Table 7.2 Security issues in packet switched networks [13].
Security Issue Type
Security Issue Description
Based on attack type
De‐authentication
The intruder endeavors to defeat the authorization mechanism in Wireless
LANs. With this, the intruder steals the legitimate wireless users’ identities.
In addition, the intruder tries to gain the control of authorized wireless
access points’ deployment rights and deploy rogue access points without
going through the security process and review.
The possible security issues that fall into this category are:
i) MAC spoofing: the intruder bypasses the MAC filtering policies
through the modification of the MAC address of a wireless client;
ii) IP spoofing: the intruder can evade the IP address‐based
authentication by pretending to be a legitimate user by altering the
source IP address of the end‐user;
iii) Rogue access points: The intruder can gain open access to the WLAN
by deploying an unauthorized wireless access point
Eavesdropping and
interception in
wireless domain
The intruder can eavesdrop/intercept the legitimate wireless traffic flows
by compromising the legitimate users’ radio access channel. From this,
he can gain access to all the information transmitted by the end user.
Security attacks that comes under this category are:
i) Network Traffic eavesdropping: the intruder makes use of the
network sniffer to eavesdrop the network traffic in the
whole Wireless LAN;
ii) Man‐in‐the‐middle attacks: the intruder tries to obtain, intercept,
modify and impersonate the end‐to‐end communication between
source and destination, who believe they have a secure channel by
monitoring in the middle of the two‐way communications;
iii) Network injection: the intruder injects fake network traffic into
legitimate user traffic and makes an attempt to achieve malicious goals;
iv) Session hijacking: the intruder will steal a legitimate authenticated
conversation session ID and control the whole session of specific
traffic flow between source and destination
Traffic jamming
The intruder attacks by heavily consuming the bandwidth of the WLAN
to drown the legitimate traffic, by flooding with fake messages or through
high radio frequency signals. Attacks that comes under this category are:
i) Denial of Service (DoS) attacks: the intruder interrupts the legitimate
user traffic to reach the receiver, by flooding with high frequency
radio signals or fake messages;
ii) Spam attacks: the intruder will launch spam attacks by flooding with
spam messages over the wireless communication channels
Brute force attack to
gain the control over
Access Point (AP)
passwords
The intruder brute forces dictionary attacks to compromise the single
shared password (in point‐to‐point (P2P) communication) of an access
point by testing every possible password
Attack against
security protocols
The intruder targets the information stored in the 5G communication
system and causes damage by altering or inserting and/or deleting the
data stored in the system
Attacks based on
messages
The intruder compromises the vulnerabilities of existing Wired Equivalent
Privacy (WEP) and WiFi Protected Access (WPA) security protocols
Misconfiguration
The intruder exploits the limited security knowledge of the WLAN
administrator, human misconfiguration, or improper operations to gain
control of the access point
Security Issue Type
Security Issue Description
Based on attack type
De‐authentication
The intruder endeavors to defeat the authorization mechanism in Wireless
LANs. With this, the intruder steals the legitimate wireless users’ identities.
In addition, the intruder tries to gain the control of authorized wireless
access points’ deployment rights and deploy rogue access points without
going through the security process and review.
The possible security issues that fall into this category are:
i) MAC spoofing: the intruder bypasses the MAC filtering policies
through the modification of the MAC address of a wireless client;
ii) IP spoofing: the intruder can evade the IP address‐based
authentication by pretending to be a legitimate user by altering the
source IP address of the end‐user;
iii) Rogue access points: The intruder can gain open access to the WLAN
by deploying an unauthorized wireless access point
Eavesdropping and
interception in
wireless domain
The intruder can eavesdrop/intercept the legitimate wireless traffic flows
by compromising the legitimate users’ radio access channel. From this,
he can gain access to all the information transmitted by the end user.
Security attacks that comes under this category are:
i) Network Traffic eavesdropping: the intruder makes use of the
network sniffer to eavesdrop the network traffic in the
whole Wireless LAN;
ii) Man‐in‐the‐middle attacks: the intruder tries to obtain, intercept,
modify and impersonate the end‐to‐end communication between
source and destination, who believe they have a secure channel by
monitoring in the middle of the two‐way communications;
iii) Network injection: the intruder injects fake network traffic into
legitimate user traffic and makes an attempt to achieve malicious goals;
iv) Session hijacking: the intruder will steal a legitimate authenticated
conversation session ID and control the whole session of specific
traffic flow between source and destination
Traffic jamming
The intruder attacks by heavily consuming the bandwidth of the WLAN
to drown the legitimate traffic, by flooding with fake messages or through
high radio frequency signals. Attacks that comes under this category are:
i) Denial of Service (DoS) attacks: the intruder interrupts the legitimate
user traffic to reach the receiver, by flooding with high frequency
radio signals or fake messages;
ii) Spam attacks: the intruder will launch spam attacks by flooding with
spam messages over the wireless communication channels
Brute force attack to
gain the control over
Access Point (AP)
passwords
The intruder brute forces dictionary attacks to compromise the single
shared password (in point‐to‐point (P2P) communication) of an access
point by testing every possible password
Attack against
security protocols
The intruder targets the information stored in the 5G communication
system and causes damage by altering or inserting and/or deleting the
data stored in the system
Attacks based on
messages
The intruder compromises the vulnerabilities of existing Wired Equivalent
Privacy (WEP) and WiFi Protected Access (WPA) security protocols
Misconfiguration
The intruder exploits the limited security knowledge of the WLAN
administrator, human misconfiguration, or improper operations to gain
control of the access point
