Rogue access point
A wireless access point connected to an organisation's network without authorisation, creating an unmanaged wireless way into the wired network that bypasses perimeter controls.
A rogue access point is a wireless access point attached to an organisation’s network without approval. The classic case is not an attacker at all: an employee plugs a consumer access point into a desk socket for convenience, with default settings. The effect is the same as a malicious plant. Anyone within radio range who can join it may now reach the internal network through a path that never crosses the perimeter controls.
The term is often confused with the evil twin attack. An evil twin imitates a legitimate network name to lure users, so the victims are the clients. A rogue access point is unauthorised hardware on the inside of the network, so the main victim is the network itself, although clients that join it are exposed too. Defences therefore start at the wired edge: IEEE 802.1X or wider network access control can stop an unknown device from being granted access through a network port, and wireless intrusion detection or regular wireless surveys find access points that should not be there. NIST SP 800-153 describes a rogue access point as a possible back door into the wired network that bypasses perimeter security.
Exam relevance: a scenario in which an unapproved access point turns up on an office network is likely to concern a rogue access point, with port-based access control as the preventive measure. Candidates are expected to keep it distinct from an evil twin.