Event Definitions

Modified on Fri, Oct 2, 2020 at 4:20 PM

Every event in the 802 Secure Console as well as external alerts (email, sms, syslog, etc) will include an identifier and severity along with other pertinent information. The specific information sent will change based on the type of alert. For instance a cellular tower based alert will include cellular information, while a trust policy violation will include both client and access point information. 


Source
Description

 AIRSHIELD

AIRSHIELD operational events

AIRCELL

AIRCELL related events

INTERROGATOR

INTERROGATOR related events

CONSOLE

Events from the Console/Platform

POLICY

Trust Policy assignments and event triggers

ANALYTICS

Results of analytic functions

WIDS

Wireless intrusion detection events sourced from AIRSHIELD

LRWPAN

802.15.4 LoRWPAN related events
PERFORMANCEWiFi Performance events


The table below provides a high-level definition of each alert type (Identifier), sorted by Severity from highest to lowest. This information is helpful to identify the specific events that may impact your organization, as well as to plan integration and incident response.



SeverityIdentifierDefinition
10NULLPROBERESPONSEA probe response to a nil SSID has been detected. Null probe responses are used by an attacker to lock up a client interface.
10ENCRYPTION CHANGEEncryption settings have changed on the Access Point
10KRACKRepeating nonces have been discovered. This indicates an AP that is vulnerable to the KRACK attack. If numerous alerts are generated, it is likely that an attack is underway.
10DISCONCODEINVALIDA disassociation frame gave an invalid disconnect reason
7CLIENT TO AIRDECOY APA client has connected to the 802 Secure AirDecoy honeypot
7NEW ACCESS POINTA new Access Point has been discovered in your air space
7WEAK OR UNENCRYPTED ACCESS POINTA new Access Point was discovered with weak or no encryption
7AP ADVERTISING NEW ESSIDAn Access Point is advertising a new / different ESSID
7ADVCRYPTOThe advertised encryption type has changed on the Access point
6AMAZON ECHO DETECTEDAn Amazon Echo client has been identified in your air space
6DRONE DETECTEDA Drone has been identified in your air space
6WIFI PRINTER DETECTEDA WiFi enabled Printer has been identified in your air space
5TRUST POLICY VIOLATIONA client has connected to a network that violates your trust policy settings
5EXCESSIVE CONNECTIONSHigh connection attempts between a client and Access Point
5CAPTIVE PORTAL ACCEPTEDA client has accepted the 802 Secure AirDecoy honeypot captive portal
5AUTOMATIC AP TRUST LEVEL ASSIGNMENT TO SUSPECTED NEIGHBORA persistent Access Point with strong encryption has been assigned to the Suspected Neighbor Trust Level. Manual assignment to a Trust Level is recommended.
5SIMILAR ESSIDAn ESSID was discovered that is similar to an ESSID identified in your Trust Level configuration
5NEW CELLULAR TOWERA new cellular tower has been detected in your air space
5AUTOMATIC AP TRUST LEVEL ASSIGNMENT TO HIGH THREATA persistent access point with weak or no encryption has been assigned to the High Threat Trust Level. Investigation and assignment to the proper Trust Level is recommended.
4VEHICLE DETECTEDA vehicle has been identified in your air space
4CONSUMER CAMERA DETECTEDA consumer camera has been identified in your air space
4DEAUTHCODEINVALIDDeauthentication frame gave an invalid disconnect reason 
4WIFI DIRECT DETECTEDA WiFi-Direct enabled device has been identified in your air space
4WIRELESS STORAGE DEVICE DETECTEDA WiFi enabled memory card (i.e. USB thumbdrive) has been identified in your air space
4DASH CAMERA DETECTEDA dash camera has been identified in your air space
4MEDICAL DEVICE DETECTEDA medical device has been identified in your air space
4WIFI TELEVISION DETECTEDA WiFi enabled TV or sign has been identified in your air space
4AMAZON FIRETV DETECTEDAn Amazon FireTV WiFi-Direct enabled media player has been identified in your airspace
4GOOGLE HOME DETECTEDA Google Home device has been identified in your air space
4ROKU DETECTEDA Roku WiFi direct enabled media player has been identified in your air space
3CHANCHANGEAn Access Point has changed channels
3AIRDECOY CLIENT CONNECTA client has connected to the 802 Secure AirDecoy honeypot
3AIRDECOY CLIENT DISCONNECTA client has disconnected from the 802 Secure AirDecoy honeypot
1NEW WPA/WPA2 HANDSHAKENew WPA handshake received
1CLIENT ASSIGNED TO GROUPA client was automatically assigned to a client group in accordance with your Trust Level rules
1AIRSHIELD ONLINEAn AirShield sensor has come online
1LOGINUser logged in
1SUSPICIOUS CELLULAR TOWERA suspicious cellular tower was identified in your air space. This could indicate nefarious activity and warrants further investigation.
1LOGOUTUser logged out
1NEW X.509 CERTIFICATEA new X.509 Server Certificate has been found on an access point. This could indicate a compromise and investigation is warranted if this was not planned or intentional.
1AIRDECOY STARTEDThe 802 Secure AirDecoy honeypot has started and is operational


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article