Intrusion prevention using reconfiguration multi-link elements in WiFi 7
A communication link between an unauthorized AP MLD in a wireless network and a client device is terminated in response to spoofing a communication from the unauthorized AP MLD. The communication is sent from a device different than the unauthorized AP MLD to the client device and includes a source identifier that identifies the unauthorized AP MLD as a source device of the communication. The communication additionally or alternatively may contain or indicate a management or configuration element. The management or configuration element may include a reconfiguration multi-link element that specifies the first wireless communication link as no longer available.
1 . One or more non-transitory media having instructions which, when executed by one or more processors, cause a plurality of operations, the operations comprising:
upon determining that an access point multi-link device (AP MLD) prohibited from connecting to a client device is connected to the client device over a first wireless communication link:
causing a communication from the AP MLD to be spoofed by transmitting, from a device different than the AP MLD, a frame comprising (a) a source identifier that identifies the AP MLD as a source device of the frame and (b) a reconfiguration multi-link element indicating that the first wireless communication link is no longer available,
wherein the reconfiguration multi-link element comprises a value in a type subfield of a multi-link control field of the frame, and
wherein the client device terminates the first wireless communication link in response to receiving the frame.
2 . The one or more non-transitory media of claim 1 , wherein the frame further comprises (c) a destination identifier that identifies the client device as a destination device.
3 . The one or more non-transitory media of claim 1 , wherein the operations further comprise determining that the first wireless communication link is impermissible, and wherein causing the communication from the AP MLD to be spoofed is further responsive to the determining that the first wireless communication link is impermissible.
4 . The one or more non-transitory media of claim 1 , wherein the reconfiguration multi-link element further indicates that a second wireless communication link, which connects the AP MLD and the client device, is no longer available.
5 . The one or more non-transitory media of claim 1 , wherein the first wireless communication link is one of a plurality of wireless communication links established between the client device and the AP MLD, wherein the frame indicates that each of the plurality of wireless communication links is no longer available, and wherein the client device terminates each of the plurality of wireless communication links in response to receiving the frame.
6 . The one or more non-transitory media of claim 1 , wherein the frame includes an unencrypted frame.
7 . The one or more non-transitory media of claim 1 , wherein the frame includes an unencrypted beacon frame.
8 . The one or more non-transitory media of claim 1 , wherein the frame includes an unencrypted probe response frame.
9 . A system having one or more processors configured to facilitate a plurality of operations, the operations comprising:
determining that an access point multi-link device (AP MLD), prohibited from connecting to a client device, is connected to the client device over a first wireless communication link; and
based on the determining, spoofing a communication from the AP MLD by causing transmission, from a device different than the AP MLD, of a frame comprising:
a source identifier indicating the AP MLD as a source device of the frame; and
a reconfiguration multi-link element indicating that the first wireless communication link is no longer available,
wherein the frame comprises a multi-link control field having a value indicative of the reconfiguration multi-link element,
wherein the value is in a type subfield of the multi-link control field, and
wherein the frame is configured to cause the client device to terminate the first wireless communication link.
10 . The system of claim 9 , wherein the frame further comprises a destination identifier configured to identify the client device as a destination device.
11 . The system of claim 9 , wherein spoofing the communication from the AP MLD is responsive further to a determination, by the one or more processors, that the first wireless communication link is impermissible.
12 . The system of claim 9 , wherein the first wireless communication link is one of a plurality of wireless communication links established between the client device and the AP MLD, and wherein the frame indicates termination of each of the plurality of wireless communication links.
13 . The system of claim 12 , wherein the frame includes an unencrypted frame, and wherein the client device terminates each of the plurality of wireless communication links in response to receiving the unencrypted frame.
14 . A method, comprising:
in response to determining a prohibited wireless communication link between an access point multi-link device (AP MLD) and a client device, generating a frame comprising:
a source identifier and a reconfiguration multi-link element indicating that the AP MLD is a source device of the frame and that the prohibited wireless communication link is no longer available, wherein the reconfiguration multi-link element comprises a value in a multi-link control field of the frame and wherein the value is in a type subfield of the multi-link control field of the frame; and
causing the frame to be transmitted from a device different than the AP MLD, wherein the transmitting causes the client device to terminate the prohibited wireless communication link.
15 . The method of claim 14 , further comprising determining that the prohibited wireless communication link is impermissible.
16 . The method of claim 15 , wherein determining that the prohibited wireless communication link is impermissible is based on stored information indicating the AP MLD is an unauthorized AP MLD, and wherein the frame includes a destination identifier that identifies the client device as a destination device.
17 . The method of claim 14 , wherein: the prohibited wireless communication link is one of a plurality of wireless communication links established between the client device and the AP MLD; the frame indicates that each of the plurality of wireless communication links is no longer available; and the client device terminates each of the plurality of wireless communication links in response to receiving the frame.