At a Glance
 
Central Software
CityVoD - CSC Forum Archive
Software List on CSC Student LAN

Online Tour of the CSC Student Terminal Area
Opening Hours of the CSC
Systems Maintenance Schedule
List of Blocked Network Cards / IP Addresses
List of CSC Representatives
List of Departmental Network Administrators
Staff Computer Courses
Sitemap
 
CSC e-Forms
 
Submit CSC Work Req.
Req. for Printing
Req. for Dump / Restore
Teaching Studio Booking / Cancellation
Apply for a Computer Account
Email Alias Application
Apply for a New Domain Name
Remove an Existing Domain Name
Modify the Hosting of an Existing Domain Name
 
Useful Links
 
網上中文網頁繁簡轉換
CityU Email Services
Computing Dictionary
High-Tech Dictionary
Webopedia
Web Glossary
What is?
 
Home
 
CityU e-Portal
CityU Home
CSC Home
Network Computing Home
 
Got any questions, comments or suggestions? Contact the editors at ccnetcom@cityu.edu.hk
Issue 62 - December 2009
Protecting Your Wireless Communication
By Clevin Wong

In recent years, due to the proliferation of low cost mobile devices like notebook/netbook computers and Wi-Fi phones, more and more people use these devices for communication and Internet access via the wireless networks.

However, wireless networks are insecure by nature. In wireless networks, data transmissions are broadcast over radio waves through the open air. Hence, they are more susceptible to security attacks (e.g. eavesdropping, unauthorized access) than wired networks [1]. Data interception and tampering is easy for anyone with the proper hardware and/or software tools and knowledge.

Therefore, it is important to provide additional measures to protect the communication to ensure the data confidentiality and integrity of your data. Data encryption and user authentication are two of the basic security measures. Data encryption protects the vulnerable wireless link between client devices and access points by encrypting all data in the transmission. User authentication protects against unauthorized access to the wireless network. Currently, there are three common protection methods for wireless networks, namely, WEP, WPA and WPA2.

Wired Equivalent Privacy (WEP)

WEP was introduced in 1997, intended to give wireless networks the equivalent level of privacy protection comparable to that of a traditional wired network. However, due to its imperfect encryption key implementation and lack of authentication, several serious security weaknesses of WEP have been identified and publicly reported since 2001 [2]. Today, with publicly available tools, hackers may intercept and modify the transmissions protected by WEP within minutes. Hence, WEP is regarded as insecure and vulnerable to network attacks. It is only a little better than having no encryption. WEP was deprecated as a wireless privacy mechanism in 2004 though it still is being widely used to-day due to many legacy mobile devices support only WEP.

Wi-Fi Protected Access (WPA)

Owing to the weaknesses of WEP, WPA was introduced in 2003 to address all the known weaknesses of WEP. WPA uses a strong encryption technology called Temporal Key Integrity Protocol (TKIP) to overcome the security weaknesses of WEP. It also bundles with authentication service that WEP does not offer. WPA provides assurance that user data will be protected and that only authorized users may access the wireless networks. Although considered as a secure method, it still has its weaknesses chiefly on the TKIP protocol with weak passwords [8][9].

Wi-Fi Protected Access 2 (WPA2)

WPA2 was introduced in 2004 as the next generation of WPA [4][5]. It is based on the ratified IEEE 802.11i standard. WPA2 is backward compatible with WPA. WPA2 enhances the encryption strength of WPA by replacing the TKIP protocol with the Advanced Encryption Standard (AES) encryption algorithm. AES satisfies the U.S. government security requirements and complies with the Federal Information Processing Standards (FIPS) 140-2 standard. Today, WPA2 is by far the strongest security system available for wireless networks.

Wireless Networks in CityU

The CityU wireless local area network (WLAN) was introduced in 1997 and matured in 2006. Currently two types of connections are supported: (1) Secure connection with data encryption via WPA/WPA2, and (2) Insecure connection without data encryption via web logon. The CSC strongly recommends users to the secure WPA/WPA2 connection for the sake of data protection. The insecure connection should be avoided unless your device does not support WPA/WPA2 and data privacy is unimportant. For details, please refer to the CityU WLAN page [6].

References:

Also in this issue...
Google Analytics: Tells you About your Website Visitors
Implementation of Windows 7: An update
Business Intelligence with Microsoft SQL Server 2008


 

Current & Back Issues
 
 
Search Articles
 
 
Chat with the CIO
 
OCIO Newsletter CIO's Blog Twitter Facebook CityU ICT-Idea Exchange [login required] Subscribe to CIO's Blog
 
FAQs
 
Microsoft Windows Vista
Microsoft Office 2007
中文支援常見問題
Anti-spyware
Internet Explorer 7
General Email Services
Wireless LAN
CityU-Net for Alumni
Virtual Private Network (VPN)
Cascading Style Sheets (CSS)
 
Technical Guides
 
Guideline to Back Up your Computer and Important Files
VPN Connection Setup Guide for Windows XP
VPN Connection Setup Guide for Windows 2000
Student Residence Network Connection Guide
Webmail User 2.0 Guide
 

Copyright© Computing Services Centre, City University of Hong Kong. Best viewed in 1024x768 with IE. Javascript enabled. Last modified on Friday, 13-Jan-12 16:00:27 .