Skip to main content

Wireless Network Security and Privacy

Code: TBD · Credits: 4 · Hours: 60 · Type: ELECTIVE

Wireless links — Wi-Fi, cellular, Bluetooth, NFC, LoRa, satellite — carry an outsized share of modern personal traffic, and each carries a distinct attack surface. This elective studies the radio layer, the protocols built on top, and the privacy implications of always-on identifiers.

Key topics

  • 802.11 protocol family: WEP, WPA2, WPA3, SAE handshake, PMF.
  • Enterprise Wi-Fi: 802.1X, RADIUS, EAP method comparison.
  • Bluetooth / BLE security: pairing modes, LE Secure Connections.
  • Cellular security across 2G→5G: SIM, USIM, IMSI catchers, 5G authentication (5G-AKA, EAP-AKA').
  • Localisation, privacy and MAC randomisation behaviour across OS versions.
  • Lower-power wireless: Zigbee, Thread, LoRaWAN, NB-IoT.
  • Real-world attacks: KRACK, Dragonblood, BlueBorne, BLESA, Stingray-class devices.

Learning outcomes

By the end of this subject, a student should be able to:

  • Configure WPA3-Enterprise correctly on a real AP and explain the handshake.
  • Detect rogue access points and IMSI catchers from a host or network perspective.
  • Reason about identifier linkability across radio sessions.
  • Apply the right pairing and link-layer encryption mode for IoT scenarios.

Further reading

  • Mathy Vanhoef's KRACK and Dragonblood papers.
  • Wi-Fi Alliance specs (WPA3, WPA-Enterprise).
  • 3GPP TS 33.501 (5G security architecture).
  • Bishop, Computer Security: Art and Science, chapter on wireless.

Chapter notes

Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.

· min read