We should check which network clients changed their AP association. This could be done by tracking which client MAC addresses correspond to which BSSID at the Sniffer level and detect events such as:
- FT handshake with a mobility zone change
- Just reassociating within the same ESS (no FT handshake)
- Sending encrypted data frames to another BSSID, indicating a missed AP transition cue
We should check which network clients changed their AP association. This could be done by tracking which client MAC addresses correspond to which BSSID at the
Snifferlevel and detect events such as: