MAC flooding (CAM overflow)¶
1. Context & stakes¶
Saturate the switch CAM table to force fail-open (hub) behaviour.
A switch learns MAC-to-port mappings in a fixed-size CAM table; flooding it with thousands of bogus source MACs fills that table so the switch fails open and floods every frame out every port, degrading to a hub. The attacker then sniffs traffic that switching was supposed to isolate. Port security, limiting MACs per port, is the direct defence.
2. Theory¶
A switch forwards using its CAM/MAC table (MAC -> port), learned from source addresses, and the table is finite. Flooding frames with thousands of random source MACs fills it; once full the switch fails open and floods every frame out all ports like a hub - so the attacker sees traffic meant for others.
3. Attack (PoC)¶
- Flood frames with random source MACs
- Sniff the fail-open traffic
4. Detection¶
Indicators to watch, and the associated IDS rule (see
netlab-ids).
5. Defense¶
- Port security: per-port MAC limit
- Sticky MAC, shutdown on violation
6. Exercise¶
Reproduce in the isolated lab (netns/veth): see lab setup.
7. Further reading¶
- IEEE 802.1D (MAC learning / forwarding)
- Port security (per-port MAC limits)
- dsniff (
macof)