7.3 Wireless Network Incidents, Session Hijacking, and Packet Analysis

Key Takeaways

  • Rogue access points and Evil Twin attacks deceive wireless clients by broadcasting identical SSIDs and MAC addresses, frequently leveraging 802.11 de-authentication management frame spoofing to force client disassociation.

  • WPA2-Personal security relies on the 4-way handshake, which can be captured over the air and cracked offline via dictionary attacks, whereas WPA3 mandates Simultaneous Authentication of Equals (SAE / Dragonfly) to provide forward secrecy and resist offline dictionary attacks.

  • Defending against forged wireless management frames uses Wireless Intrusion Prevention Systems (WIPS) and IEEE 802.11w Protected Management Frames (PMF) to add integrity and replay protection to robust management frames; PMF does not prevent radio jamming.

  • Network-layer session hijacking exploits local protocol trust through ARP cache poisoning (gratuitous ARP spoofing) and DNS cache poisoning, enabling Man-in-the-Middle (MitM) traffic interception and TCP sequence number manipulation.

  • Packet forensics combines tcpdump capture filters with Wireshark display filters to reconstruct TCP streams, extract cleartext protocol payloads, and analyze anomalous TCP control flag combinations and TLS handshake metadata.

Last updated: October 2026

Wireless Network Incidents, Session Hijacking, and Packet Analysis

Wireless local area networks (WLANs) and local broadcast segments present unique challenges to incident responders. Because radio waves propagate beyond physical perimeters and broadcast domains inherently trust local link-layer protocols, adversaries can intercept traffic, hijack active sessions, and execute Man-in-the-Middle (MitM) attacks without physical building intrusion. Handling these incidents requires mastery over 802.11 protocol mechanics, address resolution vulnerabilities, and packet forensics tools like tcpdump and Wireshark to reconstruct adversarial actions and recover evidentiary artifacts.

Wireless Incident Handling and Attack Vectors

Enterprise wireless security relies on the IEEE 802.11 standard, which introduces specific attack surfaces across the radio frequency (RF) medium:

Rogue Access Points and Evil Twin Attacks

  • Rogue Access Points: Unauthorized wireless radios physically connected to internal enterprise switch ports without administrative approval. Whether installed by employees for convenience or covertly by adversaries, rogue APs bypass 802.1X Network Access Control (NAC) and firewalls, exposing internal subnets.
  • Evil Twin Attacks: Rogue access points configured by an adversary to broadcast the identical Service Set Identifier (SSID) and frequently spoof the Basic Service Set Identifier (BSSID / MAC address) of an authentic enterprise network. Transmitting with stronger signals or nearer to victims, Evil Twins induce client association, deploying captive portals to harvest credentials or intercept unencrypted traffic.

802.11 De-Authentication and Handshake Exploitation

  • De-Authentication Frame Spoofing: In legacy 802.11 standards, management frames (Type 0)—including Disassociation (Subtype 10) and De-authentication (Subtype 12)—are transmitted unencrypted and unauthenticated. An attacker spoofs the AP MAC address and transmits forged de-authentication frames to connected clients or broadcast addresses. Victims are disconnected immediately. Attackers use this to disrupt operations or force client reconnections to capture authentication handshakes.
  • WPA2 4-Way Handshake Capture and Offline Cracking: WPA2-Personal relies on a 4-way Extensible Authentication Protocol over LAN (EAPOL) handshake to derive temporal session keys. Forcing reconnection via de-authentication allows attackers to intercept EAPOL messages (ANonce, SNonce, MIC) and execute offline dictionary attacks (via aircrack-ng or hashcat mode 22000) against the Pre-Shared Key (PSK) without further network interaction.
  • WPA3 SAE (Dragonfly Handshake): WPA3 replaces PSK exchanges with Simultaneous Authentication of Equals (SAE), based on the Dragonfly handshake (RFC 7664). SAE utilizes a zero-knowledge password-authenticated key exchange that prevents offline dictionary attacks—each password guess requires an active online interaction with the AP, where attempts can be rate-limited. SAE also provides forward secrecy. Handlers must monitor for Dragonblood side-channel timing and cache vulnerabilities in unpatched implementations.
  • Wireless Defenses (WIPS and 802.11w):
    • Wireless Intrusion Prevention Systems (WIPS): Dedicated RF sensors continuously monitor airspace, detecting rogue APs, SSID spoofing, and de-authentication storms, executing containment by shutting down associated switch ports via SNMP.
    • IEEE 802.11w (Protected Management Frames / PMF): Protects robust management frames: unicast frames receive confidentiality and integrity protection, while group-addressed frames use Broadcast/Multicast Integrity Protocol protection. Forged de-authentication and disassociation frames that lack valid protection are rejected after PMF negotiation, but PMF does not protect every management frame or stop RF jamming. PMF is mandatory for WPA3.

Network-Level Session Hijacking and Man-in-the-Middle Attacks

Adversaries operating within local broadcast segments or inline positions exploit foundational protocol trust to intercept and manipulate traffic:

  • ARP Poisoning / Spoofing: The Address Resolution Protocol (ARP) resolves IPv4 addresses to MAC addresses statelessly without authentication. Using utilities like arpspoof or ettercap, an adversary transmits unsolicited gratuitous ARP replies informing the victim that the default gateway IP resides at the attacker MAC, and informing the gateway that the victim IP resides at the attacker MAC. Both nodes update their ARP caches. By enabling kernel packet forwarding (sysctl -w net.ipv4.ip_forward=1), the attacker positions their host as an inline Man-in-the-Middle (MitM), intercepting all traffic. Dynamic ARP Inspection (DAI) on managed switches prevents poisoning by validating ARP packets against the DHCP snooping binding database.
  • DNS Spoofing and Cache Poisoning: Intercepting DNS queries via MitM or injecting fraudulent resource records into recursive resolver caches (e.g., Kaminsky attacks) redirects users to attacker-controlled phishing portals.
  • TCP Session Hijacking: TCP tracks session state using 32-bit Sequence (SEQ) and Acknowledgment (ACK) numbers. If an attacker can sniff traffic or predict Initial Sequence Numbers (ISNs) generated by predictable Pseudo-Random Number Generators (PRNGs), they can inject forged TCP segments carrying expected sequence numbers. The receiving server processes the payload, causing the genuine client's session to desynchronize into an ACK storm and disconnecting the legitimate user. Mitigated by modern cryptographically secure PRNGs (RFC 6528) and TLS.

Packet Forensics and Network Traffic Analysis

Digital packet forensics enables incident handlers to reconstruct malicious activity from raw packet captures (PCAP):

  • Capture Filters (BPF) vs. Display Filters:
    • Capture Filters (Berkeley Packet Filter / BPF): Evaluated by the kernel before writing packets to disk, minimizing dropped frames during high-throughput captures with tcpdump (e.g., tcpdump -i eth0 -w capture.pcap 'tcp port 80 or tcp port 443 and not broadcast').
    • Display Filters: Evaluated post-capture within Wireshark against parsed protocol trees (e.g., ip.addr == 192.168.1.50 && tcp.flags.syn == 1 && tcp.flags.ack == 0).
  • TCP Stream Analysis and Anomaly Detection:
    • Follow TCP Stream: Wireshark reassembles fragmented TCP segments into complete bidirectional application streams, exposing plain-text protocols (HTTP, FTP, Telnet).
    • Flag Anomalies: Inspecting flag combinations reveals stealth scans and malformed packets, such as NULL packets (tcp.flags == 0), Xmas packets (tcp.flags.fin == 1 && tcp.flags.push == 1 && tcp.flags.urg == 1), and illegal SYN+FIN segments.
    • Flow Anomalies: Identifying TCP ZeroWindow warnings indicates receiver buffer exhaustion, while duplicate ACKs and retransmissions highlight packet loss or network manipulation.
  • Forensic Artifact Extraction:
    • File Extraction: Reconstructing transferred binaries and scripts via Wireshark Export Objects (File -> Export Objects -> HTTP/SMB/TFTP).
    • Cleartext Credentials: Filtering for plain-text authentication tokens (e.g., frame contains "password", http.authorization, ftp.request.command == "PASS").
    • TLS Handshake Metadata: Although TLS encrypts application data, the initial Client Hello is cleartext. Handlers extract the Server Name Indication (SNI) via tls.handshake.extensions_server_name to identify accessed hostnames, inspect certificate subject fields, and calculate JA3/JA3S fingerprints to attribute malware C2 communications.
    • Beacon Intervals: Analyzing 802.11 beacon intervals and RSN Information Elements identifies rogue AP configurations and anomalous encryption cipher suites.
Loading diagram...
ARP Cache Poisoning and Man-in-the-Middle (MitM) Flow
Test Your Knowledge

A mobile workstation operating in an enterprise office suddenly disconnects from the corporate Wi-Fi network. Network packet analysis captures a surge of 802.11 management frames with Type 0 and Subtype 12 originating from the MAC address of the legitimate corporate access point. Immediately following the disconnection, the workstation transmits four EAPOL handshake messages as it attempts to reconnect, which are recorded by an adversary monitoring the radio channel. What attack occurred, and which wireless standard mitigates this vulnerability by cryptographically protecting management frames?

A

An Evil Twin attack; mitigated by WPA2-Enterprise with PEAP-MSCHAPv2

B

A Dragonblood side-channel attack; mitigated by WPA3 SAE Dragonfly handshakes

C

A de-authentication frame spoofing attack; mitigated by IEEE 802.11w Protected Management Frames (PMF)

D

An ARP cache poisoning attack; mitigated by Dynamic ARP Inspection (DAI)

Test Your Knowledge

During an incident investigation on a local corporate subnet, an incident handler observes that an internal workstation has suddenly begun directing all external internet traffic through another local host on the same switch. Inspection of the victim machine's ARP cache reveals that the IP address of the default gateway (192.168.10.1) is now mapped to the MAC address 00:11:22:33:44:55, which belongs to a peer workstation rather than the enterprise router. Furthermore, switch logs show an influx of unsolicited gratuitous ARP replies. What security incident has taken place, and what switch-level defensive control prevents it?

A

DNS spoofing; prevented by implementing DNSSEC on local caching resolvers

B

TCP session hijacking; prevented by deploying RFC 6528 random initial sequence numbers

C

A Slowloris exhaustion attack; prevented by configuring web application firewall rate limits

D

ARP cache poisoning (spoofing); prevented by enabling Dynamic ARP Inspection (DAI) bound to DHCP snooping

Test Your Knowledge

An incident handler conducts packet analysis on a packet capture (.pcap) file retrieved from a network sensor deployed at a perimeter gateway. A compromised workstation established an outbound TLS-encrypted session over TCP port 443 with a suspicious external IP address. Because TLS payload encryption prevents direct inspection of the HTTP request and response contents, which Wireshark display filter and TLS protocol artifact should the handler inspect to determine the destination fully qualified domain name (FQDN) requested by the infected client?

A

The display filter tls.handshake.type == 1 to inspect the cleartext Server Name Indication (SNI) extension in the TLS Client Hello packet

B

The display filter http.request.uri to view the HTTP GET request path within the encrypted TLS application data

C

The display filter tcp.flags.ack == 1 to decode the TCP initial sequence number offset

D

The display filter ip.checksum_bad == 1 to identify corrupted IP packet trailers

Sections you finish are checked off in the contents.