CSS334 — Wireless Networks & Firewalls Cheat Sheet
Exam-ready summary | Lecture 13 | All topics included
⚠️ Final Exam reminder: IP calculation, CIDR, VLSM, configure routing, series questions (design IPs → use to configure routing). 1 A4 sheet allowed.
1. Elements of a Wireless Network
| Element | Description | Examples |
|---|---|---|
| Wireless Host | Device with a wireless adapter — runs applications; may or may not be mobile | Laptop, smartphone, IoT device |
| Base Station (AP) | Connected to wired network; relays packets between wired network and wireless hosts | 802.11 Access Point, Cell Tower |
| Wireless Link | Channel connecting host to AP; uses multiple access protocol | 2.4 GHz, 5 GHz, 900 MHz |
⚠️ Wireless ≠ Mobile. A desktop with a Wi-Fi card is wireless but not mobile.
Two Connection Modes
| Mode | How | Supports Handoff? |
|---|---|---|
| Infrastructure | Hosts communicate through an AP → AP connects to wired network | ✅ Yes |
| Ad-hoc | Hosts communicate directly with each other — no AP needed | ❌ No |
Analogy: Infrastructure = must go through a convenience store counter to reach the outside world. Ad-hoc = neighbours talking directly to each other.
2. Wireless Link Challenges
| Challenge | Cause |
|---|---|
| Decreased signal strength (Path Loss) | Radio signal attenuates through matter and distance |
| Interference | 2.4 GHz band shared by Wi-Fi, Bluetooth, microwaves, motors |
| Multipath propagation | Signal reflects off walls/ground → arrives at different times, causing distortion |
Analogy: Radio signal = shouting in a room. Farther away = quieter. Obstacles = damage. Echo = multipath.
3. SNR & BER
Signal-to-Noise Ratio (SNR)
- Larger SNR = better — easier to extract signal from noise
- Recommended minimums:
- Data networks: ≥ 20 dB
- Voice/VoIP: ≥ 25 dB
Bit Error Rate (BER)
- Lower BER = better — fewer corrupted bits
SNR vs BER Tradeoff
| Situation | Effect | Action |
|---|---|---|
| Increase TX power | SNR ↑ | BER ↓ (fewer errors) |
| Move farther from AP | SNR ↓ | BER ↑ (more errors) |
| High SNR environment | Can use high-order modulation | Higher throughput |
| Low SNR environment | Must use low-order modulation | Lower throughput, more reliable |
Modulation Schemes (Higher modulation = faster but needs better SNR)
| Modulation | Throughput | Required SNR |
|---|---|---|
| BPSK | 1 Mbps | Low |
| QAM16 | 4 Mbps | Medium |
| QAM256 | 8 Mbps | High |
Analogy: Like speaking in a noisy room — if it's too loud, speak slowly and clearly (low modulation). If quiet, speak quickly (QAM256).
Rate Adaptation: AP + device dynamically switch modulation as SNR changes with movement. SNR drops → switch to lower modulation to maintain reliable connection.
4. 802.11 WiFi Standards
| Standard | Year | Max Rate | Range | Frequency |
|---|---|---|---|---|
| 802.11b | 1999 | 11 Mbps | 30m | 2.4 GHz |
| 802.11g | 2003 | 54 Mbps | 30m | 2.4 GHz |
| 802.11n (Wi-Fi 4) | 2009 | 600 Mbps | 70m | 2.4 & 5 GHz |
| 802.11ac (Wi-Fi 5) | 2013 | 3.47 Gbps | 70m | 5 GHz |
| 802.11ax (Wi-Fi 6) | 2020 | 14 Gbps | 70m | 2.4 & 5 GHz |
| 802.11af | 2014 | 35–560 Mbps | 1 km | Unused TV (54–790 MHz) |
| 802.11ah | 2017 | 347 Mbps | 1 km | 900 MHz (IoT/long range) |
- All standards use CSMA/CA for multiple access
- All support both infrastructure and ad-hoc modes
5. Frequency Bands: 2.4 GHz vs 5 GHz
| Property | 2.4 GHz | 5 GHz |
|---|---|---|
| Data Rate | Slower | Faster |
| Range / Coverage | Longer (better wall penetration) | Shorter |
| Channels total | 14 | 23 |
| Channel overlap | Overlapping (only 1, 6, 11 non-overlapping) | No overlap |
| Standards | 802.11b, g, n, ax | 802.11a, n, ac, ax |
| Congestion | Very crowded (shared with BT, microwaves) | Less crowded |
2.4 GHz = slow but far, like FM radio.
5 GHz = fast but short, like Bluetooth.
2.4 GHz Channels (Key Rule)
- Each channel = 20 MHz wide, spaced 5 MHz apart → heavy overlap
- Only channels 1, 6, and 11 are truly non-overlapping — always use these for adjacent APs
- Configure neighbouring APs on different non-overlapping channels to avoid interference
5 GHz Channels
- More channels available, no overlap between adjacent channels
- Some channels require DFS (Dynamic Frequency Selection) — must avoid conflict with TDWR (Terminal Doppler Weather Radar) used at airports
6. 802.11 LAN Architecture
- BSS (Basic Service Set) = one "cell" = one AP + its associated wireless hosts
- SSID (Service Set Identifier) = the human-readable Wi-Fi network name
Associating with an AP (Host Joining Process)
| Step | Action |
|---|---|
| 1 | Scan channels — listen for beacon frames (contain AP's SSID + MAC) |
| 2 | Select AP to associate with |
| 3 | Authenticate (if required — password/WPA2) |
| 4 | Run DHCP to get IP address in AP's subnet |
Passive vs Active Scanning
| Passive Scanning (Normal) | Active Scanning (Hidden SSID) | |
|---|---|---|
| Step 1 | APs periodically broadcast beacon frames | Host broadcasts Probe Request |
| Step 2 | Host selects AP → sends Association Request | APs send Probe Response |
| Step 3 | AP sends Association Response | Host sends Association Request |
| Step 4 | — | AP sends Association Response |
Passive = sit and listen for who's broadcasting. Active = shout "anyone home?" used when SSID is hidden.
7. 802.11 Frame Addressing (4 MAC Addresses)
| frame ctrl | duration | addr1 | addr2 | addr3 | seq ctrl | addr4 | payload | CRC |
| Field | Meaning |
|---|---|
| Address 1 | MAC of the receiver (host or AP receiving this frame) |
| Address 2 | MAC of the transmitter (host or AP sending this frame) |
| Address 3 | MAC of the router interface the AP is attached to |
| Address 4 | Used only in ad-hoc mode |
Example: H1 → Internet (H1 sends through AP → Router R1)
| Frame Type | Address 1 | Address 2 | Address 3 |
|---|---|---|---|
| 802.11 (Wi-Fi) | AP's MAC | H1's MAC | R1's MAC |
| 802.3 (Ethernet) | R1's MAC | AP's MAC | — |
Wi-Fi frame carries 3 MACs because the AP acts as a relay — it needs to know where the frame came from (H1), where it's going next (R1), and who it is itself.
8. CSMA/CA — Collision Avoidance
Why NOT CSMA/CD for Wi-Fi?
- Cannot detect collisions wirelessly — transmitting signal drowns out received signal (fading)
- Hidden terminal problem — two hosts can't hear each other but both can hear the AP
- Solution: avoid collisions instead of detecting them → CSMA/CA
CSMA/CA Sender Algorithm
1. Sense channel:
Idle for DIFS duration → transmit entire frame (no collision detection)
Busy → start random backoff timer
- Timer counts down while channel idle
- When timer = 0 → transmit
- If no ACK received → increase backoff interval → repeat
Key Timing Parameters
| Parameter | Full Name | Purpose |
|---|---|---|
| DIFS | DCF Interframe Spacing | Required idle time before a node may begin transmitting |
| SIFS | Short Interframe Spacing | Shorter wait used before sending ACK or CTS (priority) |
SIFS < DIFS → ACKs and CTS always get priority over new data frames.
Analogy: Polite meeting — wait for the speaker to finish (sense channel) + wait extra time (DIFS), then speak. If two people start simultaneously, both back off randomly.
RTS/CTS: Optional Collision Avoidance Enhancement
Solves the hidden terminal problem:
1. Sender → AP: RTS (Request to Send) — small control frame via CSMA
2. AP → ALL: CTS (Clear to Send) — broadcast, all nodes hear it
3. All nodes hear CTS → defer transmission (virtual carrier sense)
4. Sender transmits full data frame
5. AP → Sender: ACK
RTS may still collide, but it's tiny → much less wasted bandwidth than full data frame collision.
Analogy: Booking a room — tell the AP you need it, AP announces "Room reserved for A", everyone else waits.
9. 802.11 Mobility & Power Management
Mobility Within Same Subnet
- Host moves from AP1 to AP2 — same subnet, same IP (no DHCP needed)
- Switch updates its self-learning table when it sees the host's MAC arrive from a different port
- Seamless handoff — IP address unchanged
Power Management
- Node tells AP: "I'm going to sleep until the next beacon frame"
- AP buffers frames for sleeping node
- Beacon frame contains a list of mobiles with pending frames
- Node wakes before beacon → checks list → stays awake if frames waiting, goes back to sleep if none
10. 802.11 Wireless Security
Security Challenges
- Guest/contractor access needs (separate guest SSID)
- Mobile/endpoint devices — hard to control
- Untrusted devices and apps
- Cloud integration risks
Signal Hiding Techniques
| Technique | Effect |
|---|---|
| Disable SSID broadcast | Network not visible in scan list (hidden SSID) |
| Cryptic/non-default SSID | Doesn't reveal organisation name |
| Reduce AP signal strength | Limits range — signal doesn't leak outside building |
| Directional antennas | Focus signal toward users, away from outside |
WEP vs WPA vs WPA2
| Property | WEP | WPA | WPA2 ← Use this |
|---|---|---|---|
| Encryption | RC4 (static key) | RC4 + TKIP (rotating keys) | AES |
| Authentication | Shared Key | Shared Key + 802.1X | Shared Key + 802.1X |
| Data Integrity | CRC-32 | MIC (Message Integrity Code) | CBC-MAC |
| Key Management | None | Dynamic per-frame | Dynamic per-frame |
| Year | 1999 | 2003 | 2004 |
| Status | ❌ Broken (~5 min to crack) | ⚠️ Fallback only | ✅ Use this |
WPA2 Details
- Based on IEEE 802.11i standard
- Two modes:
- Personal (PSK): Pre-Shared Key — password for home/small office
- Enterprise: Per-user authentication via EAP (Extensible Authentication Protocol) — requires RADIUS server
Additional Protection
- Multiple SSIDs — separate guest SSID with client isolation (guests get internet but cannot reach internal LAN — perfect for visitor Wi-Fi)
- WPA2 + strong password + anti-virus + firewall = layered protection
WEP = easy-copy door key. WPA = key changes every use. WPA2 = military-grade AES encryption.
11. Firewalls
What Is a Firewall?
- Security system that monitors and controls incoming/outgoing traffic based on predefined rules
- Placed between internal network and the internet
- Can be hardware (dedicated appliance) or software (Windows Firewall, iptables)
Why Firewalls?
| Goal | Detail |
|---|---|
| Prevent DoS attacks | e.g., SYN flooding — attacker creates bogus TCP connections, exhausting server resources |
| Prevent illegal access | Block unauthorised access to internal data |
| Allow authorised access | Only whitelisted traffic enters |
| Stealth / Privacy | DROP policy = network invisible to port scans (connections time out silently) |
Inbound vs Outbound Rules
| Type | Protects against |
|---|---|
| Inbound | External threats — hackers, malware, DoS attacks coming in |
| Outbound | Compromised internal node becoming an attack source going out |
12. Firewall Strategies
a) Blacklisting (Default ACCEPT)
- Default: allow everything
- Add rules to DROP specific bad traffic
- Use case: outbound rules (flexibility for users to access internet)
b) Whitelisting (Default DROP)
- Default: block everything
- Add rules to ACCEPT only known good traffic
- Use case: inbound rules (most secure — nothing enters unless explicitly permitted)
Blacklisting = door is open, bouncer has a list of banned people.
Whitelisting = door is locked, only VIP list gets in.
13. Firewall Zones (Network Segmentation)
Group assets by trust level → define inter-zone traffic rules instead of per-IP rules.
| Zone | Trust Level | Contents | Policy |
|---|---|---|---|
| Untrusted (WAN/Internet) | Zero | Public internet | Assume everything malicious; only filtered traffic in |
| DMZ (Demilitarised Zone) | Low–Medium | Web server, Mail server, DNS, FTP | Can talk to internet; cannot initiate to internal |
| Trusted (LAN/Internal) | High | Employee workstations, internal servers, sensitive data | Full access out; heavily shielded inbound |
Inter-Zone Traffic Matrix
| From → To | Default Action | Reason |
|---|---|---|
| Trusted → Untrusted | Allow | Employees browse the internet |
| Untrusted → Trusted | Block | Prevent external attacks reaching internal LAN |
| Untrusted → DMZ | Allow (filtered) | Public accesses your web server |
| DMZ → Trusted | Block | If web server is compromised, attacker stays in DMZ |
Analogy: DMZ = castle forecourt. Visitors can enter the forecourt (DMZ) but cannot enter the castle (internal LAN).
14. Types of Firewalls (Increasing Security)
| Type | Security Level | How It Works |
|---|---|---|
| Stateless Packet Filtering | Basic | Inspects each packet independently by IP, port, protocol — no memory of past |
| Stateful Inspection | Moderate | Tracks state of active TCP connections — verifies incoming packets were actually requested |
| Next-Generation (NGFW) | High | Adds deep packet inspection, antivirus, encrypted traffic inspection, Layer 7 App Awareness |
| Proxy Firewall | Very High | Acts as middleman — external party never directly connects to your internal host |
15. Stateless Packet Filtering
Filters each packet individually — no memory of previous packets.
Decision based on:
- Source / Destination IP address
- TCP/UDP source / destination port numbers
- ICMP message type
- TCP SYN / ACK flag bits
ACL (Access Control List) Format
| action | source addr | dest addr | protocol | src port | dst port | flag |
ACL is read top-to-bottom — first matching rule wins (like an if-else chain). Always end with a default
deny all.
Example ACL Rules
| Action | Source | Destination | Protocol | Src Port | Dst Port | Flag |
|---|---|---|---|---|---|---|
| allow | 222.22/16 | outside 222.22 | TCP | >1023 | 80 | any |
| allow | outside 222.22 | 222.22/16 | TCP | 80 | >1023 | ACK |
| allow | 222.22/16 | outside 222.22 | UDP | >1023 | 53 | — |
| allow | outside 222.22 | 222.22/16 | UDP | 53 | >1023 | — |
| deny | all | all | all | all | all | all |
Common Stateless Filtering Policies
| Policy | Rule |
|---|---|
| No outside web access | Drop outgoing packets to any IP, dest port 80 |
| No incoming TCP connections | Drop inbound TCP with ACK=0 (SYN only) — blocks connection initiation from outside |
| Block web radio | Drop all incoming UDP except DNS (port 53) and router broadcasts |
| Anti-Smurf (DoS) | Drop ICMP packets destined to broadcast address |
| Stealth mode | Drop outgoing ICMP TTL-Expired — hides topology from traceroute |
16. Stateful Packet Filtering
Problem with stateless: It admits nonsense packets — e.g., an ACK arriving with no prior SYN (no TCP connection was opened).
Stateful inspection adds:
- Tracks every TCP connection — connection setup (SYN) and teardown (FIN/RST)
- Verifies incoming packets match an established session
- Times out inactive connections → stops admitting their packets
Analogy: Stateless = checking each letter individually. Stateful = remembering who called you first — if someone sends a reply but never called, it's suspicious.
17. Firewall in Practice
Linux iptables (3 Chains)
| Chain | Applies to |
|---|---|
| INPUT | Packets destined to this host |
| FORWARD | Packets passing through (routing between interfaces) |
| OUTPUT | Packets originating from this host |
Each chain has a default policy (ACCEPT or DROP) + ordered rules applied top-to-bottom.
# Example iptables rules:
Chain INPUT (policy ACCEPT):
DROP icmp from 192.178.18.0/24 ← Drop all ICMP from this subnet
DROP tcp from 192.178.18.10 ← Drop all TCP from this specific host
Chain FORWARD (policy ACCEPT):
DROP udp from 192.178.18.10 ← Block UDP in both directions
DROP udp to 192.178.18.10
Chain OUTPUT (policy DROP):
ACCEPT icmp to any ← Allow outgoing ICMP (ping works out)AWS Defence-in-Depth
Internet Gateway → Route Table → Network ACL (subnet level) → Public Subnet → Security Group (instance level) → EC2 Instance
- Misconfiguration in one layer doesn't fully expose the host — two layers must both fail.
18. IDS — Intrusion Detection System
Firewall Limitations (Why IDS is Needed)
| Limitation | Detail |
|---|---|
| Operates on headers only | Cannot see inside encrypted or application data |
| No cross-session correlation | Can't detect patterns spanning multiple flows |
IDS vs Firewall
| Aspect | Firewall | IDS |
|---|---|---|
| Position | At the perimeter — blocks traffic | Inside — monitors and alerts |
| Action | Block / Allow | Detect / Alert / (IPS: also block) |
| Analogy | Door (blocks intruders) | CCTV (watches for suspicious behaviour inside) |
IDS Capabilities
- Deep Packet Inspection (DPI): looks at packet contents — checks against virus/attack signature database
- Anomaly detection: compare traffic against baseline "normal" → detect zero-day attacks
- Signature matching: match patterns against known threat signatures
- Correlation analysis across multiple sessions:
- Port scanning detection
- Network mapping detection
- DoS attack detection
Two Types of IDS
| Type | Scope | Data Sources |
|---|---|---|
| HIDS (Host-based) | Single system | Audit logs, file changes, syslog, kernel logs, SNMP traps |
| NIDS (Network-based) | Network traffic | PCAP (packet capture), port mirroring |
NIDS Component Pipeline
| Component | Role |
|---|---|
| Network Traffic Processing | Convert raw traffic into signature patterns |
| Anomaly Detection | Compare to baseline normal traffic — catches unknown/zero-day |
| Signature Matching | Compare to known threat database |
| Threat Classification | Categorise the threat type |
| Threat Reporting | Log and alert |
| Prevention System | If IPS (Intrusion Prevention): actively block the threat |
IDS Placement Strategy
- Inside internal network: detects insider threats and lateral movement
- In the DMZ: monitors public-facing servers (web, mail, DNS)
- Multiple sensors at different positions = different types of checking coverage