Source-linked AI summary
Jamming Attacks and Anti-Jamming Strategies in Wireless Networks: A Comprehensive Survey
Hossein Pirayesh, Huacheng Zeng
TL;DR
Wireless networks remain vulnerable to radio jamming, while practical jamming-resistant decoding technologies and consolidated knowledge are limited. This paper surveys attacks and anti-jamming strategies across many wireless networks, grounding the review in PHY/MAC-layer foundations and discussing open research directions. It reports representative findings on mitigation techniques, including throughput recovery through channel hopping and successful decoding under strong jamming with MIMO mitigation.
Problem
Wireless networks remain vulnerable to radio jamming, while progress in practical jamming-resistant wireless networking systems is limited.
Method
The paper conducts a comprehensive survey of jamming attacks and anti-jamming strategies across wireless networks, with PHY/MAC-layer primers, comparative synthesis, and open-issue analysis.
Results
The survey reports mitigation examples including 60% Wi-Fi throughput under reactive jamming with channel hopping and successful Wi-Fi decoding under 20 dB stronger broadband jamming using MIMO mitigation.
Takeaways & Limitations
The review maps existing jamming and defense techniques and identifies promising research directions toward jamming-resilient wireless networking systems.
Abstract
from arXiv · showhide
Wireless networks are a key component of the telecommunications infrastructure in our society, and wireless services become increasingly important as the applications of wireless devices have penetrated every aspect of our lives. Although wireless technologies have significantly advanced in the past decades, most wireless networks are still vulnerable to radio jamming attacks due to the openness nature of wireless channels, and the progress in the design of jamming-resistant wireless networking systems remains limited. This stagnation can be attributed to the lack of practical physical-layer wireless technologies that can efficiently decode data packets in the presence of jamming attacks. This article surveys existing jamming attacks and anti-jamming strategies in wireless local area networks (WLANs), cellular networks, cognitive radio networks (CRNs), ZigBee networks, Bluetooth networks, vehicular networks, LoRa networks, RFID networks, and GPS system, with the objective of offering a comprehensive knowledge landscape of existing jamming/anti-jamming strategies and stimulating more research efforts to secure wireless networks against jamming attacks. Different from prior survey papers, this article conducts a comprehensive, in-depth review on jamming and anti-jamming strategies, casting insights on the design of jamming-resilient wireless networking systems. An outlook on promising antijamming techniques is offered at the end of this article to delineate important research directions.
I. INTRODUCTION
Wireless services are increasingly important, yet open wireless channels leave networks vulnerable to easy-to-launch radio jamming attacks. This survey organizes current attacks and defenses across wireless systems, reviews their PHY/MAC foundations, and identifies open research directions.
- Motivation: Wireless networks face significant jamming exposure because radio jamming attacks are easy to launch against open wireless channels.A small $10 USB dongle can be programmed as a jammer covering 20 MHz below 6 GHz with up to 100 mW transmission power.
- Scope: The survey covers jamming attacks and anti-jamming strategies across WLANs, cellular, CRNs, vehicular, Bluetooth, ZigBee, LoRaWANs, UAVs, RFID, and GPS systems.It also provides PHY/MAC-layer knowledge for understanding the destructiveness of attacks in these networks.
- Organization: For each wireless network, the article reviews system design and PHY/MAC layers before examining existing jamming and defense strategies.The survey then discusses open issues and promising research directions.
- Contribution: Unlike prior surveys, this work provides an up-to-date, comprehensive review with PHY/MAC background across multiple wireless networks.The paper positions this broader technical foundation as necessary for understanding jamming and anti-jamming strategies.
- Anti-jamming strategies: The article surveys anti-jamming approaches including power control, spectrum spreading, frequency hopping, MIMO-based mitigation, and jamming-aware protocols.It quantifies jamming mitigation capability and discusses applications.
- Outlook: The article concludes by identifying open problems and promising research directions for securing wireless networks against jamming attacks.Its structure spans network-specific reviews followed by an open-problems section and conclusion.
1) MAC-Layer Protocols:
Wi-Fi communications use CSMA/CA at the MAC layer and OFDM-based frame and baseband processing at the PHY layer. Generic jamming attacks can disrupt channel access, packet reception, or multichannel operation.
- MAC-Layer Protocols: CSMA/CA senses the channel, defers after a busy indication, and uses random backoff before transmission.
- MAC-Layer Protocols: RTS/CTS mitigates hidden-node collisions when multiple nodes can reach an access point but cannot sense one another.
- MAC-Layer Protocols: 802.11ax adds centralized features including OFDMA, uplink and downlink MU-MIMO, trigger-based random access, spatial frequency reuse, and target wake time.
- MAC-Layer Protocols: Wi-Fi frames use OFDM, with legacy and VHT formats combining preambles, signal fields, and data fields for synchronization, channel estimation, and demodulation.
- MAC-Layer Protocols: The transmitter scrambles, encodes, modulates, maps, and IFFT-converts data before appending cyclic prefixes and a preamble; the receiver synchronizes, estimates channels, equalizes, and passes recovered bits to MAC.
- MAC-Layer Protocols: Generic attacks include constant jamming that occupies bandwidth and disrupts reception, reactive jamming that targets detected transmissions, and frequency sweeping across channels.
2) WiFi-Specific Jamming Attacks:
Wi-Fi-specific attacks exploit timing synchronization, cyclic prefixes, beamforming sounding, MAC control exchanges, and rate-adaptation behavior. Countermeasures include channel hopping and several PHY/MAC mitigation classes, but no generic defense addresses all jamming types.
- WiFi-Specific Jamming Attacks: Timing attacks such as false preamble, preamble nulling, and preamble warping disrupt packet-start detection and timing synchronization.
- WiFi-Specific Jamming Attacks: CP jamming corrupts the cyclic prefix, can produce false linear-equalizer outputs, and saves more than 80% energy versus constant jamming, but requires precise transmission timing.
- WiFi-Specific Jamming Attacks: Beamforming sounding attacks jam NDP transmissions so users cannot estimate channels and report false compressed beamforming feedback.
- WiFi-Specific Jamming Attacks: Less than 7% of packets could be successfully beamformed in MU-MIMO transmission under NDP jamming.
- WiFi-Specific Jamming Attacks: MAC-layer attacks target CTS, ACK, DIFS waiting, or RTS reservations to interrupt transmissions or keep the medium busy.
- WiFi-Specific Jamming Attacks: Under reactive jamming, ARF required a higher ratio of jammed packets than SampleRate to keep point-to-point throughput below a specified threshold.
- Anti-Jamming Techniques: Anti-jamming techniques are categorized as channel hopping, MIMO-based mitigation, coding protection, rate adaptation, and power control, with no generic solution for all attacks.
- Channel Hopping Techniques: Channel hopping achieved 60% of no-jamming Wi-Fi throughput under reactive jamming, while reactive jamming reduced throughput by 80% without that comparison.
2) Spectrum Spreading Technique:
Spectrum spreading, MIMO mitigation, coding, rate adaptation, power control, fragmentation, and learning-based detection represent anti-jamming approaches reviewed for WLANs and related wireless systems.
- Spectrum spreading: Spectrum spreading improves resilience to narrowband interference and jamming; 802.11b uses Barker sequences and complementary code keying at different data rates.The reviewed systems include 3G cellular, ZigBee, and 802.11b.
- MIMO-based mitigation: MIMO mitigation projects received mixtures into a subspace orthogonal to jamming signals, enabling decoding with existing channel equalizers.The technique is described for reactive jamming in OFDM-based Wi-Fi networks.
- MIMO-based mitigation: Blind MIMO equalization can mitigate unknown jammers without jamming-channel information, while synchronization recovery supports packet timing and frequency recovery under strong jamming.The approach was evaluated using real-world Wi-Fi implementations.
- Coding techniques: For long packets of a few thousand bits, LDPC coding achieves throughput close to the Shannon limit with low decoding complexity under low-duty-cycle pulse jamming.The comparison concerns LDPC and Reed-Solomon codes across packet sizes.
- Rate adaptation and power control: Rate adaptation and power control can improve jamming mitigation when devices have sufficient power and jamming power is limited, but rate adaptation is generally effective in lossy channels with low-power interference.Lower data rates can be paired with increased transmit power to alleviate jamming.
- Packet fragmentation: Packet fragmentation improves reliability under periodic and noise jamming by reducing each packet’s jamming probability, although smaller packets create greater network overhead.The approach is presented as an alternative for rate adaptation under low-power jamming.
A. A Primer of Cellular Networks
The cellular primer presents LTE’s architecture, resource grids, physical channels, transceiver processing, synchronization, channel estimation, equalization, and random access procedures.
- LTE overview: LTE supports 1.4–20 MHz bandwidth, targets 100 Mbps downlink and 50 Mbps uplink peak rates, and uses OFDM downlink with SC-FDMA uplink.LTE supports both TDD and FDD transmission schemes.
- Resource grids: An LTE frame lasts 10 ms and contains ten 1 ms subframes; each subframe has two slots of seven or six OFDM symbols.The description concerns the downlink resource grid.
- Random access: PRACH enables initial radio-link access, while PSS and SSS support frame-timing synchronization and cell-ID detection.The random-access procedure requires prior synchronization with a cell and successful decoding of system information.
- Physical channels: PDSCH carries user data and system information, while PDCCH carries downlink scheduling decisions and power-control commands.These channels occupy distinct roles in LTE downlink operation.
- Physical channels: PBCH carries the MIB, including downlink bandwidth, PHICH configuration, and transmit-antenna count, and maps to the central 72 subcarriers.PBCH is transmitted in the first four OFDM symbols of the second slot in subframe 0.
- Transceiver processing: The PDSCH transmitter applies CRC attachment, segmentation, coding, rate matching, scrambling, modulation, antenna mapping, resource mapping, OFDM modulation, and carrier up-conversion.Turbo coding provides error correction, while CRC supports receiver-side error detection.
- Transceiver processing: The receiver performs synchronization, OFDM demodulation, channel estimation, equalization, and data extraction before reversing PDSCH processing to recover transport data.MMSE and zero-forcing are identified as the two principal cellular equalizers.
B. Jamming Attacks
Cellular jamming attacks target generic transmissions and LTE-specific synchronization signals, control channels, data channels, broadcast information, and random-access procedures.
- Attack scope: Cellular jamming can use generic attacks or strategies targeting cellular-specific signaling and channels.The survey focuses on attacks against PHY-layer downlink and uplink signaling.
- Generic and uplink attacks: A frequency-sweeping jammer was evaluated against LTE uplink reference signals by sweeping a 20 MHz channel within T microseconds and measuring demodulation-reference-signal EVM.The experiments varied T within [1, 200] microseconds for a given signal-to-jamming ratio.
- Generic and uplink attacks: A 37 dBm jammer was sufficient in experiments to force a WCDMA user from WCDMA service to GSM by degrading primary common-pilot SNR.The attack exploits service-selection behavior after the WCDMA signal falls below a threshold.
- Synchronization attacks: Synchronization-signal spoofing can deny service because synchronization signals occupy less than 0.7% of a 5 MHz downlink resource grid and fake signals can lure LTE users.Synchronization is required for cell search, random access, reselection, and handover.
- Control and data-channel attacks: PDCCH and PUCCH are attractive targets because they carry control information for downlink and uplink resource allocation.Attacking PDSCH or PUSCH additionally requires cell synchronization, control information, and cell-ID knowledge.
- Broadcast and access attacks: PBCH jamming can block LTE communications when the jamming signal is 3 dB stronger than the desired signal at LTE receivers.PBCH carries MIB information required for initial random access and packet reception.
5) Jamming Attacks on PHICH:
The reviewed cellular defenses include MIMO mitigation and spectrum spreading, while the section also describes vulnerabilities involving reference signals and random-access channels.
- PHICH: PHICH carries one-bit hybrid-ARQ ACK/NACK responses, repeated three times, BPSK-modulated, and spread with an orthogonal sequence.Its design aims to minimize acknowledgment-detection errors.
- Reference signals: Reference signals support channel estimation and equalization by providing known pilot positions whose estimated responses are interpolated across the bandwidth.Downlink pilots use pseudo-random frequency-domain sequences with QPSK modulation.
- Reference-signal attacks: Jamming cell-specific reference signals can prevent downlink-channel demodulation, disrupt synchronization, and block handover, but requires prior knowledge of cell identity.The attack depends on identifying reference-signal positions in the resource grid.
- Reference-signal attacks: Reference-signal nulling attacks force pilot-sample energy toward zero, disabling channel estimation at cellular receivers.Pilot jamming in MIMO-OFDM targets the estimated channel matrix.
- Random-access attacks: Jamming PRACH can cause denial of service by preventing LTE users from connecting to the network or reestablishing links during handover.PRACH attacks are identified as critical PHY-layer vulnerabilities.
- MIMO defenses: Massive-MIMO jamming-resilient receivers reserve pilots to estimate the jammer’s channel while legitimate users estimate desired channels in the presence of jamming.The approach uses the large-number law and is designed for constant broadband uplink jamming.
- Spectrum spreading: Spectrum spreading is particularly effective against narrowband jamming and is used in 3G CDMA, WCDMA, and TDS-CDMA systems.WCDMA spreads bit streams with OVSF codes whose spreading factor varies by transmission direction.
- Spectrum spreading: For WCDMA with SF = 32, acceptable uplink quality requires SJR ≥−22 dB for voice, ≥−13 dB for text, and ≥−16 dB for data services.Downlink thresholds are −26 dB, −14 dB, and −18 dB for voice, text, and data, respectively.
3) Multiple Base Stations Schemes:
Cellular anti-jamming strategies include reconnecting through alternative base stations, protecting critical physical channels, and detecting attacks with machine learning. The section then introduces cognitive radio networks and their spectrum-access vulnerabilities, including primary-user emulation attacks.
- Cellular anti-jamming: When a serving eNodeB is jammed, users can reconnect to the strongest available neighboring eNodeB after failing to decode the current MIB.This rerouting mechanism is already used in LTE networks.
- Cellular anti-jamming: Spectrum spreading and scrambling are proposed to protect crucial LTE physical channels, including PBCH, PUCCH, and PDCCH, from jamming.
- Cellular vulnerabilities: Static PUCCH resource allocation is identified as an LTE vulnerability because jamming can disrupt HARQ acknowledgments and cause denial of service.
- Cellular anti-jamming: Neural networks, SVM, and random forests were evaluated for jamming detection in 5G communications.
- Cognitive radio networks: CRNs enable unlicensed secondary users to access licensed spectrum alongside incumbent primary users without inducing interference to primary communications.
- Cognitive radio attacks: Spectrum hand-off wastes secondary users’ access time, while primary-user emulation attacks mimic incumbent signals to prevent secondary users from accessing channels.
2) False-Report Attacks:
False-report attacks manipulate cooperative spectrum sensing by sending misleading reports to centralized or decentralized decision processes. The surveyed literature covers malicious, selfish, statistical, and learning-based attack or defense perspectives, alongside game-theoretic countermeasures.
- Attack models: False-report attacks, also called SSDF or Byzantine attacks, send misleading sensing reports to cause incorrect spectrum-access decisions.
- Attack models: Malicious attackers inject false local sensing results, whereas selfish attackers report channels as busy to reserve spectrum for exclusive use.
- Network settings: False-report attacks have been studied in both centralized fusion-center networks and decentralized networks that make decisions through iterative information exchange.
- Attack evaluation: Statistical false-report attacks are more difficult to detect than non-probabilistic attacks, and attack population affects their performance.
- Control-channel attacks: A common-control-channel attack overwhelms the secondary network with fake MAC control frames to cause denial of service.
- Learning-based attacks: A deep-learning jammer uses ACK reports to predict ACK transmissions and was compared with random and sensing-based reactive jamming.
- Learning-based attacks: 0.38 packet/slot under random jamming and 0.14 packet/slot under sensing-based jamming are reported comparison values for the deep-learning jamming study.
- Anti-jamming strategies: Game-theoretic models represent interactions between secondary users and jammers, while channel hopping, cooperation, reinforcement learning, and network coding support anti-jamming strategies.
V. JAMMING AND ANTI-JAMMING ATTACKS IN ZIGBEE NETWORKS
ZigBee supports low-power, low-data-rate, short-range applications and uses IEEE 802.15.4-based PHY processing. Its surveyed attacks include constant, reactive, energy-depletion, and cross-technology jamming, with reactive attacks demonstrating particularly strong packet disruption.
- ZigBee overview: ZigBee targets low-power, low-data-rate, short-range services such as home automation, medical data collection, and industrial control.It operates under IEEE 802.15.4 across several unlicensed frequency bands.
- PHY processing: Every 4 data bits are mapped to a predefined 32-chip PN sequence, half-sine shaped, and modulated using OQPSK at the ZigBee transmitter.
- Jamming attacks: Generic constant, reactive, deceptive, random, and frequency-sweeping jamming strategies can also be applied to ZigBee networks.
- Jamming attacks: Constant jamming was experimentally evaluated in an indoor IEEE 802.15.4 tree-topology network using a modified commercial ZigBee module.
- Jamming attacks: A reactive jammer detects ZigBee PHY headers before transmitting a short signal that corrupts the detected packets.
- Jamming attacks: More than 26 µs of reactive jamming reduced packet reception to zero, while a USRP prototype blocked more than 96% of packets in all scenarios.
- Jamming attacks: Energy-depletion attacks send fake packets to keep receivers busy and consume resources such as CPU and airtime.
- Jamming attacks: A modified Wi-Fi dongle can continuously transmit packets as a cross-technology jammer against ZigBee communications.
C. Anti-Jamming Techniques
ZigBee anti-jamming approaches combine existing techniques with DSSS, MIMO-based learning, randomized spreading, channel hopping, segmentation, filtering, and exploitation of jammer reaction times. Bluetooth provides a contrasting frequency-hopping design with 79 conventional or 40 BLE channels.
- ZigBee techniques: ZigBee’s DSSS PHY can improve link reliability against jamming and interference, while generic MIMO mitigation and spectrum spreading are also applicable.
- ZigBee techniques: BER was 10^-1 at SNR = 3 dB, 10^-2 at SNR = 6 dB, and 10^-3 at SNR = 8 dB in the AWGN ZigBee baseline.
- ZigBee techniques: A MIMO jamming-resilient receiver used preamble-trained online learning and achieved 100% packet reception against jamming 20 dB stronger than the ZigBee signal.It also provided an average 26.7 dB jamming-mitigation gain over commercial ZigBee receivers.
- ZigBee techniques: RD-DSSS uses unpredictable spreading-code correlation, while Dodge-Jam combines channel hopping and frame segmentation against reactive jamming.
- ZigBee techniques: ZigBee defenses include confidential SFD symbols, channel hopping, packet fragmentation, and redundant encoding for different jamming patterns.
- ZigBee techniques: A digital filter rejects periodic jammer frequencies, while other methods exploit reactive-jammer reaction time to transmit during unjammed slots.
- Bluetooth overview: Bluetooth uses FHSS to transmit packets across 79 separate 1 MHz channels, whereas BLE uses 40 channels of 2 MHz bandwidth.
B. Jamming Attacks
The survey reviews jamming vulnerabilities and attacks in Bluetooth and LoRa networks, including attacks that exploit protocol behavior, channel access, or packet structure.
- Bluetooth Networks: Bluetooth FHSS mitigates narrowband, low-power jamming but fails against high-power signals spanning the entire 2.4–2.4835 GHz ISM band.This leaves Bluetooth vulnerable to generic constant, reactive, and deceptive jamming attacks.
- Bluetooth Networks: Bluetooth frequency hopping depends on a pre-shared key, making key establishment vulnerable to adversarial jamming.Uncoordinated FHSS schemes were proposed to secure this procedure.
- Bluetooth Networks: Collaborative broadcast removes pre-shared-key exchange by relaying messages across channels, improving jamming resiliency under the assumption that not all channels are blocked.Sweeping selection performs better with fewer than 50 slave nodes, whereas static selection performs better with larger networks.
- LoRa Networks: LoRaWAN remains highly susceptible to triggered and selective jamming despite using spread-spectrum transmission at low data rates.Triggered jamming begins after preamble detection, while selective jamming targets a device after decoding its MAC header and address.
- LoRa Networks: 0.5% packet reception rate was measured for a legitimate LoRa device under triggered jamming by a commodity LoRa end-device.Selective jamming can block one device while avoiding interference with other LoRaWAN devices.
- LoRa Networks: A commodity LoRa module was used to build a reactive jammer that jointly exploits preamble detection and RSSI to detect channel activity.The evaluation considered spreading factor and jammer bandwidth effects on signal detection.
C. Anti-jamming Techniques
The survey describes LoRa’s physical-layer resilience and jamming-detection mechanisms, then outlines the architectures and communication constraints shaping vehicular and UAV anti-jamming strategies.
- LoRa Networks: LoRa CSS maps each transmitted bit to 2^SF chips on a chirp waveform, providing the primary spread-spectrum defense against interference and jamming.At 125 KHz bandwidth and SF = 8, a receiver recovered packets at −121 dBm RSSI with zero packet error rate.
- LoRa Networks: 7–10 dB lower receiving sensitivity and up to 15 dB packet reception ratio gain were reported for LoRa versus conventional FSK at a 1.2 Kbps data rate.These results characterize LoRa’s reported reception advantage under the specified comparison conditions.
- LoRa Networks: A LoRaWAN jamming detector uses Kullback–Leibler divergence and Hamming distance to compare received-signal characteristics with jamming-free behavior.Join-request transmissions are used to derive a signaling mass function for detection.
- Vehicular Networks: VANETs require reliable, timely delivery while coping with rapidly changing topology caused by high vehicle speeds.These constraints distinguish vehicular networks from stationary and semi-stationary wireless networks.
- Vehicular Networks: DSRC uses IEEE 802.11p with EDCA prioritized access, while 100 ms sync periods divide control-channel listening and service-channel access into two 50 ms intervals.The control interval carries safety messages and service-access information.
- UAV Networks: UAV networks commonly use star or mesh topologies in the unlicensed 2.4 GHz and 5.8 GHz ISM bands, while cellular networks offer wide-coverage support.3GPP Release 15 enhanced LTE capability for UAV communications.
B. Jamming Attacks
Vehicular and UAV networks face generic and specialized jamming threats, while proposed defenses use relaying, learning, game theory, and signal processing to detect or mitigate attacks.
- Vehicular Attacks: Vehicular networks are exposed to constant, reactive, deceptive, and frequency-sweeping jamming because their wireless medium is open.UAV networks face the same generic attack classes.
- VANET Attacks: Ten radio jammers reduced network packet send ratio to 0.4 in an IEEE 802.11p V2X experiment using 100 vehicles and 20 roadside units.Outdoor packet delivery rates reached zero below reported SNJR thresholds under constant and periodic jamming.
- UAV Attacks: GPS jamming or spoofing can disrupt UAV positioning, navigation, and routing, while control-command attacks can cause UAV loss and mission failure.Control-command attacks may block legitimate signals or transmit fake information.
- VANET Defenses: A UAV relay can forward vehicular data to alternative roadside units when a serving roadside unit is jammed.A game-theoretic model captures adaptive jammer power selection and UAV relay decisions.
- VANET Defenses: 98.9% accuracy was achieved for classifying constant jamming, compared with 44.5% for periodic jamming, using unsupervised learning and relative-speed information.The detector was evaluated in two mobile-jammer scenarios.
- VANET Defenses: 99.9% accuracy was reported for estimating a jamming vehicle’s position with frequency-change detection, noise filtering, and CatBoost.The method combines a foster rationalizer, Morsel filter, and CatBoost algorithm.
- UAV Defenses: UAV anti-jamming studies model jammer–UAV interactions with Stackelberg games and derive power-control strategies using reinforcement learning.Bayesian Stackelberg formulations also address co-channel mutual interference in UAV ad-hoc networks.
B. Jamming Attacks
The survey examines jamming and related security threats in RFID and GPS systems, emphasizing RFID’s distinctive energy constraints and the severe impact of relatively weak jamming signals.
- RFID Attacks: RFID systems face spoofing, denial-of-service, replay, and passive attacks alongside generic constant, reactive, and deceptive jamming.Denial of service can prevent tag reading by isolating tags or overwhelming the reader with data.
- RFID Attacks: When the reader signal power is 0 dBm, a −15 dBm received jamming signal was sufficient to break down UHF RFID communications.This result came from a simulation study of constant jamming.
- RFID Defenses: RFID anti-jamming is constrained by passive or low-energy tags, making generic MIMO, spectrum-spreading, and frequency-hopping techniques unsuitable or ineffective.One low-power detector instead exploits adjacent-channel power, preamble, and tag uplink-response side information.
- GPS Systems: The GPS section introduces GPS communication and reviews attacks and anti-jamming mechanisms designed specifically for GPS systems.The supplied passages identify GPS navigation-message and receiver structures but do not report a specific defense result.
A. A Primer of GPS Communication System
GPS provides users with location and timing information through satellite broadcasts, but its weak on-earth signals are vulnerable to jamming. The survey reviews GPS jamming effects and mitigation approaches, including spreading gain and antenna-based processing.
- GPS users estimate satellite distance from signal travel time after acquiring satellite timing and location information.
- GPS navigation messages use five subframes, each containing ten data words with 24 raw bits followed by six parity bits.
- The navigation message is transmitted at 50 bps on the L1 and L2 frequency channels.
- C/A code provides approximately 43 dB spreading gain for civilian L1 signals, while P-code provides approximately 53 dB for authorized military users.
- Because GPS is one-way and satellite signals are weak at Earth, jamming primarily threatens on-earth GPS user devices.
- A 60 MHz wide-band jammer at the L1 carrier frequency was used to study GPS receiver performance under jamming.
- Spectrum spreading offers inherent jamming resistance, while MIMO-based mitigation and CLEAN processing are reviewed as additional defenses.
- A proposed four-antenna receiver acquired four GPS signal streams at 40 dB JNR and correctly determined position at 20 dB JNR experimentally.
2) Efficiency of Anti-Jamming Techniques:
The survey identifies efficiency, practicality, and continuity as unresolved requirements for anti-jamming systems. It highlights trade-offs in spectral use, the need to connect theory with implementation, and promising cross-domain, cross-layer, and learning-based directions.
- Efficiency of Anti-Jamming Techniques: Frequency hopping mitigates narrowband jamming but reduces spectral efficiency; Bluetooth uses only one of 79 channels at a time.
- Efficiency of Anti-Jamming Techniques: Theoretical anti-jamming studies using game theory and cross-layer optimization remain difficult to deploy because of unrealistic assumptions.
- Securing Wireless Communication System by Design: Conventional defense separates jamming detection, countermeasure invocation, and communication recovery, preventing constant connectivity during attacks.
- Securing Wireless Communication System by Design: Designing anti-jamming protection into wireless systems aims to maintain service without disconnection, while balancing communication efficiency against mitigation capability.
- MIMO-based Jamming Mitigation: MIMO-based mitigation is identified as a promising direction because it can improve jamming mitigation and spectrum utilization compared with frequency hopping and spectrum sharing.
- MIMO-based Jamming Mitigation: Existing interference-management results can support MIMO anti-jamming design, whose findings may also apply to unknown interference in Wi-Fi, cellular, and vehicular networks.
- Cross-Layer and Multi-Domain Strategies: Constant jamming increasingly motivates cross-layer designs that jointly address PHY-layer processing and protocol-specific attacks.
- Learning-Based Strategies: Machine learning is being applied to jamming defense for complex wireless-engineering problems whose underlying mathematical models are unknown.