Wireless Networking Security: WPANs, WLANs, and WWANs
This paper examines wireless networking technologies, protocols, and security vulnerabilities across three primary network types: Wireless Personal Area Networks (WPANs), Wireless Local Area Networks (WLANs), and Wireless Wide Area Networks (WWANs). Drawing on a qualitative literature review, the paper surveys WPAN technologies — Bluetooth, ZigBee, and Near Field Communications (NFC) — and the specific attacks each faces, including Bluejacking, BlueSnarf, Bluesmack, and data insertion attacks. The paper also addresses P2P wireless security architecture, 3G cellular radio planning challenges, and the broader security landscape of wireless communications. A final section evaluates proactive wireless self-protection approaches, with particular emphasis on anomaly-based Wireless Intrusion Detection Systems (WIDSs) as a promising solution for detecting both known and novel wireless attacks.
- Introduction to Wireless Networking Technologies: Defines WPANs, WLANs, WWANs and study scope
- WPAN Security: Bluetooth, ZigBee, and NFC: Attacks and defenses for three WPAN technologies
- P2P Wireless Technology and Security Policy: Security architecture for peer-to-peer conference systems
- Radio Planning and 3G Cellular Networks: W-CDMA planning models and base station optimization
- Security Challenges, Risks, and Approaches: Cross-technology wireless security risks summarized
- Proactive Wireless Self-Protection and Anomaly-Based Detection: WSPS framework and anomaly-based intrusion detection results
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper systematically organizes a complex technical landscape by network type (WPAN, WLAN, WWAN), making it easy for readers to follow the progression from small-scale to large-scale wireless environments.
- Specific attack names and mechanisms — Bluejacking, BlueSnarf, BlueDump, Bluesmack, and data insertion — are defined and explained clearly, grounding abstract security concepts in concrete examples.
- The paper moves from problem identification (attacks and vulnerabilities) to potential solutions (anomaly-based WIDSs and the WSPS framework), giving the work a logical arc from diagnosis to remedy.
Key academic technique demonstrated
This paper demonstrates effective synthesis of a multi-source literature review. Rather than summarizing each source in isolation, the author weaves together findings from Kennedy and Hunt, Fayssal et al., Amaldi et al., and Liu and Koenig into a cohesive argument about the inadequacy of current wireless security tools and the promise of anomaly-based detection. This technique is especially useful in technical research papers where no single source covers the full scope of the topic.
Structure breakdown
The paper opens with an introduction defining the three network types and stating the study's purpose and rationale. Five numbered sections follow: WPAN security (Bluetooth, ZigBee, and NFC vulnerabilities), P2P wireless security architecture, 3G cellular radio planning, a synthesis of cross-technology security challenges, and a detailed treatment of proactive anomaly-based intrusion detection. The bibliography closes the paper with APA-formatted citations.
Introduction to Wireless Networking Technologies
This work focuses on wireless networking technologies, protocols, standards, and operations. Also examined are the capabilities of Wireless Personal Area Networks (WPANs), Wireless Local Area Networks (WLANs), and Wireless Wide Area Networks (WWANs). The paper describes wireless networking capabilities, recent initiatives, and the advantages and limitations of wireless networks in accommodating goals, objectives, and requirements in government and academic environments. Finally, a security component relating to these wireless network technologies is examined.
Wireless devices are highly prone to being attacked and exploited; however, the benefits of these wireless technologies far exceed the risks that accompany their use. The Wireless Personal Area Network (WPAN) is a wireless network with a maximum range of 10 meters and is used for the interconnection of devices with one another. The Wireless Local Area Network (WLAN) has a signal range of approximately 30 meters indoors and 100 meters outdoors, and is often also referred to as Wireless Fidelity (Wi-Fi). The Wireless Wide Area Network (WWAN) provides a wireless connection over a much wider geographic area.
The purpose of this study is to identify a security protocol that will serve to protect wireless communication across the range of WPANs, WLANs, and WWANs.
The problem addressed in this research study is related to wireless technology and the limitations that currently exist in wireless network security. There are various applications of wireless networks, various wireless devices, and various communication protocols; however, there is not yet wireless network security protection with the necessary capabilities to cover all types of wireless network communication across the full spectrum of wireless network technology communication security needs.
The methodology of this study is qualitative in nature and involves an extensive review of the literature in this area of study.
WPAN Security: Bluetooth, ZigBee, and NFC
The work of Todd Kennedy and Ray Hunt entitled "A Review of WPAN Security: Attacks and Prevention" states that Wireless Personal Area Networks (WPANs) "fill an important role in local area network technology complementing traditional IEEE 802.11 Wireless LANs." The key emergent WPAN technologies — Bluetooth, ZigBee, and NFC (Near Field Communications) — are "subject to the usual range of security vulnerabilities found in wireless LANs such as spoofing, snooping, man-in-the-middle, denial of service and other attacks" (Kennedy and Hunt, 2008, p. 1).
WPANs are stated to form "an important niche in wireless area technology that are particularly applicable for applications demanding low data rate transfer, limited range, low power consumption as well as requiring devices to be physically small and of low cost" (Kennedy and Hunt, 2008, p. 1). Bluetooth and ZigBee are stated to operate "in the same frequency spectrum as IEEE 802.11b Wireless LANs and are thus subject to interference" (Kennedy and Hunt, 2008, p. 1).
Bluetooth technology was designed specifically for small form factor, low cost, and short-range radio links that communicate between "PCs, handheld devices, mobile phones and other computing devices based on IEEE 802.15.1" (Kennedy and Hunt, 2008, p. 2). This technology is viewed as a "cable replacement that allows one's device to connect to another through a 10-meter personal bubble (which may extend up to 100 meters) and supports simultaneous transmission of both voice and data for multiple devices" (Kennedy and Hunt, 2008, p. 2).
Profiles supported by Bluetooth include: (1) imaging; (2) file transfer; (3) generic access, discovery and link establishment; (4) human interface device (keyboard, mouse); and (5) LAN access using Point-to-Point Protocol (Kennedy and Hunt, 2008, p. 2). Bluetooth Version 2.0 + Enhanced Data Rate (EDR) was released in 2004, with Bluetooth Version 2.1 + EDR Specification adopted in July 2007, incorporating various new operational features. Bluetooth 3.0 was being drafted at the time of the Kennedy and Hunt study, with the likelihood of including Ultra Wide Band (UWB) features. Bluetooth operates in the "unlicensed 2.4 GHz band, which is shared with other wireless communication standards such as 802.11b LANs" (Kennedy and Hunt, 2008, p. 2).
Bluetooth attacks are generally associated with mobile telephony devices, but "they are equally applicable to other devices used in the WPAN environment" (Kennedy and Hunt, 2008, p. 1). Bluejacking refers to the process of sending unsolicited content to Bluetooth-enabled devices, generally containing a message such as a BlueChat (chatting over Bluetooth). These messages are short and may be used to mimic authentication dialogues, compelling users to reveal access codes, which the attacker then uses to access files stored on the device (Kennedy and Hunt, 2008, p. 1).
BlueSnarf is a similar process in which unsolicited content is sent to Bluetooth-enabled devices, and just as in Bluejacking, the attack attempts to mimic authentication dialogues, tricking the user into disclosing access codes and granting the attacker read access to the vulnerable device — including the calendar and phone book — without authentication. This attack has been upgraded to BlueSnarf++, which makes use of the Object Exchange FTP service to connect to vulnerable devices and grants the attacker read and write access to the device's entire file system, including memory extensions such as memory sticks. A third attack, known as BlueBump, exposes a weakness in "the handling of Bluetooth link keys, giving devices that are no longer authorized the ability to access services as if still paired. It can lead to data theft or the use of mobile Internet connectivity services, such as Wireless Application Protocol" (Kennedy and Hunt, 2008, p. 1).
Bluesmack is a Denial of Service (DoS) attack "that can be performed with standard tools such as the Linux Bluez utils package" (Kennedy and Hunt, 2008, p. 1). This attack is similar to the Ping of Death attack in that it targets the L2CAP layer, which can request another Bluetooth peer echo. The tool enables the user to specify a certain acceptable packet length, and when a packet exceeds that length by more than 600 bytes the results may be devastating (Kennedy and Hunt, 2008, p. 3).
Before an attacker can conduct a BlueDump attack, the attacker must know "the Bluetooth address of a set of paired devices" (Kennedy and Hunt, 2008, p. 3). This involves the attacker spoofing the address of one of the devices and then connecting to the other. When the device asks for authentication, the attacker does not have a link key, which can result in the link key being deleted by the target device and the device reverting to pairing mode (Kennedy and Hunt, 2008, paraphrased).
BlueChop is also a DoS attack, capable of disrupting any piconet established by Bluetooth even when the attacking device is non-participatory. The non-participating device disrupts the piconet by spoofing a random slave and contacting the piconet master. Kennedy and Hunt report that Bloover was created "as a proof-of-concept tool that can be used to initiate a BlueSnarf attack from a J2ME-enabled mobile device" (p. 3); however, the intent in creating Bloover was to use it as an auditing tool to check for vulnerability in mobile devices. Bluetooth is also reported to be vulnerable to traditional computer attacks including self-propagating viruses, malware, and worms — one such attack being the Cabir worm, which uses the Bluetooth device to self-replicate but affects only Symbian platforms.
Because Bluetooth is wireless, it is particularly difficult to prevent signals from leaking outside set boundaries. For this reason, individuals should not enter a PIN into a Bluetooth device for pairing in public, as this mitigates the risk of eavesdropping by an attacker. Understanding Bluetooth pairing is important in defending against attacks. The Bluetooth specification enables the use of NFC for the creation of a secure pairing process.
Bluetooth devices generally save the link key in non-volatile memory for future use. When the same Bluetooth devices communicate again, the stored link key is used; however, some Bluetooth devices require that a PIN be entered each time communication takes place, which increases the likelihood that an attacker may eavesdrop on the communication. Bluetooth devices use encryption, which requires a "unique session key to derive per-packet keys, thus avoiding frequent key reuse" (Kennedy and Hunt, 2008, p. 4).
Kennedy and Hunt report that ZigBee is a reasonably priced, low-energy-consumption, two-way CDMA/BA-based wireless communications standard based on IEEE 802.15.4, commonly referred to as Low Rate Wireless Personal Area Networks (LR-WPANs), and is targeted primarily "at radio frequency applications requiring low data rate, long battery life and secure networking" (p. 4).
LR-WPANs "offer device-level wireless connectivity" and "enable a range of new applications as well as enhance existing applications" (2008, p. 4). These devices are low in cost and low in energy use, and their self-organization features make them useful for public security applications, inventory tracking, and home and office automation. A wireless device may be jammed in a manner equivalent to a DoS attack. Jamming can take place at the PHY layer through continuous transmission, and an attacker can also create collisions.
Kennedy and Hunt report that the 'void address' attack is particularly powerful: since LR-WPANs use 16-bit short addresses and the cluster-tree may use only part of the address, the attacker can send a packet to a nonexistent address beyond the cluster-tree address scope. While the address does not exist, the packet will be sent up the tree, and when it arrives, the root may fail to validate the address and forward the packet to a branch that does not exist. Since the root does not receive a packet acknowledgement, the packet is then retransmitted.
The LR-WPAN device has its key management "based on the trust centre which is neither robust nor efficient. Communications between the trust centre and a device can be lost, especially in a multi-hop and/or mobile environment" (p. 4). This reliance on the trust centre reduces system robustness, particularly for key transports and updates, since keys are currently unicast. The trust centre and devices near it are heavily burdened due to the need to relay traffic. For this reason, Kennedy and Hunt state that distributed or hierarchical key management schemes should be considered for large-scale networks.
Kennedy and Hunt relate that Near Field Communications (NFC) is a "short-range wireless connectivity technology" that provides "intuitive and simple communication between electronic devices" (2008, p. 5). Communication takes place when two NFC-compatible devices are brought within a few centimeters of each other, and NFC is compatible with existing RFID (Radio Frequency Identification) standards. This technology operates in the 13.56 MHz frequency band and transfers data "at up to 242 Kbps as defined by ISO 14445" (Kennedy and Hunt, 2008, p. 3).
Due to the short transmission range, NFC transactions are potentially secure. However, eavesdropping attacks represent a high risk since antennas can be used to receive signals. NFC communication generally takes place between devices 10 centimeters apart or less, and while this range does not eliminate attackers, the operating mode is a limiting factor — specifically, whether the RF field is generated by the sender or by a separate device. When NFC generates its own RF field, this is referred to as the 'active' mode; when NFC uses the RF field of another device, this is the 'passive' mode. Various transmission methods make eavesdropping more difficult in passive mode. When active mode is used to send data, eavesdropping can occur within approximately 10 meters.
Data corruption attacks are also a risk with NFC communication. The simplest form involves the attacker disturbing the receiver's communication, rendering the transmitted data unreadable by the receiver. This is perpetrated through transmitting valid frequencies of the data spectrum at the correct time. An attacker with knowledge of the modulation and coding scheme will be able to calculate that correct time. Another form of attack is the 'Data Insertion' attack, in which the attacker inserts messages into the data being exchanged between two devices; however, this can only occur when the answering device accepts delayed replies.
The Data Insertion attack allows the attacker to insert a message prior to the expected reply, and it will succeed if that message reaches the answering device first. If the data stream overlaps, the data will become corrupt. While the passive mode of transmitting data is considerably safer, eavesdropping may still occur; for this reason, an NFC device can establish a secure channel by monitoring the RF field during transmission.
There are three possible countermeasures to a Data Insertion attack: (1) the answering device answers with no delay, making it impossible for the attacker to respond as quickly as the correct device; (2) the answering device can listen to the channel during transmission, making it more difficult for an attacker to insert data and easier to detect if insertion does occur; and (3) a secure channel is established between the two devices (Kennedy and Hunt, 2008).
Data Insertion countermeasures can be performed by establishing a secure channel between the two NFC devices and then applying a standard key agreement protocol "such as Diffie-Hellman based on RSA or Elliptic Curve cryptography. Since the man-in-the-middle is no significant threat, the unauthenticated version of Diffie-Hellman will be adequate. The shared secret can then be used to derive a key for use in a symmetric encryption algorithm such as 3DES or AES, which then secures the channel" (Kennedy and Hunt, 2008).
Kennedy and Hunt (2008) state: "Although application of the key security principles of encryption and authentication are clearly required in any wireless network architecture, they are more difficult to achieve as the size and scale of wireless devices is reduced. Implementing authentication and encryption algorithms in hardware on an IEEE 802.11 device installed, for example, in a laptop is not difficult, but the same cannot be said for a number of WPAN devices. Encryption and authentication need to be fast — particularly in a highly mobile environment which demands hardware implementation" (Kennedy and Hunt, 2008, p. 5). WPAN devices are too small to handle this challenge, and current cryptographic algorithm demands including AES and MD5, among others, are difficult to achieve due to the requirements of complex mathematical processing combined with miniature power sources.
A technology stated to "significantly alter this landscape is Ultra Wide Band (UWB), which operates by spreading pulses across a very wide frequency spectrum (3.1 to 10.6 GHz), although currently it is still in the standards specification phase. The combination of this larger spectrum, lower power, and pulsed data improves speed and reduces interference with other wireless devices. This short-range radio technology could be very valuable for WPANs, as it would provide a cost-effective, power-efficient, high-bandwidth solution for relaying data between hosts and intermediate devices (up to 10 meters). UWB is establishing partnerships with Bluetooth (draft version 3.0, May 2008) and Wireless USB to gain value from this new technology, which may change the face of the next generation of mobile devices" (Kennedy and Hunt, 2008, p. 5).
P2P Wireless Technology and Security Policy
The work of Liu and Koenig (2008) entitled "Security Policy Management for Peer Group Meetings" states that the privacy of P2P meetings requires "appropriate security architecture" (p. 1). Security architecture "specifies how to incorporate the needed cryptographic methodologies and the security functions (key management) into the system to meet the defined security requirements" (Liu and Koenig, 2008, p. 68). Security architecture is reported to be built in a "modular manner" to ease systems expansion and maintenance, with each module serving "a specific security function in the system such as key management and the security policy management" (Liu and Koenig, 2008, p. 68).
The level of protection of a conference is determined by the security policy, which also specifies the application of security algorithms. The primary concern in the security policy module design is how the diverse security policies may be reconciled. Absent a unified security policy, participants will not be able to initiate communication with one another.
While security policies play a primary role in controlling security activity in a system, research on security has historically failed to examine this adequately. The conventional principle is that central security policy management is the responsibility of the server, which creates, disseminates, and reconciles security policies; however, this approach cannot be applied to P2P systems because these systems use serverless architecture. There are not yet any appropriate solutions for security policy management in P2P settings. Liu and Koenig propose a solution for P2P security policy management, specifically for P2P conference systems. Each peer in a P2P video conference system is stated to possess the same capabilities and to use the same system structure, meaning that peers are capable of setting up meetings without any central server.
Different functional modules comprise the system, grouped by distinctive functionalities into three layers: (1) an application layer; (2) a security layer; and (3) a group communication layer (Liu and Koenig, 2008, p. 68). The application layer contains application-specific functions regarding the transfer of media data, including group management for supervising group composition, quality of service (QoS) management which controls media parameters, and floor control which regulates access to shared resources. The sending and receiving of video and audio streams — including digitalization and compression for efficient network transmission — comprises the media data transfer functions. The group communication layer forms "the basis for a reliable operation of the collaborative functions in the upper layers" and includes group management data updates among peers (Liu and Koenig, 2008, p. 68).
Because this is a distributed setting, all peers must "have the same view on the actual group state and can uniquely decide all group-related issues by themselves" (Liu and Koenig, 2008, p. 69). This includes QoS parameter settings, security policy reconciliations, and floor assignments. The required virtual synchrony is provided by a "decentralized group communication protocol such as GCP" (Liu and Koenig, 2008, p. 69). The security layer provides the security services needed in P2P conferences.
The security requirements that a conference is expected to comply with are: (1) user authentication; (2) authorization; (3) confidentiality; and (4) data integrity. Liu and Koenig explain that the decision about which security level and type of security algorithm are required in a conference is made by the 'security policy module' (Liu and Koenig, 2008, p. 69). Mutual user authentication between the new participant and the members of the group when a new participant joins the conference is performed by the 'authentication module'. Incoming calls are automatically filtered by the 'authorization module', ensuring that only calls from users listed in specified contact lists are accepted. The group key is refreshed by the 'group key management module' each time the group composition changes. The confidentiality and integrity of signaling data and media data exchange are ensured by the 'data security module'.
Always verify citation format against your institution’s current style guide requirements.