Rogue AP
Rogue Access Point
Unautorisierter WLAN-Zugangspunkt
A rogue AP is an unauthorised Wi-Fi access point — either set up by an attacker to intercept users or carelessly plugged into the network by employees. In both cases an uncontrolled access arises that bypasses the network boundary. A particularly tricky variant is the „evil twin“, which deceptively imitates a familiar network.
History & facts. Two cases are distinguished: the malicious rogue AP, such as an evil twin that imitates the name of a known network so that devices connect automatically and their traffic can be intercepted (a precursor to MitM); and the unintentional access point installed by employees, which opens an unsecured door into the internal network. Both undermine the planned network architecture.
Outlook & recommendation. Protection begins with visibility over one's own radio landscape: regular detection of unknown access points, clear policies against privately connected devices and port security at the switch level. For end devices it helps to restrict automatic connection to known network names and to handle sensitive matters only over trustworthy, encrypted connections. Since a rogue AP is frequently the first building block of further attacks, its detection belongs in network monitoring.