdoor placement would be necessary.
  1. Line of Sight from Above: Defenders should recognize that their Wi-Fi networks might be visible from unexpected vantage points, particularly from elevated positions. A network designed for ground-level coverage might still be easily detectable from 1500 feet up if there are no significant obstructions directly above it. This means that even seemingly "hidden" networks in suburban or rural areas could be mapped by aerial reconnaissance.
  1. 5 GHz Band Visibility: The finding that 5 GHz networks are five times more prevalent than 2.4 GHz is critical. While 5 GHz signals generally have shorter ranges and are more susceptible to obstruction than 2.4 GHz, their sheer density means they form a significant part of the aerial RF landscape. Defenders should not assume that migrating to 5 GHz inherently makes their network less detectable from the air; rather, the challenge shifts to understanding the propagation characteristics of these higher frequencies from an aerial perspective.
  1. Signal Strength and Propagation: The detection of access points from distances of at least 1-2 miles away underscores the robust propagation of some Wi-Fi signals, even from consumer-grade equipment. Organizations should be aware that their Wi-Fi signals can travel significant distances, potentially beyond their intended coverage areas, and be picked up by adversaries using specialized equipment or even modified consumer devices. This reinforces the need for strong encryption and robust authentication on all Wi-Fi networks.
  1. Relevance for Site Surveys and Security Audits: The methodologies developed in this project could be adapted for aerial site surveys. For large campuses, industrial facilities, or critical infrastructure, warflying could offer a quick, high-level assessment of external Wi-Fi coverage, identifying potential signal leakage or unauthorized access points that are not visible from ground-based surveys. This perspective could be invaluable for security audits.
  1. The Mystery of 00D97: The persistent appearance of strong, distant signals from 00:00:D9:XX:XX:XX MAC addresses warrants further investigation by the security community. Identifying the nature of these devices (e.g., IoT, specific vendor hardware, industrial control systems) could reveal widespread, potentially unmanaged or vulnerable, wireless infrastructure.

Key Takeaways

  • Warflying is a viable and efficient method for broad-area Wi-Fi reconnaissance, offering a less obstructed view than ground-based wardriving.
  • Specialized hardware like the Wi-Fi Coconut significantly enhances detection capabilities by simultaneously monitoring all Wi-Fi channels, but even smartphones can collect useful data.
  • Aircraft fuselage acts as a major RF shield, requiring careful antenna placement and potentially external mounting for comprehensive coverage.
  • Antenna orientation and type critically influence detection performance, with omnidirectional whips often outperforming directional panels if not optimally aimed from altitude.
  • 5 GHz Wi-Fi networks are far more prevalent than 2.4 GHz, indicating a shift in network deployment and a significant component of the aerial RF landscape.
  • Wi-Fi signals can be detected from significant distances (1-2+ miles) from an aircraft, highlighting the importance of understanding signal propagation and securing networks against aerial monitoring.

About the Speaker(s)

Matthew Thomassen is a security architect by profession, working with computers in his day job. His passion extends beyond traditional cybersecurity into aviation, holding a commercial pilot certificate with multi-engine and instrument ratings, as well as an airframe and power plant mechanic certificate. This unique blend of skills makes him uniquely qualified to lead the warflying project, combining his expertise in security with his extensive knowledge of aircraft operation and maintenance.

Sean McKeever is Matthew Thomassen's colleague and a key contributor to the warflying project. Described as a cybersecurity researcher, architect, hacker, and race car driver, Sean brings a diverse set of technical skills and a hacker mindset to the team. Although he was unable to present at the conference, his collective work with Matthew was central to the project's advancements and findings, particularly in the setup and execution of data collection runs.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Genuinely fun niche research with a clear methodology and some real findings — the fuselage blocking confirmation, the 5GHz prevalence discovery, and the warflying-vs-wardriving trade-off quantification are all legitimately useful. But this is RF Village-tier content, not main stage material: the findings are incremental, the threat model is thin, and the mysterious 00D97 MAC addresses being left unresolved is the most interesting hook they declined to pull.

Heather Calloway (CISO) — WEAK

Technically earnest warflying research with real craft behind it — but it stops at the map. The defensive implications section is bolted on rather than built in, and no one in a security program leaves knowing what to do differently.

→ Top-rated talks at RF Village @ DEF CON 33

All talks from RF Village @ DEF CON 33