MIB Viewer

CISCO-DOT11-WIDS-MIB

45 objects
This MIB is intended to be implemented on the following IOS based network entities for the purpose of providing network management stations information about the various attempts to compromise the security in the 802.11-based wireless networks. (i) 802.11 Access Points that accept wireless client associations. The MIB reports the information about the following attacks that can happen either at the initial authentication phase or during normal data communication between the client and the AP. EAPOL flooding - This is an attempt made by an invalid 802.11 client to send too many EAPOL-Start messages and bring the authentication services on the Authenticator, typically the AP, down. BlackListing - This is the process of marking a client as invalid when its authentication attempts fail. The client is put in a list when its authentication attempt fails for the first time. If the number of consecutive failed authentication attempts reach a threshold, any subsequent authentication requests made by the client will be rejected from that point for a configurable period of time. Protection Failures - These kind of failures happen when the attacker injects invalid packets onto the wireless network thereby corrupting the 802.11 data traffic between an AP and its associated wireless clients. The administrator, through the NMS, can configure the thresholds on the AP using this MIB to enable the AP detect the EAPOL flood attacks and provide related statistics to the NMS. To detect protection failures, the AP provides the relevant statistics about the protection errors in the form of MIB objects, which are compared against the thresholds configured on the NMS and appropriate events are raised by the NMS, if thresholds are found to be exceeded. The hierarchy of the AP and MNs is as follows. +~-~-~+ +~-~-~+ +~-~-~+ +~-~-~+ + + + + + + + + + AP + + AP + + AP + + AP + + + + + + + + + +~-~-~+ +~-~-~+ +~-~-~+ +~-~-~+ .. . . . .. . . . . . . . . . . . . . . . . . . . . . . . \/ \/ \/ \/ \/ +.....+ +.....+ +-.-.-.+ +~-~-~+ +......+ + + + + + + + + + + + MN + + MN + + MN + + MN + + MN + + + + + + + + + + + +.....+ +.....+ +-.-.-.+ +~-~-~+ +......+ The wireless connections are represented as dotted lines in the above diagram. GLOSSARY Access Point ( AP ) An entity that contains an 802.11 medium access control ( MAC ) and physical layer ( PHY ) interface and provides access to the distribution services via the wireless medium for associated clients. Mobile Node ( MN ) A roaming 802.11 wireless device in a wireless network associated with an access point. Service Set Identifier (SSID) The Radio Service Set ID that is used by the mobile wireless clients for identification during the association with the APs. Temporal Key Integrity Protocol (TKIP) A security protocol defined to enhance the limitations of WEP. Message Integrity Check and per-packet keying on all WEP-encrypted frames are two significant enhancements provided by TKIP to WEP. Counter mode with CBC-MAC Protocol (CCMP) A security protocol that uses the counter mode in conjunction with cipher block chaining. This method divides the data into blocks, encrypts the first block, XORs the results with the second block, encrypts the result, XORs the result with the next block and continues till all the blocks are processed. This way, this protocol derives a 64-bit MIC which is appended to the plaintext data which is again encrypted using the counter mode. Message Integrity Check (MIC) The Message Integrity Check is an improvement over the Integrity Check Function (ICV) of the 802.11 standard. MIC adds two new fields to the wireless frames - a sequence number field for detecting out-of-order frames and a MIC field to provide a frame integrity check to overcome the mathematical shortcomings of the ICV. 802.1x The IEEE ratified standard for enforcing port based access control. This was originally intended for use on wired LANs and later extended for use in 802.11 WLAN environments. This defines an architecture with three main parts - a supplicant (Ex. an 802.11 wireless client), an authenticator (the AP) and an authentication server(a Radius server). The authenticator passes messages back and forth between the supplicant and the authentication server to enable the supplicant get authenticated to the network. Extensible Authentication Protocol Over LAN (EAPOL) This is an encapsulation method defined by 802.1x passing EAP packets over Ethernet frames.
Imported Objects
CISCO-SMIciscoMgmt
IF-MIBifIndex
SNMPv2-CONFMODULE-COMPLIANCE OBJECT-GROUP
SNMPv2-SMICounter32 Integer32 MODULE-IDENTITY OBJECT-TYPE Unsigned32
SNMPv2-TCMacAddress TimeStamp TruthValue
OIDNameAccessStatusDescription
1.3.6.1.4.1.9.9.456IdentityciscoDot11WidsMIBThis MIB is intended to be implemented on the following IOS based network entities for the purpose of providing network management stations information about t…
1.3.6.1.4.1.9.9.456.0NodeciscoDot11WidsMIBNotifs
1.3.6.1.4.1.9.9.456.1NodeciscoDot11WidsMIBObjects
1.3.6.1.4.1.9.9.456.1.1NodeciscoDot11WidsAuthFailures
1.3.6.1.4.1.9.9.456.1.1.1ScalarcDot11WidsFloodDetectEnableread-writecurrentThis object is used to enable or disable the WIDS flood detection feature. Set this MIB object to 'true' to enable the flood detection and 'false' to disable i…
1.3.6.1.4.1.9.9.456.1.1.2ScalarcDot11WidsEapolFloodThresholdread-writecurrentThis object specifies the maximum number of authentication attempts allowed for all the clients taken together in the interval specified by cDot11WidsEapolFloo…
1.3.6.1.4.1.9.9.456.1.1.3ScalarcDot11WidsEapolFloodIntervalread-writecurrentThis object specifies the time duration for which the client authentication attempts have to be monitored for detecting the flood attack.
1.3.6.1.4.1.9.9.456.1.1.4ScalarcDot11WidsBlackListThresholdread-writecurrentThis object configures the maximum threshold on the number of unsuccessful authentication attempts, that can be made by a particular client. Once the threshold…
1.3.6.1.4.1.9.9.456.1.1.5ScalarcDot11WidsBlackListDurationread-writecurrentThis object indicates the time duration for which a particular client has to be kept in the black list after the number of unsuccessful attempts reach the thre…
1.3.6.1.4.1.9.9.456.1.1.6ScalarcDot11WidsFloodMaxEntriesPerIntfread-writecurrentThis object indicates the maximum number of entries that can be held for a particular 802.11 radio interface identified by ifIndex.
1.3.6.1.4.1.9.9.456.1.1.7TablecDot11WidsEapolFloodTablenot-accessiblecurrentThis table gives the statistics on the EAPOL flood attacks observed at this radio interface. An entry in this table is created by the agent when this 802.11 st…
1.3.6.1.4.1.9.9.456.1.1.7.1RowcDot11WidsEapolFloodEntrynot-accessiblecurrentAn entry holds the statistics about one instance of EAPOL flood attack observed at this particular radio interface.
1.3.6.1.4.1.9.9.456.1.1.7.1.1ColumncDot11WidsEapolFloodIndexnot-accessiblecurrentThis object identifies the set of information about one instance of an EAPOL flood event observed at this radio interface between the start and stop times indi…
1.3.6.1.4.1.9.9.456.1.1.7.1.2ColumncDot11WidsEapolFloodClientMacread-onlycurrentThis object identifies the MAC address of the wireless client that has made the maximum number of authentication attempts in the duration specified by the cDot…
1.3.6.1.4.1.9.9.456.1.1.7.1.3ColumncDot11WidsEapolFloodClientCountread-onlycurrentThis object provides the count associated with the client with largest number of attempts in the last interval. When the flood event is observed to be stopped,…
1.3.6.1.4.1.9.9.456.1.1.7.1.4ColumncDot11WidsEapolFloodStartTimeread-onlycurrentThis object indicates the time at which the EAPOL flood event identified by one entry of this table was observed first at this radio interface.
1.3.6.1.4.1.9.9.456.1.1.7.1.5ColumncDot11WidsEapolFloodStopTimeread-onlycurrentThis object indicates the time at which the the EAPOL flood event observed first at the time indicated by cDot11WidsEapolFloodStartTime has stopped. If this 80…
1.3.6.1.4.1.9.9.456.1.1.7.1.6ColumncDot11WidsEapolFloodTotalCountread-onlycurrentThis object gives the accumulated count of the number of authentication attempts made by all the clients at the time of query.
1.3.6.1.4.1.9.9.456.1.1.8TablecDot11WidsBlackListTablenot-accessiblecurrentThis table gives the information about the 802.11 wireless clients that have been blacklisted while attempting to get authenticated with this 802.11 station at…
1.3.6.1.4.1.9.9.456.1.1.8.1RowcDot11WidsBlackListEntrynot-accessiblecurrentEach entry holds the information about one 802.11 wireless client that has been blacklisted when attempting to get authenticated with this 802.11 station at th…
1.3.6.1.4.1.9.9.456.1.1.8.1.1ColumncDot11WidsBlackListClientMacnot-accessiblecurrentThis object indicates the Mac Address of the blacklisted client.
1.3.6.1.4.1.9.9.456.1.1.8.1.2ColumncDot11WidsBlackListAttemptCountread-onlycurrentThis object counts the total number of attempts made by the client identified by cDot11WidsBlackListClientMac to get authenticated with the 802.11 station thro…
1.3.6.1.4.1.9.9.456.1.1.8.1.3ColumncDot11WidsBlackListTimeread-onlycurrentThis object indicates the time at which the client was blacklisted after failing in its attempt to get authenticated with this 802.11 station at this radio int…
1.3.6.1.4.1.9.9.456.1.2NodeciscoDot11WidsProtectFailures
1.3.6.1.4.1.9.9.456.1.2.1TablecDot11WidsProtectFailClientTablenot-accessiblecurrentThis table gives the statistics on the various protection failures occurred during the data communication of this 802.11 station with a particular client curre…
1.3.6.1.4.1.9.9.456.1.2.1.1RowcDot11WidsProtectFailClientEntrynot-accessiblecurrentEach entry holds the information about the protection failures observed at this radio interface when this 802.11 station communicates with its associated clien…
1.3.6.1.4.1.9.9.456.1.2.1.1.1ColumncDot11WidsSsidnot-accessiblecurrentThis object specifies one of the SSIDs of this radio interface using which the client has associated with the 802.11 station.
1.3.6.1.4.1.9.9.456.1.2.1.1.2ColumncDot11WidsClientMacAddressnot-accessiblecurrentThis object identifies the MAC address of the associated client to which this set of statistics are applicable.
1.3.6.1.4.1.9.9.456.1.2.1.1.3ColumncDot11WidsSelPairWiseCipherread-onlycurrentThis object identifies the pairwise cipher used by the client identified by cDot11WidsClientMacAddress during its association with this 802.11 station at the i…
1.3.6.1.4.1.9.9.456.1.2.1.1.4ColumncDot11WidsTkipIcvErrorsread-onlycurrentThis object counts the total number of TKIP ICV Errors observed in the data communication between this 802.11 station and the client indicated by cDot11WidsCli…
1.3.6.1.4.1.9.9.456.1.2.1.1.5ColumncDot11WidsTkipLocalMicFailuresread-onlycurrentThis object counts the total number of TKIP local MIC failures observed in the data communication between this 802.11 station and the client indicated by cDot1…
1.3.6.1.4.1.9.9.456.1.2.1.1.6ColumncDot11WidsTkipRemoteMicFailuresread-onlycurrentThis object counts the total number of TKIP remote MIC failures observed in the data communication between this 802.11 station and the client indicated by cDot…
1.3.6.1.4.1.9.9.456.1.2.1.1.7ColumncDot11WidsCcmpReplaysread-onlycurrentThis object counts the total number of CCMP replay failures observed in the data communication between this 802.11 station and the client indicated by cDot11Wi…
1.3.6.1.4.1.9.9.456.1.2.1.1.8ColumncDot11WidsCcmpDecryptErrorsread-onlycurrentThis object counts the total number of CCMP decryption failures observed in the data communication between this 802.11 station and the client indicated by cDot…
1.3.6.1.4.1.9.9.456.1.2.1.1.9ColumncDot11WidsTkipReplaysread-onlycurrentThis object counts the total number of TKIP replay failures observed in the data communication between this 802.11 station and the client indicated by cDot11Wi…
1.3.6.1.4.1.9.9.456.1.2.1.1.10ColumncDot11WidsWepReplaysread-onlycurrentThis object counts the total number of WEP Replay errors observed in the data communication between this 802.11 station and the client indicated by cDot11WidsC…
1.3.6.1.4.1.9.9.456.1.2.1.1.11ColumncDot11WidsWepIcvErrorsread-onlycurrentThis object counts the total number of WEP ICV errors observed in the data communication between this 802.11 station and the client indicated by cDot11WidsClie…
1.3.6.1.4.1.9.9.456.1.2.1.1.12ColumncDot11WidsCkipReplaysread-onlycurrentThis object counts the total number of CKIP replay errors observed in the data communication between this 802.11 station and the client indicated by cDot11Wids…
1.3.6.1.4.1.9.9.456.1.2.1.1.13ColumncDot11WidsCkipCmicErrorsread-onlycurrentThis object counts the total number of CKIP-CMIC errors observed in the data communication between this 802.11 station and the client indicated by cDot11WidsCl…
1.3.6.1.4.1.9.9.456.2NodeciscoDot11WidsMIBConform
1.3.6.1.4.1.9.9.456.2.1NodeciscoDot11WidsMIBCompliances
1.3.6.1.4.1.9.9.456.2.1.1ComplianceciscoDot11WidsMIBCompliancecurrentThe compliance statement for the SNMP entities that implement the ciscoDot11WidsMIB module.
1.3.6.1.4.1.9.9.456.2.2NodeciscoDot11WidsMIBGroups
1.3.6.1.4.1.9.9.456.2.2.1GroupciscoDot11WidsAuthFailGroupcurrentThis collection of objects provide information about configuration needed on the 802.11 station to detect the EAPOL flood attacks and black-list clients, the g…
1.3.6.1.4.1.9.9.456.2.2.2GroupciscoDot11WidsProtectFailGroupcurrentThis collection of objects provide information about the various protection failures observed during the associated clients' data communications with this 802.…