Skip to content

MACsec / MKA

1. Context & stakes

The "TLS of Layer 2": point-to-point encryption + integrity.

MACsec (802.1AE) provides line-rate encryption and integrity for each Ethernet hop - the TLS of Layer 2 - defeating tapping, injection and MITM on the wire itself. Its security rests on MKA key agreement and on links never silently downgrading to cleartext. Where it is deployed, physical-layer attacks such as tapping and ARP or DHCP spoofing lose their payoff.

2. Theory

MACsec (802.1AE) encrypts and integrity-protects Ethernet frame by frame between two peers, keys negotiated by MKA (802.1X). It is the 'TLS of layer 2': a tap or rogue device sees only ciphertext, and injected/replayed frames fail the integrity check. This module studies the MKA session and what breaks it.

3. Attack (PoC)

netlab-macsec attack --i-own-this-network --iface veth-host
  1. Attempt to replay/hijack an MKA session

4. Detection

netlab-macsec detect --iface veth-host

Indicators to watch, and the associated IDS rule (see netlab-ids).

5. Defense

  • 802.1AE: per-link confidentiality and integrity
  • MKA key rotation

6. Exercise

Reproduce in the isolated lab (netns/veth): see lab setup.

7. Further reading