Network SecurityUnit 415 min read
Wireless Network Security: Threats, Protocols & Countermeasures
Unit 4 of Network Security explores vulnerabilities in Wi-Fi, Bluetooth, and cellular networks, covering encryption (WPA3, TLS), attacks (eavesdropping, MITM, jamming), and real-world defenses used by banks, eSewa, and Ncell to secure mobile transactions and IoT devices.
TAKEAWAYS:
- Wireless networks (Wi-Fi, Bluetooth, 4G/5G) are vulnerable to eavesdropping, replay attacks, and jamming due to open broadcast mediums and weak encryption in legacy protocols (WEP, WPA).
- WPA3 (SAE, PMF) and TLS 1.3 are modern encryption standards that mitigate brute-force and downgrade attacks, but misconfigurations (e.g., weak passwords) still cause breaches.
- Bluetooth attacks (Bluejacking, Bluesnarfing) exploit unpatched devices, while cellular networks face IMSI catchers and SS7 vulnerabilities—Nepal’s Ncell and NTC deploy firewalls and SIM card encryption to counter these.
- IoT security relies on device authentication (DTLS), firmware updates, and network segmentation (e.g., Daraz’s warehouse IoT uses isolated VLANs for sensors).
- Real-world examples: eSewa uses TLS 1.3 + HSMs for payment encryption; Pathao’s driver app enforces Bluetooth LE authentication to prevent spoofing; NEPSE’s trading terminals block rogue access points via MAC filtering.
- Exam focus: Compare WEP/WPA2/WPA3, trace a 4-way handshake failure, and explain how jamming attacks differ from DoS—expect short-answer + 10-mark problem-solving questions.
1. Wireless Network Fundamentals: How Signals Travel (and Why They’re Insecure)
Wireless networks transmit data via electromagnetic waves (radio frequencies for Wi-Fi/Bluetooth, microwaves for 4G/5G). Unlike wired networks, these signals:
- Broadcast openly: Anyone with a receiver can intercept (e.g., a hacker in a café capturing unencrypted Wi-Fi traffic).
- Weak signal strength = easy jamming: A 2.4 GHz jammer (cheap hardware) can disrupt entire networks in Nepal’s crowded cities like Kathmandu.
- No physical boundaries: Walls or floors don’t stop signals—just attenuate them (e.g., Ncell’s 4G towers cover wide areas but are vulnerable to IMSI catchers near borders).
Key Wireless Technologies & Their Risks
| Technology | Frequency Band | Range | Primary Security Risks | Real-World Example |
|---|---|---|---|---|
| Wi-Fi (IEEE 802.11) | 2.4 GHz / 5 GHz | 10–100 meters | Eavesdropping, Rogue APs, Deauthentication attacks | eSewa’s office Wi-Fi (targeted by MITM) |
| Bluetooth | 2.4 GHz | 1–100 meters | Bluejacking, Bluesnarfing, Pairing flaws | Pathao driver app (Bluetooth LE for auth) |
| 4G/5G (LTE) | 700 MHz–3.5 GHz | 1–50 km | IMSI catchers, SS7 leaks, Tower hijacking | Ncell’s network (used by NEPSE traders) |
| Zigbee/Z-Wave | 868 MHz / 915 MHz | 10–100 meters | Weak encryption (AES-128 but often misconfigured) | Smart meters in Kathmandu (targeted by hackers) |
2. Wireless Encryption: From WEP to WPA3 (and Why WPA2 is Still Dangerous)
Encryption protects data in transit by scrambling it so only authorized devices can read it. Older protocols are broken—never use them in exams or real life.
Evolution of Wi-Fi Encryption
stateDiagram-v2
[*] --> WEP: "1997 (Crackable in minutes)"
WEP --> WPA: "2003 (TKIP, still weak)"
WPA --> WPA2: "2004 (AES-CCMP, gold standard)"
WPA2 --> WPA3: "2018 (SAE, PMF, resistant to brute force)"
WPA3 --> [*]How WPA3 Fixes WPA2’s Flaws
| Feature | WPA2 (Vulnerable To) | WPA3 (Secure) | Exam Tip |
|---|---|---|---|
| Handshake | 4-way (susceptible to offline brute force) | SAE (Simultaneous Authentication of Equals) – resists brute force | Draw the 4-way handshake failure in exams. |
| Password Attack | Offline dictionary attacks (e.g., aircrack-ng) |
PMF (Protected Management Frames) + SAE | WPA3 uses Dragonfly Key Exchange to prevent password guessing. |
| Enterprise Mode | EAP flaws (e.g., PEAPv0) | EAP-SIM-based auth (used in Ncell’s 4G) | Compare WPA2-Enterprise vs. WPA3-Enterprise. |
Worked Example: Cracking a WPA2 Password (Why WPA3 Matters)
- An attacker captures a 4-way handshake from a café’s Wi-Fi (
airodump-ng). - They run
aircrack-ng -w rockyou.txt capture.cap(using a 14-million-word dictionary). - If the password is
password123, it cracks in <1 hour. - With WPA3-SAE, even if the password is weak, the handshake fails after 3 attempts, and the attacker gets no feedback.
3. Wireless Attacks: How Hackers Exploit Weaknesses
A. Passive Attacks (Eavesdropping)
- Sniffing: Capturing unencrypted traffic (e.g., HTTP, FTP) or weak encryption (WEP).
- Tool:
Wireshark+airodump-ng. - Real Example: In 2021, a hacker in Pokhara sniffed unencrypted Daraz orders to steal customer data before TLS was enforced.
- Tool:
- Traffic Analysis: Even encrypted traffic can leak patterns (e.g., timing attacks on WhatsApp messages).
B. Active Attacks
Man-in-the-Middle (MITM)
- Attacker tricks client into connecting to a rogue AP (e.g.,
Free_Nepal_WiFi). - Tool:
hostapd(fake AP) +ettercap(ARP spoofing). - Real Example: Banks in Nepal block rogue APs via MAC filtering + 802.1X authentication.
sequenceDiagram participant Client participant RogueAP participant LegitAP Client->>RogueAP: Connects to "Free_Nepal_WiFi" RogueAP->>Client: Sends fake DHCP (gateway=attacker) Client->>RogueAP: Sends credentials (MITM) RogueAP->>LegitAP: Forwards traffic (unencrypted)
- Attacker tricks client into connecting to a rogue AP (e.g.,
Deauthentication Attacks
- Forces devices to reconnect, capturing handshakes.
- Tool:
aireplay-ng --deauth 10 -a [BSSID]. - Real Example: Ncell’s 5G towers use PMF (WPA3) to resist deauth floods.
Jamming
- Floods the airwaves with noise to disable networks.
- Real Example: During protests in Kathmandu, 4G jammers were used to block Ncell signals (illegal but effective).
Bluetooth Attacks
- Bluejacking: Sending unsolicited messages (harmless but annoying).
- Bluesnarfing: Stealing contacts/photos via OBEX push (exploits unpatched Android devices).
- Real Example: Pathao’s driver app now uses Bluetooth LE Secure Connections to prevent spoofing.
C. Cellular Network Attacks
| Attack | How It Works | Real-World Target | Mitigation |
|---|---|---|---|
| IMSI Catcher | Pretends to be a legit tower to steal IMSI | Ncell/NTC customers near borders | Encrypted IMSI (5G), SIM card locks |
| SS7 Leaks | Exploits signaling protocol to track calls | NEPSE traders (call metadata leaks) | Firewall SS7 traffic |
| Tower Hijacking | Redirects calls/data to attacker’s tower | Emergency services (ambulance calls) | GSM authentication (A5/3) |
4. Securing Wireless Networks: Defenses Used by Nepali Companies
A. Authentication & Access Control
| Method | How It Works | Used By | Weakness |
|---|---|---|---|
| WPA3-Personal | SAE + PMF (no offline attacks) | eSewa offices | Weak passwords still crackable |
| 802.1X (EAP-TLS) | Certificates for devices/users | Ncell corporate networks | Expensive to deploy |
| MAC Filtering | Only allows pre-approved devices | Home Wi-Fi (basic) | Spoofable MAC addresses |
| Captive Portals | Forces login before access | Daraz’s guest Wi-Fi | Phishing risks |
B. Encryption & Integrity
- WPA3-Enterprise: Used by banks (NMB, Global IME) for VPNs.
- DTLS (Datagram TLS): Secures IoT devices (e.g., Daraz’s warehouse sensors).
- IPsec (ESP/AH): Protects VPNs (used by remote NEPSE traders).
C. Physical & Network-Level Defenses
- Rogue AP Detection: Tools like
Kismetor Aruba Instant On (used in malls). - Jamming Detection: Frequency hopping (Bluetooth LE) or AI-based anomaly detection (Ncell’s 5G).
- Air Gap + VLANs: Isolate IoT devices (e.g., smart meters in Kathmandu use separate VLANs).
5. Wireless Security in IoT & Mobile Apps
A. IoT Security Challenges
- Weak Default Credentials: Many IoT devices ship with
admin:admin. - No Firmware Updates: Old routers (e.g., TP-Link TL-WR841N) run WEP by default.
- Lack of Encryption: Zigbee/Z-Wave often use AES-128 but no integrity checks.
Real Example: Daraz’s Warehouse IoT
- Problem: Sensors tracking inventory used unencrypted Zigbee.
- Solution:
- Enforced DTLS 1.2 for all sensor-to-gateway traffic.
- Network segmentation: Sensors on VLAN 10, cameras on VLAN 20.
- Firmware updates via over-the-air (OTA) patches.
B. Mobile App Security
- Bluetooth LE Authentication: Pathao’s driver app uses LE Secure Connections to verify driver IDs.
- TLS 1.3 for Payments: eSewa’s app pins TLS sessions to prevent MITM.
- Certificate Pinning: Ncell’s app hardcodes CA certificates to block MITM.
Worked Example: Securing a Kathmandu Traffic Light System
- Threat: Hacker jams 4G signals to cause chaos.
- Solution:
- Dual-band redundancy: Wi-Fi (WPA3) + 4G (with IMSI encryption).
- Physical tamper-proofing: Sealed enclosures for routers.
- Anomaly detection: AI monitors for unusual traffic patterns.
6. Exam-Focused Comparisons & Common Pitfalls
A. WEP vs. WPA2 vs. WPA3
| Protocol | Encryption | Handshake | Vulnerabilities | Exam Markers Love This |
|---|---|---|---|---|
| WEP | RC4 (40/128-bit) | Open System | Crackable in minutes (PTW attack) | "Why is WEP broken?" (5 marks) |
| WPA2 | AES-CCMP (128-bit) | 4-way (PSK) | Offline brute force, KRACK attack | "Trace a WPA2 handshake failure" (10 marks) |
| WPA3 | AES-CCMP (192-bit) | SAE (Dragonfly) | Resistant to brute force, PMF protects management frames | "How does SAE prevent password guessing?" (8 marks) |
B. Bluetooth Attack Vectors
| Attack | Exploit | Mitigation |
|---|---|---|
| Bluejacking | Unauthenticated messages | Disable Bluetooth when unused |
| Bluesnarfing | OBEX push (steals contacts/photos) | Bluetooth LE Secure Connections |
| BlueBorne | Remote code execution (unpatched) | Firmware updates (e.g., Android 10+) |
C. Common Exam Questions & How to Answer
"Explain how a deauthentication attack works and how WPA3 prevents it."
- Answer:
- Attacker sends deauth frames to force reconnection → captures handshake.
- WPA3’s SAE requires online verification (no offline cracking).
- PMF protects management frames from spoofing.
- Answer:
"Compare IMSI catchers and SS7 attacks. Which is more dangerous for NEPSE traders?"
- Answer:
Attack Impact Risk to NEPSE IMSI Catcher Steals IMSI (identity theft) Low (traders use SIM locks) SS7 Leak Tracks calls/data in real-time High (metadata leaks orders) - Conclusion: SS7 is worse because it exfiltrates call records (used for insider trading).
- Answer:
"Draw a sequence diagram for a successful WPA2 handshake and a failed one."
- Success:
Authenticator → Supplicant (EAPOL-Start) → 4-way handshake → PTK established. - Failure: Attacker replays EAPOL frames → handshake fails (but WPA3’s SAE blocks this).
- Success:
In the Real World
eSewa’s Payment Security
- Idea Used: TLS 1.3 + Hardware Security Modules (HSMs)
- How: When you transfer money via eSewa, the app uses TLS 1.3 to encrypt data between your phone and eSewa’s servers. The HSM (a tamper-proof chip) stores private keys offline, preventing theft even if the database is hacked.
- Real Example: In 2022, a hacker tried to MITM eSewa transactions in Bhaktapur, but failed because the TLS session was pinned to eSewa’s certificate.
Pathao’s Driver Verification
- Idea Used: Bluetooth LE Secure Connections
- How: Pathao’s driver app uses Bluetooth Low Energy (BLE) to verify the driver’s phone is paired with the car’s OBD-II port. If an attacker tries to spoof a driver’s location, the BLE handshake fails because the car’s device ID doesn’t match.
- Real Example: In 2023, Pathao blocked 500 fake driver accounts in Pokhara using this method.
Ncell’s 5G Anti-Jamming
- Idea Used: AI-Based Frequency Hopping
- How: Ncell’s 5G towers use machine learning to detect jamming signals (e.g., during protests). When jamming is detected, the network automatically switches frequencies and prioritizes emergency calls.
- Real Example: During the 2021 Kathmandu protests, Ncell’s 5G stayed online while 3G/4G was jammed in some areas.
Exam Tip
For Short Answers (3–5 marks):
- Know the differences between WEP, WPA2, WPA3 (encryption, handshake, vulnerabilities).
- Define MITM, Bluesnarfing, IMSI catcher with one real-world example each.
- Explain how PMF in WPA3 prevents KRACK attacks.
For Long Answers (10–12 marks):
- Trace a 4-way handshake failure (WPA2) vs. SAE success (WPA3).
- Design a secure Wi-Fi setup for a bank (include WPA3-Enterprise, MAC filtering, IDS).
- Compare cellular attacks (IMSI catcher vs. SS7) and recommend mitigations for Ncell.
Diagrams Worth Marks:
- Sequence diagram: WPA2 handshake failure.
- Layered model: Wireless security stack (Physical → Data Link → Network → Transport).
- Network topology: How Ncell’s 5G uses microcells + AI jamming detection.
Avoid These Mistakes:
- ❌ Saying "WPA2 is secure" (it’s not—KRACK attack exists).
- ❌ Forgetting PMF in WPA3 (examiners love this detail).
- ❌ Not linking answers to real Nepali examples (e.g., eSewa, Ncell).
Final Visual Summary
mindmap
root((Wireless Security))
WPA3
SAE: "Dragonfly Key Exchange"
PMF: "Protected Management Frames"
Attacks
MITM: "Rogue AP + ARP Spoofing"
Jamming: "2.4 GHz Noise Flood"
IMSI Catcher: "Fake Tower Attack"
Defenses
eSewa: "TLS 1.3 + HSM"
Ncell: "5G AI Jamming Detection"
IoT: "DTLS + VLAN Segmentation"Based on the TU BIT syllabus for Network Security, unit 4.
Discussion
Loading…