Skip to content

Rogue AP Detection

Wireless networks are vulnerable to rogue access points (APs), which can be deployed to intercept traffic, spoof legitimate networks (Evil Twin attacks), or create entry points for further exploitation. Detecting and mitigating rogue APs requires a combination of traffic analysis, monitoring tools, and proactive network policies. This section outlines techniques for identifying unauthorized APs and implementing countermeasures like MAC address filtering to reduce attack surfaces.


Detection Techniques

Traffic Analysis for Rogue APs

Rogue APs often exhibit anomalies in network traffic patterns. Use packet capture tools to identify suspicious behavior, such as:
- Unexpected SSIDs or BSSIDs (MAC addresses of APs).
- High traffic volumes from unknown clients.
- Unusual protocols or ports in client-to-AP communication.

Example: Use tcpdump to monitor traffic for anomalies:

tcpdump -i wlan0 -nn -s 0 'tcp port 80'  # Capture HTTP traffic for potential data exfiltration
tcpdump -i wlan0 -nn -s 0 'icmp'        # Identify rogue APs spoofing ICMP responses

Monitoring Tools

Leverage tools like Kismet, Wireshark, or NetSpot to detect rogue APs:
- Kismet can identify unauthorized APs by comparing their MAC addresses against a whitelist.
- Wireshark allows deep inspection of packet headers for mismatched SSIDs or BSSIDs.

Example: Use Kismet to scan for rogue APs:

kismet -c <channel> -d <driver>  # Replace with actual channel and driver

Anomalies in Traffic Patterns

Look for:
- Clients connecting to APs with SSIDs that match legitimate networks.
- Sudden spikes in traffic to/from unknown IP addresses.
- Clients associating with APs that have inconsistent signal strength or location data.


Mitigation Strategies

MAC Address Filtering

MAC address filtering restricts devices to only those with pre-approved MAC addresses. While not foolproof (as MAC addresses can be spoofed), it adds a layer of defense:
- Implementation: Configure switches or APs to allow only known MAC addresses.
- Example (Cisco switch):

switchport port-security mac-address 0000.0000.0000  # Whitelist specific MAC
switchport port-security maximum 1                  # Limit to one device per port

Network Segmentation

Isolate critical systems into separate VLANs or subnets to limit the impact of a rogue AP:
- Use VLANs to segment IoT devices, guest networks, and internal systems.
- Deploy firewalls to enforce rules between segments.

Regular Audits and Whitelisting

  • Maintain an updated whitelist of authorized APs and devices.
  • Use tools like Nmap or ARP tables to verify active devices on the network.
  • Example:
    nmap -sn 192.168.1.0/24  # Scan for active devices on the network
    arp -a                   # View ARP table for known devices
    

Key takeaways

  • Use traffic analysis tools like tcpdump and Kismet to detect rogue APs by identifying anomalies in SSIDs, BSSIDs, or traffic patterns.
  • Implement MAC address filtering as a basic defense, but recognize its limitations against spoofing.
  • Segment networks into VLANs to limit lateral movement and isolate sensitive systems.
  • Conduct regular audits and maintain up-to-date whitelists of authorized devices.