It's not just denial of service. First step is to kick the client off. That's DoS. Next step is spoof the station so when it tries logging back in it grabs the password. I am asking how to mitigate against that, and don't see anything beyond disabling auto logging and password rotation.