0% found this document useful (0 votes)
12 views26 pages

Wireless Network Security Overview

The document discusses security in wireless networks, focusing on WiFi and cellular networks, highlighting the rapid growth of wireless technology and its advantages. It outlines various security levels in wireless networks, including basic, medium, and high-level security mechanisms such as SSID, WEP, WPA1, and WPA2. Additionally, it explains the architecture and operation of wireless networks, including components like access points and the process of connecting wireless clients.

Uploaded by

Jay Kania
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views26 pages

Wireless Network Security Overview

The document discusses security in wireless networks, focusing on WiFi and cellular networks, highlighting the rapid growth of wireless technology and its advantages. It outlines various security levels in wireless networks, including basic, medium, and high-level security mechanisms such as SSID, WEP, WPA1, and WPA2. Additionally, it explains the architecture and operation of wireless networks, including components like access points and the process of connecting wireless clients.

Uploaded by

Jay Kania
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CSCI 4174/6708 Network Security

Security in Wireless Networks

• Bird’s eye view of wireless


• Security in WiFi networks
• Security in cellular networks

Network Security: Module 8 Srini Sampalli 1


Wireless is the fastest growing telecom industry today….

Wireless network data traffic:


More than one billion smartphones
66 Exabytes/month (2021 Q1)
are sold every year.
(1 Exabyte = 1018 bytes or 1 billion GB)

There are more than 500 million wireless Number of IoT devices around the globe is
hotspots around the world. around 35 billion –
That is one hotspot for every 15 humans. majority have wireless connectivity

Sources: [Link], [Link], Gartner insights

WHAT IS ATTRACTIVE ABOUT WIRELESS?

• CAMP: Convenience, Affordability, Mobility, Productivity

• Deployment advantages: Installation flexibility, speed and scalability


• Regions without or with limited wired infrastructure can easily establish
wireless communication.
• Wireless networks have a better chance of surviving disasters.
• 802.11 wireless LANs, 3G+ and 5G cellular networks promise high
bandwidths, global mobility, quality of service and seamless integration
with one another.

Network Security: Module 8 Srini Sampalli 2


What is wireless communication?
Process of transmitting information in the form of electro-
magnetic waves in free space at certain frequencies.

Frequencies are measured in Hertz (1 Hz = 1 cycle per sec.)

Audible Sound Radio Frequencies Infrared, Visible Light


Xrays, Gamma rays, ...

20Hz- 20KHz 20 KHz - 300 GHz 300 GHz -

Wireless
Services
800 KHz - 5 GHz

Classification of Wireless Networks

WIRELESS CELLULAR WIRELESS DATA


NETWORKS NETWORKS

Con-
vergent

Mainly for voice Mainly for data


communications communications

Network Security: Module 8 Srini Sampalli 3


WIRELESS TECHNOLOGIES BASED ON RANGE
WIDE AREA NETWORK (Cellular)

RADIO ACCESS NETWORK (Cellular)

METROPOLITAN AREA NETWORK (Cellular)

CAMPUS AREA NETWORK (Campus WiFi)

LOCAL AREA NETWORK (WiFi)

PERSONAL AREA NETWORK (Bluetooth, NFC)

BODY AREA NETWORK (Sensors on body)

NANO NETWORK (micro-sensors inside materials


Source: Wikipedia and body)

Overview of WiFi Networks


Architecture and Operation

Network Security: Module 8 Srini Sampalli 4


IEEE Wireless LAN Standards

Source: [Link]

IEEE Wireless LAN Standards

WiFi 7 expected to be
ratified this year.
Also called 802.11 be EHT
(Extremely High Throughput)
2, 4, 6 GHz frequency bands
30 Gbps

Source: [Link]

Network Security: Module 8 Srini Sampalli 5


Components and Architecture
• All components that can connect to the
wireless medium in an 802.11 WLAN are called
stations.
• Stations fall into two broad categories:
– Wireless clients: Mobile nodes (laptops, personal
digital assistants, IP phones, etc.), fixed nodes with
wireless access (desktops, workstations, etc.).
– Access points (APs): Base stations to facilitate
communications.
• All stations are equipped with wireless
network interface cards.

• The basic building block of an 802.11 WLAN is


called a basic service set (BSS).

• It is a set of stations that can communicate


with each other.

• BSSs can be set up in one of two ways:


– Independent BSS: No access points. Also called ad
hoc networks.
– Infrastructure BSS: Access points serve as base
stations for receiving and broadcasting messages.

Network Security: Module 8 Srini Sampalli 6


Infrastructure BSS
• Stations communicate via an AP.
• A set of infrastructure BSSs connected together in a
network is referred to as an extended service set (ESS).
• Traffic within the BSS and also from one BSS to another is
via the APs.
• The APs in an ESS are connected by a distribution system
which facilitates communication among the APs.
• The distribution system is typically (but not necessarily) a
wired LAN.
• Two significant addresses:
– BSS ID à MAC address of the AP serving the BSS.
– ESS ID à Character string (max 32 bytes) assigned by admin. Also
called the SSID. E.g., DalWPA, Dal, eduroam

I
tI
17 i i 1
1 Is I
ÉÉÉ

Network Security: Module 8 Srini Sampalli 7


Operation
GETTING CONNECTED
• There are a number of management frames that enable
a wireless client to get connected and also to break an
existing connection with an AP:

– Probe Request
– Probe Response
– Association Request
– Association Response
– Beacon
– Reassociation Request
– Reassociation Response
– Authentication
– Deauthentication

802.11 Networks: Operation


Association

Access Point
Probe R
Wireless Station

equest

Probe Response

Associa
tion Req
u est

onse
Association Resp

Network Security: Module 8 Srini Sampalli 8


Beaconing

Access Point
Wireless Station

Beacon

Beacon

Associa
tion Req
u est

onse
Association Resp

Reassociation

Reassoc.
Request BSS (Basic
Service Set)

DS (Distribution System)
Access Point

Wireless Station

Disassoc. Access Point

BSS (Basic
Service Set)

Extended Service Set (ESS) Wireless Station

Network Security: Module 8 Srini Sampalli 9


Wireless 802.11 System Overview

Router/Switch
Wired Network
IP Network

Access Point (AP)


Focus is on the
security in this
domain
IP phone

Laptop
Laptop

Network Security: Module 8 Srini Sampalli 10


Security in 802.11 WLANs

• Basic Level Security


– Service Set Iden3fier (SSID)
– MAC Address Filtering
• Medium Level Security
– Wired Equivalent Privacy (WEP)
• High Level Security
– Wi-Fi Protected Access Version 1 (WPA1)
– Wi-Fi Protected Access Version 1 (WPA2) a.k.a. IEEE
802.11i Security Standard
– Wireless VPNs

Basic Level Security

Service Set Iden,fier (SSID)


– SSID or ESSID is a character string programmed in the
APs serving the WLAN.
– It is a rudimentary authen,ca,on value - every
wireless client must know the SSID in order to get
connected to the WLAN.
– Access points periodically broadcast SSIDs in clear text.
– If the broadcast feature is turned off, then only clients
which know the SSID can get connected.

Network Security: Module 8 Srini Sampalli 11


Basic&Level&Security&(cont d.)&

MAC$Address$Filters$
– Access$points$can$be$programmed$to$accept$
authen7ca7on$requests$only$from$wireless$
clients$with$legi7mate$MAC$addresses.$
– Work$similar$to$access$control$lists$but$at$the$
MAC$layer.$

ssipsaYe
[Link]
I 2
is turned off
broadcast feature
Even if this SSIDs
sniffers like kismet can decloak
passive
MAC addresses can be spoofed
3

Network Security: Module 8 Srini Sampalli 12


Medium Level Security

Wired Equivalent Privacy (WEP)


• WEP was proposed to provide link-level security
in 802.11 networks.
• Its intended security goals were confiden?ality,
access control, integrity and authen?ca?on.

Medium Level Security - WEP (cont d.)

• WEP uses a shared secret key for encryp4ng and


authen4ca4ng data between a wireless client and
an access point.
• One of the four shared keys can be manually
configured in the AP and the wireless clients.
• Some wireless cards rotate the key used among
the four keys periodically.
• Key sizes: 40 bits or 104 bits.

Network Security: Module 8 Srini Sampalli 13


WEP$Encryp*on$

• The$40'bit$or$the$104'bit$secret$key$is$concatenated$with$a$
24'bit$ini7aliza7on$vector$(IV)$to$give$a$64'bit$or$a$128'bit$
WEP$key.$
• The$WEP$key$is$input$to$a$pseudo'random$number$
generator$based$on$RC4$algorithm$to$produce$a$key$
stream.$
• An$integrity$check$value$(ICV)$based$on$CRC$is$computed$
for$the$plaintext.$
• The$plaintext$concatenated$with$the$ICV$is$XORed$with$the$
key$stream$to$generate$the$ciphertext.$
• The$transmiPed$message$consists$of$IV$(in$plain$text)$and$
the$cipher$text.$

secret key
Hi
I
Network Security: Module 8 Srini Sampalli
IÉ 14
WEP$Decryp+on$

• The$40'bit$or$the$104'bit$secret$key$is$concatenated$with$
the$received$24'bit$ini8aliza8on$vector$(IV)$to$get$back$the$$
64'bit$or$a$128'bit$WEP$key.$
• The$WEP$key$is$input$to$the$same$pseudo'random$number$
generator$algorithm$to$produce$the$same$key$stream.$
• The$ciphertext$is$XORed$with$the$key$stream$to$get$back$
the$plaintext$and$the$ICV.$
• An$integrity$check$value$(ICV)$is$independently$computed$
and$checked$against$the$received$ICV.$

Et
tE

Me Be I iI
Match
É
Network Security: Module 8 Srini Sampalli 15
WEP$Authen+ca+on$

• The$wireless$client$sends$an$authen0ca0on$request$to$the$
access$point.$
• The$access$point$sends$a$random$challenge$text$in$clear.$
• The$client$encrypts$the$challenge$text$using$the$secret$key$
and$sends$it$back$to$the$access$point.$
• The$access$point$authen0cates$the$client$by$decryp0ng$
the$challenge$response.$

client of

CHACLENGETEX
Fitt

Tian

Network Security: Module 8 Srini Sampalli 16


WEAKNESSES IN WEP

Same key for all clients


1 S edsecrtky
does not change renters manually
2 key key done
next This means the actual

IEzdgjo
3
or 104 bits not 64
or 128 bits
bits This means IVs are
4 Sizegivisonty repeated
PNG k 101 where Pl Plaintext
Let Ci Pl Cl ciphertext
K Servetkey
PNG K IV27
C2 P2
I V2 7U
If IV1
P2 PnafkI
CI C2 Pl PIV
Ci C2 Pl P2
reverse engineering the key
This can help in
5 useyercasamenagedigestalfhmis
6 Authenhahonverealsapyff peretpair
7 Caat challenge the AP
8 ManagementLanesarenoteneypted
Network Security: Module 8 Srini Sampalli 17
HIGH LEVEL SECURITY MECHANISMS IN 802.11 WLANs

WI-FI PROTECTED ACCESS VERSION 1 (WPA 1)

• Designed to remove WEP’s weaknesses and also to add a


stronger authentication feature compared to WEP.
• Consists of two main components

802 Ix for authentication


key management

confidentiality
TRIP for
integrity
WPA 1 Components

Temporal Key Integrity Protocol (TKIP)

Features

• Per packet Key Mixing: Change the encryption and


authentication keys for every frame.
• Stronger integrity check algorithm: Algorithm MIC (Message
Integrity Code) based on HMAC is used (unlike the CRC check
in WEP).
• Sequence numbers are added to frame fragments (to prevent
replay attacks).
• Increased IV size: IV size is increased to 48 bits (from 24 bits in
WEP). This avoids IV reuse.

Network Security: Module 8 Srini Sampalli 18


TKIP Encryption Process

t
encryption Intermediate Phase Fragment
key11
14 key
key
Mixer Key WEP
Sender's
MACadv sequence Encapsul
a
number ator E
forfragment R
PAYLOAD T
PAYLOAD E
Mee MD Fragmenta X
T
Fragment
64 bit
integrity
Sender's MAC ads
Receiver'sMacadr

• Two keys derived from the master key (from the 802.1x process)
are used as input keys: a 128-bit encryption key and a 64-bit data
integrity key.
• Phase 1 key mixing generates an intermediate key from the
encryption key and the sender’s MAC address.
• MIC generates the payload plus the message digest from the data
integrity key, sender and receiver’s MAC addresses and the
payload.

I
• Payload plus digest is fragmented and each fragment is assigned
a sequence number.
• Phase 2 key mixing uses the intermediate key and the sequence
number to generate a per packet key (for each fragment).
• The per-packet key and the fragment undergo the regular WEP
encapsulation process to produce the ciphertext.

Network Security: Module 8 Srini Sampalli 19


802.1x

802.1x is a protocol for authenticating wireless nodes and also for


generating keys.

802.1x process

1. When a new wireless client (supplicant) requests access to the


WLAN, the access point (authenticator) asks for the identity of
the client and issues a temporary encryption key.
2. The client sends the user name and password (encrypted) to
the authenticator.
3. The authenticator relays it to an authentication server (AS)
using another secret key encryption.
4. The authentication server verifies the client’s credentials and
sends a permit message if the verification is successful. It also
issues keys for TKIP.

aumYi arm
an y
not protected
2 Management frames

Network Security: Module 8 Srini Sampalli 20


Wi-Fi PROTECTED ACCESS VERSION 2 (WPA 2) OR 802.11i

• Improved version of WPA.


• Ratified in June 2004.
• Provides an alternative encryption algorithm based on AES
called CCMP (Cipher block Chaining Mode Message
Authentication Code Protocol). (Note: TKIP and WEP use RC4
encryption, which is weak).
• 802.1x has been extended to provide bi-directional
authentication between the client and the access point.

directional
Enhanced biauthentication
802.1 X

TRIP COMP
AES based
encryption
for
backward
compatibility Strong

Weakness
frames are not protected
1 Management

Network Security: Module 8 Srini Sampalli 21


Wireless VPN Configura2on 1

VPN
Server

Mobile Node Firewall


AP
with VPN client
with VPN
support
Private Wired Network

IPSec Tunnel

Wireless VPN Configura2on 2


VPN Server
BH

Mobile Node AP
with VPN client with VPN
support Private
i Network

DMZ

IPSec Tunnels

78 7 does not protect against


link
attacks
physical layers
launched at the data
Network Security: Module 8 Srini Sampalli 22
CELLULAR NETWORK SECURITY

3G+ CELLULAR NETWORK ARCHITECTURE

ED g

BYEE
Iekahi [Link]

111 I
Dm
it Tentower I Internet

DIVEcellphone MS

Acronyms and Functions

UE/MS: User Equipment/ Mobile Station


Consists of the physical device plus USIM card (UMTS Subscriber Identity Module)

UMTS: Universal Mobile Telecom System

BTS: Base Transceiver Station (Cell Tower)

RNC: Radio Network Controller à serves many BTSs.


à connects to the circuit switched and packet
switched networks

MSC: Mobile Switching Center à serves many RNCs


à routes calls from and to mobile stations
à manages all switching and signaling functions

HLR: Home Location Register à stores data related to each subscriber


à there may be many HLRs for a given provider

VLR: Visitor Location Register à Works in conjunction with MSC.


à contains information on active subscribers in the
area served by the MSC

AuC: Authentication Center à physically located in the HLR.


à responsible for authentication and security
services.

GSN: Gateway Support Node à Interfaces to data network(Internet)

Network Security: Module 8 Srini Sampalli 23


SECURITY PROCEDURE: CONNECTION TO VOICE NETWORK

AUTHENTICATION AND KEY AGREEMENT

Cellphone MSC GMSC


USIM VER AUC

III GENERATE
Avs
SATs CEI
D
Pigged

verify
It
RANDCI
AUTNID verify XRE li
Ggg
[Link]
i

AVI Aviz Aven is a long binary string


generate the same set of
Auc can
Only USIM
Avs

t ffautke
Ava
Network Security: Module 8 Srini Sampalli 24
Integrity Message Expected
Random Encryption
number key Digest
key Response

Phase I

1. Visited network’s VLR requests a set of Authentication Vectors (AVs) from


the AuC of the HLR.

2. AuC generates an array of AVs: AV(1…n).

3. Each AV(i) is computed by means of authentication algorithms and the


user’s private secret key K, which is stored only in the HLR/AuC and the
USIM card of the user’s device.

4. HLR/AuC sends the set of n AVs to VLR.

Phase II

1. VLR randomly chooses one AV(i) and challenges the mobile station by
sending the RAND(i) and the AUTN(i) fields of the AV(i) to it.

2. The mobile station’s USIM processes the AUTN. With the same secret key
K, the USIM is able to verify the validity of the AU(i).

3. The user computes the response RES and sends it to the VLR.

4. It proceeds to compute the Cipher key CK(i) and the Integrity key IK(i).

5. The VLR checks the RES against XRES and if correct, proceeds to select
the CK(i) and the IK(i).

SECURITY PROCEDURE: CONNECTION TO VOICE NETWORK (Cont’d.)

ENCRYPTION OF SIGNALING AND USER DATA

It Dem algorithm
Ikey stream
Plaintext Of Ciphertext
Network Security: Module 8 Srini Sampalli 25

You might also like