1/147
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Terminologies
In a wireless network, data are transmitted through EM wavesthat carry signals over the communication path.
Global System for Mobile Communications (GSM):
A universal system used for mobile data transmission in wireless networks worldwide.
Bandwidth
Describes the amount of information that may be broadcast over a connection. Usually, bandwidth refers to the data transfer rate and is measured in bits (amount of data) per second (bps).
Access Point (AP)
Connects wireless devices to a wireless/wired network. It allows wireless communication devices to connect to a wireless network through wireless standards such as Bluetooth and Wi-Fi. It serves as a switch or hub between a wired LAN and a wireless network.
Basic Service Set Identifier (BSSID)
The media access control (MAC) address of an access point (AP) or base station that has set up a basic service set (BSS).
Industrial, Scientific, and Medical (ISM) Band
A set of frequencies used by the international industrial, scientific, and medical communities.
Hotspot
Places where wireless networks (Wi-Fi) are available for public use.
Association:
The process of connecting a wireless device to an AP.
Service Set Identifier (SSID
A 32-alphanumeric-character unique identifier given to a wireless local area network (WLAN) that acts as a wireless identifier of the network. Devices connecting to the same WLAN should use the same SSID to establish connections.
Orthogonal Frequency-division Multiplexing (OFDM)
A method of digital modulation of data in which a signal, at a chosen frequency, is split into multiple carrier frequencies that are orthogonal (occurring at right angles) to each other. It produces a transmission scheme that supports higher bit rates than parallel channel operation. It is also a method of encoding digital data on multiple carrier frequencies.
Multiple Input, Multiple Output-Orthogonal Frequency-division Multiplexing (MIMO-OFDM
Influences the spectral efficiency of 4G and 5G wireless communication services and reduces interference and increases the channel robustness.
Direct-sequence Spread Spectrum (DSSS)
A spread spectrum technique that multiplies the original data signal with a pseudo-random noise-spreading code. Also referred to as a data transmission scheme or modulation scheme, the technique protects signals against interference or jamming.
Frequency-hopping Spread Spectrum (FHSS
Also known as frequency-hopping code-division multiple access (FH-CDMA), is a method of transmitting radio signals by rapidly switching a carrier among many frequency channels. It decreases the efficiency of unauthorized interception or jamming of telecommunications.
Wireless Network
An unbounded data communication system that uses radio-frequency technology to communicate with devices and obtain data.
Wireless Network
This network frees the user from complicated and multiple wired connections using electromagnetic (EM) waves to interconnect two (2) individual points without establishing any physical connection
Extension to a Wired Network
A user can extend a wired network by placing APs (Access Points) between a wired network and wireless devices. A wireless network can also be created using an AP.
In this type of network, the AP acts as a switch, providing connectivity for computers that use a wireless NIC.
Software APs(SAPs)
SAPs can be connected to a wired network, and they run on a computer equipped with a wireless network interface card (NIC).
Hardware APs(HAPs)
Support most wireless features
Multiple Access Points
Connects computers wirelessly using multiple APs. If a single AP cannot cover an area, various APs or extension points can be established. The wireless area of each AP must overlap its neighbor's area. This provides users the ability to move around seamlessly using a feature called roaming.
LAN-to-LAN Wireless Network
APs provide wireless connectivity to local computers, and local computers on different networks can be interconnected. All hardware APs can interconnect with other hardware APs. However, interconnecting LANs over wireless connections is a complex task
3G/4G Hotspot
A type of wireless network that provides Wi-Fi accessto Wi-Fi-enabled devices, including MP3 players, notebooks, tablets, cameras, PDAs, netbooks, and more.
IEEE Standard 802.s11
has evolved from a standard for a basic wireless extension to a wired LAN to a mature protocol that supports enterprise authentication, strong encryption, and quality of service
802.11:
standard applies to WLANs and uses FHSS or DSSS as the frequencyhopping spectrum. It allows an electronic device to establish a wireless connection in any network.
802.11a
The first amendment to the original 802.11 standard. The 802.11 standard operates in the 5 GHz frequency band and supports bandwidths up to 54 Mbps using orthogonal frequency-division multiplexing (OFDM). It has a high maximum speed but is relatively more sensitive to walls and other obstacles.
802.11b:
IEEE extended the 802.11 standard by creating the 802.11b specifications in 1999. This standard operates in the 2.4 GHz ISM band and supports bandwidths up to 11 Mbps using directsequence spread spectrum (DSSS) modulation.
802.11d
standard is an enhanced version of 802.11a and 802.11b that supports regulatory domains. The specifications of this standard can be set in the media access control (MAC) layer.
IEEE 802.11e
Used for real-time applications such as voice, VoIP, and video. To ensure that these time-sensitive applications have the network resources they need, 802.11e defines mechanisms to ensure quality of service (QoS) to Layer 2 of the reference model, which is the MAC layer.
802.11g:
An extension of 802.11 and supports a maximum bandwidth of 54 Mbps using OFDM technology. It uses the same 2.4 GHz band as 802.11b. The IEEE 802.11g standard defines high-speed extensions to 802.11b and is compatible with the 802.11b standard, which means 802.11b devices can work directly with an 802.11g AP.
802.11i:
The IEEE 802.11i standard improves WLAN security by implementing new encryption protocols such as the Temporal Key Integrity Protocol (TKIP) and Advanced Encryption Standard (AES).
802.11n
The IEEE 802.11n is a revision that enhances the 802.11g standard with multiple-input multiple-output (MIMO) antennas. It works in both the 2.4 GHz and 5 GHz bands. Furthermore, it is an IEEE industry standard for Wi-Fi wireless local network transportation. Digital Audio Broadcasting (DAB) and WLAN use OFDM
802.11ah
Also called Wi-Fi HaLow, uses 900 MHz bands for extended-range Wi-Fi networks and supportsInternet of Things(IoT) communication with higher data rates and wider coverage range than the previous standards.
802.11ac
Provides a high-throughput network at a frequency of 5 GHz. It is faster and more reliable than the 802.11n standard. Moreover, it involves Gigabit networking, which provides an instantaneous data-transfer experience.
802.11ad
The 802.11ad standard includes a new physical layer for 802.11 networks and works on the 60 GHz spectrum. The data propagation speed in this standard is much higher than those of standards operating on the 2.4 GHz and 5 GHz bands, such as 802.11n.
802.12
Media utilization is dominated by this standard because it works on the demand priority protocol. The Ethernet speed with this standard is 100 Mbps. Furthermore, it is compatible with the 802.3 and 802.5 standards. Users currently on those standards can directly upgrade to the 802.12 standard
802.15
Defines the standards for a wireless personal area network (WPAN) and describes the specifications for wireless connectivity with fixed or portable devices
802.15.1 (Bluetooth)
Bluetooth is mainly used for exchanging data over short distances on fixed or mobile devices. This standard works on the 2.4 GHz band.
802.15.4 (ZigBee)
The 802.15.4 standard has a low data rate and complexity. The specification used in this standard is ZigBee, which transmits long-distance data through a mesh network. The specification handles applications with a low data rate of 250 Kbps, but its use increases battery life
802.15.5
This standard deploys itself on a full-mesh or half-mesh topology. It includes network initialization, addressing, and unicasting.
Wireless Encryption
A process of protecting a wireless network from attackers who attempt to collect sensitive information by breaching the RF traffic.
Types of Wireless Encryption
Attacks on wireless networks are increasing daily as the use of wireless networks increases. The encryption of information before it is transmitted on a wireless network is the most popular method of protecting wireless networks against attackers. Several types of wireless encryption algorithms can secure a wireless network. Each wireless encryption algorithm has advantages and disadvantages
802.11i
An IEEE amendment that specifies security mechanisms for 802.11 wireless networks.
Wired Equivalent Privacy (WEP)
is an encryption algorithm for IEEE 802.11 wireless networks. It is an outdated wireless security standard that can be easily cracked.
The Extensible Authentication Protocol (EAP)
supports multiple authentication methods, such as token cards, Kerberos, and certificates.
Lightweight EAP (LEAP)
is a proprietary version of EAP developed by Cisco.
WPA
An advanced wireless encryption protocol using TKIP and Message Integrity Check (MIC) to provide strong encryption and authentication. It uses a 48-bit initialization vector (IV), 32-bit cyclic redundancy check (CRC), and TKIP encryption for wireless security.
(TKIP) Temporary Key Integrity Protocol
is a temporary security protocol used in WPA as a replacement for WEP. It is used in a unicast encryption key that changes for every packet.
WPA2
It is an upgrade to WPA using AES and the Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP) for wireless data encryption.
Advanced Encryption Standard (AES)
is a symmetric-key encryption used in WPA2 as a replacement for TKIP.
CCMP
An encryption protocol used in WPA2 for strong encryption and authentication.
WPA2 Enterprise
Integrates EAP standards with WPA2 encryption.
Remote Authentication Dial-In User Service (RADIUS)
Protected Extensible Authentication Protocol (PEAP)
is a protocol that encapsulates the EAP within an encrypted and authenticated Transport Layer Security (TLS) tunnel.
WPA3
A third-generation Wi-Fi security protocol that has better security than WPA2 across the network and protects sensitive data using many cryptographic concepts and tools. It uses Galois/Counter Mode-256 (GCMP-256) for encryption and the 384-bit hash message authentication code with the Secure Hash Algorithm (HMAC-SHA-384) for authentication.
Rogue AP Attack
APs connect to client NICs by authenticating with the help of SSIDs. Unauthorized (or rogue) APs can allow anyone with an 802.11-equipped device to connect to a corporate network. An unauthorized AP can give an attacker access to the network. Client Mis-Association: Mis-association is a security flaw that
Client Mis-Association
Mis-association is a security flaw that can occur when a network client connects with a neighboring AP. Client mis-associations can occur for various reasons, such as misconfigured clients, insufficient coverage of corporate Wi-Fi, lack of a Wi-Fi policy, restrictions on the use of the Internet in the office, ad-hoc connections that administrators do not manage regularly, and attractive SSIDs. They can occur with or without the knowledge of the wireless client and rogue AP.
Misconfigured AP Attack
Most organizations spend significant amounts of time defining and implementing Wi-Fisecurity policies, butit may be possible for a client of a wireless network to change the security settings of an AP unintentionally. This, in turn, may lead to misconfigurations in APs. A misconfigured AP can expose an otherwise well-secured network to attacks.
Unauthorized Association
A major threat to wireless networks. It has two (2) forms: accidental association and malicious association. An attacker performs a malicious association with the help of soft APs instead of corporate APs. The attacker infects the victim's machine and activates soft APs, allowing an unauthorized connection to the enterprise network. An attacker who gains access to the network using unauthorized association may steal passwords, launch attacks on a wired network, or plant Trojans. On the other hand, accidental association involves connecting to the target network's AP from a neighboring organization's overlapping network without the victim's knowledge.
Ad-Hoc Connection Attack
Wi-Fi clients can communicate directly via an ad-hoc mode that does not require an AP to relay packets. Data can be conveniently shared among clients in ad-hoc networks, which are quite popular among Wi-Fi users. An attacker can easily connect to and compromise a client operating in ad-hoc mode. An attacker who penetrates a wireless network can also use an ad-hoc connection to compromise the security of the organization's wired LAN.
Honeypot AP Attack
If multiple WLANs coexist in the same area, a user can connect to any available network that is vulnerable to attacks. Normally, when a wireless client is switched on, it probes a nearby wireless network for a specific SSID. An attacker takes advantage of this behavior of wireless clients by setting up an unauthorized wireless network using a rogue AP. This AP has high-power(highgain) antennas and uses the same SSID as the target network. Users who regularly connect to multiple WLANs may connect to the rogue AP. Such APs mounted by attackers are called "honeypot" APs. If an authorized user connects to a honeypot AP, a security vulnerability is created, and sensitive user information, such as identity, username, and password, may be revealed to the attacker.
AP MAC Spoofing
In wireless networks, the transmit probes of APs respond through beacons to advertise presence and availability. The probe responses contain information on the AP identity (MAC IT2511 01 Handout 1 *Property of STI Page 6 of 10 address) and the identity of the network it supports (SSID). Clients in the vicinity connect to the network through these beacons based on the MAC address and the SSID it contains. An attacker can spoof the MAC address of the AP by programming a rogue AP to advertise the same identity information as that of the legitimate AP. An attacker connected to the AP as an authorized client can have full access to the network.
Key Reinstallation Attack (KRACK):
This exploits the flaws in the implementation of the four-way handshake process in the WPA2 authentication protocol that establishes a connection between a device and an AP. All secure Wi-Fi networks use the four-way handshake process to establish connections and to generate a fresh encryption key that will be used to encrypt network traffic.
Jamming Signal Attack
This is performed on a wireless network to compromise it. In this type of exploitation, overwhelming volumes of malicious traffic result in a DoS to authorized users, obstructing legitimate traffic. All wireless networks are prone to jamming, and spectrum jamming attacks usually block all communications.
Aircrack-ng Suite
A network software suite consisting of a detector, packet sniffer, WEP and WPA/WPA2 PSK cracker, and analysis tool for 802.11 wireless networks. This program runs under Linux and Windows.
AirMagnet WiFi Analyzer PRO
A Wi-Fi network traffic auditing and troubleshooting tool that provides the real-time, accurate, independent, and reliable Wi-Fi analysis of 802.11a/b/g/n/ax wireless networks, missing any traffic.
Bluetooth
is a wireless technology that allows devices to share data over short distances. Bluetooth technology is vulnerable to various types of attacks.
Discoverable
When Bluetooth devices are in the discoverable mode, they are visible to other Bluetooth-enabled devices. If a device attempts to connect to another, the device attempting to establish the connection must search for a device that is in the discoverable mode; otherwise, the device attempting to initiate the connection will not be able to detect the other device. The discoverable mode is necessary only while connecting to a device for the first time. Upon saving the connection, the devices remember each other; therefore, the discoverable mode is not necessary for lateral connection establishment.
Limited discoverable
In the limited discoverable mode, the Bluetooth devices are discoverable only for a limited period, for a specific event, or during temporary conditions. However, there is no Host Controller Interface (HCI) command to set a device directly in the limited discoverable mode. A user has to do this indirectly. When a device is set to the limited discoverable mode, it filters out nonmatched IACs and reveals itself only to those that matched.
Non-discoverable
Setting a Bluetooth device to the non-discoverable mode prevents that device from appearing on the list during a Bluetooth-enabled device search process. However, it remains visible to users and devices that were previously paired with it or know its MAC address.
Non-pairable mode
in the non-pairable mode, a Bluetooth device rejects pairing requests sent by any device.
Pairable mode
In the pairable mode, a Bluetooth device can accept pairing requests and establish a connection with a device that requested pairing.
Bluetooth Hacking
he exploitation of Bluetooth stack implementation vulnerabilities to compromise sensitive data in Bluetooth enabled devices and networks. Bluetooth-enabled devices connect and communicate wirelessly through adhoc networks known as piconets. Attackers can gain information by hacking the target Bluetooth-enabled device from another Bluetooth-enabled device.
Bluesmacking
Occurs when an attacker sends an oversized ping packet to a victim's device, causing a buffer overflow. This type of attack is similar to an Internet Control Message Protocol (ICMP) ping-of death attack
Bluejacking
The use of Bluetooth to send messages to users without the recipient's consent, similar to email spamming. Prior to any Bluetooth communication, the device initiating the connection must provide a name that is displayed on the recipient's screen. As this name is user-defined, it can be set to an annoying message or advertisement. Strictly speaking, Bluejacking does not cause any damage to the receiving device. However, it may be irritating and disruptive to the victims.
Bluesnarfing
A method of gaining access to sensitive data in a Bluetooth-enabled device. An attacker within the range of a target can use specialized software to obtain the data stored on the victim's device. To perform Bluesnarfing, an attacker exploits a vulnerability in the Object Exchange (OBEX) protocol that Bluetooth uses to exchange information. The attacker connects with the target and performs a GET operation for files with correctly guessed or known names, such as /pb.vcf for the device's phonebook or telecom /cal.vcs for the device's calendar file.
BlueSniff
A proof-of-concept code for a Bluetooth wardriving utility. It is useful for finding hidden and discoverable Bluetooth devices. It operates on Linux.
Bluebugging
An attack in which an attacker gains remote access to a target Bluetooth-enabled device without the victim's awareness. In this attack, an attacker sniffs sensitive information and might perform malicious activities such as intercepting phone calls and messages and forwarding calls and text messages
BluePrinting
A footprinting technique performed by an attacker to determine the make and model of a target Bluetooth-enabled device. Attackers collect this information to create infographics of the model, manufacturer, etc., and analyze them to determine whether the device has exploitable vulnerabilities.
Btlejacking
Thisis detrimental to Bluetooth low energy (BLE) devices. The attacker can sniff, jam, and take control of the data transmission between BLE devices by performing a MITM attack. Following a successful attempt, the attacker can also bypass security mechanisms and listen to the information being shared. To implement this attack, the attacker must use affordable firmware-embedded equipment and minor software coding.
KNOB attack:
A Key Negotiation of Bluetooth (KNOB) attack enables an attacker to breach Bluetooth security mechanisms and perform an MITM attack on paired devices without being traced. The attacker leverages a vulnerability in the Bluetooth wireless standard and eavesdrops on all the data being shared in the network, such as keystrokes, chats, and documents. A KNOB attack is especially detrimental to two Bluetooth-enabled devices sharing encrypted keys. The attack is launched on short-distance communication protocols of Bluetooth negotiating the encryption keys required to be shared between nodes to establish a connection.
MAC spoofing attack
A passive attack in which attackers spoof the MAC address of a target Bluetooth enabled device to intercept or manipulate the data sent to the target device.
Man-in-the-Middle/impersonation attack
: In an MITM/impersonation attack, attackers manipulate the data transmitted between devices communicating via a Bluetooth connection (piconet). During this attack, the devices intended to pair with each other unknowingly pair with the attacker's device, thereby allowing the attacker to intercept and manipulate the data transmitted in the piconet.
Cisco Adaptive Wireless Intrusion Prevention System (IPS)
offers advanced network security for dedicated monitoring and detection of wireless network anomalies, unauthorized access, and RF attacks. Fully integrated with the Cisco Unified Wireless Network, this solution delivers integrated visibility and control across the network, without the need for an overlay solution.
Adaptive WIPS
provides wireless-network threat detection and mitigation against malicious attacks and security vulnerabilities. It also provides security professionals with the ability to detect, analyze, and identify wireless threats.
AirMagnet WiFi Analyzer PRO
A professional Wi-Fi analysis tool that audits network performance, detects connectivity issues, and identifies security vulnerabilities in real time.
WatchGuard WIPS
A wireless intrusion prevention solution that provides continuous monitoring, rogue AP detection, and automated wireless threat mitigation
RFProtect
Aruba Networks' built-in Wireless Intrusion Prevention System (WIPS)that protects against rogue APs, man-in-the-middle attacks, and unauthorized Wi-Fi devices
AirMagnet Planner
A Wi-Fi planning tool that allows network engineers to design optimal wireless coverage, predict signal strength, and plan AP placement before deployme
Extreme AirDefense
An enterprise-grade WIPS and wireless monitoring platform that provides centralized detection, alerting, and response to wireless threats.
The Device
Vulnerabilities in mobile devices pose significant risks to sensitive personal and corporate data. Attackers targeting the device itself can use various entry points.
Phishing
emails or pop-ups redirect users to fake web pages that mimic trustworthy sites, asking them to submit their personal information. Mobile users are more likely to be victims of phishing sites because the devices are small in size and they display only short URLs, limited warning messages, scaled-down lock icons, and so on.
Framing
Involves a web page integrated into another web page using the iFrame elements of HTML. An attacker exploits iFrame functionality used in the target website, embeds his/her malicious web page, and uses clickjacking to steal users' sensitive information
Clickjacking
also known as a user interface redress attack, is a malicious technique used to trick web users into clicking something different from what they think they are clicking
Man-in-the-Mobile
An attacker implants malicious code into the victim's mobile device to bypass password verification systems that send one-time passwords (OTPs) via SMS or voice calls. Thereafter, the malware relays the gathered information to the attacker
Buffer Overflow
An abnormality whereby a program, while writing data to a buffer, surfeits the intended limit and over writes the adjacent memory. This results in erratic program behavior, including memory access errors, incorrect results, and mobile device crashes.
Data Caching
Data caches in mobile devices store information that is often required by these devices to interact with web applications, thereby preserving scarce resources and resulting in betterresponse time for client applications. Attackers attempt to exploit these data caches to access the sensitive information stored in them.
Baseband Attacks
Attackers exploit vulnerabilities in a phone's GSM/3GPP baseband processor, which sends and receives radio signals to cell towers.
SMiShing
A phishing fraud in which an attacker uses SMS to send text messages containing deceptive linkstomalicious websites ortelephone numbersto a victim. The attacker tricksthe victim into clicking the link or calling the phone number and revealing his or her personal information.
Sensitive Data Storage
Some apps installed and used by mobile users employ weak security in their database architecture, which makes them targets for attackers who seek to hack and steal the sensitive user information stored in them.
No Encryption/Weak Encryption
Apps that transmit unencrypted or weakly encrypted data are susceptible to attacks such as session hijacking
Improper SSL Validation
Security loopholes in an application's SSL validation process may allow attackers to circumvent the data security.