A security analyst reviews wireless intrusion prevention system (WIPS) alert logs following reports of intermittent connectivity issues at a corporate office. The log reveals that multiple wireless workstations simultaneously disconnected from the corporate SSID 'Enterprise-Secure' after receiving spoofed 802.11 Subtype 12 management frames. Immediately following the disconnection, the affected workstations attempted to re-authenticate against an unauthorized access point broadcasting the same SSID on an adjacent channel, but using a degraded WPA2-PSK security mechanism instead of 802.1X WPA3-Enterprise. Which TWO of the following wireless attack indicators and techniques are demonstrated in this scenario?
- 802.11 deauthentication frame injection used to disrupt active client connectionsAnswer
- An Evil Twin deployment combined with a wireless security protocol downgrade attackAnswer
- CMAC address table exhaustion used to force switch ports into fail-open unicast flooding mode
- DAddress Resolution Protocol (ARP) cache poisoning to perform intra-VLAN session hijacking
Answer
The scenario demonstrates an 802.11 deauthentication frame injection attack and an Evil Twin access point deployment executing a wireless protocol downgrade.
The scenario highlights two distinct indicators: 802.11 Subtype 12 management frames (which define deauthentication messages used to disconnect clients) and an unauthorized access point broadcasting a matching SSID while offering a weaker security posture (which defines an Evil Twin executing a protocol downgrade attack).
Step-by-Step Solution
Key Concept
Identifying wireless attack indicators, specifically 802.11 deauthentication frame injection, Evil Twin rogue access points, and security downgrade techniques.
Estimated Time:1m 30s