Wireless Network Security and Privacy
Code: TBD · Credits: 4 · Hours: 60 · Type: ELECTIVE
Wireless links — Wi-Fi, cellular, Bluetooth, NFC, LoRa, satellite — carry an outsized share of modern personal traffic, and each carries a distinct attack surface. This elective studies the radio layer, the protocols built on top, and the privacy implications of always-on identifiers.
Key topics
- 802.11 protocol family: WEP, WPA2, WPA3, SAE handshake, PMF.
- Enterprise Wi-Fi: 802.1X, RADIUS, EAP method comparison.
- Bluetooth / BLE security: pairing modes, LE Secure Connections.
- Cellular security across 2G→5G: SIM, USIM, IMSI catchers, 5G authentication (5G-AKA, EAP-AKA').
- Localisation, privacy and MAC randomisation behaviour across OS versions.
- Lower-power wireless: Zigbee, Thread, LoRaWAN, NB-IoT.
- Real-world attacks: KRACK, Dragonblood, BlueBorne, BLESA, Stingray-class devices.
Learning outcomes
By the end of this subject, a student should be able to:
- Configure WPA3-Enterprise correctly on a real AP and explain the handshake.
- Detect rogue access points and IMSI catchers from a host or network perspective.
- Reason about identifier linkability across radio sessions.
- Apply the right pairing and link-layer encryption mode for IoT scenarios.
Further reading
- Mathy Vanhoef's KRACK and Dragonblood papers.
- Wi-Fi Alliance specs (WPA3, WPA-Enterprise).
- 3GPP TS 33.501 (5G security architecture).
- Bishop, Computer Security: Art and Science, chapter on wireless.
Chapter notes
Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.
· min read