Rogue Detection and Countermeasures 559

IDS Log Message Examples

Table 34 shows examples of the log messages generated by IDS.

Table 34: IDS and DoS Log Messages

Message Type

Example Log Message

 

 

Probe message flood

Client aa:bb:cc:dd:ee:ff is sending probe message flood.

 

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Authentication

Client aa:bb:cc:dd:ee:ff is sending authentication message flood.

message flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Null data message

Client aa:bb:cc:dd:ee:ff is sending null data message flood.

flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

Management frame 6

Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame 6 message flood.

flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Management frame 7

Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame 7 message flood.

flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Management frame D

Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame D message flood.

flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

Management frame E

Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame E message flood.

flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Management frame F

Client aa:bb:cc:dd:ee:ff is sending rsvd mgmt frame F message flood.

flood

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Associate request flood

Client aa:bb:cc:dd:ee:ff is sending associate request flood on port 2

 

 

Reassociate request

Client aa:bb:cc:dd:ee:ff is sending re-associate request flood on port 2

flood

 

 

 

Disassociate request

Client aa:bb:cc:dd:ee:ff is sending disassociate request flood on port 2

flood

 

 

 

Weak WEP

Client aa:bb:cc:dd:ee:ff is using weak wep initialization vector.

initialization vector

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

(IV)

 

 

 

Decrypt errors

Client aa:bb:cc:dd:ee:ff is sending packets with decrypt errors.

 

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

Spoofed

Deauthentication frame from AP aa:bb:cc:dd:ee:ff is being spoofed.

deauthentication

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

frames

 

 

 

Spoofed disassociation

Disassociation frame from AP aa:bb:cc:dd:ee:ff is being spoofed.

frames

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Null probe responses

AP aa:bb:cc:dd:ee:ff is sending null probe responses.

 

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

 

 

Broadcast

AP aa:bb:cc:dd:ee:ff is sending broadcast deauthentications.

deauthentications

Seen by AP on port 2, radio 1 on channel 11 with RSSI -53.

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 559
Image 559
Nortel Networks 2300 manual IDS Log Message Examples, IDS and DoS Log Messages