Wireless Intrusion Detection - Sharkfest - Wireshark

Wireless Intrusion Detection - Sharkfest - Wireshark Wireless Intrusion Detection - Sharkfest - Wireshark

sharkfest.wireshark.org
from sharkfest.wireshark.org More from this publisher
13.01.2015 Views

Detecting saturation attacks • Can look for absurdly long CTS/RTS durations • Can look for CTS/RTS without corresponding data • Both vulnerable to false positives, especially if your monitoring hardware can't see all data • 11g seeing 11n will see control frames but not data, for example 30

Get off my lawn: Deauth/disassoc • Network tells clients when they're allowed in, and when they're being disconnected • Of course this is unencrypted... • Deauthentiction or disassociation packets both cause the client to leave • All you need is the BSSID and client MAC 31

Detecting saturation attacks<br />

• Can look for absurdly long CTS/RTS durations<br />

• Can look for CTS/RTS without corresponding data<br />

• Both vulnerable to false positives, especially if your<br />

monitoring hardware can't see all data<br />

• 11g seeing 11n will see control frames but not data,<br />

for example<br />

30

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!