skip to content

A laptop in the car park beacons your corporate SSID — what does hunting and containing it cost?

level: seniorimportance: nice to knowfreq 28%

answer

  1. detection is bounded by sensor coverage
  2. off-channel scanning costs airtime
  3. sensors cost capital per site
  4. containment can hit the neighbours
  5. it never fixes the client profile

basics

~20 s

Detection costs airtime or hardware: serving radios must leave the channel to scan, or you buy sensors per site. Containment costs more, since it can disrupt a neighbouring tenant, may be unlawful, and never fixes the client setting.

solid answer

~50 s

Rogue hunting is the only detection you have for a radio that is not your equipment, and it is bounded by where your sensors are. Serving access points can scan off-channel, but every excursion is airtime taken from clients on the serving channel, which shows first on latency-sensitive traffic; dedicated monitor radios avoid that and cost capital per site, including the branch sites with one access point and no budget line. Physical walks fill the gap and cost staff time on a cadence somebody must own. Containment is worse: it works by disrupting associations, so on a shared floor it can hit a neighbouring tenant, and deliberately disrupting other people's wireless is a regulatory problem in some jurisdictions. And it treats a symptom — remove this rogue and the next one works identically on the same unvalidated supplicants.

go deeper

for a junior

Know that detecting a rogue access point requires something listening on the air, and that anywhere without a sensor is simply unseen.

for a middle

Explain the trade between off-channel scanning on serving radios and dedicated sensors, and what each one costs.

for a senior

Show you scope containment carefully, understand the collateral on a shared floor, and report coverage alongside findings rather than a bare alert count.

for a principal

Be able to argue the detection budget against the cheaper fix, and to say who must sign for disrupting transmissions you do not own.

## What detection can actually see A wireless intrusion detection capability compares what the air contains against what your infrastructure is. Your corporate SSID transmitted from a radio whose identifier is not in your inventory is the signal. Signal strength across several sensors gives a rough bearing, which is what turns an alert into a walk. Everything about that depends on coverage. A radio the sensors cannot hear does not exist to you, and the estate this leaf describes — branch sites with one or two access points on consumer broadband, plus a shared floor where neighbouring radios overlap yours — has enormous gaps. So the first honest statement is a direction-of-claim one: the absence of a rogue alert is not evidence that no rogue operated. It is evidence that none was heard. ## The three ways to pay for detection **Off-channel scanning on serving radios.** The access points that carry your clients periodically leave the serving channel to listen elsewhere. This is the cheapest option because you already own the hardware, and the cost is airtime: clients on that radio get nothing during the excursion. It is invisible on file transfers and very visible on real-time traffic, so the scan aggressiveness knob is a direct trade of detection latency against call quality. Sites running voice or handheld scanners are exactly the sites that cannot afford aggressive scanning, and are often the sites with the least other coverage. **Dedicated monitor radios or sensors.** A radio that never serves clients scans continuously and costs nothing in airtime. It costs capital, per site, and it has to be mounted, cabled and maintained. Getting that funded for a flagship office is easy and for two hundred branches is not, so coverage ends up shaped like the budget rather than like the risk. **Feet.** A scheduled walk with a handheld survey covers what no sensor does, including the car park. It costs staff time on a cadence somebody has to own and defend when the quarter is busy, and it only samples — a laptop that runs for forty minutes on a Tuesday is not there when you walk on Thursday. Most estates end up with a mix, and the mix should be stated explicitly: which sites have continuous coverage, which have opportunistic scanning, which have neither and are covered only by a walk cadence. ## Why containment is the expensive answer Automatic containment works by disrupting the associations between the rogue and its clients. Three problems follow. First, **collateral**. Identification is by network name and radio identifier, and on a shared multi-tenant floor a mis-scoped containment rule reaches a neighbouring tenant's clients. You have then caused an outage in someone else's business from your own equipment. Second, **legality and contract**. Deliberately disrupting radio transmissions you do not own is treated as interference in several jurisdictions, and regulators have penalised venue operators for blocking guests' own wireless. Building leases for shared floors frequently say something about it too. This is not a setting an engineer should switch on alone; it needs someone who can accept the consequence. Third, and most importantly, **it treats the symptom**. The rogue in the car park is only valuable because some devices complete an authentication exchange with anything that announces the right name. Containing this one changes nothing about that. The fix is in the supplicant profile, and rogue hunting exists to tell you the failure is being exploited — not to be the defence. ## How to size the programme honestly Set the cadence from what you can staff, not from what you would like: continuous sensing where it is funded, a stated scan aggressiveness elsewhere with the airtime cost written down, and a walk frequency per site tier. Then record the coverage gaps as gaps rather than as zero findings. A quiet quarter from a programme with no sensors at half the estate is not a result, and reporting it as one is how these programmes get quietly defunded — and then genuinely stop working.

  • You had no rogue alerts all quarter. What can you conclude?
    That nothing was heard, not that nothing operated. The claim is bounded by sensor coverage, scan duty cycle and the hours a rogue was active. Report it as coverage plus findings — which sites had continuous sensing, which had opportunistic scanning, which were covered only by a walk — so a quiet quarter is not mistaken for an assured one.
  • Your platform offers automatic containment of rogues. Do you enable it?
    Not by default and not alone. Scope it to radios you can positively identify as unauthorised on your own premises, never to anything merely reusing a name, and get a decision from someone who can accept the regulatory and lease consequences of disrupting a neighbour. On a shared floor the default answer is manual investigation with a walk.

Patrolling for counterfeit signs outside your shop is worth doing, but the real fix is that customers check the receipt rather than the sign. Patrols cost wages and never scale to every street.

saying these in an interview costs you the question

  • Treats zero rogue alerts as proof no rogue existed
  • Enables automatic containment without scoping or sign-off
  • Ignores the airtime cost of off-channel scanning on voice sites
  • Assumes sensor coverage extends to a car park
  • Presents containment as the fix for unvalidated supplicants

context