Ph.D.
Course Work – Wireless and Web
Security Notes
Wireless Security
Wireless security involves protecting wireless networks (such as Wi-Fi) from unauthorized
access or damage. Encryption (WPA3/WPA2), MAC filtering, and strong authentication are
essential.
Wireless Network Threats
1. Eavesdropping
2. Rogue access points
3. DoS attacks
4. Man-in-the-middle attacks
5. MAC spoofing
Wireless Network Measures
1. Use WPA3 or WPA2 encryption
2. MAC address filtering
3. Disable SSID broadcast
4. Regular firmware updates
5. Network segmentation
Mobile Device Security & Threats
Mobile devices face threats such as loss, theft, malware, phishing, and insecure Wi-Fi.
Strategies include encryption, MDM, app whitelisting, and user training.
Mobile Device Security Strategy
1. Strong passwords & biometric lock
2. Remote wipe & device tracking
3. Secure app sources
4. VPN usage
5. Regular OS updates
IEEE 802.11 Wireless LAN Overview
IEEE 802.11 is the set of standards for implementing wireless local area network (WLAN)
communications in various frequencies including 2.4GHz and 5GHz.
The Wi-Fi Alliance
A non-profit organization promoting Wi-Fi technology and certifying product
interoperability and security.
IEEE 802 Protocol Architecture
Divided into MAC (Media Access Control) and PHY (Physical Layer). Ensures organized
communication and access control in wireless networks.
IEEE 802.11i Services and Phases of Operation
802.11i provides robust security with AES and TKIP. Phases:
1. Discovery
2. Authentication
3. Key Management
4. Protected Data Transfer
IEEE 802.11i Pseudorandom Function
Used for generating cryptographic keys from shared secrets to ensure secure wireless
communication.
Web Security Threats
1. XSS
2. CSRF
3. SQL Injection
4. Clickjacking
5. Session hijacking
Web Traffic Security Approaches
1. HTTPS (SSL/TLS)
2. Secure cookies
3. CSP (Content Security Policy)
4. Input validation
5. WAF (Web Application Firewall)
SSL Architecture and Protocols
Includes Handshake, Record, Change Cipher Spec, and Alert protocols. Ensures
authentication, encryption, and integrity.
SSL Cryptographic Computations
Involves RSA/DH key exchange, symmetric encryption (AES), and MACs (HMAC). Provides
secure communication.
TLS (Transport Layer Security)
TLS is the successor of SSL. Includes versioning, MAC, PRF, alert codes, cipher suites, and
message verification.
HTTPS Connection Initiation & Closure
TLS handshake begins HTTPS. Closure involves session termination and discarding keys to
prevent reuse.
SSH (Secure Shell) Protocols
SSH includes:
1. Transport Layer Protocol – provides encryption and integrity
2. User Authentication Protocol – validates users
3. Connection Protocol – manages multiple channels like terminals, file transfers