13

Updated 4 Oct 2026

CSS334 — Wireless Networks & Firewalls Cheat Sheet

Exam-ready summary | Lecture 13 | All topics included
⚠️ Final Exam reminder: IP calculation, CIDR, VLSM, configure routing, series questions (design IPs → use to configure routing). 1 A4 sheet allowed.


1. Elements of a Wireless Network

ElementDescriptionExamples
Wireless HostDevice with a wireless adapter — runs applications; may or may not be mobileLaptop, smartphone, IoT device
Base Station (AP)Connected to wired network; relays packets between wired network and wireless hosts802.11 Access Point, Cell Tower
Wireless LinkChannel connecting host to AP; uses multiple access protocol2.4 GHz, 5 GHz, 900 MHz

⚠️ Wireless ≠ Mobile. A desktop with a Wi-Fi card is wireless but not mobile.

Two Connection Modes

ModeHowSupports Handoff?
InfrastructureHosts communicate through an AP → AP connects to wired network✅ Yes
Ad-hocHosts communicate directly with each other — no AP needed❌ No

Analogy: Infrastructure = must go through a convenience store counter to reach the outside world. Ad-hoc = neighbours talking directly to each other.


ChallengeCause
Decreased signal strength (Path Loss)Radio signal attenuates through matter and distance
Interference2.4 GHz band shared by Wi-Fi, Bluetooth, microwaves, motors
Multipath propagationSignal reflects off walls/ground → arrives at different times, causing distortion

Analogy: Radio signal = shouting in a room. Farther away = quieter. Obstacles = damage. Echo = multipath.


3. SNR & BER

Signal-to-Noise Ratio (SNR)

SNR (dB)=Received Signal Power (dBm)−Noise Floor (dBm)\text{SNR (dB)} = \text{Received Signal Power (dBm)} - \text{Noise Floor (dBm)}

  • Larger SNR = better — easier to extract signal from noise
  • Recommended minimums:
    • Data networks: ≥ 20 dB
    • Voice/VoIP: ≥ 25 dB

Bit Error Rate (BER)

BER=Number of bit errorsTotal bits sent\boxed{BER = \frac{\text{Number of bit errors}}{\text{Total bits sent}}}

  • Lower BER = better — fewer corrupted bits

SNR vs BER Tradeoff

SituationEffectAction
Increase TX powerSNR ↑BER ↓ (fewer errors)
Move farther from APSNR ↓BER ↑ (more errors)
High SNR environmentCan use high-order modulationHigher throughput
Low SNR environmentMust use low-order modulationLower throughput, more reliable

Modulation Schemes (Higher modulation = faster but needs better SNR)

ModulationThroughputRequired SNR
BPSK1 MbpsLow
QAM164 MbpsMedium
QAM2568 MbpsHigh

Analogy: Like speaking in a noisy room — if it's too loud, speak slowly and clearly (low modulation). If quiet, speak quickly (QAM256).

Rate Adaptation: AP + device dynamically switch modulation as SNR changes with movement. SNR drops → switch to lower modulation to maintain reliable connection.


4. 802.11 WiFi Standards

StandardYearMax RateRangeFrequency
802.11b199911 Mbps30m2.4 GHz
802.11g200354 Mbps30m2.4 GHz
802.11n (Wi-Fi 4)2009600 Mbps70m2.4 & 5 GHz
802.11ac (Wi-Fi 5)20133.47 Gbps70m5 GHz
802.11ax (Wi-Fi 6)202014 Gbps70m2.4 & 5 GHz
802.11af201435–560 Mbps1 kmUnused TV (54–790 MHz)
802.11ah2017347 Mbps1 km900 MHz (IoT/long range)
  • All standards use CSMA/CA for multiple access
  • All support both infrastructure and ad-hoc modes

5. Frequency Bands: 2.4 GHz vs 5 GHz

Property2.4 GHz5 GHz
Data RateSlowerFaster
Range / CoverageLonger (better wall penetration)Shorter
Channels total1423
Channel overlapOverlapping (only 1, 6, 11 non-overlapping)No overlap
Standards802.11b, g, n, ax802.11a, n, ac, ax
CongestionVery crowded (shared with BT, microwaves)Less crowded

2.4 GHz = slow but far, like FM radio.
5 GHz = fast but short, like Bluetooth.

2.4 GHz Channels (Key Rule)

  • Each channel = 20 MHz wide, spaced 5 MHz apart → heavy overlap
  • Only channels 1, 6, and 11 are truly non-overlapping — always use these for adjacent APs
  • Configure neighbouring APs on different non-overlapping channels to avoid interference

5 GHz Channels

  • More channels available, no overlap between adjacent channels
  • Some channels require DFS (Dynamic Frequency Selection) — must avoid conflict with TDWR (Terminal Doppler Weather Radar) used at airports

6. 802.11 LAN Architecture

  • BSS (Basic Service Set) = one "cell" = one AP + its associated wireless hosts
  • SSID (Service Set Identifier) = the human-readable Wi-Fi network name

Associating with an AP (Host Joining Process)

StepAction
1Scan channels — listen for beacon frames (contain AP's SSID + MAC)
2Select AP to associate with
3Authenticate (if required — password/WPA2)
4Run DHCP to get IP address in AP's subnet

Passive vs Active Scanning

Passive Scanning (Normal)Active Scanning (Hidden SSID)
Step 1APs periodically broadcast beacon framesHost broadcasts Probe Request
Step 2Host selects AP → sends Association RequestAPs send Probe Response
Step 3AP sends Association ResponseHost sends Association Request
Step 4—AP sends Association Response

Passive = sit and listen for who's broadcasting. Active = shout "anyone home?" used when SSID is hidden.


7. 802.11 Frame Addressing (4 MAC Addresses)

| frame ctrl | duration | addr1 | addr2 | addr3 | seq ctrl | addr4 | payload | CRC |
FieldMeaning
Address 1MAC of the receiver (host or AP receiving this frame)
Address 2MAC of the transmitter (host or AP sending this frame)
Address 3MAC of the router interface the AP is attached to
Address 4Used only in ad-hoc mode

Example: H1 → Internet (H1 sends through AP → Router R1)

Frame TypeAddress 1Address 2Address 3
802.11 (Wi-Fi)AP's MACH1's MACR1's MAC
802.3 (Ethernet)R1's MACAP's MAC—

Wi-Fi frame carries 3 MACs because the AP acts as a relay — it needs to know where the frame came from (H1), where it's going next (R1), and who it is itself.


8. CSMA/CA — Collision Avoidance

Why NOT CSMA/CD for Wi-Fi?

  • Cannot detect collisions wirelessly — transmitting signal drowns out received signal (fading)
  • Hidden terminal problem — two hosts can't hear each other but both can hear the AP
  • Solution: avoid collisions instead of detecting them → CSMA/CA

CSMA/CA Sender Algorithm

1. Sense channel:
     Idle for DIFS duration → transmit entire frame (no collision detection)
     Busy → start random backoff timer
       - Timer counts down while channel idle
       - When timer = 0 → transmit
       - If no ACK received → increase backoff interval → repeat

Key Timing Parameters

ParameterFull NamePurpose
DIFSDCF Interframe SpacingRequired idle time before a node may begin transmitting
SIFSShort Interframe SpacingShorter wait used before sending ACK or CTS (priority)

SIFS < DIFS → ACKs and CTS always get priority over new data frames.

Analogy: Polite meeting — wait for the speaker to finish (sense channel) + wait extra time (DIFS), then speak. If two people start simultaneously, both back off randomly.

RTS/CTS: Optional Collision Avoidance Enhancement

Solves the hidden terminal problem:

1. Sender → AP:  RTS (Request to Send) — small control frame via CSMA
2. AP → ALL:     CTS (Clear to Send)   — broadcast, all nodes hear it
3. All nodes hear CTS → defer transmission (virtual carrier sense)
4. Sender transmits full data frame
5. AP → Sender:  ACK

RTS may still collide, but it's tiny → much less wasted bandwidth than full data frame collision.

Analogy: Booking a room — tell the AP you need it, AP announces "Room reserved for A", everyone else waits.


9. 802.11 Mobility & Power Management

Mobility Within Same Subnet

  • Host moves from AP1 to AP2 — same subnet, same IP (no DHCP needed)
  • Switch updates its self-learning table when it sees the host's MAC arrive from a different port
  • Seamless handoff — IP address unchanged

Power Management

  • Node tells AP: "I'm going to sleep until the next beacon frame"
  • AP buffers frames for sleeping node
  • Beacon frame contains a list of mobiles with pending frames
  • Node wakes before beacon → checks list → stays awake if frames waiting, goes back to sleep if none

10. 802.11 Wireless Security

Security Challenges

  • Guest/contractor access needs (separate guest SSID)
  • Mobile/endpoint devices — hard to control
  • Untrusted devices and apps
  • Cloud integration risks

Signal Hiding Techniques

TechniqueEffect
Disable SSID broadcastNetwork not visible in scan list (hidden SSID)
Cryptic/non-default SSIDDoesn't reveal organisation name
Reduce AP signal strengthLimits range — signal doesn't leak outside building
Directional antennasFocus signal toward users, away from outside

WEP vs WPA vs WPA2

PropertyWEPWPAWPA2 ← Use this
EncryptionRC4 (static key)RC4 + TKIP (rotating keys)AES
AuthenticationShared KeyShared Key + 802.1XShared Key + 802.1X
Data IntegrityCRC-32MIC (Message Integrity Code)CBC-MAC
Key ManagementNoneDynamic per-frameDynamic per-frame
Year199920032004
Status❌ Broken (~5 min to crack)⚠️ Fallback only✅ Use this

WPA2 Details

  • Based on IEEE 802.11i standard
  • Two modes:
    • Personal (PSK): Pre-Shared Key — password for home/small office
    • Enterprise: Per-user authentication via EAP (Extensible Authentication Protocol) — requires RADIUS server

Additional Protection

  • Multiple SSIDs — separate guest SSID with client isolation (guests get internet but cannot reach internal LAN — perfect for visitor Wi-Fi)
  • WPA2 + strong password + anti-virus + firewall = layered protection

WEP = easy-copy door key. WPA = key changes every use. WPA2 = military-grade AES encryption.


11. Firewalls

What Is a Firewall?

  • Security system that monitors and controls incoming/outgoing traffic based on predefined rules
  • Placed between internal network and the internet
  • Can be hardware (dedicated appliance) or software (Windows Firewall, iptables)

Why Firewalls?

GoalDetail
Prevent DoS attackse.g., SYN flooding — attacker creates bogus TCP connections, exhausting server resources
Prevent illegal accessBlock unauthorised access to internal data
Allow authorised accessOnly whitelisted traffic enters
Stealth / PrivacyDROP policy = network invisible to port scans (connections time out silently)

Inbound vs Outbound Rules

TypeProtects against
InboundExternal threats — hackers, malware, DoS attacks coming in
OutboundCompromised internal node becoming an attack source going out

12. Firewall Strategies

a) Blacklisting (Default ACCEPT)

  • Default: allow everything
  • Add rules to DROP specific bad traffic
  • Use case: outbound rules (flexibility for users to access internet)

b) Whitelisting (Default DROP)

  • Default: block everything
  • Add rules to ACCEPT only known good traffic
  • Use case: inbound rules (most secure — nothing enters unless explicitly permitted)

Blacklisting = door is open, bouncer has a list of banned people.
Whitelisting = door is locked, only VIP list gets in.


13. Firewall Zones (Network Segmentation)

Group assets by trust level → define inter-zone traffic rules instead of per-IP rules.

ZoneTrust LevelContentsPolicy
Untrusted (WAN/Internet)ZeroPublic internetAssume everything malicious; only filtered traffic in
DMZ (Demilitarised Zone)Low–MediumWeb server, Mail server, DNS, FTPCan talk to internet; cannot initiate to internal
Trusted (LAN/Internal)HighEmployee workstations, internal servers, sensitive dataFull access out; heavily shielded inbound

Inter-Zone Traffic Matrix

From → ToDefault ActionReason
Trusted → UntrustedAllowEmployees browse the internet
Untrusted → TrustedBlockPrevent external attacks reaching internal LAN
Untrusted → DMZAllow (filtered)Public accesses your web server
DMZ → TrustedBlockIf web server is compromised, attacker stays in DMZ

Analogy: DMZ = castle forecourt. Visitors can enter the forecourt (DMZ) but cannot enter the castle (internal LAN).


14. Types of Firewalls (Increasing Security)

TypeSecurity LevelHow It Works
Stateless Packet FilteringBasicInspects each packet independently by IP, port, protocol — no memory of past
Stateful InspectionModerateTracks state of active TCP connections — verifies incoming packets were actually requested
Next-Generation (NGFW)HighAdds deep packet inspection, antivirus, encrypted traffic inspection, Layer 7 App Awareness
Proxy FirewallVery HighActs as middleman — external party never directly connects to your internal host

15. Stateless Packet Filtering

Filters each packet individually — no memory of previous packets.

Decision based on:

  • Source / Destination IP address
  • TCP/UDP source / destination port numbers
  • ICMP message type
  • TCP SYN / ACK flag bits

ACL (Access Control List) Format

| action | source addr | dest addr | protocol | src port | dst port | flag |

ACL is read top-to-bottom — first matching rule wins (like an if-else chain). Always end with a default deny all.

Example ACL Rules

ActionSourceDestinationProtocolSrc PortDst PortFlag
allow222.22/16outside 222.22TCP>102380any
allowoutside 222.22222.22/16TCP80>1023ACK
allow222.22/16outside 222.22UDP>102353—
allowoutside 222.22222.22/16UDP53>1023—
denyallallallallallall

Common Stateless Filtering Policies

PolicyRule
No outside web accessDrop outgoing packets to any IP, dest port 80
No incoming TCP connectionsDrop inbound TCP with ACK=0 (SYN only) — blocks connection initiation from outside
Block web radioDrop all incoming UDP except DNS (port 53) and router broadcasts
Anti-Smurf (DoS)Drop ICMP packets destined to broadcast address
Stealth modeDrop outgoing ICMP TTL-Expired — hides topology from traceroute

16. Stateful Packet Filtering

Problem with stateless: It admits nonsense packets — e.g., an ACK arriving with no prior SYN (no TCP connection was opened).

Stateful inspection adds:

  • Tracks every TCP connection — connection setup (SYN) and teardown (FIN/RST)
  • Verifies incoming packets match an established session
  • Times out inactive connections → stops admitting their packets

Analogy: Stateless = checking each letter individually. Stateful = remembering who called you first — if someone sends a reply but never called, it's suspicious.


17. Firewall in Practice

Linux iptables (3 Chains)

ChainApplies to
INPUTPackets destined to this host
FORWARDPackets passing through (routing between interfaces)
OUTPUTPackets originating from this host

Each chain has a default policy (ACCEPT or DROP) + ordered rules applied top-to-bottom.

# Example iptables rules:
Chain INPUT (policy ACCEPT):
  DROP  icmp  from 192.178.18.0/24   ← Drop all ICMP from this subnet
  DROP  tcp   from 192.178.18.10     ← Drop all TCP from this specific host
 
Chain FORWARD (policy ACCEPT):
  DROP  udp   from 192.178.18.10     ← Block UDP in both directions
  DROP  udp   to   192.178.18.10
 
Chain OUTPUT (policy DROP):
  ACCEPT icmp  to any                ← Allow outgoing ICMP (ping works out)

AWS Defence-in-Depth

Internet Gateway → Route Table → Network ACL (subnet level) → Public Subnet → Security Group (instance level) → EC2 Instance
  • Misconfiguration in one layer doesn't fully expose the host — two layers must both fail.

18. IDS — Intrusion Detection System

Firewall Limitations (Why IDS is Needed)

LimitationDetail
Operates on headers onlyCannot see inside encrypted or application data
No cross-session correlationCan't detect patterns spanning multiple flows

IDS vs Firewall

AspectFirewallIDS
PositionAt the perimeter — blocks trafficInside — monitors and alerts
ActionBlock / AllowDetect / Alert / (IPS: also block)
AnalogyDoor (blocks intruders)CCTV (watches for suspicious behaviour inside)

IDS Capabilities

  • Deep Packet Inspection (DPI): looks at packet contents — checks against virus/attack signature database
  • Anomaly detection: compare traffic against baseline "normal" → detect zero-day attacks
  • Signature matching: match patterns against known threat signatures
  • Correlation analysis across multiple sessions:
    • Port scanning detection
    • Network mapping detection
    • DoS attack detection

Two Types of IDS

TypeScopeData Sources
HIDS (Host-based)Single systemAudit logs, file changes, syslog, kernel logs, SNMP traps
NIDS (Network-based)Network trafficPCAP (packet capture), port mirroring

NIDS Component Pipeline

ComponentRole
Network Traffic ProcessingConvert raw traffic into signature patterns
Anomaly DetectionCompare to baseline normal traffic — catches unknown/zero-day
Signature MatchingCompare to known threat database
Threat ClassificationCategorise the threat type
Threat ReportingLog and alert
Prevention SystemIf IPS (Intrusion Prevention): actively block the threat

IDS Placement Strategy

  • Inside internal network: detects insider threats and lateral movement
  • In the DMZ: monitors public-facing servers (web, mail, DNS)
  • Multiple sensors at different positions = different types of checking coverage