A security analyst is investigating network security logs following user complaints of sudden, repeated disconnections from the corporate Wi-Fi network. Shortly after being disconnected, several user devices automatically reconnected to an unauthorized access point broadcasting the corporate ESSID. Which TWO of the following wireless network indicators specifically point to an active disassociation and Evil Twin attack sequence?
- A sudden flood of unencrypted 802.11 management frames containing deauthentication reason codes transmitted with the spoofed MAC address of the legitimate access pointAnswer
- Beacon frames broadcasting the corporate ESSID on a different RF channel using a distinct BSSID with significantly higher signal strength than the authorized access pointsAnswer
- CUnsolicited ARP reply packets arriving at workstation interfaces mapping the default gateway IP to multiple distinct dynamic MAC addresses
- DA high rate of ICMPv6 Router Advertisement frames announcing an unexpected prefix with a high router preference value
Answer
The correct indicators of an active disassociation and Evil Twin attack sequence are a sudden flood of unencrypted 802.11 management frames containing deauthentication reason codes sent from the spoofed MAC address of the legitimate access point, and beacon frames broadcasting the corporate ESSID on a different RF channel with higher signal strength than authorized access points.
In a combined disassociation and Evil Twin attack, the attacker first transmits spoofed 802.11 deauthentication frames using the MAC address of the legitimate access point to break active client connections. Simultaneously or immediately following, the attacker's rogue access point broadcasts 802.11 beacon frames configured with the corporate ESSID (often operating on a different channel with higher transmission power), causing client devices to automatically reconnect to the malicious AP.
Step-by-Step Solution
Key Concept
Wireless Disassociation and Evil Twin Attack Indicators