Wireless

 View Only
last person joined: yesterday 

Expand all | Collapse all

Airwave - AP Impersonation

This thread has been viewed 13 times
  • 1.  Airwave - AP Impersonation

    Posted Oct 26, 2022 03:26 PM
    In the RAPIDS IDS events, I see "AP Impersonation".  What actions can/should I take?

    ------------------------------
    Peter
    ------------------------------


  • 2.  RE: Airwave - AP Impersonation

    MVP GURU
    Posted Oct 27, 2022 07:29 AM
    In AP impersonation attacks, the attacker sets up an AP that assumes the BSSID and ESSID of a valid AP. AP impersonation attacks can be done for man-in-the-middle attacks, a rogue AP attempting to bypass detection, or a honeypot attack.

    Within your WIDS/WIPS configuration you can set up containment. Be careful not to put other peoples wireless into containment unless it is a true rogue device, and not just a neighboring system. If they are using the same BSSID and ESSID then they must be a rogue device.:

    Wireless containment-When enabled, the system attempts to disconnect all clients that are connected or attempting to connect to the identified Access Point.

    None-Disables all the containment mechanisms.

    Deauthenticate only-With deauthentication containment, the Access Point or client is contained by disrupting the client association on the wireless interface.

    Tarpit containment-With Tarpit containment, the Access Point is contained by luring clients that are attempting to associate with it to a tarpit. The tarpit can be on the same channel or a different channel as the Access Point being contained.



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022
    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: Airwave - AP Impersonation

    Posted Oct 27, 2022 12:09 PM

    How do I know what AP is doing the impersonation in order to contain it?



    ------------------------------
    Peter
    ------------------------------



  • 4.  RE: Airwave - AP Impersonation

    MVP GURU
    Posted Oct 27, 2022 04:36 PM
    Are you seeing what AP discovered the rogue. that should help you locate the AP. Also, are you using airwave? Uploading floorplans, and adding AP locations will help you locate the device on a map. Aruba Central also has this capability.

    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022
    If my post was useful accept solution and/or give kudos
    ------------------------------