AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/1/1-3)
Unit 1 · Topic 1.3
1.3 Best Practices for Public Networks
Public Wi-Fi is convenient, but you don't control who else is on it or who set it up. This topic covers how adversaries differ in skill and motive, three wireless attacks (evil twin, jamming and war driving), and the simple habits that keep your data safe on public networks.
Key terms
- low-skilled vs. high-skilled adversary
- zero-day
- evil twin
- jamming
- war driving
- virtual private network (VPN)
Who the adversaries are
An adversary is anyone trying to attack you or your systems. One way to classify them is by skill.
Low-skilled adversaries use ready-made attack tools that other people built and sell online. Those tools only work against known vulnerabilities, which are weaknesses that have already been discovered and usually have a fix.
High-skilled adversaries can write new tools, or change existing ones to get around new defenses. They can also find undocumented vulnerabilities that no one else knows about yet. These are called zero-days, because defenders have had zero days to fix them.
Adversaries also have different motives: greed (money), wanting recognition, dedication to a cause, revenge, politics or beliefs. Knowing the motive helps you predict what they'll target.
Three wireless attacks
A wireless access point (WAP) is the device that broadcasts a Wi-Fi network. The network's name is its SSID (service set identifier).
- Evil twin: the attacker sets up their own access point with an SSID that matches or closely copies a real one, like Maple_Cafe_Guest next to the real Maple_Cafe. Anyone who connects to the fake sends their traffic through the attacker, who can capture it. The attacker can't read traffic protected by an encrypted protocol like HTTPS, but anything unencrypted is exposed.
- Jamming: the attacker floods the area with a strong electromagnetic signal on the same frequencies the Wi-Fi uses. The noise drowns out real traffic, so nobody can connect. An attack that keeps people from using a resource is called a denial of service (DoS).
- War driving: the attacker drives or walks around a target while scanning for wireless network signals. They learn what kind of network is in use and where its signal leaks outside the building, which tells them where they could sit to attack it.
Staying safe on public Wi-Fi
- Check that the network name exactly matches the one you mean to join. Ask staff for the exact name if you're unsure. An evil twin depends on you not noticing a small difference.
- Rely on encryption. Most internet traffic today is encrypted, including every site that uses HTTPS (browsers warn you when a site doesn't), so even on an open network an eavesdropper can't read it. But some data can still leak on unencrypted networks, such as DNS queries, the lookups that reveal which websites you're visiting. For sensitive tasks, think about whether an open network is worth the risk.
- Consider a virtual private network (VPN). A VPN encrypts all your traffic from your device to the VPN company's servers. The local network and its provider can't see what you're doing, but the VPN provider can, so you're moving your trust to them, not removing the need for trust.
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Identifying the adversary type
Two attacks hit a small business in the same week. In the first, someone used a tool bought on a criminal forum to exploit a router flaw that was announced and patched last year. In the second, someone used a flaw in the business's accounting software that the software maker had never heard of. Classify each adversary by skill level and explain your reasoning.
Show the solutionHide the solution
- Step 1: Attack 1: the tool was bought, not built, and the flaw was already known and patched. Relying on others' tools against known vulnerabilities is the mark of a low-skilled adversary.
- Step 2: Attack 2: the flaw was unknown even to the vendor, which makes it a zero-day. Discovering undocumented vulnerabilities takes a high-skilled adversary.
- Step 3: Note the lesson for defenders: patching would have stopped attack 1 but not attack 2, which is why layered defenses matter.
Answer: Attack 1 was a low-skilled adversary (purchased tool, known vulnerability). Attack 2 was a high-skilled adversary (exploited a zero-day, an undocumented vulnerability).
- Example 2
Choosing a network at an airport
At an airport, your phone shows three open networks: Airport_Free_WiFi, Airport-Free-WiFi and FreeAirportWiFi_Fast. The airport's signs say the official network is Airport_Free_WiFi. You want to check your bank balance. Describe the risk and what you should do.
Show the solutionHide the solution
- Step 1: Identify the risk: the two look-alike names could be evil twins set up by an attacker to capture traffic.
- Step 2: Apply the first habit: join only the network whose name exactly matches the official one, Airport_Free_WiFi.
- Step 3: Recognize the limit: even the real network is open, so other people on it could try to watch unencrypted traffic.
- Step 4: Add protection for a sensitive task: make sure the bank site uses HTTPS (or use the bank's app), or use a VPN, or wait and use your cellular data instead.
Answer: The look-alike names may be evil twins. Join only the exact official name, and for banking rely on HTTPS or a VPN, or use cellular data instead of the open network.
Common mistakes
- Thinking a VPN makes you invisible. It hides your traffic from the local network, but the VPN provider can see it.
- Saying an evil twin lets the attacker read everything. Traffic protected by encryption like HTTPS stays unreadable; the danger is to unencrypted data.
- Calling jamming a way to steal data. Jamming blocks the signal so no one can connect; it's a denial of service.
- Confusing war driving with an evil twin. War driving is scouting for networks and signal leaks; an evil twin is a fake network meant to lure people.
On the exam
- Expect scenario questions that describe what an attacker did and ask you to name the attack or the adversary's skill level. A bought tool against a known flaw means low-skilled; a zero-day means high-skilled.
- For protection questions, the best answers are specific: verify the exact SSID, rely on encrypted protocols like HTTPS, or use a VPN while understanding who can still see the traffic.
Connected topics
Videos
Check yourself: 1.3 Best Practices for Public Networks
4 questions on 1.3 Best Practices for Public Networks. Pick an answer to see if you got it, and why.
Sam opens a laptop at the Bean Street Cafe. Two open networks appear: BeanStreet_Guest and BeanStreet-Guest. A sign at the counter says the cafe's network is BeanStreet_Guest.
BeanStreet-Guest has the stronger signal, so Sam joins it. Sam then checks a bank balance on a site that uses HTTPS and looks up several other websites.
Later the cafe manager learns that BeanStreet-Guest comes from a small access point hidden in a backpack at a nearby table.
Invented scenario
Which type of attack does the BeanStreet-Guest network represent?
Which of Sam's activities could the adversary NOT read, even though Sam's traffic passed through the adversary's access point?
Which action would have best protected Sam from this attack?
Sam decides to use a VPN on public Wi-Fi from now on. Which statement about the VPN is accurate?
0 of 4 answered