Evil Twin Detection with OnGuard

Policy Manager OnGuard Agent supports Evil Twin Detection for Wired Interfaces.

Introduction

To enable OnGuard Agent to check for the presence of an "evil twin" with Wired interface, a new option, Evil Twin Detection, has been added to the Agent Enforcement Profile attributes (for details, see Agent Enforcement Profile). When OnGuard Agent detects an Evil Twin for Wired interface, it sends a WebAuth request with the Host:EvilTwin attribute having the value "MayExist,” indicating that an Evil Twin may exist. The Host:EvilTwin attribute is available in Service rules, Role Mapping, and Enforcement profiles. Admins can use this attribute to take action by applying Policy Manager enforcement profiles.

 

This feature is supported only with wired interfaces; it is not available for wireless interfaces. Additionally, this feature is only supported with a network hub, not an unmanaged switch.

Configuring Evil Twin Detection for Agent Enforcement Profile

Policy Manager administrators can use the Host:EvilTwin attribute to apply other enforcement profiles to send email, issue a disconnect request, update endpoint attributes, and/or send updates to third-party firewalls Firewall is a network security system used for preventing unauthorized access to or from a private network..

To enable the Evil Twin Detection attribute for an Agent Enforcement profile:

1. Navigate to Configuration > Enforcement > Profiles.

The Enforcement Profiles page opens.

2. Click Add.

The Add Enforcement Profiles > Profile tab opens.

3. From the Template drop-down, select Agent Enforcement.

The Agent Enforcement > Profile dialog opens.

4. Specify the Profile tab parameters as described in Agent Enforcement Profile.

5. Select the Attributes tab.

6. Add the Enable Evil Twin Detection attribute as shown in Figure 1:

Figure 1  Agent Enforcement Profile > Attributes Tab

7. Click Save.

Configuring Evil Twin Detection for Enforcement Policy

To configure an enforcement policy with the Host:EvilTwin condition:

1. Navigate to Configuration > Enforcement > Enforcement Policies.

The Enforcement Policies page opens:

2. Click Add.

The Add Enforcement Policy page opens to the Enforcement tab.

3. Specify the Add Enforcement Policy > Enforcement tab parameters as described in Configuring Enforcement Policies.

4. In the Rules tab, click Add Rule to display the Rules Editor.

5. Configure the Host:EvilTwin EQUALS MayExist condition as shown in Figure 2:

Figure 2  Configuring Enforcement Policy with Evil Twin May Exist Condition

6. Click Save.

Evil Twin OnGuard WebAuth Request Attribute in Access Tracker

The Input tab shows protocol-specific attributes that Policy Manager received in a transaction request, including authentication and posture details (if available). The Input tab also shows computed attributes that Policy Manager derived from the request attributes. All of these attributes can be used in role-mapping rules.

Access Tracker records the presence of the Host:EvilTwin attribute on the WebAuth Request Details > Input page.

1. Navigate to Live Monitoring > Access Tracker.

2. From the Access Tracker page, select the pertinent WebAuth session.

The Request Details page opens.

3. Click the Input tab and select the Computed Attributes section.

The Host:EvilTwin attribute is displayed as shown in Figure 3.

Figure 3  Host:EvilTwin Attribute Displayed in Access Tracker > Request Details