|
RTS Virtual Carrier Sense Attack
|
This alarm extends the RTS flood alarm introduced in Cisco IOS XE Bengaluru 17.4.x. The alarm triggers when an RTS frame with a large duration value is detected. An attacker can use these frames to exhaust airtime and disrupt wireless client services.
|
|
CTS Virtual Carrier Sense Attack
|
This alarm extends the CTS flood alarm introduced in Cisco IOS XE Bengaluru 17.4.x. The alarm triggers when a CTS frame with a large duration value is detected. An attacker can use these frames to exhaust airtime and disrupt wireless client services.
|
|
Deauthentication Flood by Pair
|
This alarm provides enhanced threat context by tracking both the source (attacker) and the destination (victim) involved in the attack.
|
|
Fuzzed Beacon
|
A fuzzed beacon occurs when an attacker introduces invalid, unexpected, or random data into a beacon frame and replays the modified frames over the air. This can cause unexpected behavior on the destination device, such as driver crashes, operating system crashes, and stack-based overflows, and may allow execution of arbitrary code.
|
|
Fuzzed Probe Request
|
A fuzzed probe request occurs when an attacker introduces invalid, unexpected, or random data into a probe request and replays the modified frames over the air.
|
|
Fuzzed Probe Response
|
A fuzzed probe response occurs when an attacker introduces invalid, unexpected, or random data into a probe response and replays the modified frames over the air.
|
|
PS Poll Flood by Signature
|
A PS poll flood occurs when an attacker spoofs the MAC address of a wireless client and sends a large number of PS poll frames. The access point sends buffered data frames to the client, which may cause the client to miss data frames while operating in power-save mode.
|
|
EAPOL Start Flood by Signature
|
An Extensible Authentication Protocol over LAN (EAPOL) start flood occurs when an attacker floods an access point with EAPOL start frames to exhaust its internal resources.
|
|
Reassociation Request Flood by Destination
|
A reassociation request flood occurs when a device floods an access point with a large number of spoofed client reassociation requests to exhaust its resources, particularly the client association table. When the table overflows, legitimate clients cannot associate, resulting in a denial-of-service (DoS) attack.
|
|
Beacon Flood by Signature
|
A beacon flood occurs when stations receive a large number of beacons generated with different MAC addresses and SSIDs. This flood prevents clients from detecting beacons sent by corporate access points and can result in a denial-of-service (DoS) attack.
|
|
Probe Response Flood by Destination
|
A probe response flood occurs when a device floods clients with a large number of spoofed probe responses. This prevents clients from detecting valid probe responses sent by corporate access points.
|
|
Block Acknowledgement Flood by Signature
|
A block acknowledgement flood occurs when an attacker sends an invalid Add Block Acknowledgement (ADDBA) frame to an access point while spoofing a valid client MAC address. The access point then ignores valid traffic from the client until traffic outside the invalid frame range is received.
|
|
AirDrop Session
|
An AirDrop session uses Apple AirDrop to establish a peer-to-peer link for file sharing. This activity can introduce security risks by allowing unauthorized peer-to-peer networks to appear in the WLAN environment.
|
|
Malformed Association Request
|
A malformed association request occurs when an attacker sends a malformed request to an access point to exploit software defects, potentially resulting in a denial-of-service (DoS) attack.
|
|
Authentication Failure Flood by Signature
|
An authentication failure flood occurs when a device floods an access point with invalid authentication requests spoofed from a valid client, which can cause client disconnections.
|
|
Invalid MAC OUI by Signature
|
An invalid MAC OUI event occurs when a spoofed MAC address that does not contain a valid organizationally unique identifier (OUI) is used.
|
|
Malformed Authentication
|
Malformed authentication occurs when an attacker sends malformed authentication frames that may expose vulnerabilities in certain wireless drivers.
|