| Current Wi-Fi security standard | WPA3 (Wi-Fi Alliance, 2018 onwards) |
| Common public Wi-Fi threat | Man-in-the-middle attack |
| Router update type that patches security flaws | Firmware update |
| Consumer network segmentation example | Guest Wi-Fi network |
| DNS function | Translates domain names to IP addresses |
Why This Glossary Exists
Network security advice is full of acronyms and technical shorthand that most articles never stop to explain. When a router setup guide tells you to enable WPA3 or warns you about DNS hijacking, it assumes you already know what those terms mean. This reference removes that assumption.
The terms below are organized thematically — starting with the building blocks of how networks are identified and secured, then moving to the categories of threats that exploit weaknesses in those systems. Each definition focuses on what the term means in practice, not just in theory.
These Terms Appear Across Multiple Contexts
Many of the terms below — such as DNS, IP address, and firewall — appear in both security discussions and general troubleshooting. If you encounter them in error messages or router settings, our companion guide Understanding IP Addresses, DNS, and Gateways Without the Jargon covers the networking fundamentals in plain English. For broader Wi-Fi vocabulary, see What SSID, WPA, DHCP, and Other Wi-Fi Terms Actually Mean.
For the practical steps that put these concepts to work, see our home network security checklist or the complete home network security foundation guide.
Core Network Security Terms
The following terms form the foundation of almost every network security conversation. Knowing them makes router settings, security alerts, and advice articles significantly easier to interpret.
SSID
Short for Service Set Identifier, this is the name your Wi-Fi network broadcasts so devices can find it. Hiding your SSID offers minimal security benefit, since tools can still detect it — a strong password matters far more.
Encryption
A process that scrambles data so only authorized parties with the correct key can read it. On Wi-Fi networks, WPA3 is the current standard encryption protocol, replacing the older and less secure WPA2.
Firewall
A security system — built into your router or operating system — that monitors and filters incoming and outgoing network traffic based on predefined rules. Think of it as a gatekeeper deciding what data is allowed through.
Man-in-the-Middle Attack
An attack where a third party secretly intercepts communications between two devices — for example, between your phone and a public Wi-Fi access point. The attacker can read, alter, or inject data without either party initially knowing.
VPN (Virtual Private Network)
A service that encrypts your internet traffic and routes it through a server in another location, hiding your activity from your ISP and others on the same network. Useful on public Wi-Fi but not a complete security solution on its own.
MAC Address
A unique hardware identifier assigned to every network interface — your phone, laptop, or router all have one. Routers can use MAC address filtering to control which devices are allowed to connect, though this is not a strong standalone security measure.
Rogue Access Point
A fake Wi-Fi access point set up by an attacker to mimic a legitimate network, such as a coffee shop's Wi-Fi. Connecting to one routes your traffic through the attacker's equipment.
DNS (Domain Name System)
The internet's address book — it translates human-readable URLs like example.com into IP addresses. DNS hijacking is a common attack where traffic is redirected to malicious sites without your knowledge.
Firmware
The built-in software that runs your router or other network hardware. Manufacturers release firmware updates to patch security vulnerabilities, making regular updates an important habit.
WPA3
The latest Wi-Fi Protected Access standard, offering stronger encryption and better protection against password-guessing attacks than its predecessor WPA2. Supported by most routers and devices released after 2019.
Zero-Day Vulnerability
A security flaw that is unknown to the software or hardware vendor — and therefore unpatched — at the time attackers begin exploiting it. The name refers to the fact that developers have had zero days to fix it.
Network Segmentation
Dividing a network into separate zones to contain threats. A common consumer example is enabling a guest Wi-Fi network so that visitors' devices are isolated from your main devices and local data.
| Current Wi-Fi security standard | WPA3 (Wi-Fi Alliance, 2018 onwards) |
| Common public Wi-Fi threat | Man-in-the-middle attack |
| Router update type that patches security flaws | Firmware update |
| Consumer network segmentation example | Guest Wi-Fi network |
| DNS function | Translates domain names to IP addresses |
Understanding how these concepts interrelate matters as much as knowing individual definitions. For example, encryption protects data traveling over your network, but if your firmware is outdated, an attacker may exploit a vulnerability in the router itself — bypassing encryption entirely. Strong individual settings can still be undermined by neglecting adjacent ones.
For device-level equivalents of these terms — covering the security of your phone, tablet, and computer directly — see Device Security From the Ground Up. Password-specific terminology such as credential stuffing and encryption salting is covered separately in the password security terminology reference.
83%
of routers with known vulnerabilities never patched by users
According to research cited by the American Consumer Institute, the vast majority of home routers in use contain unpatched firmware vulnerabilities.
34%
of public Wi-Fi hotspots lack any encryption
Kaspersky security researchers have reported that roughly one in three public Wi-Fi networks operates without encryption, leaving users exposed.
