Wireless Intrusion Detection - Sharkfest - Wireshark

Wireless Intrusion Detection - Sharkfest - Wireshark Wireless Intrusion Detection - Sharkfest - Wireshark

sharkfest.wireshark.org
from sharkfest.wireshark.org More from this publisher
13.01.2015 Views

Monitoring wireless • Multiple methods of monitoring, not all equal • “Scanning mode” - same mechanism a client uses to connect, asks “What access points are available” • “Monitor mode” - Requires support in the driver, such as Linux, or AirPCAP • “Promsic mode” - Doesn't mean much in WiFi 12

WIDS can be hard • Many vulnerabilities in Wi-Fi are not fingerprintable in traditional way • Protocol violations can often be completely legit packets, just used in a weird way • Have to be able to monitor trends over time not just single packet events 13

Monitoring wireless<br />

• Multiple methods of monitoring, not all equal<br />

• “Scanning mode” - same mechanism a client uses<br />

to connect, asks “What access points are available”<br />

• “Monitor mode” - Requires support in the driver,<br />

such as Linux, or AirPCAP<br />

• “Promsic mode” - Doesn't mean much in WiFi<br />

12

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!