MAC Flooding
Chapter Sixty-Two
Syllabus topic Module 1, "Network Sniffing and Man-in-the-Middle Attacks: ... MAC flooding ... and countermeasures"
Pages 298 to 301 of 578
In one line
A switch's address table has a limited size. MAC flooding fills it with fake entries, and many switches, unable to record where a real address belongs, fall back to sending traffic to every port, like a hub, so an attacker can read it. The fix is one switch feature: port security.
In examination wording: MAC flooding is an attack that overwhelms a switch's finite MAC address table with a large number of frames bearing forged source addresses; when the table is exhausted, some switches fail open and broadcast frames for which they have no table entry to all ports, restoring the shared-medium behaviour of a hub and permitting sniffing.
The mechanism
The previous chapter said a switch learns which MAC address is on which port by watching the source addresses of the frames it receives, and stores those mappings in a table. That table is the key to the attack, and to its defence, so understand it precisely.
The table is finite: a switch has room for a certain number of MAC-to-port mappings, and no more. Under normal operation this is ample, because a network has far fewer machines than the table can hold.
MAC flooding abuses the learning mechanism. The attack sends a flood of frames with many different forged source MAC addresses, each of which the switch dutifully learns and records, because learning from source addresses is exactly what it is built to do. Very quickly the table fills up with these fake entries.
Now the switch faces a full table and a frame for a real destination it can no longer find room to have recorded. What it does next depends on the switch, and the dangerous behaviour is the common one: it fails open, meaning that for any destination not in its table it falls back to sending the frame out of every port, exactly as a hub would. The switch has, in effect, been turned back into a hub, and every machine now receives everyone's traffic, which the attacker (in promiscuous mode) reads.
Two things to note. First, this is noisy: a flood of thousands of new MAC addresses in a short time is a conspicuous event, quite unlike normal traffic. Second, it is indiscriminate: it degrades the switch for everyone, so it is disruptive as well as a sniffing method, and a switch that fails open under it is also easier to overload.
Why not every switch fails open
An honest qualification. Not all switches fail open under table exhaustion; some fail closed, dropping frames for destinations they cannot record rather than broadcasting them, which turns the attack into a denial of service (legitimate traffic is dropped) rather than a sniffing opportunity. And managed switches with the countermeasure below do not reach the failure state at all.
MAC Flooding
So MAC flooding is most effective against older or unmanaged switches that fail open, and its relevance today is partly historical and partly a reminder that unmanaged switches on a network are a weakness. It remains examinable and it remains the clearest illustration of the "defeat the switch" idea, which is why it opens the trio.
The countermeasure: port security
The defence is a single, widely available switch feature called port security, and understanding the mechanism makes the control obvious.
Port security limits the number of MAC addresses a switch will learn on each port, and defines what to do when that limit is exceeded. A normal access port connects to one machine, or a small known number, so it should never see dozens of different source addresses. Configuring the port to accept only a small number, and to shut the port down or drop the excess when more appear, means the flood cannot fill the table: the attacking port hits its limit almost immediately and is disabled or ignored, and the flood never reaches the switch-wide table.
Additional switch controls that harden this further:
- Sticky or static MAC bindings, tying a port to the specific address expected on it, so an unexpected address is rejected outright.
- Disabling unused ports, so there is no open socket to plug a flooding device into.
- Storm control, which caps the rate of broadcast and unknown-destination traffic, limiting the effect even if a table were exhausted.
Because port security is a standard feature of managed switches, the practical recommendation is straightforward: use managed switches, enable port security on access ports, and do not have unmanaged switches on the network. And, as always in this block, encrypt traffic in transit, so that even a switch that somehow failed open would leak only ciphertext, which is the countermeasures chapter's universal point applied here.
A worked example, run as a defender
An assessor reviews a client's switching, with authorisation.
- The access-layer switches are managed and have port security enabled, limiting each access port to a small number of MAC addresses and shutting a port that exceeds it. A flooding attempt against such a port would disable that port at once and never fill the table. Recorded as the correct posture.
- One area uses a small unmanaged switch under a desk, added for convenience. It has no port security and, being older, would fail open under flooding. Finding: an unmanaged switch is a weak point that could be turned into a hub.
- Sensitive internal applications use TLS, so even a successful flood would expose only ciphertext for their contents. Recorded as defence in depth.
MAC Flooding
Recommendations: replace the unmanaged switch with a managed one and enable port security; disable unused ports; and, as the durable control, ensure applications encrypt in transit so that no switch failure exposes contents. The assessor establishes the risk by inspecting configuration, not by flooding the live network, which would be disruptive and is unnecessary to make the finding.
What beginners get wrong
- Thinking MAC flooding breaks the switch cleverly. It simply overflows a finite table by abusing the normal learning mechanism; the effect is to make the switch behave like a hub.
- Assuming every switch fails open. Some fail closed, turning the attack into a denial of service; managed switches with port security do not reach the failure state.
- Believing it is stealthy. A flood of thousands of new MAC addresses is conspicuous and disruptive.
- Forgetting unmanaged switches. They are the switches without the countermeasure, and they are where this attack still works.
- Relying on the switch alone. The durable defence is encryption in transit, so that a switch failing open leaks only ciphertext.
Quick revision
- A switch learns MAC-to-port mappings into a finite table. MAC flooding sends many frames with forged source MACs, filling the table.
- Many switches then fail open, broadcasting frames for unknown destinations to every port, behaving like a hub and permitting sniffing; some fail closed (a denial of service instead). Most effective against older or unmanaged switches.
- It is noisy and disruptive, degrading the switch for everyone.
- Countermeasure: port security, limiting the number of MAC addresses per port and shutting or restricting a port that exceeds it, so the flood cannot fill the table. Plus static/sticky MAC bindings, disabling unused ports, storm control, and managed switches only.
- As always, encrypt in transit so a switch failing open leaks only ciphertext.
Test yourself
- Explain the mechanism of MAC flooding.
A switch learns which MAC address is on which port by recording the source addresses of incoming frames into a finite table. MAC flooding sends a large number of frames with different forged source MAC addresses, each of which the switch records, quickly exhausting the table. With the table full, the switch can no longer record where real destinations are, and many switches then fail open, broadcasting frames for unknown destinations to every port like a hub, which permits sniffing.
- Why does MAC flooding not work equally against all switches?
Because switches differ in how they behave when the table is exhausted: some fail open and broadcast, which enables sniffing, while others fail closed and drop frames they cannot record, which produces a denial of service rather than a sniffing opportunity. Managed switches with port security do not reach the exhaustion state at all, so the attack is most effective against older or unmanaged switches that fail open.
MAC Flooding
- What is port security, and how does it stop MAC flooding?
Port security is a switch feature that limits the number of MAC addresses learned on each port and specifies an action, such as shutting the port or dropping the excess, when the limit is exceeded. Because a normal access port connects to only one or a few machines, the flood's many forged addresses immediately breach the limit on the attacking port, which is disabled or ignored, so the forged entries never fill the switch-wide table.
- Why is MAC flooding considered disruptive as well as a sniffing method?
Because it is indiscriminate: filling the table degrades forwarding for every machine on the switch, and a switch that fails open by broadcasting all unknown-destination traffic loses the efficiency that a switch provides, so the attack harms availability for everyone, not only the intended eavesdropping target.
- Why does encryption in transit remain relevant even where port security is deployed?
Because it is the defence in depth that makes any switch failure harmless: if a switch were somehow made to fail open despite the controls, encrypted traffic would still expose only ciphertext for its contents, so the durable protection of the data does not depend solely on the switch configuration being correct.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.