03-16-2016 06:10 AM - edited 07-05-2021 04:47 AM
Hi
for access points not supporting ELM, and only operating in normal local mode with no submode, does the access point also go off-channel scanning and detects threats etc.. ?
what is the difference between an access point operating in normal Local mode and ELM in terms of WIPS, IDS, detecting threats etc... ?
03-17-2016 06:52 AM
Local Mode with wIPS provides wIPS detection “on-channel”, which means attackers will be detected on the channel that is serving clients. For all other channels, ELM provides best effort wIPS detection. This means that every frame the radio would go “off-channel” for a short period of time. While “off-channel”, if an attack occurs while that channel is scanned, the attack will be detected.
An AP in local mode with wIPS spends only 50 ms for off-channel scanning; it will take a long time if the attacks are off-channel. This is why ELM only provides the best effort with regard to off-channels attacks. It is recommended to use monitoring mode (MM) AP to detect off-channel attacks. On the other hand, because ELM is on operating channel most of time, it detects on-channel attacks much faster than MM AP.
To get the best output, ELM AP with WSM module is the recommended solution for WIPS deployment. Threshold-based alarms tend to cause more false positives compared to non threshold-based ones. But for some of them, the accuracy of alarms can be increased when out of sequence (OOS) logic is also taken into consideration. Therefore, these alarms are subjects for administrators to monitor, review, and fine-tune.
The features of ELM are:
03-20-2016 01:22 AM
Hello Prakash,
what can the access points without ELM support ( only Local Mode without WIPS submode) do in terms of detection, on/off channel scanning ?
03-21-2016 11:14 PM
Bump
if the access point doesn't support ELM, can it still detect on and off channel ?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: