How to Enhance Wi-Fi Security Controls for PCI DSS
Summary
But, more could be done to help protect against Wi-Fi Layer 2 attacks such as flooding an access point (AP) with de-authentication frames, cracking WPA2/WPA3, and connecting a Rogue AP onto the network that allows attackers to siphon cardholder data over Wi-Fi. Wayne outlines each of the six known threat categories, as defined by the Trusted Wireless Environment framework, in this new PCI Ramblings blog post. These APs will then provide the threat actor with connectivity into the organisations networks and IT systems. Think of a Rogue AP like a long invisible ethernet cable that attackers can use to connect to a company’s Local Area Network (LAN) and comfortably work their way into the rest of the network over a Wi-Fi connection. This can occur if the client has been involved in an “Evil Twin” attack, which has resulted in malware being installed.