| RTS Virtual Carrier Sense Attack |
This alarm extends the RTS flood alarm introduced in Cisco IOS XE Bengaluru 17.4.x. The alarm triggers when an RTS frame with a large duration value is detected. An attacker can use these frames to exhaust airtime and disrupt wireless client services. |
| CTS Virtual Carrier Sense Attack |
This alarm extends the CTS flood alarm introduced in Cisco IOS XE Bengaluru 17.4.x. The alarm triggers when a CTS frame with a large duration value is detected. An attacker can use these frames to exhaust airtime and disrupt wireless client services. |
| Deauthentication Flood by Pair |
This alarm provides enhanced threat context by tracking both the source (attacker) and the destination (victim) involved in the attack. |
| Fuzzed Beacon |
A fuzzed beacon occurs when an attacker introduces invalid, unexpected, or random data into a beacon frame and replays the modified frames over the air. This can cause unexpected behavior on the destination device, such as driver crashes, operating system crashes, and stack-based overflows, and may allow execution of arbitrary code. |
| Fuzzed Probe Request |
A fuzzed probe request occurs when an attacker introduces invalid, unexpected, or random data into a probe request and replays the modified frames over the air. |
| Fuzzed Probe Response |
A fuzzed probe response occurs when an attacker introduces invalid, unexpected, or random data into a probe response and replays the modified frames over the air. |
| PS Poll Flood by Signature |
A PS poll flood occurs when an attacker spoofs the MAC address of a wireless client and sends a large number of PS poll frames. The access point sends buffered data frames to the client, which may cause the client to miss data frames while operating in power-save mode. |
| EAPOL Start Flood by Signature |
An Extensible Authentication Protocol over LAN (EAPOL) start flood occurs when an attacker floods an access point with EAPOL start frames to exhaust its internal resources. |
| Reassociation Request Flood by Destination |
A reassociation request flood occurs when a device floods an access point with a large number of spoofed client reassociation requests to exhaust its resources, particularly the client association table. When the table overflows, legitimate clients cannot associate, resulting in a denial-of-service (DoS) attack. |
| Beacon Flood by Signature |
A beacon flood occurs when stations receive a large number of beacons generated with different MAC addresses and SSIDs. This flood prevents clients from detecting beacons sent by corporate access points and can result in a denial-of-service (DoS) attack. |
| Probe Response Flood by Destination |
A probe response flood occurs when a device floods clients with a large number of spoofed probe responses. This prevents clients from detecting valid probe responses sent by corporate access points. |
| Block Acknowledgement Flood by Signature |
A block acknowledgement flood occurs when an attacker sends an invalid Add Block Acknowledgement (ADDBA) frame to an access point while spoofing a valid client MAC address. The access point then ignores valid traffic from the client until traffic outside the invalid frame range is received. |
| AirDrop Session |
An AirDrop session uses Apple AirDrop to establish a peer-to-peer link for file sharing. This activity can introduce security risks by allowing unauthorized peer-to-peer networks to appear in the WLAN environment. |
| Malformed Association Request |
A malformed association request occurs when an attacker sends a malformed request to an access point to exploit software defects, potentially resulting in a denial-of-service (DoS) attack. |
| Authentication Failure Flood by Signature |
An authentication failure flood occurs when a device floods an access point with invalid authentication requests spoofed from a valid client, which can cause client disconnections. |
| Invalid MAC OUI by Signature |
An invalid MAC OUI event occurs when a spoofed MAC address that does not contain a valid organizationally unique identifier (OUI) is used. |
| Malformed Authentication |
Malformed authentication occurs when an attacker sends malformed authentication frames that may expose vulnerabilities in certain wireless drivers. |