Q1. Define frequency reuse in cellular communication.
Illustrate various frequency sharing techniques.
Frequency Reuse
● Frequency reuse means using the same frequencies in different cells again.
● It improves spectrum efficiency in cellular communication.
● Cellular networks divide areas into small cells.
● Same frequencies are reused only in non-adjacent cells.
● Proper frequency planning reduces interference and supports more users.
Frequency Sharing Techniques
1. Frequency Division Multiple Access (FDMA)
● Used in early 1G cellular networks.
● Available spectrum divided into separate frequency channels.
● Each user gets a dedicated frequency band.
● No time synchronization required.
● Inefficient because unused channels remain idle.
Advantages
● Simple implementation.
● Low latency.
● Continuous transmission possible.
Disadvantages
● Poor spectrum efficiency.
● Fixed allocation limits capacity.
● Requires precise filters to avoid interference.
2. Time Division Multiple Access (TDMA)
● Used in 2G cellular networks.
● Single frequency channel divided into time slots.
● Multiple users share same channel by transmitting in turns.
● Requires synchronization.
Advantages
● Better spectrum efficiency than FDMA.
● Increased network capacity.
● Supports multiple users on same frequency.
Disadvantages
● Requires strict synchronization.
● Latency due to waiting for time slots.
● Fixed slots may cause inefficiency.
3. Code Division Multiple Access (CDMA)
● Spread-spectrum technology used in 3G networks.
● Multiple users share same frequency simultaneously.
● Each user assigned unique code.
● Reduces interference and improves bandwidth efficiency.
Advantages
● Better spectral efficiency.
● Higher security.
● Supports more users.
● Lower interference.
Disadvantages
● Complex signal processing.
● Requires precise power control.
● Near-far problem may occur.
Q2. Explain the evolution of mobile communication
technologies from 1G to 5G.
1G – AMPS
● Introduced in 1983.
● Analog communication using FDMA.
● Supported only voice communication.
● Poor voice quality and limited security.
● Calls were unencrypted and phones could be cloned.
2G – GSM and CDMA
● Introduced in early 1990s.
● Digital communication replaced analog systems.
● Introduced SMS and SIM cards.
● Improved voice quality and security.
● Calls and data encrypted.
2G+ – GPRS and EDGE
● Introduced mobile internet services.
● Supported emails and web browsing.
● EDGE improved data rates over GPRS.
● Still too slow for multimedia applications.
3G – High-Speed Data Networks
● Introduced in early 2000s.
● Supported high-speed data and multimedia.
● Enabled video calling and mobile internet.
● Better encryption and authentication mechanisms.
● Increased cybersecurity risks due to smartphones.
4G – LTE
● Fully IP-based network.
● Supports HD video streaming and cloud applications.
● Speeds up to 1 Gbps.
● Lower latency and improved broadband services.
● Vulnerable to internet-based attacks like DDoS.
5G – Ultra-Fast Connectivity
● Introduced around 2019.
● Speeds up to 10 Gbps.
● Supports IoT, AR, VR, and autonomous vehicles.
● Ultra-low latency.
● Supports massive device connectivity.
● Security challenges increased due to IoT and data privacy concerns.
Q3. Explain the expanded principles of information
security with modern challenges.
1. Confidentiality
● Ensures information is accessible only to authorized users.
● Prevents unauthorized disclosure of sensitive data.
Threats
● Data theft
● Eavesdropping
● Unauthorized access
Protection Methods
● Encryption
● Access control
● Authentication
2. Integrity
● Ensures information remains accurate and unaltered.
● Prevents unauthorized modification of data.
Threats
● Malware
● Data tampering
● Unauthorized editing
Protection Methods
● Hashing
● Digital signatures
● Integrity checks
3. Availability
● Ensures systems and data are available when needed.
● Prevents service interruptions.
Threats
● Denial of Service (DoS)
● Network failures
● Malware attacks
Protection Methods
● Backup systems
● Redundancy
● Disaster recovery plans
4. Accountability
● Makes users responsible for their actions in a system.
● Helps track activities and identify misuse.
Importance
● Prevents insider threats from authorized users.
● Improves monitoring and security management.
Mechanisms
Authentication : Verifies user identity using usernames and passwords.
Authorization
● Grants access based on roles and responsibilities.
● Example: Role-Based Access Control (RBAC).
Audit Trails and Logs
● Record user activities for investigation and review.
● Help detect suspicious behavior.
Risks
● Lost devices or access credentials can cause security breaches.
● Reporting stolen devices quickly is important.
5. Nonrepudiation
● Prevents users from denying their actions.
● Provides proof of communication or transaction.
Importance
● Important in e-commerce and financial transactions.
● Used in legal and business communications.
Mechanism – Digital Signatures : Provide proof of sender
and receiver identity.
Nonrepudiation of Origin : Sender signs the document or message.
Nonrepudiation of Delivery : Receiver signs acknowledgement of receipt.
Challenges
● Read receipts are not legally reliable.
● Credentials can be stolen on unsecured networks like public Wi-Fi.
Q4. Categories of Wireless/Mobile Threats
1. Data Theft
● Theft of personal or corporate information.
● Can occur through malware or insecure wireless networks.
● Leads to privacy and financial loss.
2. System Access Threats
● Unauthorized access to mobile devices and systems.
● Attackers may gain control over applications or accounts.
● Weak passwords increase risk.
3. Malware Threats
● Includes viruses, worms, spyware, and ransomware.
● Can steal data or damage systems.
● Commonly spread through malicious apps.
4. Wireless Threats
● Rogue access points and Wi-Fi attacks.
● Signal interception and packet sniffing.
● Unauthorized network access.
5. BYOD Risks
● Mixing personal and company data on same device.
● Personal devices may lack proper security.
● Increases chances of data leakage.
Q5. Key Components of Defense in Depth
1. Physical Controls
● Protects using locks, cameras, gates, fences
● Prevents unauthorized physical access
2. Logical / Technical Controls
● Uses firewalls, antivirus, HIPS, NIPS
● Protects systems from attacks and unauthorized access
3. Administrative Controls
● Includes policies, rules, procedures
● Controls how users and systems are managed securely
Layers of Defense in Depth:
● Uses multiple layers of security to protect systems
● If one layer fails, other layers still provide protection
1. External Network Layer
● Exposed to internet and external users
● Uses firewalls and DMZ for protection
2. Perimeter Network Layer
● Separates external and internal networks
● Uses inner firewall and IPS
3. Internal Network Layer
● Contains users and internal systems
● Uses ACLs, firewalls for access control
4. Application Server Network
● Hosts application services
● Allows only authorized access
5. Database Server Network
● Stores sensitive data
● Has very restricted and secure access
Q6. Explain cellular communication and coverage maps
in mobile networking.
● Earlier communication depended on PSTN, which required wires.
● In the early 1990s, mobile phones enabled communication without landlines.
● Mobile phones became affordable, efficient, and widely used worldwide.
● Cellular networks divide geographic areas into small cells for efficient communication
and frequency reuse.
Cellular Coverage Maps
Coverage maps are used to design mobile networks for proper signal coverage and efficient
communication.
1. Cellular Design
● Mobile networks are divided into small geographic areas called cells.
● Each cell is covered by a cell tower.
● Hexagonal cell structure ensures full coverage with minimum gaps.
2. Base Transceiver Station (BTS)
● Each cell contains a BTS or cell tower.
● BTS manages communication between mobile phones and the network.
● BTS towers may be disguised to blend with surroundings.
3. Backhaul Connection
● Towers connect to the Base Controller Station (BCS).
● Connection uses fiber-optic or microwave links.
● BCS further connects to core network, PSTN, and Internet.
4. Frequency Reuse
● Same frequencies are reused in non-adjacent cells.
● Reduces interference and improves spectrum efficiency.
● Proper frequency planning minimizes overlap.
5. Macrocells
● Large cells used in rural areas.
● Cover long distances.
● Useful where user density is low.
6. Microcells
● Smaller cells used in urban areas.
● Handle high subscriber density.
● Improve coverage in crowded locations.
7. Picocells
● Very small cells used inside buildings and stadiums.
● Improve indoor connectivity.
● Also used in dense city areas and remote locations.
Solving Frequency Interference Issues
● Frequency segmentation ensures that adjacent cells operate on different
frequencies.
● Power control mechanisms prevent signal overlap and maintain clear
communication.
● Adaptive cell sizes (macro, micro, picocells) optimize coverage for different
areas,ensuring efficient bandwidth usage.
Q7. Impact of BYOD policies on mobile networking in
businesses + Mitigation
BYOD (Bring Your Own Device) allows employees to use personal mobile devices such
as smartphones, tablets, and laptops for organizational work.
Impact of BYOD:
● Employees use personal devices for work
● Reduces cost of company devices
● Increases productivity and availability
● Enables work beyond office hours
● Improves communication and flexibility
Risks:
● Loss of IT control over devices
● Risk of data breaches and malware
● Mixing personal and company data
● Unauthorized access to corporate systems
Mitigation Techniques
1. Mobile Device Management (MDM)
● Helps monitor and control employee devices.
● Enables remote locking and data wiping.
2. Encryption and Security Policies
● Encrypt sensitive corporate data.
● Apply strong organizational security policies.
3. Authentication and Access Control
● Use strong passwords and multi-factor authentication.
● Restrict unauthorized access to systems.
4. Regular Monitoring
● Continuously monitor connected devices.
● Detect suspicious activities quickly.
5. Employee Security Training
● Train employees about cyber threats and safe practices.
● Improve awareness regarding phishing and malware.
[Link] Standards: ISO, NIST, PCI DSS
ISO/IEC 27001:2013 and 27002:2013
● International standards for Information Security Management System (ISMS).
● Help manage information security in organizations.
● Cover areas like asset management, cryptography, and access control.
● Follow Plan–Do–Check–Act (PDCA) cycle for continuous improvement.
NIST SP 800-53
● Developed by National Institute of Standards and Technology (NIST).
● Provides security controls and risk management framework.
● Includes incident response and business continuity controls.
● Widely used in government and federal systems.
PCI DSS (Payment Card Industry Data Security Standard)
● Security standard for protecting credit card information.
● Ensures secure handling and processing of payment data.
● Prevents financial fraud and data breaches.
● Used by organizations handling card transactions.
Regulatory Compliance
1. Sarbanes–Oxley Act (SOX)
● Improves corporate governance and financial reporting.
● Requires controls for financial data integrity.
● Supports secure information management.
2. Gramm–Leach–Bliley Act (GLBA)
● Requires information security programs.
● Protects integrity and confidentiality of financial data.
3. HIPAA & HITECH
● Protect healthcare and patient information.
● Ensures CIA of health data.
● Focuses on privacy and healthcare security.
4. Payment Card Industry Data Security Standard (PCI DSS)
● Secures credit cardholder information.
● Protects payment card transactions.
● Requires encryption and access control.
● Important for businesses handling card payments.
5. GDPR & CCPA
● Protect personal data and user privacy.
● GDPR applies to EU citizens’ data.
● CCPA protects privacy of California residents.
● Gives users greater control over personal data.
Handoff in mobile phones
Frequency reuse