0% found this document useful (0 votes)
14 views71 pages

Wireless Network Security Solutions

The document presents a scientific work dedicated to the security of wireless networks, focusing on RADIUS authentication. It addresses the security issues related to the use of the Internet by companies and proposes solutions to protect IT resources. The research focuses on the Department of Living Languages at the University of Kinshasa, using experimental and documentary methodology.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views71 pages

Wireless Network Security Solutions

The document presents a scientific work dedicated to the security of wireless networks, focusing on RADIUS authentication. It addresses the security issues related to the use of the Internet by companies and proposes solutions to protect IT resources. The research focuses on the Department of Living Languages at the University of Kinshasa, using experimental and documentary methodology.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

[i]

EPIGRAPH

The fear of the Lord teaches wisdom, and humility precedes


glory.

Proverbes 15:33

DEDICATION
[ii]

To the eternal our Almighty God, He the author of all


things, may His holy name be blessed.

To my late mother Agnès MUKANA whom I loved dearly.


loved in this mortal flesh, may her soul rest in peace.

To my parents, Bernard MUBANGA and Bernadette


THANK YOU, for their support, encouragement and indescribable love.

To my brothers and sisters: Simon MUBANGA, Ruben


MUBANGA, Charlène MUBANGA, Paulin KELENDE, Lina KAMAYI, Rachel
MBUYI, Grace MUBANGA, Gloire KALAMBA, and Kyria NDOMBA.

May this scientific work be for us all the products


efforts made despite various difficulties endured.

THANKS
[iii]

The work presented here was realized with the support of


several people. Their availability, their critiques, advice and
suggestions have been undeniably valuable. We want to address our
sincere thanks.

Our thanks go straight to our director,


Professor MABELA Rostin and our supervisor Mr. the assistant
KATSHITSHI, who have abandoned their multiple occupations have
take the trouble to lead this work with dedication.

Our thanks also go to my


struggle companions: Jacques ILUNGA, Blanchard KANGULUMBA, Felly
TSHIMANGA, Carmel META, Gentille BILONDA, Joseph NGWABA,
Nickson MINGA and Tracy MUJINGA.

That all those whose names are not mentioned do not feel
not to abandon but that they find through these lines the expression of
our sincere gratitude and consideration.

LIST OF ABBREVIATIONS
[iv]

ACL Access Control List


ADSL Asymmetrical Digital Subscriber
AES Advanced Encryption Standard
AP Access Point
ARP Address Resolution Protocol
ASCII American Standard Code for Information Interchange
ATM Asynchronous Transfer Mode
CLI Command Line Interpreter
CNIL National Commission for Information and Liberty
CSMA/CD Carrier Sense Multiple Access/Collision Detection
DHCP Dynamic Host Configuration Protocol
DNS Domain Name Service
EAP Extensible Authentication Protocol
FDDI Fiber Data Distribution Interface
FTP File Transfer Protocol
GHz Giga Hertz
GPS Global Positioning System
HDD Hard Disk Drive
HTML Hypertext Markup Language
htp Hypertext Transfer Protocol
ICMP Internet Control Message Protocol
IEEE Institute of Electrical and Electronic Engineers
IETF Internet Engineering Task Force
IP Internet Protocol
IPSEC Internet Protocol Security
IPV4 Internet Protocol Version 4
IPX Internetwork Packet Exchange
LAN Local Area Network
LLC Logical Link Control
LLC Logical Link Control
MAC Medium Access Control
MAN Metropolitan Area Network
Mbps Megabit per Second
NetBios Network Basic Input-Output System
NPS Network Policy Server
OFDM Orthogonal Frequency Division Multiplexing
OSI Open System Interconnect
PAN Personal Area Network
[v]

PCI Peripheral Component Interconnect


PCMCIA Personal Computer Memory Card International Association
PDA Personal Digital Assistant
POP3 Post Office Protocol Version 3
PSK Pre Shared Key
Quality of Service Quality of Service
RADIUS Remote Authentication, Authorization and Accounting
RAM Random Access Memory
RARP Reverse Address Resolution Protocol
RFC Request for Comment
RIP Routing Information Protocol
SMTP Simple Mail Transfer Protocol
SNMP Simple Network Management Protocol
SSH Site Security Handbook
SSID Service Set Identifier
TCP Transmission Control Protocol
TFTP Trivial File Transfer Protocol
TKIP Temporal Key Integrity Protocol
TLS Transport Layer Security
UDP User Datagram Protocol
USB Universal Serial Bus
voIP Voice Over IP
VPN Virtual Private Network
WAN Wide Area Network
WAP Wi-Fi Protected Access
WEP Wired Equivalent Privacy
WIFI Wireless Fidelity
WIMAX Worldwide Interoperability for Microwave Access
WLAN Wireless Local Area Network

LIST OF FIGURES
[vi]

Figure 1 Diagram of a peer-to-peer network


Figure2 Diagram of a client-server network
Figure3 Schematic of a bus topology
Figure 4 Diagram of a star topology
Figure 5 Diagram of a ring topology
Figure 6 Diagram of the functioning of the OSI model
Figure 7 Wireless adapter
Fiureg8 Access point
Figure 9 war-chalking
Figure 10 wired network and secure Wi-Fi
Figure 11 centralized authentication system
Figure 12 The architecture of authentication
Figure 13 operating principle
Figure 14 the architecture of the network
Figure 15 Solution concept based on EAP-TLS 802.1X authentication

GENERAL INTRODUCTION
[vii]

Organizations and businesses always tend to


increase their activities and maximize their profits. Nowadays, with the evolution
technological, computing, science of automatic and rational processing
information, considered as a support for human knowledge, takes a
capital importance, because its integration into information systems allows to
maximize the activities and performance of the services.
The term "computer science," derived from the contraction of the words: "information" and
automatic was proposed in 1962 by Philippe DREYFUS, and accepted by the academy
French in 19661.

The development of internet usage has allowed many


companies to open their information systems to their partners or their
suppliers. Therefore, it is essential to know the resources of
the company to protect and thus control access and rights of
system information users.

Communication is not only internal to the company but


also external with other companies, suppliers, clients, and employees.

Indeed, the number of nomadic workers is increasing.


and they may need to access the company's resources at any time.
place and at all times. This is particularly true for salespeople.

To meet these needs, new means of exchange have


were developed based on which we find computing, networks, and the Internet.

Today, numerous companies, regardless of their


size or their activity are connected to the Internet, thus having access through this network
public, from an access point to a gigantic infrastructure.

But the use of the Internet poses a significant problem: the


security of exchanges.
This security is addressed under several criteria:

Mutual authentication of correspondents to be sure of one's


interlocutor

The integrity of transmitted data to ensure that they have not been
accidentally or intentionally modified;

Confidentiality to prevent data from being read by systems or


unauthorized persons;
[Link]
1
[viii]

The non-repudiation to prevent the sender from contesting the sending of


data;

theavailabilityto guarantee access to a service or resources.

In this work, we will focus on security of


wireless networks, as these technologies embody undeniable progress, are emerging
new ways to access computing resources and exchanges
data. When one must ensure the proper functioning of a network that exceeds
the dimensions of the family network, it becomes necessary to ensure that the
danger does not come from within. With the proliferation of personal computers
portables, the risk of seeing an unknown machine come to pollute the network of
the interior must be taken seriously. Provided that there is also Wi-Fi access
disponible, il convient en plus de s'assurer que seules les personnes autorisées
may cling to it.
This work aims to provide some drafts of solutions
to all these problems. We will appeal to the generality on the computer network,
to Wi-Fi standards, implementing RADIUS authentication.
[ix]

1. CHOICE AND INTEREST OF THE SUBJECT

At the moment when the entire world is experiencing considerable growth on


the new information and communication technologies, companies are
called to regain their places in this growth to play the role of driving element
of social, economic, and political progress.

Thus, two main reasons justify the choice and interest of


this subject, namely:

First of all, we fulfill our legitimate duty as finalists of the


graduation cycle that requires each student to write a final paper
cycle, as well as the ongoing concern to deepen our knowledge in the
network security domain (WLAN);
Secondly, this intellectual work allows us to bring closer the
theoretical notes accumulated throughout our training to practice,
and constitutes an undeniable source of supply for the future
researchers who will address the same research theme as us;

2. ISSUE

The issue is the step that brings together the questions asked.
by the researcher during their research in order to bring out all the difficulties
of the system, in other words it is the set of questions posed by a subject
precise2
Dictionary: The Little Larousse 2010, page 648
2
[x]

Specifically, it represents the question marks at


subject of a troubling issue for a researcher and which he wishes to define the fields
theoretical knowledge. Thus, throughout this work, we will seek to
understanding the issue of establishing a secure system based on
authentication in a WLAN network.

Knowing what the issue is, we will be led to


we ask ourselves the following questions:

-What security mechanism can be applied to control access to the


wireless network?

What role will the security policy have once implemented on the network?

Can the network in question meet the common needs of


user groups located in the department of modern languages and
those from outside?

3. HYPOTHESIS

A hypothesis is a proposition from which one


reasoning to solve a problem, to demonstrate a theorem. Or again
proposition resulting from an observation and that is submitted to control of
the experience or that we verify by deduction3
The hypothesis is defined as a proposition of the
provisional answers to questions we have about the research subject
formulated in such a way that observation and analysis can provide an answer.4

Thus, we believe that the implementation of this system at


the department of living languages will facilitate its administration and the mechanism of
security that would be applied to control access in this network is
authentication before entering the company's intranet.

Once the new security policy is in place, it


will consist of controlling all access to the network, this operation will be carried out as soon as
the physical access of all authorized and unauthorized users to the site
of the company but access to the resources of the information system is conditional
through an authentication. The policy implemented will serve to secure the
local network against all intrusions.

4. DELIMITATION OF THE SUBJECT

Dictionary: [Link]., page 356


3

BAKASANDA Jeannot A., course on scientific research methodology G2Design, unpublished ESIS 2006-2007
4
[xi]

Our subject is limited in time and space.

In space, the environment in which we immerse ourselves


work focuses much more on the implementation of a security system based
on authentication in a wireless network (WLAN) within the department
living languages, which is located at the University of Kinshasa precisely in the
faculty of letters.

In the past, the information used in this work


cover the period from March 2013 to June 2013.

5. METHODS AND TECHNIQUES USED

Any scientific work worthy of its name requires in its


developing a methodology that creates the means and ways to achieve the goal
discounted in a satisfactory manner.

In our work, we used the experimental method.


which allows one to affirm a thing only after testing or experience. As for the technique,
which is a set of essential tools used to achieve a result, we
used the documentary technique and the observational technique which has
allows for the consultation of various documents, in addition to scientific works, books and
even websites.

6. DIVISION OF LABOR

Apart from the general introduction and the conclusion, three main
chapters will allow for a quick grasp. First of all, the first chapter
talk about the generalities, the second on the 802.11 standard (WIFI) and security and the
The third chapter is focused on the implementation of the chosen solution.
[xii]

CHAPTER I: GENERALITIES ON NETWORKS


INFORMATICS

I.1. DEFINITION OF A COMPUTER NETWORK

A computer network is a set of equipment


interconnected devices that can communicate (to exchange information) and aims to
to transmit information from one computer to another.5
A network in general is the result of connecting several
machines among themselves, so that users and the applications that operate on
these last ones can exchange information.6
A computer network connects computers, like
a telephone network connects people. Computers are said to be 'in
networks " as long as they share a technology that allows them to communicate
together.

I.2. CLASSIFICATION OF COMPUTER NETWORKS

The classification is done based on a given criterion, so we


we can classify computer networks in the following way:

according to their geographical extent;

according to the functions assumed by computers;


according to the topology.

5
KASENGEDIA MOTUMBE Pierre. Course on telematics and networks, Unpublished, L2 computer science Iss/Kin, 2011-2012
MABELA, course on Computer Structure and Network, Unpublished, G2 AIA, Unikin, 2011-2012
6
[xiii]

I.2.1. Classification according to their geographical scope

According to the geographical size occupied by a network, they can be classified as large
following categories:

LAN (Local Area Network);

MAN (Metropolitan Area Network);


WAN (Wide Area Network);

a) The LAN (local area network)

Local networks connect several computers located on


a relatively restricted geographical area, such as a home, an office, a
building, a university campus.
They also allow companies to share locally
files and printers efficiently and make possible the
internal communications.
Example of types of technologies used in LANs:

Token ring
IEEE 802 LANs
Ethernet and Fast Ethernet
FDDI (Fiber Distributed Data Interface)
ATM
802.11b (Wireless)

b) The MAN network (Metropolitan Area Network)

Any metropolitan network is essentially a LAN, from the point


from the perspective of the technology used. It corresponds to an interconnection of a few
buildings located in a city (campus).7

c) The WAN (Wide Area Network)

For economic and technical reasons, local networks


(LAN) are not suitable for communications covering long distances.

MABELA, course on Computer Structure and Networks, Unpublished, G2 AIA, Unikin, 2011-2012
7
[xiv]

It is for all these reasons that wide area network (WAN) technologies
different from those of local networks. A WAN is a long-distance network that
covers a significant geographical area (a country, or even a continent).

A WAN refers to computers connected between different


cities (Metropolitan Area Network) or countries. The technology used is
traditionally less efficient than that of a LAN, it is for example a
leased telephone line operating at 64 kbps, an ISDN connection, or a
transatlantic link at 1Mbits/second.
The technological improvements made to LANs
allowing them to expand more and more geographically, those provided to
WANs significantly increase bandwidths, these two trends create
that the distinction between these two types of networks is becoming less and less clear.8

I.2.2. Classification according to the functions performed by computers

From a network architecture point of view, we have two main


network categories:

POST-TO-POST Network (Peer to Peer);


dedicated server network or client-server (server based).

A server: A computer that makes its resources and services available to


others. It is, generally, from the perspective of its performance, more powerful than the
others.

A client: A computer that, for the execution of certain of its applications, does
call to resources and services contained in the SERVER.

a) Peer-to-peer network
It's a dedicated serverless network, cheaper because it doesn't
not requiring a powerful server and a very advanced security mechanism.
Each computer connected to the network can act as a client or server.
In general, it's a small network of about 10 stations, without an administrator.
network9.

http : //[Link]/cours/[Link]
8

[Link]
9
[xv]

Fig 1. Diagram of a peer-to-peer network

1. Advantages

Less costly implementation;


Does not require a network operating system;
Does not require a dedicated network administrator.

2. Disadvantages

Less secure;
Each user must be trained in administration tasks;
So quickly make the administration very complex.

b) Dedicated server network or client-server

In a client-server configuration, network services are


placed on a dedicated computer, called a server, which responds to client requests.
A server is a central computer, permanently available to respond to
requests made by clients related to file services, printing,
of applications or others10.

Most network operating systems adopt a


client-server relations. Generally, desktop computers act as
customers, while one or more computers equipped with dedicated software, which are
equipped with greater processing power and memory ensure the
function of servers. Servers are designed to handle simultaneously the
requests from many clients.

Same
10
[xvi]

Fig2. Diagram of a client-server network

a) Advantages

Guarantees better security;


Easier to manage when the network is extensive because the administration is
centralized;
Possibility to save all data in a central location.

Disadvantages

Requires the use of a network operating system, such as NT,


Novell Netware, Windows Server 2003, etc ...
The server requires more powerful but expensive hardware;
Requires a professional administrator;
Presents a single point of failure if there is only one server; if the
the server is down, the user's data may no longer be
available.

1.2.3. Classification according to network topology

The network topology defines the structure of the network.


represents the interconnection of equipment on the network. This equipment is
called nodes. Nodes can be computers, printers,
routers, bridges or any other component connected to the network. A network is
composed of two topologies: physical and logical.

[Link]. Physical topology

The physical topology of the network refers to the arrangement of


equipment and supports.
[xvii]

a) Bus topology

All the devices in a bus topology are connected by


the same cable, which goes from one computer to another, like a bus would
traverse the city. That is why we often speak of linear buses. The end of the
the main cable segment must include a terminator that absorbs the signal
when the latter reaches the end of the line or the cable. In case of absence of
terminator, the electrical signal representing the data is sent back to the end
the cable, which generates an error on the network.

Fig3. Diagram of a bus topology

b) Star topology
The star topology is the most commonly used in local networks.
Ethernet. This topology resembles the spokes of a bicycle wheel. It is
consisting of a central connection point. This is a device, like a hub.
or a switch, where all the cable segments connect. Each host of the
The network is connected to the central equipment by its own cable.
[18]

Fig4. Diagram of a star topology

b) Ring topology

Ring topology is also very useful for the


connectivity of local networks. As its name suggests, the form of connection
the hosts is that of a circle or a ring. Unlike the bus topology,
none of its ends requires termination. The mode of transmission of
data is different from that used in star or bus topologies. A
The token, called a token, circulates around the ring and stops at each node. If a
the node wishes to transmit data, it adds the data and the information on
the addresses in the frame. The frame continues to circulate around the ring until it
that finds the destination node. The latter then retrieves the data from the
track. The advantage of this topology is that there is no risk of collisions
data packets.
nineteen

Fig5. Diagram of a ring topology

d) Mesh topology
The mesh topology allows for connecting all the equipment,
or nodes, between them in order to achieve redundancy and, therefore, tolerance to
breakdowns.

[Link]. Logical topology

The logical topology represents the paths through which are


transmit the signals on the network (data access mode to the media and of
data packet transmission.

I.3. OSI MODEL (OPEN SYSTEMS INTERCONNECTION)

Reference model for the interconnection of open systems,


this model is based on a recommendation from ISO (International Standards
An open system is one that allows interconnection with others.
open systems. in order to facilitate communication and interoperability. This
Layered architecture allows for good management of complexity.

The OSI reference model is an abstract representation in


layers serving as a guide to the design of network protocols. It divides the process
of a network in seven logical layers. Each of the layers of this model represents
a category of problem that one encounters in a network.11

Fig. 6. Diagram of the OSI model operation

MABELA, cours de Structure des Ordinateurs et Reseau, Inedit, G2 AIA, Unikin, 2011-2012
11
[xx]

1.3.1. Physical layer

She takes care of:

. The transmission of bits over a communication channel;


. The initialization of the connection and release at the end of the communication
between the transmitter and the receiver;
. The mechanical, electrical, and functional interface;
. physical media for data transmission;
. The possibility of physical transmission in both directions (Half and Full duplex).
This level brings together the properties that specify the
mechanical, electrical, and functional characteristics of data circuits. 12

1.3.2. Data Link Layer

The main task of the data link layer is to


take a RAW transmission medium and transform it into a link that appears
free from transmission errors at the network layer.
This level is responsible for the routing of units of
data called frames (structured sequence of bits) while ensuring the best quality
of possible transmission.13

She also takes care of:

. As a RECEIVER, to build frames from sequences of


bits received;
. As an ISSUER, constructs frames from received packets and
sends them in sequence. She is the one who manages the acknowledgment frames.
returned by the receiver.
. the correction of errors and flow control14.

The data link layer is often divided into two sub-


layers: an upper layer and a lower layer.

12
MABELA, course on Computer Structure and Network, Unpublished, G2 AIA, Unikin, 2011-2012
13
the same
14
[Link]
[xxi]

The upper sub-layer defines the software processes that provide services.
to network layer protocols. The LLC (Logical Link Control) sublayer manages the
communication between the upper layers and networking software as well
between the lower layers and the material. The LLC sublayer extracts the data
of network protocols, in principle an IPv4 packet, and adds information to it
control to facilitate the transmission of the packet to the destination node.

The lower sublayer defines the access processes to the medium executed by the
material. It ensures three basic functions: frame delimitation, addressing
and error detection.

This sublayer adds a header and a footer to the data unit.


Layer 3 protocol.

1.3.3. Network layer

The network layer manages the subnet, the way in which


The packets are routed from the source to the destination. It determines the path to
browse to go from one computer to another, (in case of multiple paths, in
function of network conditions, priorities, congestion issues) and
ensures the conversion of logical addresses into physical addresses. It is said that this
layer manages transmission in the network15She is responsible for the routing.
packets that can traverse multiple intermediate nodes.

On the show, she can bring together different data.


between them but too small to be emitted alone on the network, or at
opposite to breaking down large data into small pieces for it to be
sent over the network and at the reception, it reconstructs the data packets for
to restore them to their original size.

Two main types of protocols exist: the datagram,


in which the packets constituting the data do not necessarily follow all together
the same route, and the virtual circuit in which all packets follow the same
route.

We can mention IP and IPX (Novell) but also X.25 for public networks.

CABARE Michel., Local Networks Theory and Standards, inter Éditon, page 18
15
[xxii]

IP protocol: a protocol known as "datagram in connectionless mode" is


the one used in private networks. Internet protocol, it's a way to route
the information from one place to another. Each packet manages to find
on his way, the first parts can very well arrive last, and there is no
for a particular reason that all packages always take the same one
path (on the contrary). If during an exchange, a node is destroyed (cut), the
communication is not interrupted as a result.

IPX Protocol (novel): it is a protocol inspired by IP but proprietary to


NOVELL NETWARE.

X25 Protocol (transpac): This protocol known as 'virtual circuit in mode


connected is the one uincluded in the public networks of France Telecom. One establishes a
virtual network from the moment the first packet arrived with a
receipt from the recipient. This leads to a connected mode that reserves
a unique path throughout the duration of the exchange. If during an exchange, a
Node is destroyed (cut), communication is interrupted!

The network layer is responsible, among other things, for:

Addressing: The network layer must first provide a mechanism for


the addressing of its end devices. If data elements
individuals must be routed to a final device, this latter must
having a unique address is the case notably in an IPv4 network.

Encapsulation: The network layer must also provide encapsulation,


during the encapsulation process, layer 3 receives the data unit from
protocol of layer 4 and adds a layer 3 header to create the unit
of layer 3 protocol data. In a network layer context,
this protocol data unit is called a packet.

Routing: The network layer must then provide services to direct these
packets to their destination host. The source and destination hosts do not
are not always connected to the same network. In fact, the packet may have
many networks to cross. Along the way, each packet must be guided on the
network in order to reach its final destination.
[xxiii]

The uncapping: Finally, the package arrives at the destination host and is processed.
through layer 3. The host examines the destination address to verify if the
the packet was well addressed to this device. If the address is correct, the packet
is uncapsulated by the network layer, and the protocol data unit of the
Layer 4 contained in the packet is transmitted to the appropriate service of the
transport layer.

1.3.4. Transport Layer

One of the most important roles of the "Transport Layer" is the


reliable end-to-end communication management between the sender and the receiver
which act as endpoint machines, while the layer protocols
bases act between neighboring machines.

This layer is responsible for detection and correction.


errors. That is to say, it must ensure that the transmitted packets have been properly received.
This layer is responsible for the proper transmission of messages from the layer
application. To do this, it divides long messages into several packets and
Group the short messages into one to allow for easier transmission.
effective on the network (a bit like the network layer for frames)
TCP can be cited as a representative protocol of this.
layer. Transport protocols are complementary to those of the layer
network. If we primarily look at IP we find then:

TCP Protocol: A logical complement to IP, it introduces at this level a notion of


port. If network layer addressing, such as IP, allows for designation, in a way
unique a machine located anywhere on the network, when the machine is reached
One must be able to know which application should process the data.

Indeed, a computer often needs more than one access.


on the network: we may need to download FTP files while retrieving
his mail via a POP3 server...
Ports provide 65535 access points to a computer starting from
from a single physical address. The whole, consisting of the physical addresses of
computers trying to communicate and the port numbers used, create what
it is called a 'SOCKET'

It was thus arbitrarily decided on a Port No for each


usage.
[xxiv]

For example:

Port n° 21: File Transfer Protocol

Port No. 22: Secure remote SSH connection

Port No. 23: Telnet

Port No. 25: SMTP mail reception

Port no. 53: DNS Domain Name Server

Port No. 80: HTTP web pages

Port n° 88: Kerberos authentication

Port No. 110: POP3 mail reading

Port number 113 to 139: NetBios

Port No. 546: DHCP

1.3.5. Session layer

The Session layer allows users working on


different machines, to establish a type of connections between them called 'sessions'.
A user can also establish a session to connect to a system in real time.
sharing or transferring a file between 2 machines. One of the roles of the session layer
concerns the management of dialogue. The sessions can use unidirectional mode.
Bidirectional traffic. When working in alternating bidirectional mode (half-
logical duplex), the session layer determines who has control. This type of service is
called token management.

This layer is responsible for management and security.


du dialogue (nom d’utlisateur, mot des passes, etc) entre les divers équipements,
applications and network users.16

1.3.6. Presentation layer

MABELA, course on computer structures, Inedit, G2 AIA unikin, 2011-2012


16
[xxv]

Unlike the lower layers, which are only


concerned with the reliable transmission of bits from one point to another, the layer
The presentation focuses on the syntax and semantics of the transmitted information.

It converts purely electronic information (known as internal)


to make it adopt its final form, the one that the applications will understand and the
users.17

I.4.7. Application layer

It is the layer that will link the programs wanting


access the network one and the network. It represents the link with the applications of
the user, like file transfer software, database access
or the email.
NOTE: what to remember:

The physical layer reconstructs the bits of the message


2. The link layer recalculates the checksum, confirms the reception and
record the packets
3. The network layer recounts the packets
4. The transport layer recalculates the checksum and reassembles the
segments of the message
5. The session layer keeps the different parts of the message until
complete reception
6. The presentation layer decompresses and decrypts the message
7. The application layer converts bits into characters and transmits them to
the application

I.5. TCP/IP Model

The first layered protocol model for the


Network communications were created in the early 1970s and are called the model.
Internet. It defines four categories of functions that must be executed for the
communications succeed.
Most protocol models describe a stack of
vendor-specific protocols. However, since the TCP/IP model is a

17
Same
[26]

open standards, no company controls the definition of the model. The definitions
The standards and TCP/IP protocols are discussed in a public forum and defined.
in a set of publicly available documents. These documents are called
RFC (Request For Comments) documents. They contain formal specifications.
data protocols as well as resources that describe the use of
protocols.
RFC documents also contain documents
techniques and organizational aspects regarding the Internet, including the specifications
techniques and strategy documents provided by the IETF working group.

I.5.1. Network access layer

The network interface layer of the TCP/IP model corresponds to the


data link layer and the physical layer of the OSI model. This layer
defines the TCP/IP functions associated with the data preparation step before their
transfer to the physical medium, notably addressing. The network interface layer
also determines the types of support that can be used for the
data transmission.

I.5.2. Internet Layer

The Internet layer of the TCP/IP model defines addressing and the
Path selection. This function is identical to the network layer of the OSI model.
Routers use Internet layer protocols to identify the path
that the data packets will take when transferring from one network to another.
Among the protocols defined in this layer are the IP and ICMP protocols.
(Internet Control Message Protocol), ARP (Address Resolution Protocol) and RARP
Reverse Address Resolution Protocol

I.5.3. Layer transport

The transport layer segments the data and is responsible for


necessary control for the reassembly of these data blocks in the various flows of
communication. To do this, he must:

monitor individual communications between the applications


residing on the source and destination hosts;

segment the data and manage each individual block;


[xxvii]

gather the segments in application data flow;

identify the different applications;


Flow control.

The transport layer uses the TCP (Transmission Control Protocol).


Control Protocol) and the UDP (User Datagram Protocol). These two protocols
manage the communications of many applications.
The UDP protocol (User Datagram Protocol) is a protocol
simple, connectionless, described by document RFC 768. It has the advantage
to impose little overhead for the transmission of data. The blocks of
communications used in the UDP protocol are called datagrams. These
Datagrams are sent 'best effort' by this transport layer protocol.
Le protocole UDP est notamment utlisé par des applicatons de :

Domain Name System (DNS)

Voice over IP (VoIP)

SNMP (Simple Network Management Protocol)

DHCP (Dynamic Host Configuration Protocol)

RIP (Routing Information Protocol)

TFTP (Trivial File Transfer Protocol)


Etc...

The TCP (Transmission Control Protocol) is a


protocol with connection described in document RFC 793. It imposes an overhead
to enhance the features, also specify other functions, namely the
delivery in order, reliable shipping and flow control. Each segment
the TCP protocol uses 20 bytes of overhead in the header to encapsulate the
application layer data while each segment of the UDP protocol
does not add on 8 bytes of overhead.
The TCP protocol is used by applications for:

Web Browsers (HTTP)

Email
File transfer (FTP)

I.5.4. Application layer


[xxviii]

The application layer encompasses the three services at the level


above the OSI model. It includes dozens of applications such as the
electronic messaging (SMTP Simple Mail Transfer Protocol), the Web (HTTP
HyperText Transfer Protocol), file transfer (FTP File Transfer Protocol)...
Transport can be reliably ensured by Transmission
Control Protocol (TCP), or unreliable, by User Datagram Protocol (UDP). The layer
The Internet encompasses several protocols, including Internet Protocol (IP), providing, among others
others, a logical addressing.
One of the great qualities of this stack of protocols is that the
The network technology used in the lower layer is transparent. Thus, regardless of
the extent and the transmission interface, the TCP/IP protocol stack can be used,
which is most often the case. In the following part of this work, we will not return
more about these middle and high layer protocols, assuming that the frames
Ethernet, WiFi, Bluetooth and others encapsulate this type of protocols.18 .

The application layer is the layer that serves as an interface between the
applications that we use to communicate and the underlying network through which
Our messages are transmitted. The application layer protocols are used.
to exchange data between the programs running on the source and destination hosts
of destination. There are many application layer protocols such as:

The DNS (Domain Name Service) protocol

On data networks, devices are labeled by


digital IP addresses, which allows them to participate in sending and to the
receipt of messages via the network. However, most users
they find it very difficult to memorize these numerical addresses. It is for this reason that
Domain names were created to convert numeric addresses into names.
simple and explicit.

On the Internet, these domain names (for example,


[Link]) are much easier to memorize than their equivalents
digital (for example, [Link], the digital address of the server
the ISTA). Furthermore, if ISTA decides to change its digital address, this change is
transparent for the user because the domain name [Link].

The HTTP protocol (Hypertext Transfer Protocol)

The HTTP protocol is one of the protocols of the TCP/IP suite, which has
was developed to publish and extract HTML pages. The HTTP protocol is used

PHILIP ATELIN., wireless networks 802.11 second edition, ENI editions, 2008, page 9
18
[xxix]

through the Web for data transfer and constitutes one of the protocols
the most used applications.

The protocols POP (Post Office Protocol) and SMTP (Simple Mail Transfer Protocol)

When the user writes an email, they generally call upon


to an application known as a messaging agent, or client of
messaging. The messaging agent allows sending messages and places the
messages received in the client's mailbox, these two processes being
distinct processes.
To receive the email from a mail server, the client of
messaging can use the POP protocol. Sending email from a client or
A server involves the use of commands and defined message formats.
by the SMTP protocol.

The FTP protocol (File Transfer Protocol)

The FTP protocol is another application layer protocol.


commonly used. It was developed to allow file transfer between
a client and a server. An FTP client is an application running on a
computer and used to extract files from a server running the FTP daemon
(FTPd).
To transfer files correctly, the FTP protocol
requires that two connections be established between the client and the server: one
connection for commands and responses and another for the transfer itself
of files.
The client establishes the first connection to the server on the TCP port.
21, this connection is used for control traffic and consists of
client commands and server responses. The client establishes the second connection to
server via TCP port 20.
The DHCP (Dynamic Host Configuration Protocol)

The DHCP protocol allows devices on a network


to obtain IP addresses and other information from a DHCP server. This service
automate the assignment of IP addresses, subnet masks,
gateway settings and other IP network settings.

The TELNET protocol

Telnet dates back to the early 1970s and is among the most
old protocols and application layer services of the TCP/IP suite. Telnet offers
a standard method for emulating text terminal devices via the
data network. The term Telnet generally refers to the protocol itself and
the client software that implements it.
[xxx]

Logically, a connection that uses Telnet is called


connection or VTY session (Virtual Terminal). Rather than using a device
physical connection to the server, Telnet uses software to create a
virtual device that offers the same functionalities as a terminal session
with access to the command line interface (CLI, Command Line Interface) of the
server.

I.7. STANDARDS AND TECHNOLOGIES OF LOCAL NETWORKS

I.7.1. Ethernet (IEEE 802.3)

The foundations of Ethernet technology emerged in the


1970s, with a program called Alohanet. It was a radio network.
digital designed to transmit information via a shared radio frequency
between the Hawaiian islands. With Alohanet, all the stations had to follow a
protocol according to which a transmission without receipt was to be retransmitted after a
court deadline. Similar techniques allowing the use of a shared medium have
were later applied to wired technology, in the form of Ethernet. Ethernet has
was developed with the aim of hosting multiple interconnected computers on a
shared bus topology19.
The first version of Ethernet incorporated a method of
access control to the media called CSMA/CD (Carrier Sense Multiple Access
with Collision Detection). This access method has solved the problems
related to the communication of multiple devices on a shared physical medium.
NB: Ethernet is the main protocol used in local area networks.20

I.7.2. Token ring

La société IBM est à l’origine de Token Ring, une architecture de


reliable network based on the token passing access control method.
The Token Ring architecture is often integrated into mainframe computer systems.
IBM. It is used both with traditional computers and computers
central. It uses the IEEE 802.5 standard.

Token Ring technology is classified as a 'ring' topology.


starred" because its external appearance is that of a star design. The
computers are connected to a central hub, called access unit
multistation (MSAU). Within this device, however, the wiring forms a
circular data path, creating a logical ring. The logical ring is created
through the circulation of the token, which goes from the MSAU unit port to a computer.

[Link]
19

MABELA, computer architecture course, Inedit, G2 AIA unikin, 2011-2012


20
[xxxi]

If the computer has no data to send, the token is returned.


at port MSAU, then exits through another port to access the next computer.
This process continues for all computers offering a great similarity to
a physical ring.

I.7.3. FDDI (Fiber Distributed Data Interface)

FDDI (Fiber Distributed Data Interface) is a type of


Token Ring network. The implementation and topology of FDDI is different from those
of an IBM Token Ring local network architecture. The FDDI interface is often
used to connect different buildings within a university campus or
of a complex corporate structure. FDDI networks operate via cable in
optical fiber. They combine high-speed performance with the advantages of topology.
in a ring with token passing. FDDI networks offer a speed of 100 Mbits/s
on a double ring topology. The outer ring is called the primary ring
and the inner ring is the secondary ring.

1.8 Wireless support

Wireless communication relies on equipment called


emitters and receivers. The source interacts with the emitter that converts the data
in electromagnetic waves, then sends them to the receiver. The receiver reconverts
Then these electromagnetic waves are converted into data to be sent to the destination.
In the context of bidirectional communication, each device requires a
transmitter and a receiver. Most network equipment manufacturers
integrate the transmitter and receiver into a single unit called transmitter-
wireless receiver or network card.

All equipment in a wireless local area network must be equipped


from the appropriate wireless network card. Four standards of communications
current data applies to wireless media, namely:

. IEEE 802.11 standards: wireless local area network (WLAN) technology,


commonly called Wi-Fi, uses a contention system or non
deterministic based on a process of accessing the support through multiple access with
carrier sensing/collision avoidance (CSMA/CA).

. IEEE 802.15 standards: the standard for wireless personal area networks (PAN), commonly
called Bluetooth, uses a device pairing process to
communicate over distances of 1 to 100 meters.
[xxxii]

. IEEE 802.16 standards: the access technology commonly referred to as WiMAX


Worldwide Interoperability for Microwave Access uses a point-to-
multi-point to provide wireless broadband access.21

I.9 Network Equipment

A local network is made up of many types of equipment.


They are called hardware components of the local network. Some of the
the most commonly used hardware components for local networks are as follows:
repeaters, hubs, bridges, and switches.

a) Repeater

A repeater is a network device that serves the purpose of


regenerates and retransmits the signal. The repeater receives a signal, regenerates it and
retransmit. In general, repeaters are used at the edges of networks in order to
to extend the cable and thus allow the addition of additional workstations.
A repeater is placed between two objects in order to increase the intensity of the signal.
cable.
b) Concentrator Hub

Concentrators are devices that allow


to extend the scope of the network by receiving data on a port, and then by.
regenerating and sending them to all other ports. This process means that
all the traffic coming from a device connected to the hub is
transferred to all other devices also connected to the hub, to
whenever it transmits data.
c) Switch
The switch is a more sophisticated device than the
concentrator. It maintains a table of MAC addresses of connected computers.
each of its ports. When a frame arrives at a port, the switch compares
the address data of the frame to its MAC address table. It determines which port
will be used to transfer the frame. 20

Router

The router is a specialized device that plays a key role in


the functioning of a data network. Routers are primarily responsible
the interconnection of networks by determining the best path to send
packets and transfer them to their destination.

[Link]
21
[33]

They also perform packet transfer by obtaining


information on remote networks and managing routing information. In
In addition to that, it is the junction, or the intersection, that connects several IP networks.

The router's routing table allows you to find the best


correspondence between the destination IP of a packet and a network address in the
routing table. Ultimately, the routing table determines the interface for
transfer the packet and the router encapsulates this packet in the link frame of
appropriate data for this outgoing interface.

e) Bridge:
A bridge offers the possibility to extend a 802.3-Ethernet network.
LAN beyond the authorized limits (number of nodes, maximum length, etc...). The
Bridges are increasingly used to control traffic and the stability of a network.
They work at layer 2 (data link layer) of the OSI model and serve to connect two
networks. This means that bridges should not analyze packets (for example
X25) or the datagrams (for example IP or IPX) from the network layer, they must
simply content themselves with inserting them into frames and sending them. They
process all packets regardless of their destination address(Promiscuous Mode).
[xxxiv]

CHAPTER II: THE 802.11 STANDARD (WIFI) AND THE


SECURITY

SECTION I. THE 802.11 STANDARD

I. Presentation of the Wi-Fi standard

The 802.11 standard focuses on defining the lower layers of the model.
OSI for a wireless link using electromagnetic waves, that is to say:

Physical layer (sometimes referred to as PHY layer), proposing three types of


encoding of information.
xxxv

Data link layer, consisting of two sub-layers: the control of


the logical link (Logical Link Control, or LLC) and the media access control
(Media Access Control, or MAC).
The physical layer defines the modulation of waves.
radioelectric and signaling characteristics for transmission of
data, while the data link layer defines the interface between the bus of the
machine and the physical layer, notably a method of access close to that
used in the Ethernet standard and the communication rules between the
different stations22. The 802.11 standard actually proposes three physical layers,

Data Link (MAC) 802.2


802.11
Physical Layer (PHY) DSSS FHSS infrared

It is possible to use any protocol on a Wi-Fi wireless network.


to be than over an Ethernet network.

I.1 The different Wi-Fi standards

The IEEE 802.11 standard is actually the initial standard offering


speeds of 1 or 2 Mbps. Revisions have been made to the original standard in order to
to optimize the throughput (this is the case for the 802.11a, 802.11b, and 802.11g standards, referred to
802.11 physical standards) or specify elements to ensure better
security or better interoperability

Wi-Fi is a collection of several IEEE 802.11 standards.


(802.1 1a, b, g, e, h,...), defining data transmission via the medium
"hertzian", they differ mainly according to the bandwidth, the distance
broadcast, as well as the bandwidth they offer. The main extensions are the
following23:

I.1.1 The 802.11a standard

Site [Link] - "Wireless network: The WiFi technology"


22

23
[Link] memory/wireless technologies wifi and security/ Nadia [Link]
[xxxvi]

.
The IEEE 802.11a standard (also known as Wi-Fi 5) was defined in 2001.24She
allows for high speed (theoretical 54 Mbps, actual 30 Mbps). Its advantage
Compared to the 802.11b/g standards, does it have a wider bandwidth?
passing (5 GHz) therefore little crowded, and offers higher speeds than
802.11 b (11 Mbps). IEEE 802.11 a used an OFDM modulation technique.
The disadvantages of this standard are its limited range (15m) and its incompatibility with
802.11b.

I.1.2 The 802.11b standard

The term Wi-Fi refers to this standard which was the first
WLAN standard used by a large number of users, it was approved on
December 16, 1999 by the IEEE. The Wi-Fi standard enables interoperability between the
different existing materials, it offers speeds of 11 Mbps, with a range of
300m in an open environment. It operates in the 2.4GHz band,
separated into several channels.
Its disadvantage is the risk of interference with devices.
operating on the same frequencies (microwave oven, wireless equipment, ...).

I.1.3 The 802.11g standard

This standard was developed in 2003. It extends the standard


802.11b, by increasing the throughput up to a theoretical 54Mbps (real 30 Mbps). It
also operates at 2.4GHz, which makes the two standards perfectly compatible.
Thanks to this, 802.11b equipment is usable with the
802.11g access points and vice versa. However, 802.11g uses the technique of
modulation OFDM.

I.1.4 The standard 802.11e:

Available since 2005. It aims to provide opportunities in


quality of service (QoS) issues at the data link layer. Thus,
this standard aims to define the needs of different packages in terms of
bandwidth and transmission delay in such a way as to allow in particular
a better transmission of voice and video.

I.1.5 The 802.11h standard


She seeks to better manage the emission power and the selection.
channels in the 5 GHz band. It also aims to bring the 802.11 standard closer to
European standard (HiperLAN 2) and comply with the regulations
European in terms of frequency and energy efficiency.

I.1.6 The 802.11i standard


Same
24
37

Ratified in June 2004, this standard describes mechanisms of


security of transmissions. It offers encryption of communications for the
transmissions using 802.11a, 802.11b, and 802.11g technologies. The 802.11i acts
in interaction with the 802.11b and 802.11g standards. The theoretical throughput is therefore
unchanged, namely 11 Mbps for 802.11b and 45 Mbps for 802.11g.

I.1.7 The 802.11IR standard

The 802.11j standard was developed in such a way as to use...


infrared signals. This standard is now technically obsolete.

I.1.8 The 802.11j standard

The 802.11j standard is to Japanese regulation what the


802.11h is related to European regulation.

I.2 Wi-Fi equipment

There are different types of equipment for setting up


of a Wi-Fi wireless network:

a)Wireless adapters or access cards

In English, Wireless adapters or network interface Controllers,


Noted NIC. This is a network card compliant with the 802.11 standard that allows a machine to
connect to a wireless network. Wi-Fi adapters are available in
many formats (PCI card, PCMCIA card, USB adapter, compact card)
flash, ...). We call a station any equipment that has such a card. It should be noted that
Wi-Fi components are becoming standards on laptops (Centrino Label
of Intel).
[xxxviii]

Fig 7: Wireless adapter

b)Access points

Noted as AP for Access Point, sometimes referred to as wireless access points,


allowing to provide access to the wired network (to which it is connected) to
different nearby stations equipped with Wi-Fi maps. This kind of hub is
the necessary element to deploy a centralized network in infrastructure mode.
Some models offer ADSL modem functions and include more or
fewer functions like a firewall.

[Link] point

c) Other equipment

Smart Display: mobile screens, supported by Microsoft.


Wi-Fi channels: offering the ability to play MP3s directly from the hard drive
from a computer via the built-in wireless Ethernet interface. It foreshadows
a whole generation of products, capable of reading, in addition to audio CDs,
radios that broadcast in MP3 on the Internet.
[xxxix]

Personal assistants: PDAs with integrated Wi-Fi are sometimes more advantageous
a mobile phone to read emails, import documents, and surf the
net.
Projectors: for presentations with mobile laptops.
Video camera: transmitting images remotely to the computer that
record.

Wi-Fi components are not more expensive than those of


wired networks, soon all platforms will be sold with modules
Integrated Wi-Fi. This is already the case in the world of laptops, which, driven by
Intel is making its wireless revolution thanks to Centrino25.

1.3 Conclusion

Wireless networks in general, and Wi-Fi in particular are


interesting and very widely used technologies in various fields such as industry,
health and the military field. This diversification of use goes back to
different advantages brought by these technologies, such as mobility, simplicity
of installation (lack of wiring), availability (both commercial and in
the experiences). But safety in this area remains a very sensitive subject, as
Since the use of this type of networks, several vulnerabilities have been detected.

SECTION II: WI-FI SECURITY


II.1 Introduction

IT security is considered one of the criteria.


the most important in assessing the reliability of a computer system26.
However, wireless networks do not face this constraint, which makes them a
interesting target for pirates. Organizations are deploying today the
wireless technology at a fast pace, often without considering reliability and
their level of security.
The success of wireless networks can be easily explained by the
advantages they provide: speed and ease of installation, a mobility that
simplify the movement of the user (between offices, meeting rooms...)
shared access to high-speed Internet services, they also allow for a response
to the issue of large sites where wiring is too costly and expensive.
Although the transmission support in Wi-Fi meets the
constraints imposed by wired equipment (high costs, difficulty of cabling
between places that are too far apart, etc.), a number of problems arise,

[Link] - "Wireless Network: The WiFi Technology"


25

26
Magazine [Link] - November 2003 - 'the essentials to know' File prepared by [Link] GALLO.
[xl]

which implies a need for the establishment of a security policy


specific and effective.
Another criterion that influences security is the nature of the signal.
transmission which makes mastering the propagation difficult. Consequently, it is easy
to listen to messages and possibly even to infiltrate such networks,
to carry out malicious acts without leaving a trace.
In this chapter, we will discuss the different attacks.
against wireless networks and present the solutions that enable to increase the
security for this connection mode.

II.2 Presentation of wireless networks

Wi-Fi is a technology that allows the creation of networks.


Wireless computer networks. This is a standard from the IEEE called 802.11.27.

Its range varies from one device to another between a few dozen.
meters to several hundred meters, making it a cutting-edge technology
choice for the home network with internet connection.

It is increasingly used by various computer hardware.


computers, organizers (PDA), portable game consoles, and even printers
they also use Wi-Fi to simplify their connection.

A Wi-Fi network can operate in two different ways:

Ad-Hoc mode: with this mode, there is no need for an access point to manage.
the network. Each member of the network retransmits the information they receive
to the other members of the network. The problem with this type of network is that
on one hand, the network bandwidth is based on the host speed
slower and on the other hand, the network bandwidth is divided by the
number of hosts on this network, which can quickly become a handicap.
Nevertheless, this mode can be used in a house for a simple network,
it has the advantage of not being costly (also known as computer to computer).
The Infrastructure mode: with this mode, everything is managed by an access point, the
Data that a host emits is transmitted to them and they alone send it back to others.
members of the network. Thus, bandwidth is saved. Moreover,
multiple access points can be connected together (by cable or by wifi)
repeaters) to extend the range of the Wi-Fi network. This mode is the most used because
it is much more reliable.

II.3 The characteristics of wireless networks and their impact on security

The main characteristics of wireless networks are:

[Link]/wifi/wifitech.php3
27
[the]

Transmission by electromagnetic waves

Wireless networks have the particularity of using waves


electromagnetic for data transmission. This type of transmission has the
property of spreading in all directions and over a large area. It is
So it is very difficult to envisage an absolute limit to the network, and its border is not
observable.
The main consequence of this "wild propagation" of
radio waves is the ease with which an unauthorized person can listen to the
network, possibly outside the building where the wireless network is
deployed.
This technology (wireless) is therefore an open door to listening.
and allows a malicious actor to take advantage of the connection (if the company's network is
connected to an Internet network), and it will even be possible to insert illegal traffic and
to infiltrate the network to produce malicious actions.

Characteristics of implementations

Network identifiers and encryption keys are


generally stored in a file on the machine's disk or on Windows
in the registry like with Agere, or, more rarely, on the card itself
like Cisco. The theft of the computer or the wireless card then poses the risk of
key theft28.

Radio jamming

Always, because of the use of radio waves as support


communication that is very sensitive to interference, a signal can easily
to be interfered with by a radio broadcast having a frequency close to the one used
in the wireless network. A simple microwave, for example, can thus render
totally inoperative a wireless network when it operates in the action radius
from an access point.

The use of batteries

One of the major problems with the Wi-Fi standard is the


energy overconsumption, even more than the use of the phone, knowing that
the battery is their only means of energy supply since the machines are
mobiles. As a result, the main attack is the denial of service on the battery
of equipment. Indeed, a hacker can send a large amount of data
(encrypted) to a machine in such a way as to overload it.

II.4 Attacks on wireless networks

[Link] online/the wireless technologies Wi-Fi and security/ Nadia [Link]


28
[xlii]

The main attacks against wireless networks are:

Denial of service

The network access method of the 802.11 standard is based on


the CSMA/CA protocol, which consists of waiting for the network to be free before transmitting.
Once the connection is established, a station must associate with an access point in order to
to be able to send him packages. Thus, the methods of accessing the network and
Since the association is known, it is easy for a hacker to send packets.
demanding the disassociation of the station. This is a denial of service, that is to say
to send information in such a way as to deliberately disrupt the
operation of the wireless network. On the other hand, the connection to wireless networks
it is energy-consuming. Even if wireless devices are equipped with
features allowing them to save the maximum amount of energy, a hacker can
possibly send a large amount of data (encrypted) to a machine of
such a way as to overload it. Indeed, a large number of portable devices
(digital personnel, laptop, ...) have a battery life
limited. That is why a hacker may want to provoke overconsumption
of energy in such a way as to render the device temporarily unusable, this is what
what is called a denial of service on battery.

The Sneaking

This is the most classic attack. By definition, a wireless network


is open, that is to say unsecured29This attack consists of listening to the
transmissions from different users of the wireless network, and to retrieve any
whatever data is transmitted over the network, if it is not encrypted. It
it is an attack on confidentiality.
For an individual, the threat is low because the data are
rarely confidential. On the other hand, in the case of a corporate network, the stakes
strategic can be very important.

War chalking

War chalking is based on the same principle as the one described.


previously. The difference is that, rather than compiling information from sites
Internet is simply set up right at the locations. Its purpose
is to make wireless networks visible by drawing directly on the sidewalk or on

htp://mémoire online/les technologies sans fil le wifi et la sécurité/ Nadia [Link]


29
[xliii]

the walls of buildings with chalk symbols indicating the presence of a network
Wireless.

A new generation of hackers

Like any new technology, wireless Ethernet has everything to


many interested hackers who have embarked on new hacking activities
which lewardriving (or war-Xing for "war crossing"). Coming from the United States, this
The goal is to detect public or private wireless networks and to attempt to
Enter. The pirates are 'patrolling' by car in pre-defined areas.
Using a laptop and a PCMCIA network card, 802.11b
Preference, the pirates scan the frequencies in search of networks. It is the
basic technique that can be improved by modifying a directional antenna
coupled with powerful detection software. Specialized software in this type
This activity allows for the establishment of a very precise mapping by exploiting a
Geolocation equipment (GPS, Global Positioning System). The maps established
thus allowing to highlight the deployed unsecured wireless networks,
sometimes even offering access to the Internet. Many sites capitalizing on this
information emerged on the Internet, so much so that London students had
the idea of inventing a "sign language" whose purpose is to make networks visible
without a wire by drawing symbols on the sidewalk with chalk indicating the presence
of a wireless network, it is referred to as 'war-chalking' (Frenchified as craieFitou craiefit).

Fig 9: war-chalking

Two opposing semicircles thus denote an open network


offering access to the Internet, a circle indicates the presence of an open wireless network
without access to a wired network and finally a circled W highlights the presence
from a properly secured wireless network
[xliv]

This new form of hacking, born with the advent of wireless networks
strike a serious pose security issues and
confidentiality for equipped companies
in wireless networks 802.11b. To such an extent that the CNIL will block the
sonnet of alarm by warning users
against the risks of radio network hacking. Some
prudent the wardriving like a game, but it can
to be formidable in the field of industrial espionage. Thanks to the
wave propagation, a wireless network is an open set. It belongs to its
administrator to decide whether to make it available to others and what the uses are
that it allows shared access to the Internet or games30).

II.5 Securing Wi-Fi

Security is the crucial point in wireless networks, and this is


because of their characteristics described above. Nevertheless, it is possible to
secure a network to a greater or lesser extent, according to security objectives.
Total cybersecurity does not exist, it takes more.
modestly speak of the level of security. With Wi-Fi technology, the level of
default security is generally very low. It is therefore necessary to increase it as soon as
the installation.
Security in wireless networks relies on three elements.
essentials :

Confidentiality:
To ensure confidentiality, it is obviously necessary to encrypt the
data exchanged in the network and this must respect two properties
essentials:
Be easy and quick to use.
Be difficult to break

Authentication:
Authentication is an important element in the security of a
information system. It allows to authenticate any station wanting to associate with
a network. It is therefore a necessary and very sensitive step. If authentication is
not guaranteed, access to data will be easier for attackers, as well as their
possible modifications.

Integrity

Site [Link] - "Wireless network: The WiFi technology"


30
[xlv]

It allows to know if the data sent has not been


altered during transmission.

Before securing a wireless network, one must first take into account
some basic services:

a) An appropriate infrastructure:

The first thing to do when setting up a network


wireless consists of strategically positioning the access points according to the area in which one
wish to cover and configure their power in order to limit propagation
of the signal in public areas. Overall network control will allow
also to detect pirated deployments.

b) Avoid default values

When the access point is first installed, it is


set up with default values, including regarding the password
of the administrator. A large number of aspiring administrators believe that at
From the moment the network is working, it is unnecessary to modify the configuration.
of the access point. However, the default settings are such that security is
minimal. It is therefore imperative to connect to the administration interface
(generally via a web interface on a specific port of the access point)
notably to define an administration password.

On the other hand, to connect to an access point, it is essential to know


the network identifier (SSID)). Thus it is strongly advised to change the name of the
default network and ofdisable broadcasting(SSID broadcast: broadcasting the SSID name)
of the latter on the network. Changing the default network identifier is
even more important as it can provide the pirates with information elements about
the brand or model of the access pointused. The ideal is even to modify
regularly the SSID name!

One should even avoid choosing words that reflect the identity of the company or its
localization, which are more likely to be guessed more easily.

c) Activate WEP or WAP encryption

Many terminals and WiFi interfaces are installed without


implementation of WEP encryption which helps to limit the risks of interception
data. It is strongly recommended to prefer a 128-bit WEP key, as it
often used by default, 64 bits. Certainly, enabling WEP is a plus but it
It is important to know that it slows down the information flow: encryption - decryption time.
Don't forget to regularly change the WEP encryption keys..
[xlvi]

d) MAC address filtering


Each network adapter has a physical address assigned to it.
is clean (called MAC address). This address is represented by 12 digits
hexadecimals grouped in pairs and separated by colons. The access points
generally allow, in their configuration interface, to manage a list of
access rights (called ACL) based on the MAC addresses of the authorized devices
connect to the wireless network. By activating this MAC Address Filtering
MAC addresses), even if this precaution is a bit restrictive, it allows for
limit network access to a certain number of machines. In return, this does not
does not solve the problem of the confidentiality of exchanges.

e) Improve authentication
In order to manage authentications more effectively, the
authorizations and user account management (in English AAA for
Authentication, Authorization, and Accounting) it is possible to resort to a server
RADIUS (Remote Authentication Dial-In User Service). The RADIUS protocol (defined
by RFC 2865 and 2866), is a client/server system that allows managing
In a centralized way, the user accounts and associated access rights.

f) Setting up a VPN
To connect remote users connecting to the network
through a public terminal, and for all communications requiring a
high level of security, a virtual private network (VPN) needs to be set up which
will offer a good level of security and will prevent most intrusions
indesirables.

g) Define fixed IP addresses

The risks of external intrusion are significantly reduced by allocating


fixed IP addresses to the fleet stationsbenefitingof a wireless connection. It
It is thus possible to manage a table of authorized connection addresses. It is necessary,
In this case, disable the DHCP function at the level of the server to which it is connected.
the WiFi terminal.

h) Install a firewall

You can also install a firewall as if the access point were


an internet connection. This firewall can be the serverIPsec(VPN) clients without
Files. A "secure" WiFi network can be schematized like this. Here we consider that
[xlvii]

the entire WiFi network is foreign to the local network, as well as the Internet.
The use of a firewall for the Internet connection allows for
filter the MAC addresses associated with fixed IP addresses. In the case of the VPN, the firewall
or a server behind it acts as a VPN terminal. Some access points
They propose a 'petts' firewall allowing for additional filtering of clients.
your network.
Everyone is free to modify these rules by adding layers.
supplementary. It should be noted that the future IP protocol ipv6 contains in its packets.
the IPSec security. IPv6 can be used in WiFi if the clients manage IPv6,
Currently, all Linux, Unix have a functional IPv6 stack, on Windows 2000.
And XP, IPv6 can be enabled and used but will be offered by default in the
next versions.

Fig 10: wired and secure Wifi network

II.6 Security protocols

II.6.1 WEP

(Wired Equivalent Privacy). Based on a key solution of


shared static encryption by all members of the same Wi-Fi network, with a
encryption algorithm that has become quite weak today, it has been clearly
demonstrated that this protection is no longer one, and we will not linger
above.
Just know that with tools like airodump, aircrack
and aireplay3, it is possible to discover a WEP key in just a few dozen
minutes, or even less.
[48]

II.6.2 WPA

In the face of the panic generated by the discovery of WEP vulnerabilities,


and while the different partners were working on developing a standard
intended to secure wireless networks, it was necessary to establish a process of
rescue: the 'WiFi Protected Access', resulting from the still unfinished work of the
a standard that has been finalized and is known by the sweet name of 802.11i. WPA appears
like a set of software patches, intended to fill the biggest gaps
WEP security, all while having the constraint of being able to function on the
existing equipment. It is generally possible to exploit WPA on equipment
designed for WEP. WPA is ultimately just a compromise, acceptable if one has to.
integrate old equipment into its network, not supporting methods of
encryption recommended by 802.11i.

II.6.3 WPA2

It is nothing more than the commercial designation of the standard.


802.11i. This standard was finalized in 2004 and therefore, the hardware has chances
to be compatible only if it was designed around that date. The encryption
Recommended requires the presence of a dedicated hardware component.

WPA and WPA2 can be used in two ways:

Personal mode
The so-called 'personal' method, that is to say, the one that is
recommended for individuals with a small less strategic network, done
call for a shared encryption key, the PSK (Pre Shared Key). This key, at the
contrary to WEP, does not directly serve to encrypt data. It serves to
base à la créaton de clés dérivées, qui sont non seulement différentes pour chaque
session (two users on the same network, even if they have the same PSK,
will use different session keys), but still of limited use in the
time. These keys are frequently renegotiated during the session, which makes their
discovery clearly more difficult.
This solution (currently WPA2-PSK) remains completely
acceptable in the case of a home wireless network, provided that it uses a
PSK not obvious. Practically, the PSK key is a numerical sequence, calculated from
of a 'secret phrase' in ASCII and the SSID of the access point.
[xlix]

2. Business mode

Here, we have more technical resources and above all, more


security needs. There is no shared key. We will resort to a system
centralized authentication, combined with a protocol defined by the 802.1x standard.
Typically, we will need to set up an authentication server of type
RADIUS (Remote Authentication Dial-In User Service) is an access point supporting
the 802.1x standard (Finalized in 2001). There is, once again, no shared secret,
the entire cryptographic system will be built during and after the process
of authentication, as we will see in detail.

Technically

Fig 11: centralized authentication system

We will need several software bricks. One


The authentication server is connected to the access point via a wired network. The type of
The authentication server is not defined by the standards, but clearly, it is the
the RADIUS protocol that is implied is the one we will use. RADIUS is
an application protocol that relies on UDP, IP, and Ethernet. Between the access point and
the client station, we are on 802.11 (WI-FI). Above, we will find
802.1x.
[l]

EAP (Extensible Authentication Protocol) will operate over 802.1x in the air.
and above RADIUS on the files, to transport the chosen authentication mode
(TLS, PEAP, TTLS or others, but considered less secure).

II.7 Security extensions:


Faced with attacks and total failures of the mechanisms of
security in the 802.11 networks, described above, the search for solutions
immediate action was necessary. To address this security shortfall, two groups
Working groups have been formed within the IEEE, the first being 802.1x which is intended for
ensure the security of network access, while the second one, which is 802.11i,
based on a data encryption protocol and key management.

II.7.1 La802.1x (PortBased Network Access control):

The 802.1x standard standardized by the IEEE to secure...


Wi-Fi based transmissions are divided into two important sub-parts.
the first concerns the management and the dynamic creation of keys, while the second
it allows the implementation of client authentication procedures.
Several elements are involved in the authentication architecture:

the supplicant, who is the client wishing to connect to the network,


the authenticatorounetwork Access server (NAS)what is the equipment on which
the "supplicant" wishes to connect,
the authentication server (AS), who is the authentication server.

802.1x n'est pas une soluton exempte de failles. Il est indispensable d'utliser par
above the authentication systems that allow:

to the supplicant being authenticated by the server,


subsequently, at the access point to authenticate the supplicant,
Finally, the supplicant must also authenticate the access point.

If the last two points are not verified for each transmitted packet, we
we run the risk of seeing an attacker put a duly authenticated client offside,
to steal his spot, or set up a rogue access point to deceive the client into
session course.

TLS, PEAP, and TTLS address this issue.


[li]

Fig. 12: The architecture of authentication


When the "supplicant" discovers the access point, the latter does not
he does not open any port until the 'supplicant' is authenticated by the server.
Only the traffic necessary for 802.1x will be tolerated before a successful authentication.

Principle of operation of 802.1x:

When detecting a new client (applicant), the port on


the switch (authenticator) will be allowed and set to 'unauthorized' state. In
In this state, only 802.1x traffic will be allowed; other traffic, such as DHCP and http,
will be blocked at the data link layer.
The authenticator will sendEAP-Ask the identity to
applicant, he then sends the packageEAP-Response that the authenticator
will be sent to the authentication server (Authenticator Server) which can accept
you reject EAP-Request; in the first case, the authenticator will place the port at
modeauthorizedand normal traffic will be allowed, otherwise the port will always be in
the state "unauthorized".
When the applicant wants to disconnect, they will send a message.
EAP-Session closure at the authenticator which will thus set the port to the state 'not
"authorized", blocking all traffic again -EAP
[lii]

II7.2 The 802.11i standard (WPA2):

LeWECA announced the inclusion of IEEE 802.11i in its certification


Wi-Fi since 2003. The theoretical speeds still reach 11 Mbps for 802.11b and
54 Mbps for 802.11g.

The role of this group is to define mechanisms.


supplements to improve the security of a 802.11 system.

The I EEE 802.11 i group works in the following directions:

. Integration of the IEEE 802.1x standard, allowing for management of authentication and
the key exchange in a 802.11 network.

. Utilization of a new key management protocol, TKIP (Temporal Key)


Integrity Protocol) designed to improve packet-by-packet authentication. This
protocol generates and distributes dynamic WEP keys, which use a
initialization vector of 48 bits instead of 24 bits of WEP.

. Utilization in the IEEE 802.11 standard of a new AES encryption algorithm


(Advanced Encryption Standard) to combat the weaknesses of RC4. It is
a symmetric encryption algorithm, created by NIST in 1997
for secure encryption. The downside of this approach is the lack of
compatibility with existing equipment.

Fig 13: principle of operation

Authentication protocols (TLS, PEAP, TTLS...) are not within the scope of
802.1X, RADIUS also.
[liii]

However, given what has already been seen, it is clear that there is no
of alternatives.

Chapter III. IMPLEMENTATION OF THE SOLUTION


WITHHOLDING
This chapter is divided into two parts: the first part
talk about the study of the existing situation of our application case and the second part will be
focused on implementing the chosen policy, as well as the different
equipment configurations to carry out the implementation.

SECTION I. ANALYSIS OF THE EXISTING

The analysis of the existing system is the very root of analysis.


preliminary, during this last analysis, we conduct an in-depth study of the system
in place in order to understand its functioning that is to say it provides a
diagnostic of the current situation (diagnostic provided as needed
THE COMPANY or the organization) through the users.
[liv]

This study helps guide the decision of leaders on the


the question of whether or not to computerize.31

I.1. Geographical situation of the department of living languages

The Department of Modern Languages is located at the university of


Kinshasa within the faculty of letters and human sciences.

I.2 History

The department of modern languages was founded in 1965, under


the call of the language school of the university after the birth of the faculty of
philosophy and letters in 1956, in order to serve the academic community of
the time.

In December 2008, under the leadership of Dean NGOMA BINDA, the


Faculty of letters has decided to revitalize this school by equipping it with chairs,
cassette radios and white formica boards.

I.3. Mission of the Department of Living Languages

The department of modern languages has a single mission which


is to promote and learn languages; because language is primarily seen as
the communication.

The department of living languages does not handle the students.


like little children but he protects and takes care of the students, in order to know
if students really understand their teaching.

I.4 Organizational structure

The modern languages department has a staff


composed of a department head, Professor NGWABA BIMBALA Ferdinand;
of a secretary in charge of research, Professor Charles MBADU kia MANGUEDI;
and a secretary responsible for education, the head of work WABENO FWASA
Pierre.

MVIBUDULU KALUYIT ., course notes on Computer Analysis Method Unpublished, G3 info ISC/Gombe,
31

2010 - 2011
[lv]

ORGANIGRAM

Head Chef
department

Secretary in charge Secretary in charge of


of teaching research
[lvi]

I.5. STUDY OF THE MEANS USED

To process the information, the language department


living beings have means that they use in order to achieve the search for solutions
appropriate. Among these means we have material, financial and
humans that we will have to take into account in this study.

I.5.1 Human resources

This study is necessary to better understand the


qualifications of the personnel working within the company.

With the help of the investigations carried out by the human resources department
from the department of modern languages, we discovered that it possesses
a well-experienced personnel whose qualifications are as follows:
[lvii]

No. Qualification Function SENIORITY name obs


E
01 doctor Department Head 1
02 doctor Secretary in charge 1
of teaching
03 doctoral student Secretary in charge
research 1

04 licensed Teacher 6

Source: Human Resources

I.5.2. Material resources

The material resources are represented in the table below:

No. materials names Brand state observation


01 Desktop computer 1 Intel PIV Good Turn under
-1.8GHz Windows
-256 MB RAM
-40Go HDD
02 Computer 3 Dual core Good Turn under
portable -2.20GHz or Windows
2.8GHz
-4Go, 3Go and 2Go
RAM
-500GB and
300GB HDD
03 printer 1 good

I.5.3. Financial means

The financial resources of the department of modern languages


are constituted by study fees (participation fees, course materials, etc....).

[Link] OF EXISTING NEEDS

This part allows us to determine if the implementation of


our application would be possible. Indeed, for a company's network, its
The need will be based on the objective of centralizing resources. This centralization of
resources at a single point will require the establishment of an infrastructure based on
the client/server architecture.

Indeed, a network needs analysis would be more effective.


and real, by determining the different services that workers and students
[lviii]

will depend on this network. In order to determine these needs, here are some services that
we are going to propose:

Access to the Internet, for every worker and student in the department of
living languages will be without condition, but access to resources will be
sanctioned by valid authentication, which will give workers access
to the resources in the company's intranet.
Access to an internal Web server allowing the publication of certain
documents as well as statements concerning all workers and
students of the company.
A DHCP server for the dynamic assignment of addresses locally.

The set of needs mentioned above constitutes the state of


needs of the modern languages department, we cannot talk about the implementation of
place without thinking about safety well in advance and it is indeed about safety that
our work finds its value.

Our work has just proposed a solution related to the


network security. Indeed, in this work we will implement a mechanism of
security, which mechanism will allow administrators to protect the network
against any unauthorized access to the network. Through this mechanism, only the
Authorized users will have access to the network as well as the company's resources.

From the establishment of this mechanism, it is necessary to gather certain


equipment including: a powerful computer, on which we configure the server
RADIUS and the certificate authority. This server will allow us to control access to
network from the physical connection. We will also need an access point.
(wireless connections). Thus, for our implementation, we will use a
laptop, which will serve as a server and a hotspot. Thus, the policy
Once implemented, it will protect the system against intrusions by managing and
by controlling access to the network from the physical access to the company's network.

I.5.5. DETAILED PRESENTATION OF THE CHOSEN SOLUTION

Ultimately, the chosen solution will have the physical topology of the
following schema:
[lix]

Fig. 14 the architecture of the network

LOGICAL CONCEPTION
[lx]

Figure 15: Concept of a solution based on EAP-TLS 802.1X authentication

The client without a wire. It is a computer or a device running a


application that needs to access network resources. This client is capable of no
not only to encrypt its network traffic, but also to store and exchange
identity information (keys or passwords).

The wireless access point. In network terminology, it is also referred to as a service.


network access. This wireless access point manages access to the network and encrypts the traffic
wireless. It allows for secure exchange of encryption keys with the client, in order to
to secure network traffic. Finally, it can query an authentication service.
and authorization to grant or deny access to the network.

The NAAS service (Network Authentication and Authorization Service). This service
Store and verify the identity of authorized users, and manage access accordingly.
the defined access control strategy. It can also collect information.
of accounting and auditing on the client's access to the network.

The internal network. This is a secure area of network services to which


the wireless client application must have access.

The numbers indicated on the diagram illustrate the process of accessing the network.
The following steps describe in more detail:

1. The wireless client must, at some point, be authenticated by an authority.


central to connect to the wireless network.
2. When the client requests to access the network, he transmits his information.
identity (or, more precisely, the proof that he holds this information
identity) at the wireless access point which, in turn, sends them back to the NAAS for
ask for permission.
3. The NAAS verifies the identity information, consults its access strategy and
authorize or deny access to the client.
If recognized, the client is allowed to access the network and exchange keys
decryption with the wireless access point. In fact, the keys are generated by the
NAAS service is transmitted to the wireless access point via a secure channel. If the
the client is not recognized by the NAAS service, he is not authorized to access the
network and communication is interrupted.
[lxi]

Thanks to the encryption keys, the client and the wireless access point establish a
secure wireless connection, allowing the client and the internal network to
to communicate.
The client begins to communicate with devices on the internal network.
a. Required Hardware and Software Components:

By necessary hardware and software components, we want


say the whole set of hardware and software that we will need for the implementation
place of our solution. Indeed we will need:

ComposantLogiciel:

A server operating system "Windows 2008 Server


Enterprise Edition" the choice of the Windows Server operating system is
justifiable, we chose it because on one hand it includes the management of certificates, and
On the other hand, it has an integrated RADIUS server called NPS (Network Policy Server).
Policy Server) capable of managing an infinite number of RADIUS clients on its own. This server
relies on the Active Directory directory service to manage login/password pairs
Done. But in our work we will use the Cisco Packet Tracer software.

Hardware Components:

Regarding the hardware components, we will have


needs a server and an access point, laptops and desktop computers
having a wireless card with antenna and a Windows (XP) operating system
SP2 and SP3).

SECTION II: EFFECTIVE IMPLEMENTATION OF THE SELECTED SOLUTION


II.1 ADDRESSING PLAN:

Let us remember that the department of modern languages is not


a computerized establishment, the addresses provided below are addresses that
we offered ourselves.

In this section, we just provide the information.


regarding addressing. Thus our network will have the addressing information.
following :

Subnet address: [Link]

Subnet mask: [Link]


[lxii]

Server address: [Link]

Access point address: [Link]

Client address range: [Link] - [Link]


II.2 INSTALLATION OF PROTOCOLS

2.1. DNS Configuration

DNS allows converting numeric addresses into names


simple, for example, [Link]) are much easier to memorize than
their numerical equivalents (for example, [Link], the numerical address of
server of ISTA). Furthermore, if ISTA decides to change its digital address, this
the change is transparent for the user because the domain name remains
[Link].

To do this, we will double-click on the server/configuration/DNS.

The address of our server is [Link] which will be translated to


[Link] for the public

2.2. Configuration of the Radius server

We let's select AAA (Authentication, Authorization and


Accounting) as shown in the figure below which is a definition method
[lxiii]

of a reference framework for the secure use of network resources. This


method will allow us to know:

. Who is connecting?
. Who has the right to access what?
. Who uses what?

2.3. Configuration of the DHCP protocol

The DHCP protocol allows devices on a network


to obtain IP addresses and other information from a DHCP server. This service
automate the assignment of IP addresses, subnet masks,
gateway settings and other IP network settings.
[lxiv]

To configure it, we double-clicked on DHCP as indicated by the


figure below.

2.4. The installation of the FTP protocol

The FTP protocol was developed to allow for the transfer of


files between a client and a server
To configure it, we double-clicked on FTP
as indicated in the figure below
[65]

II.3. Wireless Router Configuration

Routers are primarily responsible for interconnecting


networks by determining the best path to send packets and transfer
these last ones towards their destination.

To do this we double-clicked on Wireless router, it is


in the screen that appears above we have set up the protocol of
security, in our case we chose the WAP protocol.
We also activated the DHCP protocol in the router by clicking on the GUI.

II.4 Configuration of Wi-Fi clients

As stated in the work, all machines obtain their


automatically assigned from the DHCP server and are in this case called
clients DHCP. So we must first connect our machines to the DHCP router.
[lxvi]

To do this, we double-clicked on the PC then


desktop/web browser, we enter the router's IP address in the URL and then validate.
An authentication window appears asking the user to provide the name and
the password to access the web page.

In User name we will put admin and in password 0000


to connect to the router.

We can also change the password. To do this, we select


administration then you will provide the password of your choice during the next
the connection will ask you for the new password.
67

The figure above shows us that our configuration has performed very well.
successful.

To connect machines in a wireless network, we have


Simply click on Desktop then on wireless pc as shown in the figure.
on top.
[68]

As we can see in the figure below which reassures us that the


The system is very well connected and the PCI card is activated. Then we clicked on
connect, there we see how the connection passes between the access point and the
machine.

Here is our network that has the capacity to accommodate at least 254 Wi-Fi clients.
69

GENERAL CONCLUSION

Here we are at the end of our work on the study of the implementation of
implementation of a security system based on authentication in a wireless network.

Our motivation is to know how we can secure the


Wi-Fi network through an access point. Despite security issues.
intrinsic, wireless networks continue and will probably continue to
develop. It is therefore important to be well aware of the issues related to the implementation
place of this type of networks in order to limit their harmful effects. It is also
It is important to determine the desired level of security in order to implement a
solution in accordance with this choice.

For a reliable network, it is better to opt for security.


WPA, even though it requires a network in infrastructure mode. Due to concern for
Confidentiality, it is preferable to have a secure network. As soon as encryption
WPA/WPA2 will be decryptable by anyone, other encryption methods
will make their appearances, and so on. This is why there is no security.
infallible.

We have finally structured our work into three chapters:

General overview of the network that explained some concepts used in the
computer networks

The 802.11 standard (wi-fi) and security, the protection mechanisms and
some security protocols;

Implementation of the chosen solution: in this chapter we have set out


set up our security system using a simulator (cisco packet)
tracer). The results obtained are the same if we used some
physical equipment. We hope to do this later if the language school
will be able to provide us with the means for this
realization.
[lxx]

Finally, we want to emphasize that we do not at all


I do not claim to have presented a perfect work, as no scientific work is perfect.
it can be, so we leave it to all those who read us and who are from
domain to send us their comments and suggestions to enrich it and
to improve it.

BIBLIOGRAPHY

I. Works

DI GALLO Fréderic, The essentials of the Wi-Fi network

PHILIP ATELIN.,Réseaux sans fil 802.11 2ème éditon, éditons ENI, 2008


CABARE Michel.,Réseaux Locaux Théorie et Normes, inter Éditon

II. Course note and TFC

KASENGEDIA MOTUMBE Pierre. Course of Telematics and Networks, Unpublished, L2


Information Iss/Kin, 2011-2012.
MABELA, course on Computer Structure and Networks, Unpublished, G2 AIA, Unikin
2011-2012.
MVIBUDULU KALUYIT., course notes on Computer Analysis Method
Unpublished, G3 info ISC/Gombe, 2010 – 2011.
BAKASANDA JeannotA., course on scientific research methods
G2Design, unpublished ESIS 2006-2007

III. Sites

htp : //[Link]/cours/[Link]
[Link]
[Link]

Site [Link] - "Wireless Network: The WiFi Technology"


[Link] online/wireless technologies wifi and security/ Nadia
[Link]
[Link]/wifi/wifitech.php3
www. Online memory establishment of a networkwifi.com
[lxxi]

IV. Magazine

Magazine [Link] - November 2003 - 'the essentials that need to be known' File
made by [Link] GALLO..

You might also like