Saturday, February 9, 2008

PHISHING

1. Phishing:

Phishing is a form of social engineering practice done by cyber criminals for gaining access into bank accounts by stealing sensitive information.
Customers of leading banks, through out the world have been a target of phishing


1.1 Definition:
Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft.


1.2 History of phishing:
The word “phishing” originally comes from the analogy that early Internet criminals used email lures to “phish” for passwords and financial data from a sea of Internet users. The use of “ph” in the terminology is partly lost in the annals of time, but most likely linked to popular hacker naming conventions such as “Phreaks” which traces back to early hackers who were involved in “phreaking” – the hacking of telephone systems.

The term was coined in the 1996 timeframe by hackers who were stealing America Online (AOL) accounts by scamming passwords from unsuspecting AOL users. The popularized first mention on the Internet of phishing was made in alt.2600 hacker newsgroup in January 1996

2. Phishing Threat:
The use of the phishing medium as a money laundering tool appears to be emerging, where volumes of compromised user data is sold to crime groups who aggregate the stolen funds into centralized false accounts by a principal organizer or “dump leader”. The use of false employment websites, encouraging users to sign up and provide their banking facilities to forward money to other accounts for a 20% administration fee has also been revealed


2.1 Social Engineering Factors:
Phishing attacks rely upon a mix of technical deceit and social engineering practices. In the majority of cases the Phisher must persuade the victim to intentionally perform a series of actions that will provide access to confidential information.Communication channels such as email, web-pages, IRC and instant messaging services are popular. In all cases the Phisher must impersonate a trusted source (e.g. the helpdesk of their bank, automated support response from their favorite online retailer, etc.) for the victim to believe

To date, the most successful Phishing attacks have been initiated by email – where the Phisher impersonates the sending authority (e.g. spoofing the source email address and embedding appropriate corporate logos). For example, the victim receives an email supposedly from support@mybank.com (address is spoofed) with the subject line 'security update’, requesting them to follow the URL www.mybank-validate.info (a domain name that belongs to the attacker – not the bank) and provide their banking PIN number


3. Phishing Message delivery:

3.1 Email and spam:
Phishing attacks initiated by email are the most common. Using techniques and tools used by Spammers, Phishers can deliver specially crafted emails to millions of legitimate “live” email addresses within a few hours (or minutes using distributed Trojan networks). In many cases, the lists of addresses used to deliver the phishing emails are purchased from the same sources as conventional spam


3.2 Web based delivery:
An increasingly popular method of conducting phishing attacks is through malicious web-site content. This content may be included within a web-site operated by the Phisher, or a third-party site hosting some embedded content.

3.3 Fake Banner Advertising:
Banner advertising is a very simple method Phishers may use to redirect an organisations customer to a fake web-site and capture confidential information. Using copied banner advertising, and placing it on popular websites, all which is necessary is some simple URL obfuscation techniques to obscure the final destination.

3.4 Trojaned Hosts:
While the delivery medium for the phishing attack may be varied, the delivery source is increasingly becoming home PC’s that have been previously compromised. As part of this compromise, a Trojan horse program has been installed which allows Phishers (along with Spammers, Warez Pirates, DDoS Bots, etc.) to use the PC as a message propagator. Consequently, tracking back a Phishing attack to an individual initiating criminal is extremely difficult.
4 Phishing attack techniques:
4.1 Man-in-the-middle Attacks
One of the most successful vectors for gaining control of customer information and resources is through man-in-the-middle attacks. In this class of attack, the attacker situates themselves between the customer and the real web-based application, and proxies all communications between the systems. From this vantage point, the attacker can observe and record all transactions.
4.2 URL Obfuscation Attacks:
The secret for many phishing attacks is to get the message recipient to follow a hyperlink (URL) to the attacker’s server, without them realizing that they have been duped. Unfortunately phishers have access to an increasingly large arsenal of methods for obfuscating the final destination of the customer’s web request.
4.3 Cross-site Scripting Attacks:
Cross-site scripting attacks (commonly referred to as CSS or XSS) make use of custom URL or code injection into a valid web-based application URL or imbedded data field. In general, these CSS techniques are the result of poor web-application development processes.

4.4 Preset Session Attack:

In this class of attack the phishing message contains a web link to the real application server, but also contains a predefined SessionID field. The attackers system constantly polls the application server for a restricted page using the preset SessionID. Until a valid user authenticates against this SessionID, the attacker will receive errors from the web-application server .

4.5 Hidden Attacks:
Extending beyond the obfuscation techniques discussed earlier, an attacker may make use of HTML, DHTML and other scriptable code that can be interpreted by the customers web browser and used to manipulate the display of the rendered information. In many instances the attacker will use these techniques to disguise fake content as coming from the real site – whether this is a man-in-the-middle attack, or a fake copy of the site hosted on the attackers own systems.


5 Defence Mechanisms:

5.1 Client-side:

The client-side should be seen as representing the forefront of anti-phishing security. Given the distributed nature of home computing and the widely varying state of customer skill levels and awareness, client-side security is generally much poorer than a managed corporate workstation deployment. However, many solutions exist for use within both the home and corporate environments.

5.2 Server-side:

By implementing intelligent anti-phishing techniques into the organisations web application security, developing internal processes to combat phishing vectors and educating customers – it is possible to take an active role in protecting customers from future attack. By carrying out this work from the server-side, organisations can take large steps in helping to protect against what is invariably a complex and insidious threat.At the client-side, protection against Phishing can be afforded by:
Using strong token-based authentication systems
Keeping naming systems simple and understandable




5.3 Enterprise Level:

Businesses and ISP’s may take enterprise-level steps to secure against Phishing scams – thereby protecting both their customers and internal users. These enterprise security solutions work in combination with client-side and server-side security mechanisms, offering considerable defence-in-depth against phishing and a multitude of other current threats.

Key steps to anti-phishing enterprise-level security include:
Automatic validation of sending email server addresses,
Digital signing of email services,
Monitoring of corporate domains and notification of “similar” registrations,
Perimeter or gateway protection agents,
Third-party managed services
CONCLUSION:
Phishing started off being part of popular hacking culture. Now, as more organisations provide greater online access for their customers, professional criminals are successfully using phishing techniques to steal personal finances and conduct identity theft at a global level. By applying a multi-tiered approach to their security model (client-side, server-side and enterprise) organisations can easily manage their protection technologies against today’s and tomorrows threats – without relying upon proposed improvements in communication security that are unlikely to be adopted globally for many years to come.

BIBLIOGRAPHY:
Cyveillance the brand monitoring network www.cyveillance.com
The Open Web Application Security Project www.owasp.org/images/a/ad/Phishing-a_new_age_weapon
Wikipedia, the free encyclopedia www.wikipedia.org
4. The phishing Guide www.ngssoftware.com

BLUETOOTH TECHNOLOGY in WIRELESS COMMUNICATION

ABSTRACT:-

Today, electronics that connect to one another are found everywhere--in the office, home, Car, etc. Keyboards connect to computers, MP3 players to headphones and so on. So, how do these devices connect to each other? Usually the answer is: with wires and cables. But, as you know, wires and cables always result in a tangled mess.

Bluetooth wireless technology eliminates many of the wires that clutter our offices, homes, etc., while allowing our electronic devices of today and tomorrow to with one communicate another .Bluetooth technology has been around for years, however for many people it is just another “tech” term.

Bluetooth technology is how mobile phones, computers, and personal digital assistants (PDAs), not to mention a broad selection of other devices, can be easily interconnected using a short-range wireless connection. Using this technology, users can have all mobile and fixed computer devices be totally coordinated.

This presentation explains the present scenario of using wireless technology for transmission of data .This includes working of Bluetooth wireless technology, protocols used, profiles and specifications needed for transmission,security provision and includes some of the devices using bluetooth.









INTRODUCTION


Today, electronics that connect to one another are found everywhere--in the office, home car, etc. keyboards connect to computers, MP3 players to headphones and so on. So, how do these devices connect to each other? Usually the answer is: with wires and cables. But, as you know, wires and cables always result in a tangled mess
Bluetooth wireless technology eliminates many of the wires that clutter our offices, homes, etc., while allowing our electronic devices of today and tomorrow to with one communicate another .Bluetooth technology has been around for years, however for many people it is just another “tech” term.
Most people have little or no understanding of the technology and have very little knowledge of its applications. However, you hear and read about it everywhere--in ads for computers, cell phones, PDAs and all types of different devices enabled with Bluetooth technology.
What is Bluetooth wireless technology?
Bluetooth technology is how mobile phones, computers, and personal digital assistants (PDAs), not to mention a broad selection of other devices, can be easily interconnected using a short-range wireless connection. Using this technology, users can have all mobile and fixed computer devices be totally coordinated.
Bluetooth wireless technology is a short-range radio technology. Bluetooth wireless technology makes it possible to transmit signals over short distances between telephones, computers and other devices and thereby simplify communication and synchronization between devices. Generally, Bluetooth has a range of up to 30 ft. or greater, depending on the bluetooth core specification version. Newer devices, using newer versions of Bluetooth, have ranges over 100 ft.
It is a global standard that:
· eliminates wires and cables between both stationary and mobile devices;
· facilitates both data and voice communication;
· offers the possibility of ad hoc networks and delivers the ultimate synchronicity between all your personal devices.
Bluetooth technology is actually derived from a combination of wireless technologies. The Bluetooth specification unites these technologies under the title: "Bluetooth technology". Bluetooth radio uses a fast acknowledgement and frequency-hopping scheme to make the link robust, even in noisy radio environments. Due to the fact that Bluetooth technology is a standardized wireless technology, you can rest assure it will be around for many years to come.

HISTORY :
The Bluetooth SIG:
The name “Bluetooth” and its logo are trademarked by the privately held trade association named the Bluetooth Special Interest Group (SIG).
Founded in September 1998, the Bluetooth SIG is a unification of leaders in the telecommunications, computing, network, industrial automation, and Automotive industries. Today, the Bluetooth SIG is responsible for encouraging and supporting research and development in Bluetooth technology.
The Bluetooth SIG includes promoter member companies Microsoft, Ericsson, IBM, Intel, Agere, Motorola, Nokia, and Toshiba, plus thousands of Associate and Adopter member companies .
· Why is It Called Bluetooth?
The developers of this wireless technology first used the name "Bluetooth" as a code name, but as time past, the name stuck.
The word "Bluetooth" is taken from the 10th century Danish King Harald Bluetooth. King Bluetooth had been influential in uniting Scandinavian Europe during an era when the region was torn apart by wars and feuding clans.
The founders of the Bluetooth SIG felt the name was fitting because: 1) Bluetooth technology was first developed in Scandinavia, and 2) Bluetooth technology is able to unite differing industries such as the cell phone, computing, and automotive markets. Bluetooth wireless technology simplifies and combines multiple forms of wireless communication into a single, secure, low-power, low-cost, globally available radio frequency.
· Where Did the Logo Come From?
A Scandinavian firm originally designed the logo at the time the SIG was formally introduced to the public. Keeping to the same origin as the Bluetooth name, the logo unites the Runic alphabetic characters "H", which looks similar to an asterisk, and a "B", which are the initials for Harald Bluetooth. If you look close enough you can see both embodied in the logo.
How Bluetooth Works?
In order to understand how Bluetooth technology works, we must first take a look at how electronic devices (Bluetooth or not) connect and communicate with one another.
There are several questions that need to be addressed before any two devices can communicate with one another.
Q: Will the devices communicate via wires or through the air?
A: Obviously, if the devices are using Bluetooth technology, they will communicate without wires. However, if the devices are not Bluetooth enabled, then they have the option of communicating either with or without wires. Devices can take advantage of several wireless technologies (Bluetooth included) by using various transmitters to send information over the airwaves.

Q: How will messages or information be sent between the two devices?
A: Information can be sent one bit at a time in a scheme called serial communications, or in groups of bits (usually 8 or 16 at a time) in a scheme called parallel communications.
Q: How will devices in this “electronic conversation” know what the information (bits or groups of bits) means? How will they know if they received the same message that was sent?

A: Most of the time these questions are answered by the creation of what is known as a protocol. A protocol is a standard that controls or enables the connection, communication, and data transfer between two electrical devices. Basically, a protocol is the "language" of devices.With so many different types of electronics available, it is probably no surprise that there are tons of established protocols. However, almost all protocols address one or more of the following:
* Detecting the presence of other devices* Establishing communications guidelines between two devices (AKA: Handshaking)* Determining the various connection characteristics* How to format a message* How to start and end a message* What to do with corrupted or incorrectly formatted messages* How to recognize unexpected connection loss, and what to do next* Ending the connection or “conversation”

Bluetooth: Low Power and Low Cost!
Bluetooth wireless technology operates on an open frequency within the 2.4 gigahertz band, which is the same as WiFi, cordless phones and various other wireless devices. Bluetooth is able to share the same frequency band without experiencing any interference because it utilizes various key technologies.
One of the ways Bluetooth avoids interference is through the use of low power signals (around one milliwatt). Devices using the Bluetooth Core Specification Version 1.1 or later are able to avoid interference with other wireless devices because their signal is so weak. Take into consideration that powerful cell phones use a signal of around three watts. Even though the signal is weaker, Bluetooth still offers a range of up to 30 feet (Newe versions can have a range over 100 feet).
The signal is also capable of passing through the walls in your home, making it useful for controlling several devices in different rooms. Data can be transferred at a rate of up to one Megabyte per second (Mbps).
Also, because Bluetooth transmitters require minimal amounts of power, they are relatively inexpensive to manufacture. Simply put, Bluetooth uses low-power radio waves to reliably communicate in an inexpensive way.
“Hopping” = No Interference
Another way Bluetooth devices are able to avoid interference is through a technique known as spread-spectrum frequency hopping. By using the “hopping” method, a device will use one of 79 different, randomly chosen frequencies within an assigned range, and will frequently change frequencies from one to another.
Bluetooth enabled devices, which all use the “hopping” method, change frequencies 1,600 times per second. As a result, more devices can use a portion of the radio spectrum.The risk of a device like a cell phone or baby monitor interfering with Bluetooth devices is minimized, since any interference on a specific frequency will last for only a fraction of a second.Bluetooth version 2.0 + EDR, the very latest of the Bluetooth specification versions, uses an enhanced technology called: Adaptive Frequency Hopping (AFH).
AFH allows Bluetooth devices to measure the quality of the wireless signal and then determine if there are bad channels present on specific frequencies due to interference from other wireless devices.If bad channels are present on a specific frequency, the Bluetooth device will adjust its hopping sequence to avoid them. As a result, the Bluetooth connection is stronger, faster, and more reliable.
Bluetooth Profiles: How Bluetooth is Used
Bluetooth enabled devices must use and understand certain Bluetooth "profiles" in order to use Bluetooth technology to connect to one another. These profiles define the possible applications that a Bluetooth enabled device can support.In order for one Bluetooth device to connect to another, both devices must share at least one of the same Bluetooth profiles.




.
Bluetooth Pairing
If you are familiar with Bluetooth wireless technology, you'll probably recognize the term "Bluetooth pairing". But do you actually know what Bluetooth pairing means?
Bluetooth pairing occurs when two Bluetooth devices agree to communicate with each other and establish a connection.In order to pair two Bluetooth wireless devices, a password (passkey) has to be exchanged between the two devices. A Passkey is a code shared by both Bluetooth devices, which proves that both users have agreed to pair with each other.
This is the normal process that occurs with Bluetooth pairing:
Bluetooth device A looks for other Bluetooth devices in the area
In order to find other Bluetooth devices, Bluetooth device A must be set to discoverable mode. When set to discoverable, Bluetooth device A will allow other Bluetooth devices to detect its presence and attempt to establish a connection.
.
Bluetooth device A finds Bluetooth device B
Usually the discoverable device will indicate what type of device it is (Such as a printer, cell phone, headset, etc.) and its Bluetooth device name. The Bluetooth device name is the name that you give the Bluetooth device or the factory name that originally was programmed.


Bluetooth Device A prompts you to enter a password (PassKey)
With advanced devices, both users must agree on the Passkey and enter it into their device. The code can be anything you like as long as it is the same for both Bluetooth wireless devices.On other devices, such as Bluetooth headsets, the Passkey stays the same. Refer to the product’s manual for the default passkey. Most often , the passkey is zero.
Bluetooth device A sends the Passkey to Bluetooth device B


Bluetooth device B sends the Passkey back to Bluetooth device A
If both Passkeys are the same, a trusted pair is formed. This will happen automatically.
Bluetooth device A and B are now paired and able to exchange data


Bluetooth technology must be examined in two separate sections in order for you to understand the entire process of how the technology works and how it is used.
* The Bluetooth protocol defines how the wireless technology works, and
* The Bluetooth Profiles describe and organize how the technology is used.
Protocol:
Overview of the Bluetooth Protocol
The Bluetooth standard requires a basic level of communication between devices, so that they can connect to each other over the airwaves, at the correct frequencies, using the correct channels, and finding the correct destination(s). In order to create this basic level of communication, a specific protocol was created. The Bluetooth protocol establishes the set of rules by which all Bluetooth devices must abide in order to establish a connection to communicate with one another.
Protocol stack
Most protocols, Bluetooth’s included, are usually layered together into “protocol stacks”, and the various tasks are split up and assigned to the different layers of protocols in the stack.




Bluetooth Protocol Architecture
Bluetooth Protocol Stack
Here is an outline of the different levels in the Bluetooth protocol stack:
Radio Layer
When looking at the different layers of the Bluetooth protocol stack, you will always find the raio layer first. Everything in Bluetooth runs over the Radio Layer, which defines the requirements for a Bluetooth radio transceiver, which operates in the 2.4GHz band. The radio layer defines the sensitivity levels of the transceiver, establishes the requirements for using Spread-spectrum Frequency Hopping and classifies Bluetooth devices into three different power classes:
* Power Class 1 – long rang devices (100m),
* Power Class 2 – normal or standard range devices (10m), and
* Power Class 3 – short (10cm)-range operation
Baseband Layer
The next “floor” in the Bluetooth protocol stack is the Baseband Layer, which is the physical layer of the Bluetooth. It is used as a link controller, which works with the link manager to carry out routines like creating link connections with other devices. It controls device addressing, channel control (how devices find each other) through paging and inquiry methods, power-saving operations, and also flow control and synchronization among Bluetooth devices.
Link Manager Protocol (LMP)
A Bluetooth device’s Link Manager Protocol (LM) carries out link setup, authentication, link configuration and other protocols. It discovers other LMs within the area and communicates with them via the Link Manager Protocol (LMP).
Host Controller Interface (HCI)
Next in the protocol stack, above the LMP is the Host Controller Interface (HCI), which is there to allow command line access to the Baseband Layer and LMP for control and to receive status information. It’s made up of three parts: 1) The HCI firmware, which is part of the actual Bluetooth hardware, 2) The HCI driver, which is found in the software of the Bluetooth device, and 3) The Host Controller Transport Layer, which connects the firmware to the driver.
Logical Link Control and Adaptation Protocol (L2CAP)
Above the HCI level is the Logical Link Control and Adaptation Protocol (L2CAP), which provides data services to the upper level host protocols. The L2CAP plugs into the Baseband Layer and is located in the data link layer, rather than riding directly over LMP. It provides connection-oriented and connectionless data services to upper layer protocols.
RFCOMM
Above L2CAP, the RFCOMM protocol is what actually makes upper layer protocols think they’re communicating over a RS232 wired serial interface, so there’s no need for applications to know anything about Bluetooth.
Service Discovery Protocol (SDP)
Also relying on L2CAP is the Service Discovery Protocol (SDP). The SDP provides a way for applications to detect which services are available and to determine the characteristics of those services.




Bluetooth Profiles

Overview of Bluetooth Profiles
The Bluetooth SIG states, "Bluetooth profiles are general behaviors through which Bluetooth enabled devices communicate with other devices."
In order to connect to one another, devices that use Bluetooth technology must support and understand certain Bluetooth profiles. Bluetooth profiles define the possible applications and describe how Bluetooth technology is to be used for each specific device.
For example, the File Transfer profile is used to define how devices like a PDA will use Bluetooth Technology to transfer files to other devices like another PDA, cell phone, or computer.When a Bluetooth device is developed, the manufacturer assigns (In accordance with the Bluetooth SIG's requirements) specific Bluetooth profiles for that device to use in order to establish applications which will work with other Bluetooth devices.
In order for one Bluetooth device to connect to another, both devices must share at least one of the same Bluetooth profiles.
For example, if you want to use a Bluetooth headset with your Bluetooth enabled cell phone, both devices must use the Headset (HS) profile (Defines how headsets and cell phones use Bluetooth technology to connect to one another).
According to the Bluetooth SIG: At minimum, every Bluetooth profile includes information on the following issues:
* Dependencies on other profiles. * Recommended user interface formats. * Particular parts of the Bluetooth protocol stack used by the profile. To perform its functions, each profile uses particular options and parameters at each layer of the stack.


An Example of Bluetooth in Action
The Wireless Office
Imagine a modern day office with various hi-tech, yet common electronic devices.
The first thing an office should have are the basic essentials: a computer, keyboard, mouse, printer and phone. Next, lets say there is a Headset that works with the phone.
Now that we have all the basics, lets make this office a little more exciting by adding some fun "toys", like a PDA, digital camera and MP3 player.
By now you should have a pretty good picture of the office and the various devices in it.
Every device is connected, or is capable of being connected to at least one other device. For example, the keyboard and mouse have to connect to the computer and the PDA has the option to connect to the computer.
Just imagine if all these devices used cables to connect to one another. The office would have cables running everywhere and we'd be left with a big, tangled mess.
Now imagine all of these devices use Bluetooth technology to connect to one another instead. The result: no more cables and no more mess.
Suppose the Bluetooth enabled printer comes with a Bluetooth Computer Adapter that plugs into the computer's universal serial bus (USB) port. The company that manufactured the printer and computer adapter programmed each device with the same Bluetooth profiles.
Bluetooth profiles are used by devices to instruct them on how to use the Bluetooth technology
After the printer is turned on, it transmits a signal, which looks for a response from other Bluetooth enabled devices with the same profile(s). Since the USB adapter shares the same profile(s), it responds and a small network (AKA: Piconet) is created.
Since this piconet is established between devices with the same specific profiles, the signals sent by other devices with different profiles, like the headset, will be ignored. All the other Bluetooth devices in the room establish similar piconets that are all separated from one another based on the specific profile(s) they use.


Bluetooth Security
Bluetooth Technology Faces Security Threats
Today, all communication technologies are facing the issue of privacy and identity theft. Bluetooth technology is no exception. The information and data we share through these communication technologies is both private and in many cases, critically important to us.
Everyone knows that email services, company networks, and home networks all require security measures. What Bluetooth users need to realize, is: Bluetooth requires similar security measures.

The Bluetooth SIG Focuses on Security
The Bluetooth SIG is constantly improving formats for combating security threats associated with Bluetooth technology. Offering a secure method to wirelessly communicate has always been one of the key benefits of Bluetooth technology
In order to lead the security effort, a group of engineers within the Bluetooth SIG formed the Bluetooth Security Experts Group. As the Bluetooth Core Specification Versions continue to advance, the Bluetooth Security Experts Group is responsible for monitoring the advancement and testing for flaws in its security.
The Fundamentals of Bluetooth Security
One of the most basic levels of security for Bluetooth devices is the “pairing” process.
Pairing = Two or more Bluetooth devices recognize each other by the Bluetooth Profiles they share, and in most cases, both must enter the same PIN.
The Bluetooth core specifications use an encryption algorithm, which is entirely secure. Once Bluetooth devices pair with one another, they too are entirely secure.
.


How Developers Can Provide Security Companies who develop Bluetooth enabled products have multiple options in order to provide security. There are three security modes for connecting two Bluetooth devices: 1.Security Mode 1: non-secure 2. Security Mode 2: service level enforced security 3. Security Mode 3: link level enforced security It is the company who develops each specific Bluetooth product that decides which security modes to use. Also, the devices and services have different security levels as well.


What is Bluejacking?
Bluejacking allows phone users to send business cards anonymously to one another using Bluetooth technology. Bluejacking does NOT involve any altercations to your phone's data. These business cards usually consist of some clever message or joke. Bluejackers are simply looking for a reaction from the recipient. To ignore bluejackers, simply reject the business card, or if you want to avoid them entirely, set your phone to non-discoverable mode
What is Bluesnarfing?
Bluesnarfing refers to a hacker who has gained access to data, which is stored on a Bluetooth enabled phone. Bluesnarfing allows the hacker to make phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations, and connect to the Internet. The good news is, bluesnarfing requires advanced equipment and expertise or requires the hacker to be within a 30 ft. range. If your phone is in non-discoverable mode, it becomes significantly more difficult for hackers to bluesnarf your phone. According to the Bluetooth SIG, only some older Bluetooth enabled phones are vunerable to bluesnarfing.
What is Bluebugging?
Bluebugging refers to a skilled hacker who has accessed a cell phone's commands using Bluetooth technology without the owner's permission or knowledge. Bluebugging allows the hacker to make phone calls, send messages, read and write contacts and calendar events, eavesdrop on phone conversations, and connect to the Internet. Just like all Bluetooth attacks, the hacker must be within a 30 ft. range. Bluebugging and bluesnarfing are separate security issues, and phones that are vulnerable to one are not necessarily vulnerable to the other.




Bluetooth Specifications
Here Are a Few Specifications From the Bluetooth SIG (Special Interest Group):
Bluetooth devices in a piconet share a common communication data channel. The channel has a total capacity of 1 megabit per second (Mbps). Headers and handshaking information consume about 20 percent of this capacity.
In the United States and Europe, the frequency range is 2,400 to 2,483.5 MHz, with 79 1-MHz radio frequency (RF) channels. In practice, the range is 2,402 MHz to 2,480 MHz. In Japan, the frequency range is 2,472 to 2,497 MHz with 23 1-MHz RF channels.
A data channel hops randomly 1,600 times per second between the 79 (or 23) RF channels.
Each channel is divided into time slots 625 microseconds long.
A piconet has a master and up to seven slaves. The master transmits in even time slots, slaves in odd time slots.
Packets can be up to five time slots wide.
Data in a packet can be up to 2,745 bits in length.
There are currently two types of data transfer between devices: SCO (synchronous connection oriented) and ACL (asynchronous connectionless).
In a piconet, there can be up to three SCO links of 64,000 bits per second each. To avoid timing and collision problems, the SCO links use reserved slots set up by the master.
Masters can support up to three SCO links with one, two or three slaves.
Slots not reserved for SCO links can be used for ACL links.
One master and slave can have a single ACL link.
ACL is either point-to-point (master to one slave) or broadcast to all the slaves. ACL slaves can only transmit when requested by the master.



The Advantages of Bluetooth
Main Reasons to Use a Bluetooth Device:
1. Bluetooth Devices are Wireless.
2. Bluetooth Technology is Inexpensive.
3. Bluetooth is Automatic.
4. Standardized Protocol = Interoperability
5. Low Interference
6. Low Energy Consumption
7. Share Voice and Data
8. Instant Personal Area Network (PAN)
9. Upgradeable



Some of the devices using Bluetooth technology are

1.wireless audio devices
2.bluetooth car where the drivers can restricted to use their cell phones while driving.
3.cell phones using Bluetooth technology
4.bluetooth computer adapters and receivers
5.bluetooth gps receivers
6.bluetooth head sets

Conclusion:
In the future Bluetooth is likely to be standard in tens of millions of mobile phones, PCs laptops and a whole range of other electronic devices. As a result, the market is going to demand new innovative applications. Value-added services, end – to – end solutions, and much more. The possibilities opened up really are limitless and because the radio frequency used is globally available, Bluetooth can offer fast and secure access to wireless connectivity all over the world. With potential like that it is no wonder that Bluetooth is set to become the fastest adopted technology in history.
Reference:
www.bluetomorrow.com

Digital Signature

Abstract

The concept of securing messages through cryptography has a long history. Throughout history, however, there has been one central problem limiting widespread use of cryptography. That problem is key management, the term key management refers to the secure administration of keys to provide them to users where and when they are required. To better understand how cryptography is used to secure electronic communications through Digital Signature.Digital signature is generally taken to be a 'subset' of electronic signatures.. A digital signature is an electronic signature that can be used to authenticate the identity of the sender of a message or the signer of a document, and possibly to ensure that the original content of the message or document that has been sent is unchanged.
In this paper digital signature is used to mean a cryptographically based signature assurance scheme. A digital signature can be used with any kind of message, whether it is encrypted or not.Digital signatures, like physical signatures, can verify that a specific user affixed their signature to a document and they can also verify that the document is the same as when the user affixed the digital signature. Digital signature systems (DSS) use public key cryptography methods to create digital signatures. The integrity of the digital signature is tied to the security of the user's private key. As long as the user's private key is secure, then only the user can affix their digital signature to a document

Contents
Key terms
Overview of
-- Public Key Cryptography (PKC)
-- Digital Signature
Digital Signature Cryptography with No Real Math
Applications
Conclusion

Key Terms:
· Keys
· Key Ring
· Finger Print
· Key Certificate
Keys:
Private key - The private key is the portion of the key we use to actually sign a document. The private key is protected by a password.
Public key - The public key is the portion of the key that is available to other people who use to check your signature. A list of other people who have signed your key is also included with your public key. You will only be able to see their identify if you already have their public keys on your key ring.
Key Ring: A key ring contains public keys. You have a key ring that contains the keys of people who have sent you their keys or whose keys you have gotten from a public key server.
Finger Print: When confirming a key, you will actually be confirming the unique series of letters and numbers that comprise the fingerprint of the key.

The fingerprint is a different series of letters and numbers.
Key Certificate :When you select a key on a key ring, you will usually see the key certificate, which contains information about the key, such as the key owner, the date the key was created, and the date the key will expire.
Overview:
This section will provide a brief introduction to public key cryptography (PKC) and digital signatures.
Public Key Cryptography (PKC):The purpose of a digital signature is to provide a means for an entity to bind its identity to a piece of information. Digital signatures use PKC, which employs an algorithm using two different but mathematically related keys: one to create a digital signature and another to verify a digital signature.
Unlike conventional symmetric-key cryptography, which uses the same secret key for encryption and decryption, PKC uses a key pair, a private and a public key, for encryption and decryption operations (see Figure 1). The public key is freely available to anyone, but the private key is protected and never shared. Each key pair shares a mathematical relationship that ties the two keys exclusively to one another, and they are related to no other keys.
Figure 1: Public Key Cryptography
A cryptographic transformation encoded with one key can be reversed only with the other key. It is computationally not feasible to deduce the private key from the public key nor to deduce the public key from the private key. This defining nature of PKC enables the following:
Confidentiality. A message encrypted with a public key can only be decrypted with the corresponding private key.
Endpoint authentication. The recipient can determine the sender's identity.
Message integrity. The recipient can easily identify whether anything has tampered with the message content during transit.
Nonrepudiation. The sender cannot deny sending the message or committed actions.

Digital Signature Protocol
Digital signatures are important because they provide end-to-end message integrity guarantees, and can also provide authentication information about the originator of a message. In order to be most effective, the signature must be part of the application data, so that it is generated at the time the message is created, and it can be verified at the time the message is ultimately consumed and processed.
As an analogy, consider a conventional letter. If I'm sending a check to my phone company, I sign the check—the message—and put it in an envelope to get privacy and delivery. Upon receipt of the mail, the phone company removes the envelope, throws it away, and then processes the check. I could make my message be part of the envelope, such as by gluing the payment to a postcard and mailing that, but that would be foolish.
PKC enables electronic messages with a mechanism analogous to signatures in the paper world, known as a digital signature. However, a digital signature verifies the authenticity of electronic documents and provides stronger security than do signatures on paper documents.
As Figure 2 shows, in order to create a digital signature, the sender first generates a small unique thumbprint of the document, called a hash or digest. Even a very minor change to the original document will cause the hash value to change. By comparing the hash that was received with the hash calculated from the received document, the recipient can verify whether the document was altered.

The hash of the document signed or encrypted with the sender's private key acts as a digital signature for that document and can be transmitted openly along with the document to the recipient. The recipient will be able to verify or decrypt the signature (see Figure 3) by taking a hash of the message and verifying it with the signature that accompanied the message and the sender's public key.
Figure 3: Digital Signature Verification
The digital signature protocol helps to ensures the following:
The signature is authentic. When the receiver verifies the message with the sender's public key, the receiver knows that the sender signed it.
The signature cannot be forged. Only the sender knows his or her private key.
The signature is not reusable. The signature is a function of the document and cannot be transferred to any other document.
The signed document is unalterable. If there is any alteration to the document, the signature verification will fail at the receiver's end because the hash value will be recomputed and will differ from the original hash value.
The signature cannot be repudiated. The sender cannot deny previous committed actions, and the receiver does not need the sender's help to verify the sender's signature.

Digital Signature Cryptography with No Real Math
Before we can really understand XML DSIG, we need to have an understanding of some basic cryptography.
A digital signature provides an integrity check on some content. If a single byte of the original content has been modified—an extra zero added to a price, a "2" changed to a "4", or a "No" to a "Yes"', and so on—then the signature will fail to verify. Here's how it works.
The first step is to ''hash'' the message. A cryptographic hash takes an arbitrary stream of bytes and converts it to a single fixed-size value known as a digest. A digest is a one-way process: it's ''computationally infeasible'' to recreate a message from the hash, or to find two different messages which produce the same digest value.
The most common hash mechanism is SHA1, the Secure Hash Algorithm. SHA1 takes any message up to 2**64 bytes in length and produces a 20-byte result.
So if I generate a message M, and create a digest, (written as H(M), for "the hash of M"), and you receive M and H(M), you can create your own digest H'(M), and if the two digest values match, we know that you got what I sent. To protect M against modification, I only need to protect H(M) from being modified. How do we do that? There are two common approaches. The first is to mix a shared secret into the digest. In other words, create H(S+M). When you get the message, you use your own copy of S to create H'(S+M). This new digest is called an HMAC, or Hashed Messsage Authentication Code.
When we use an HMAC, the strength of the integrity protection depends on the (in)ability of the attacker to figure out S. Therefore, S should be something not easily guessed, and something that should be changed often. One of the best ways to meet these requirements is to use Kerberos. In Kerberos, a central authority distributes "tickets" that contain a temporary session key whenever two entities want to communicate. This session key is used as the shared secret. When I want to send you a signature, I get a ticket to talk to you. I open my part of the ticket to get S, and I send you the message, its HMAC, and your part of the ticket. You open the ticket and get S and information about my identity. You can now take the message, M, generate your own H'(S+M), and see if they match. If they do match, you know that you received my message intact, and Kerberos told you who I am.
Another method to protect the digest is to use public-key cryptography, such as RSA. In public-key cryptography, there are two keys, a private key, known only to the holder, and a public key, accessible to anyone who wants to communicate with the key holder. In public-key cryptography, anything encrypted with the private key can be decrypted with the public key, and vice versa.
Let's look at a simple example that demonstrates how public-key cryptography works. In this example, we'll limit our messages to the letters a through z, and assign them the values one through 26. To encrypt, we'll add the value of the private key; in this case it's +4:Letter h e l l o
Numeric Value 8 5 12 12 15
Private Key 4 4 4 4 4
Encrypted Value 12 9 16 16 19
To decrypt, we add the public key, which will be +22; if the result is outside the number range, we add or subtract 26 until it's valid. E
Encrypted Value 12 9 16 16 19
Public Key 22 22 22 22 22
Raw decrypted value 34 31 38 38 41
Normalized value 8 5 12 12 15
Plaintext h e l l o
RSA works the same way, except that instead of addition we use exponentiation and the numbers are hundreds of digits long.
Using RSA, I generate a digest, H(M), and encrypt it with my private key, {H(M)}private-key, which is the signature. When you receive the message, M, you generate the digest, H'(M), and decrypt the signature using my public key, getting the H(M) that I generated. If H(M) and H'(M) are the same, then we know that M is the same. Further, you know that whoever has the private key—that is, me—is the sender of the message.





How It Works???
Assume you were going to send the draft of a contract to your lawyer in another town. You want to give your lawyer the assurance that it was unchanged from what you sent and that it is really from you.
1.You copy-and-paste the contract (it's a short one!) into an e-mail note.
2.Using special software, you obtain a message hash (mathematical summary) of the contract.
3.You then use a private key that you have previously obtained from a public-private key authority to encrypt the hash.
4.The encrypted hash becomes your digital signature of the message. (Note that it will be different each time you send a message.).
At the other end, your lawyer receives the message.
1.To make sure it's intact and from you, your lawyer makes a hash of the received message.
2.Your lawyer then uses your public key to decrypt the message hash or summary.
3.If the hashes match, the received message is valid

There are three common reasons for applying a digital signature to communications: -
Authentication:Public-key cryptosystems allow encryption of a message with a user's private key. The message itself need not be sent in cipher text. If a hash of the document is generated and then protected via encryption, the document cannot be altered in any way without changing the hash to match, which, if quality algorithms are properly used, will be quite difficult. By decrypting the hash using the sender's public key, and checking the result against a newly generated hash of the alleged plaintext, the recipient can confirm (with high confidence) that the encryption was done with the sender's private key (and so presumably by the user who should have been the only person able to use that key), and that the message hasn't been altered since it was signed. No recipient can ever be absolutely certain the purported sender is indeed the signer -- i.e., the person who used the private key -- since the cryptosystem might have been broken, the key copied, or the whole scheme evaded using social engineering.
The importance of high confidence in both the message integrity and sender authenticity is especially obvious in a financial context.
Integrity:Both parties will always wish to be confident that a message has not been altered during transmission. Encryption of the message makes it difficult for a third party to read it, but that third party may still be able to alter it, perhaps maliciously, without actually reading it. An example is the homomorphism attack: consider a bank which sends instructions from branch offices to the central office in the form (a, b) where a is the account number and b is the amount to be credited to the account. A devious customer may deposit £100, intercept the resulting transmission and then transmit (a, b3) to become an instant millionaire.
Non-repudiation:In a cryptographic context, the word repudiation refers to the act of disclaiming responsibility for a message (i.e., claiming it was sent by some third party, certainly not me; "I repudiate this message and its contents!"). A message's recipient may insist the sender attach a signature in order to make later repudiation more difficult, since the recipient can show the signed message to a third party (e.g., a court) to reinforce a claim as to its origin. However, loss of control over a user's private key will mean that all digital signatures using that key, and so 'from' that user, are suspect.

Digital Signature Applications for E-Government:
The increasing opportunities created by innovative systems and programming techniques have given rise to a new kind of application scenario, commonly referred to as electronic government. The digital signature is a technology that enables safe and legally binding transactions based on networked communication and the exchange of electronic documents. To explore possible application areas and the potential of this technology requires the modeling of processes, focusing, among other things, on administrative matters, their interlinking and interaction with other applications.
Application Development Trends In E-Business:
Applications of digital signature technology are on the rise because of legal and technological developments, along with strong market demand for secured transactions on the Internet. In order to predict the future demand for digital signature products and online security, it is important to understand the application development trends in digital signature technology. These developments promise to provide a robust security infrastructure for online businesses, which may promote e-business further in the future.

Conclusion:
Digital signatures are easily transportable, cannot be imitated by someone else, and can be automatically time-stamped. The ability to ensure that the original signed message arrived means that the sender cannot easily repudiate it later.

Reference:
· Digital Signature: Network Security Practices
by Kailash N. Gupta, Kamlesh N. Agarwala, Prateek A. Agarwala - 2005
· Handbook of Applied Cryptography - Page 426
by Alfred J. Menezes, Oorschot, Paul C. Van, Scott A. Vanstone - 1996
· R. Rivest, A. Shamir, L. Adleman. A Method for Obtaining Digital Signatures and Public-Key Cryptosystems. Communications of the ACM, Vol. 21 (2), pp.120–126. 1978.
· www.youdzone.com/signature.html

Blue Eyes Technology

ABSTRACT:
Is it possible to create a computer which can interact with us as we interact each other? For example imagine in a fine morning you walk on to your computer room and switch on your computer, and then it tells you “Hey friend, good morning you seem to be a bad mood today. And then it opens your mailbox and shows you some of the mails and tries to cheer you. It seems to be a fiction, but it will be the life lead by “BLUE EYES” in the very near future. The basic idea behind this technology is to give the computer the human power. We all have some perceptual abilities. That is we can understand each others feelings. For example we can understand ones emotional state by analyzing his facial expression. If we add these perceptual abilities of human to computers would enable computers to work together with human beings as intimate partners. The “BLUE EYES” technology aims at creating computational machines that have perceptual and sensory ability like those of human beings.

How can we make computers "see" and "feel"?
Blue Eyes uses sensing technology to identify a user's actions and to extract key information. This information is then analyzed to determine the user's physical, emotional, or informational state, which in turn can be used to help make the user more productive by performing expected actions or by providing expected information. For example, in future a Blue Eyes-enabled television could become active when the user makes eye contact, at which point the user could then tell the television to "turn on". This paper is about the hardware, software, benefits and interconnection of various parts involved in the “blue eye” technology.




INTRODUCTION:
Animal survival depends on highly developed sensory abilities. Likewise, human cognition depends on highly developed abilities to perceive, integrate, and interpret visual, auditory, and touch information. Without a doubt, computers would be much more
powerful if they had even a small fraction of the perceptual ability of animals or humans. Adding such perceptual abilities to computers would enable computers and humans to work together more as partners. Toward this end, the Blue Eyes aims at creating computational devices with the sort of perceptual abilities that people take for granted Blue eyes is being developed by the team of Poznan University of Technology& Microsoft. It makes use of the “blue tooth technology “developed by Ericsson.

PARTS OF A BLUE EYE SYSTEM :
The major parts in the Blue eye system are Data Acquisition Unit and Central System Unit. The tasks of the mobile Data Acquisition Unit are to maintain Bluetooth connections, to get information from the sensor and sending it over the wireless connection, to deliver the alarm messages sent from the Central System Unit to the operator and handle personalized ID cards. Central System Unit maintains the other side of the Blue tooth connection, buffers incoming sensor data, performs on-line data analysis, records the conclusions for further exploration and provides visualization interface.


THE HARDWARE:
Data Acquisition Unit
Data Acquisition Unit is a mobile part of the Blue eyes system. Its main task is to fetch the physiological data from the sensor and to send it to the central system to be processed. To accomplish the task the device must manage wireless Bluetooth connections (connection establishment, authentication and termination). Personal ID cards and PIN codes provide operator's authorization.
Figure Showing Jazz-multi Sensor

Communication with the operator is carried on using a simple 5-key keyboard, a small LCD display and a beeper. When an exceptional situation is detected the device uses them to notify the operator. Voice data is transferred using a small headset, interfaced to the DAU with standard mini-jack plugs.

The Data Acquisition Unit
The Data Acquisition unit comprises several hardware modules figure showing data
acquisition unit
· Atmel 89C52 microcontroller - system core
· Bluetooth module (based on ROK101008)
· HD44780 - small LCD display
· 24C16 - I2C EEPROM (on a removable ID card)

Block Diagram of Data Acquisition Unit:



· MC145483 – 13bit PCM codec
· Jazz Multisensor interface
· beeper and LED indicators, 6 AA batteries and voltage level monitor

CENTRAL SYSTEM UNIT :
Central System Unit hardware is the second peer of the wireless connection. The box contains a Bluetooth module (based on ROK101008) and a PCM codec for voice data transmission. The module is interfaced to a PC using a parallel, serial and USB cable.
The audio data is accessible through standard mini-jack sockets over view of central system unit To program operator's personal ID cards we developed a simple programming device. The programmer is interfaced to a PC using serial and PS/2 (power source) ports. Inside, there is Atmel 89C2051 microcontroller, which handles UART transmission and I2C EEPROM (ID card) programming.

THE SOFTWARE:
Blue Eyes software's main task is to look after working operators' physiological condition. To assure instant reaction on the operators' condition change the software performs real time buffering of the incoming data, real-time physiological data analysis and alarm triggering.
The Blue Eyes software comprises several functional modules System core facilitates the
transfers flow between other system modules (e.g. transfers raw data from the Connection Manager to data analyzers, processed data from the data analyzers to GUI controls, other data analyzers, data logger etc.).


The System Core fundamental are single-producer-multi-consumer thread safe queues. Any number of consumers can register to receive the data supplied by a producer. Every single consumer can register at any number of producers, receiving therefore different types of data.
Naturally, every consumer may be a producer for other consumers. This approach enables high system scalability – new data processing modules (i.e. filters, data analyzers and loggers) can be easily added by simply registering as a costumer

.
Connection Manager is responsible for managing the wireless communication between the mobile Data Acquisition Unit the central system. The Connection Manager handles:
· communication with the CSU hardware
· searching for new devices in the covered range
· establishing Bluetooth connections
· connection authentication
· incoming data buffering
· sending alerts
Data Analysis module performs the analysis of the raw sensor data in order to obtain information about the operator’s physiological condition. The separately running Data Analysis module supervises each of the working operators.
The module consists of a number of smaller analyzers extracting different types of information. Each of the analyzers registers at the appropriate Operator Manager or another analyzer as a data consumer and, acting as a producer, provides the results of the analysis. The most important analyzers are:
· saccade detector - monitors eye movements in order to determine the level of operator's visual attention
· pulse rate analyzer - uses blood oxygenation signal to compute operator's pulse rate
· custom analyzers – recognize other behaviors than those which are built-in the system. The new modules are created using C4.5 decision tree induction algorithm



Visualization module provides a user interface for the supervisors. It enables them to watch each of the working operator’s physiological condition along with a preview of selected video source and related sound stream. All the incoming alarm messages are instantly signaled to the supervisor.
The Visualization module can be set in an off-line mode, where all the data is fetched from the database.
Watching all the recorded physiological parameters, alarms, video and audio data the supervisor is able to reconstruct the course of the selected operator’s duty.
The physiological data is presented using a set of custom-built GUI controls:
· a pie-chart used to present a percentage of time the operator was actively acquiring the visual information
· A VU-meter showing the present value of a parameter time series displaying a history of selected parameters' value.

BLUE-EYES BENEFITS:
Prevention from dangerous incidents Minimization of ecological consequences financial loss a threat to a human life Blue Eyes system provides technical means for monitoring and recording human-operator's physiological condition. The key features of the system are:
· visual attention monitoring (eye motility analysis)
· physiological condition monitoring (pulse rate, blood oxygenation)
· operator's position detection (standing, lying)
· wireless data acquisition using Blue tooth technology
· real-time user-defined alarm triggering
· physiological data, operator's voice and overall view of the control room recording
· recorded data playback
Blue Eyes system can be applied in every working environment requiring permanent operator's attention:
· at power plant control rooms
· at captain bridges
· at flight control centers

CONCLUSION:
In future it is possible to create a computer which can interact with us as we interact each other with the use of blue eye technology. It seems to be a fiction, but it will be the life lead by “BLUE EYES” in the very near future. ordinary household devices -- such as televisions, refrigerators, and ovens -- may be able to do their jobs when we look at them and speak to them.

Steganography

ABSTRACT


Steganography, literally meaning “secret writing”, involves hiding a data file in another innocuous-looking file. From the time of Herodotus in Greece, to the defense mechanisms of today, steganography has been used to deny one’s adversaries the knowledge of message traffic.

Steganography is the art and science of writing hidden messages in such a way that no one apart from the intended recipient knows of the existence of the message; this is in contrast to cryptography, where the existence of the message is clear, but the meaning is obscured. hence, it is said to be the advanced cryptography.

The advantage of steganography is that it can be used to secretly transmit messages without the fact of the transmission being discovered. Using encryption can identify the sender and the receiver. Thus, steganography has a double layer of protection: first, the file itself is hidden and second, the data in it is encrypted. A person, group, or company can have a web page containing secret information meant for another.

In this paper, a detailed analysis of steganography is made. The history of steganography is briefly dealt with. How steganography works is examined, keeping in mind Bender’s specifications. Data hiding is implemented in two different media; audio and image files. Each offers challenges and solutions to these challenges are analyzed. The main characteristics of steganographic software are discussed, together with the various forms of steganographic methods. Steganalysis, the science of detecting steganography is touched upon. The weaknesses of steganography are also described, together with measures for improvement. The paper concludes by taking a look at the potential of steganography and the changes it can bring about as the future of network security.




WHAT IS STEGANOGRAPHY?
The word Steganography comes from the Greek name “stegnos” (hidden or secret) and “graphy” (writing or drawing) and literally means hidden writing. Steganography uses techniques to communicate information in a way that is hidden.
Steganography is the dark cousin of cryptography, the use of codes. While cryptography provides privacy, steganography is intended to provide secrecy. Privacy is what you need when you use your credit card on the Internet -- you don't want your number revealed to the public. For this, you use cryptography, and send a coded pile of gibberish that only the web site can decipher. Though your code may be unbreakable, any hacker can look and see you've sent a message. For true secrecy, you don't want anyone to know you're sending a message at all. For this, you use Steganography.
The most common use of Steganography is hiding information, image or sound within the information of another file by using a stegokey such as password is additional information to further conceal a message.

STEGANOGRAPHY AND CRYPTOGRAPHY:
Cryptography provides confidentiality of the message but not secrecy. In other words, the encoded message can be seen but cannot be understood. The message has a “key”, which is the only way it can be decrypted. If the message is being passed through human spies, the chances of the key falling into enemy hands is very high once suspicion has been aroused.
However, with steganography, since the message is hidden, we cannot know that a secret message even exists. The container file holds the secret message. Everyone can and will see the container file, but no one can make out that a message is hidden beneath it. If the message is passed either through human spies or through digital means, the code cannot be found without a passphrase, which only the sender and receiver have. Steganography can augment cryptography by obscuring communication and preventing the enemy from knowing a communication is being sent. Steganography should not be considered as a replacement for cryptography. The two mutually complement and complete each other.

HISTORY OF STEGANOGRAPHY:
Steganography has a long and colourful history. The idea behind steganography is pretty ancient, but it has been given a new lease of life with the advent of computers. Steganography has been widely used in historical times, especially before cryptographic systems were developed. Examples of historical usage include:
Hidden messages in wax tablets, on messenger's body: also in ancient Greece. Herodotus tells the story of a message tattooed on a slave's shaved head, hidden by the growth of his hair, and exposed by shaving his head again. Hidden messages on paper written in secret inks under other messages or on the blank parts of other messages. Later, steganography was used in various forms, until as recently as World War II. The Germans invented the “microdot”, which was a photograph the size of a dot, but with the clarity of fully type-written text. It could hold a large amount of information.
Other private codes used invisible ink. This would dry up after the message was written and would not be visible until it was exposed to heat. With the Computer age, steganography has been given a marvelous boost. Old methods like hiding data in images have been digitized and modernized through the computer.


¨ Protection Against Detection:
Most of steganography is used in protection against detection. This can be done by hiding info in user data or volatile data. The latter model is called data hiding in network model architecture. For example, in the OSI reference model, data is sent through packets. Covert channels can be established using the control data to send info that is hidden. At the receiver, the information is stripped off. Information files stay on the hard drive unless specifically deleted.

¨ Watermarking:
Steganography can be used to place a hidden trademark in music, images and software using a technique called “watermarking”. Watermarking techniques are more integrated into the image, so they can be applied without fear of destruction due to lossy compression. Watermarking extends image information and becomes an attribute of the cover information, providing copyright details.

.
A watermarked picture

Steganography is used to conceal files in various forms of data. This is done in three different media: text, images and audio signals. Steganography can and is being used widely in these media.
IMAGE STEGANOGRAPHY:
Image steganography has truly advanced with the invention of fast, powerful computers. Software is easily available for processing and hiding of data images. Images can also be retrieved very easily. Least Significant Bit Insertion is the most well-known image steganography technique. It is simple, easy to create and also easy to apply.

1. Image without embedded picture 2. Image with embedded steganographic picture.

Embedded picture in image 2


Embedded Map In The Image
Masking and filtering hide information by marking an image in a manner similar to paper watermarks. By masking a faint image with another in order to make the first non-perceptible, we exploit the fact that the human eye cannot detect faint changes in a visual image. Masking techniques are more suitable for use in lossy JPEG images than in LSB insertion because of their relative immunity to compression and cropping.

STEGANOGRAPHY IN AUDIO:
This is a very risky and challenging approach, as the human auditory system can detect even very minor changes in sound in a wide range. Random noise can be sensed easily. The four primary methods are:
¨ Low-bit encoding: Binary data can be stored in the Least Significant Bits of the sound files (similar to the image files). For example, channel capacity is 1kb per second per Hz. Therefore, if we have 8kHz sequence, the capacity is 8kbps.
¨ Phase coding: This works by substituting the phase of an audio segment with a reference phase that represents data.
¨ Spread spectrum: The encoded data is spread as much as possible over the frequency spectrum. In Direct Sequence Spread Spectrum, the signal is spread by multiplying it by a certain maximal length pseudorandom sequence, called a chip.
¨ Echo data hiding: Echo data hiding embeds data into a signal by using an echo. The data is hidden by varying three parameters of the echo: initial amplitude, decay rate and offset or delay.

CHARACTERISTICS OF STEGANOGRAPHIC SOFTWARE:
Steganographic software enables information to be hidden in graphic, sound and apparently blank media. Examples include data sent through images and pictures. Image steganography is most effectively handled by JPEG software. JPEG uses lossy encoding to compress its data. JFIF files are used for output. JFIF consist of both lossy and lossless stages. The information to be passed is hidden between these stages. File compression in JPEG is its greatest advantage. Large images in unlimited colours can be stored in relatively small files. Another example could involve data sent through sound or audio files. Various steganographic software packages available in the market are very recent and include Hide-&-Seek, StegosDos, White Noise, etc. in all versions; the messages are encrypted before being embedded, in order to provide an increased layer of protection.
FORMS OF STEGANOGRAPHY:
Many forms of steganography were devised and implemented. This includes methods like blindside, S-Mail and Scramdisk.
¨ Blindside: This is an application of steganography that allows one to conceal a file or a set of files within a standard computer image. This involves some very easy steps to store the data file. Encrypted passwords are used for authorization to access data.
¨ S-Mail: This encrypts any data in a very difficult-to-decrypt kind of way and then hides it in EXE or DLL files. The EXE file is then sent through the internet, via e-mail, to the recipient.
¨ Scramdisk: this allows the creation and use of a virtual encrypted data drive. On an existing hard drive, first an encrypted password is entered and data files are stored in the virtual drive. The recipient needs to first access the hard drive with the correct passphrase, without which the drive is inaccessible, and then the data can be extracted.

STEGANALYSIS:
This is the science of detecting hidden messages. A rising field today, it aims to discover and render useless all covert messages. A public watermark detector has been developed as an oracle to estimate a secret spread watermark. The image is first degraded and then random signals are added to completely wash out the watermark. Steganalysis is getting more and more advanced, in an effort to combat steganography.

WEAKNESSES OF STEGANOGRAPHY:
Ø Steganography is not without its disadvantages. However, these can be corrected and once implemented; it can strengthen the core of steganography.
Ø Most data hiding methods take advantage of human perceptual weaknesses, but they have weaknesses of their own. However, these can be individually rectified.
Ø One major drawback of steganography is that, unlike cryptography, it requires a lot of overhead to hide relatively few bits of data. However, it fares no worse than cryptography and is still the preferred medium.


Steganography was in the news lately, as an advanced means of secret communication. It has its obvious advantages, as an almost unbreakable system, and is complemented by cryptography. It can slip important communication without anyone knowing. Soon, we can have artists, musicians and authors using steganography to fight piracy. It can be used to track infringement of copyrights in a digital medium and can work wonders on the internet.

Steganography, if fallen into wrong hands, can create tremendous damage. It was in the news lately, as being the form by which Osama Bin Laden communicated with his associates, via Al-Jazeera television images. The US government recently released a public statement, declaring that “terrorist organizations are hiding maps, photographs of their targets and instructions for terrorist activities on chat rooms, bulletin boards and other websites using steganography”. The famous copyright infringement case against Napster, the online music website, was filed after using steganographic methods.

Currently in the news, steganography is finding increasing uses. It can be used to protect copyrights, prevent piracy and work in the transfer of top-secret data from place to place. Once its relatively minor disadvantages are rectified, steganography will be found to have amazing potential in the days to come.

REFERENCES:
[1]. Neil F Johnson, “Steganography”.
[2]. William Stallings, “Network and Interwork Security”.

Wireless Fidelity (WiFi) technology.

ABSTRACT

The internet has been around for many years. When it first came about, people were used to using the big, old clunky computers with the forever slow dial up internet connection process. Many years have passed and new technology has made amazing things possible, especially the new Wireless Fidelity (WiFi) technology. The technology is used on everything from your typical laptop, to a next generation cell phone, enabling anyone who wishes to connect to the internet or a network they belong to at their own discretion, anywhere they are. In essence, one may see the world, from wherever they are

People may connect to a wireless network, and talk to the entire world.If you are using mostly desktop computers, a wired network may work fine. However, for mobility, modifications and growth (especially if you are running a small business), WiFi provides the best answer because it enables you to move the computers anywhere in the building where they can connect to the wireless network

Today's workforce, equipped with PDAs, laptops and other mobile devices, demand access to your network from wherever they are, without the hassle of a fixed network. WiFi allows your business to deploy a network more quickly, at lower cost, and with greater flexibility than a wired system. In this presentation we just give you a brief idea of what exactly is WiFi (wireless fidelity) technology, working of WiFi, its different types, its uses in various fields, and its future to what extent it is going to improve further.












Wireless Fidelity, the wave of the future. From cell phones to computers, its uses are endless

Wireless broadband can deliver fast Internet access by using radio waves instead of cables or wires. . If you or your company move to a new location, you don't need to leave your cables, cable drops and other network investments behind. The entire wireless network comes with you and takes only moments to set up in a new location.
Wireless Internet connections come in two forms.
WiFi (Wireless Fidelity) or 802.11

WiFi (Wireless Fidelity) is the latest data transmission technology using radiofrequency energy, which allows the user to enjoy wireless broadband Internet access. WiFi allows both companies and individuals alike to enter the world of high-speed, wireless Internet access, thus optimizing connection costs and generating sales through flexibility. Using laptops, desktops or PDAs, users can read their e-mail, access their corporate network, or simply browse the Internet without wires -provided that their devices feature WiFi technology - by means of special processors, PCMCIA WiFi cards or WiFi adaptors.
WiFi is designed for communication between devices such as computers, printers and scanners. It is typically used to set up private wireless networks in a home or office, allowing you to move your PC or laptop while still having access to the Internet and to your printer and other devices. WiFi has a range of about 90m. WiFi is also being used to provide public high speed Internet access in locations such as cafes, hotels and airport lounges, providing Internet access to users who are away from their normal place of work.

WiFi is a form of WLAN (wireless local area network) technology. Its radius is typically a few hundred feet, but may be cut down depending on interference (from walls, etc.). The standards of WiFi are called 802.11b, 802.11a, 802.11g, and the most recent is called A+G, which uses a combination of the 802.11a and 802.11g standards. When using the wireless internet through WiFi, you will get fast data speeds up to 11Mbps with 802.11b and up to 54Mbps for the 802.11a and 802.11g.

WiFi is the popular protocol that allows users to connect to a computer network wirelessly.WiFi, or its technical name, 802.11b, uses an unlicensed high-radio frequency to communicate with a computer network. This means that anyone has the right to broadcast in this unlicensed 2.1 GHz spectrum. Though not as fast as hardwired connections, WiFi reaches up to 11mbs-plenty of bandwidth for surfing the Internet or sharing files.


Of course, there are issues with WiFi. One is that there are different standards of WiFi. WiFi5, also known as 802.11a, uses a higher frequency than regular WiFi, and is able to transmit about 5 times as much data. Because of this greater data rate, businesses are more apt to use 801.11a for their wireless infrastructure. As the two technologies run at different frequencies, they do not interfere with each other's signal. However that also means that they are incompatible. That's where 802.11g fills in. 802.11g, which has no "WiFi" designation yet, runs at the same frequency as 802.11b, but provides the speed of 802.11a. That said, 802.11g can provide 55mbs and still is compatible with the existing WiFi networks-which are the most prevalent.


Another issue with WiFi is that it is easily interceptable-meaning, someone with a wireless computer notebook were to travel around a city, he would likely be able to see a number of open networks to which he could connect. The act of driving around with a wireless computer and an antenna to record all the wireless networks in an area is called "war driving." Of course, security becomes an issue with an open network, and there are protocols to protect ones wireless network.


Wireless technology can be disruptive as a new channel as well as can add value to existing channels by enabling both low cost access and growth in reach. WiFi, wireless Local Area Networks (LANs) over 802.11 networks, are a low-cost, relatively simple way to gain high-speed access to the Internet. WiFi hotspots—WiFi is one of the few bright spots on the technology landscape, the one that ought to have the telecommunications industry on its feet by sheer size of opportunity it points toward.

WiFi connects you to others and to the Internet without the restriction of wires, cables or fixed connections. WiFi gives you freedom to change locations — and to have full access to your files, office and network connections wherever you are. And WiFi can do this better than other technologies used to set up a home or SOHO (small office — home office) network. In addition WiFi will easily extend an established wired network.

How Does Wi-Fi Compare to Other Networking Methods?

No other networking technology used to set up a small home or SOHO network provides the convenience or mobility of a WiFi network. That's because other methods, including standard wired Ethernet networks and phone line- and power line-based networks, all require a connection via wire or cable. WiFi uses radio waves that travel through walls and floors and connect you anywhere, indoors or out. Networks based on phone lines, also called HomePNA, must have a phone jack close to the computer or peripheral that is to be networked with the rest of your system. Unfortunately, most homes have only two or three phone outlets — or even just one! — And these outlets may not be where you want to put your computer, printer or other device. You may have problems with this type of network based on the quality of your phone line installation and especially if you have numerous phone devices plugged into each wall jack. Networks based on power lines, also called Home Plug, have location problems, too.

Of course, there are many more power outlets in a home than there are phone plugs, but power plugs may not be where you need them when you need them, especially outdoors. Power line networks are often more expensive than WiFi based equipment. Power line networks can experience interference from transformers, large appliances, power strips, surge protectors and even common "wall warts" (DV power supplies). In addition, apartments and condominiums that share power lines may also inadvertently share access to confidential files and information on the computers that are attached to the power line network — even if users think they've established tight security protections Neither power line - nor phone line-based networks provide true mobility or portability. These technologies don't allow you to just pick up your laptop or PDA and go anywhere in your home or small office and begin working or continue working in another location without losing contact with your network. Working outside on your patio or next to the pool is impossibility. And since power-line — and phone line-based networks aren't available at "Hotspots" (e.g., airports, hotels and cafes), localized access networks or at the office, they can't be used when traveling or working in a corporate office.



Is a Wired, Wireless or Wireless/Wired Network Best For You?

If you are using mostly desktop computers, a wired network may work fine. However, for mobility, modifications and growth (especially if you are running a small business), WiFi provides the best answer because it enables you to move the computers anywhere in the building where they can connect to the wireless network. If you or your company moves to a new location, you don't need to leave your cables, cable drops and other network investments behind. The entire wireless network comes with you and takes only moments to set up in a new location. Obviously if you are using laptop computers and/or other kinds of mobile computing devices.


WiFi is the only answer for both home and business. If you already have a functioning wired network, it's easy to just keep it in place and add wireless components to extend your network's reach and give users more flexibility and convenience. Many home and SOHO access points and gateways allow you to easily connect to both wired and wireless equipment through their installed Ethernet ports. To see the variety of ways you can hook up a home or small office to create a wireless or combined wired/wireless network, go to SOHO — Small Office — Home Office Networking Configurations Corporations frequently extend their wired networks with WiFi networks. They connect wireless access points to their network backbone to provide Internet and network access in meeting rooms, lobbies, cafeterias and other common areas.

Companies also add wireless access points in their general office space to make it easy for staff to meet informally. For example, someone from marketing can carry his or her laptop to the sales manager's office two floors up and, via the wireless network there, make a presentation on the spot using their laptop. When employees are mobile, as in a large warehouse or shipping center, WiFi networks can easily cover the entire area: staff can operate anywhere in the building, not just at predetermined desktops and workstations.

WiFi is meeting a long overdue demand in the office environment where cabling and re-cabling to accommodate shifting seating arrangements or company growth is not only inconvenient but expensive. Initially installing a WiFi network in an office building or warehouse was a complex business, possibly requiring software development to integrate with existing technology and testing and site surveys to ensure optimal coverage.

WiFi is only one of many types of services that can be described by the term 'wireless networking.' Don't confuse WiFi with Wireless in general. You would use wireless LAN technology to provide access to shared resources in a small geographic area, like a warehouse, an office space full of cubicles, or a home. You might want to share your printer, a digital camera or connections to the Internet with more than one computer. A wireless LAN does not replace your connection to the Internet, just the wires in your house. This becomes more important as you add network enabled devices such as MP3 and video that might be stored on a computer somewhere in your house and played back on your A/V system.


Why adopt WiFi?


Today's workforce, equipped with PDAs, laptops and other mobile devices, demand access to your network from wherever they are, without the hassle of a fixed network. WiFi allows your business to deploy a network more quickly, at lower cost, and with greater flexibility than a wired system.


Productivity increases too, since workers can stay connected longer, and are able to collaborate with their co-workers as and where needed. WiFi networks are more fluid than wired networks. A network is no longer a fixed thing, networks can be created and ripped down in an afternoon instead of the days or weeks required to create a structured cable network.


Architecture
Wireless cards can operate in two modes,
Infrastructure and Ad-hoc.

Infrastructure mode: Most business systems use wireless in Infrastructure mode. This means that devices communicate with an access point. Typically the access point also has a connection to the company wired network, allowing user’s access to servers and files as if they were physically attached to the LAN.

Ad-hoc mode: Ad-hoc connections are direct connections between wireless cards. This type of connection is more common amongst home users, but if used by business users could have serious management and security implications.

Different Types of WiFi

· IrDA
· HomeRF (Swap)
· Bluetooth
· WECE(WiFi)
IrDA: IrDA stands for Infrared Data Association. This technology is the bases for communicating using direct infrared light. It is only good for short distances and requires no interfering object with the light beam. It is capable of transferring 4 megabits per second. HomeRF and Swap : This type is basically based on the digital enhanced cordless telecommunications standard and the 802.11 wireless - Ethernet specifications. A system or a swap system can transmit up to 1 Mbps while making 50 hops per second. Bluetooth : Bluetooth basically is the way that any electronic component to connect itself to a wireless network. The advantages of this type of WIFI are short and sweet ; it's wireless, cheap and can connect on it's own with no help from the user.
WECA & WiFi : WECE & WiFi type just means there is a "seal of approval" stating that a certain wireless product is usable with the IEEE 802.11 specification. This system can transfer data or information at a very fast rate, even up to 11 Mbps.
WORKING OF WIFI SYSTEM


WiFi operates using a credit-card sized wireless PC card, which plugs into your computer and communicates over the airwaves with a local access point. From there information is transmitted via a cable or ADSL link to your Internet service provider.

The above image is a wireless network card shown with antenna


WiFi LAN technology can be described simply by saying that it is the sending of a radio signal, and receiving that signal with a antenna, transforming it into a understandable media. WiFi radios work in the same way as a walkie-talkie almost, yet it has slight differences. They have the ability to convert radio signals into one’s and zero’s, and vice versa. The main advantage of a WiFi radio however is its ability to hop frequencies. A radio may transmit on more than one band, and can split it’s bandwidth between many frequencies. This allows for less of a chance of interference. For computers, WiFi is simple. Most computers are already set up with a WiFi capability or you may add a WiFi card to an older computer very easily. With more modern computers, if you have a WiFi system, and you are within a hot spot (an area with 802.11, which is a specific frequency, either 2.4 gig, or 5 gig) you will automatically be connect to the internet and be allowed to do anything you normally would on your home pc. The wide use of notebook and other portable computers has driven advances in wireless networks. The most common use for a wireless network is to connect a single notebook computer to a broadband internet connection. Wireless networks use either infrared or radio-frequency transmissions to link these mobile computers to networks. Wifi networks use radio technologies called IEEE 802.11b or 802.11a to provide a secure, fast, and reliable wireless connection. The international standard for wireless networking uses a frequency of 2.4-2.4835GHz. These frequencies are common in microwaves, and cord less phones.


WiFi functions through a transmitting antenna which is usually linked to a DSL or high-speed land-based Internet connection and uses radio waves to beam signals. Another antenna, which is in the laptop or PC, catches the signal. The signal, usually l, has a range of about 300 feet for most home connections. The farther the user is from the signal, the slower the connection speed. Wireless LANS have capacity speeds from less than 1 Mbps to 8 Mbps. WiFi can easily be expanded in the home or business with the simple step of plugging in a card or a USB connection to the new computer or other WiFi certified product. No cords or cables, or wires are necessary.


WiFi - wireless fidelity - is mainly centered around the 802.11b standard using the unlicensed 2.4GHz band to transmit data across the radio spectrum normally occupied by cordless phones, garage door openers and a growing number of Bluetooth products designed for device connectivity.

A transmitting antenna, usually linked to a DSL or high-speed land-based internet connection, uses radio waves to beam signals to PCs, laptops, PDAs and mobile devices. A client antenna, a PC card ( PCI or USB connected) , removable PCMCIA card or chip embedded into the remote device, picks up the signal. The client device can receive strong signal within a 100 metre range of the transmitter. The further from the signal the slower the data rate - although additional transmitters can boost that rate.

Moving data using radio frequency is nothing new, in fact the first Morse code radio transmission has a lot in common with today's WiFi technology, after sending what is in effect the first binary wireless transmission mankind spent the next 20 years perfecting the reproduction of the human voice in an analogue format.

The telephone while revolutionary did mask the ability of data transmission, this was not left to rot as militaries around the world continued to develop the sending of data via RF transmissions. WIFI of today is a distant cousin of that Morse signal, although instead of a low bandwidth dot and dash being sent thousands of bits of data is sent every second and we are now measuring in kilobits per second and with newer technologies even megabits.


WiFi as a standard uses the 2.4 GHz range which is largely unused by the European military and other RF users like mobile communications, this frequency band is then broken down into channels which a wireless device can use to transmit data and in order to avoid interference the devices can frequency hop or jump between them mid data stream. So we have a method of moving data over RF but each device needs to be connected and enabled to work with WiFi, this is in effect like giving each device in your network a handheld radio (except they work at much high frequencies). Over this radio link the binary DataStream carries your data for example a webpage back to the device that requested it. A laptop for example would have a wireless access card or dongle this is both a transmit and receive device, this could connect to another laptop with the same setup and create a point to point connection. It is far more likely that the laptop and any other client device will connect to a router or access point to join a much larger wireless network.


Performance of any wireless link is limited by the same factors that affect your radio or TV signal, weather, distance, power and walls or objects, again an example if you use an indoor aerial for your TV your signal is weaker and therefore the picture quality drops. With a WiFi network if the signal strength or quality drops the effective data rate is reduced as more packets are re sent to counteract the errors, so it is important to bear in mind the maximum achievable range of a WiFi enabled device may be at the minimum sustainable speed.


WiFi Uses


In the Home:


Home networking is not fun, that is reflected in the number of homes that have cabled CAT5 networks today, and few homeowners want to run cabling under floors and have unsightly connection boxes in each room that you might use a device. So wireless is a real answer offering the ability for a broadband internet connection to be shared between users in the home, perhaps mum using the PC, dad on a laptop in the garden while the kids hook up their playststaion upstairs. It’s only a small step from sharing your internet connection to a full network, sharing a printer and even a music server with all your collection stored as MP3's


In the Workplace

The workplace on the other hand is far more cautious, most offices already have a perfectly good and fast (at least 100mbits) network in place in strict terms for desktop PC's there are few, but more and more workers are issued with laptops as standard. Those laptops will almost certainly have a wireless access card as standard and the new centurion technology for Intel means every laptop shipped has embedded WiFi.


We must also consider the number of devices in an office network there could be hundreds of devices trying to share the limited number of channels, and then there are issues of where to site access points to work most efficiently. It’s not all doom and gloom with good planning these can be overcome to fully extract the business benefits of wireless networks but it takes some guts to get started.


In Public

When is a hotspot not a hotspot? When no one knows about it!
And there lies the dilemma, while there is a market for those who wish public internet access on their mobile devices there are rarely enough users concentrated in one location to make it pay. Even when there are at airports or stations getting the average user to understand how to connect and pay for the time they will be using the service is a tough job.

Advantages of Wireless

· Some wireless technology allows users the flexibility to physically move while using a device such as a computer.
· New nodes can be added to a wireless network.
· Wireless can be used in places where it is not possible to run cables or drill holes, such as within historic buildings.
· Wireless technology can give users broadband access even when they are away from their home or office.
· Wireless is sometimes available where ADSL and cable are not.

Disadvantages of Wireless

· Wireless has a relatively high initial outlay, compared to ADSL or cable.
· Some wireless technology may require line-of-sight between the transmitting and receiving points. This can be a problem in some areas.
· Wireless suffers from potential security risks. As radio waves travel in all directions, anyone within range can access an unsecured wireless network, be they in the next office, the next building or even out in the street. However, security measures for wireless networks are continually being updated.
· Bandwidth can be limited in a congested network. WiFi shares the airwaves with devices such as microwaves and cordless phones, which can use up valuable bandwidth, or cause interference on occasions.


Security

So we intend to send data through the airwaves, well its not long before someone raises the security card and its right they should, data sent on computer networks is always private be it a web surfing session or email. Use of the industry standard triple DES encryption was deemed too slow for wireless networks which had limited bandwidth to cope with encryption overheads. So WEP the wireless encryption protocol emerged as the preferred method of securing the wireless connections, the 128bit WEP standard is not bombproof but would take a few months with a high powered server to crack, this of course assumes you don't change the key which of course you will!.

Security is the bane of everybody who puts together a wireless network. access points, using factory default settings, are not secure at all. So, if security is such a concern does that mean I shouldn't deploy WiFi? No, it doesn't. But it is something that you should bear in mind when in the planning stage. When talking about security there is no such thing as having a completely secure system. Everything is insecure to some degree or other. The degree of security you require is dictated by the sensitivity of the information you possess. If you require very high levels of security then you cannot rely on the built in security measures of a WiFi network alone. On the other hand, most small to medium sized companies do not require very high levels of security.
If you already have a wireless network you may be concerned about whether it is secure. There are four things you can do to ensure that you are secure.
· Make sure that your access point(s) are not broadcasting the SSID (identifier for N/W)
· Make sure that your access point(s) are encrypting the wireless traffic using Wireless Equivalent Privacy (WEP)
· Buy a wireless intrusion detection system.
· A number of products are available designed to help you monitor the security of your WiFi network as well as who is using it.
If you have a high security requirement, then you should either ensure your network people are appropriately trained or hire a wireless consultant. You may also need to buy proprietary, non-standard access points from the likes of Cisco (although even some proprietary standards from the likes of Cisco have their problems). Unfortunately, this will substantially increase the cost of your wireless network.
The Future of WiFi

With the spread of this new technology the future will provide fasterWiFi Protected Access (WPA) offers confidence and privacy to authorized users.WPA is a level of security that greatly increases the authentication and encryptionof your wireless system. The system works by using an access point to block LAN access until the user can be identified by entering a pass code. Once the correct pass code is entered the user can then begin surfing the net. This process will keep unauthorized users from accessing the authorized users account and keep all data safe and secured. WiFi telephones are also on the rise and soon will be widely available.
With the continuation of this progress more and more internet users will feel confident enough to upgrade from the out-dated dial up connection to the powerful WiFi network. With these high quality performance products, the future will only become more functional for everyone, everywhere.

There may also be potential problems that could occur in the future with WiFi. With more people connected to WiFi, the signals sent can become weaker causing a slow connection. Analysts are worried that the growing population of WiFi users could possibly slow down the signals making WiFi inconvenient.

Conclusion

With the increasing popularity of WiFi, several communities and businesses are setting up wireless communities that allow users to roam around the area while connected. Hotels, airports, and coffee shops are setting up more networks as the demand increases for this low-cost service. Globally, this wireless local area networking (LAN) technology is springing up in airports, cafes, and along city streets, creating ubiquitous broadband access in public and private spaces. One of the reasons for extensive growth of WiFi is the promotion of technology by collaborative group of vendors making WiFi gear, and referred as WiFi Alliance. WiFi Alliance also works on certification, standardization and interoperability of WiFi gear from all the vendors. WiFi has improved a lot since it was first introduced. Basically, the price and performance of WiFi is now at a point where it makes sense for a wider group of users