Detecting Malformed Frame-Auth
Malformed802.11 authentication frames that do not conform to the specificati on can expose vulnerabilitiesi n some
driverst hathave not implemented proper errorchecking. This feature checks for unexpectedvalues in a
Authentication frame.
Detecting a Malformed Frame-HT IE
The IEEE 802.11 n HT (HighT hroughput)IE i s used to convey information about the 802.11 n network.A 802.11
managementframe containing a malformed HT IE can crash some client implementations; potentially representing
an exploitableco ndition when transmitted by a malicious attacker.
Detecting a Malformed Frame-Large Duration
The virtual carrier-senseattack is implementedby modi fying the 802.11 MAC layer implementation to allowrandom
duration valuesto be sent periodic ally.This attack can be carried out on the ACK, data, RTS, and CTS frame types
by using largeduration values. This att ack can prevent channelaccess to legitimate users.
Detecting a Misconfigured AP
A list of parameters can be configured that defines the characteristics of a valid AP. This feature is primarily used
whennon-Dell APs are used in the network since the Dell controller cannot configuret hethird-party APs. These
parametersinclude WEP, WPA, OUI of valid MAC addresses, valid channels, and valid SSIDs.
Detecting a Windows Bridge
A Windows Bridge occurs when a client that is associated to an AP is also connected to the wired network, and has
enabledbridging between these two i nterfaces.
Detecting a Wireless Bridge
Wirelessbridges are normally used to connect multiple buildings together. However, an attacker could place (or have
an authorizedperson place) a wireless bridge inside the network that would extend the corporate network somewhere
outside the building.Wireless bridges are somewhat different fromrogue APs in that they do not use beacons and
have no concept of association. Most networks do not usebridges – in these networks,t he presenceof a bridge is a
signalt hat a security problem exists.
Detecting Broadcast Deauthent ication
A deauthentication broadcast attempts to disconnect all stations in range. Rather than sending a spoofed deauth to
a specific MAC address, this attack sends the frameto a broadcast address.
Detecting Broadcast Disassociat ion
By sending disassociation frames to the broadcast address (FF:FF:FF:FF:FF:FF), an attacker can disconnect all
stations on a network for a widespreadD oS.
Detecting Netstum bler
NetStumbleris a popularwardriving application used to locate 802 .11 networks. Whenused with certain NICs,
NetStumblergenerates a characteristic frame that can be detect ed.V ersion 3.3.0 of NetStumbler changedt he
characteristic frames lightly.
Detecting Valid SSI D Misuse
If an unauthorizedA P (neighbor or interfering)is usingthe same SSID as an authorized network, a valid client may
be tricked into connecting to the wrong network. If a client connects to a malici ous network,security breachesor
attacks can occur.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide WirelessIntrusionPr evention |376