MAC flooding
A switch attack that fills the MAC address table with forged source addresses so the switch floods frames out of every port, letting an attacker capture traffic meant for others.
A network switch learns which MAC address sits behind each port and stores the mapping in a table of limited size, often called the CAM table. It then forwards each frame only to the destination’s port. MAC flooding abuses that learning. The attacker sends a stream of frames with large numbers of forged source MAC addresses until the table is full. Once no more entries can be learned, many switches treat frames for unknown destinations the way a hub would, sending them out of every other port in the VLAN, and the attacker can capture traffic never addressed to them through packet sniffing.
The attack is commonly confused with ARP spoofing. ARP spoofing poisons the address mappings held by hosts so that traffic is redirected to the attacker; MAC flooding overloads the switch so that traffic is sent to everyone. A common countermeasure is port security, which limits how many MAC addresses a switch port will learn and can shut the port down when the limit is exceeded. IEEE 802.1X and network access control add a check on which devices may connect at all.
Exam relevance: a scenario is likely to describe a switched network where an attacker suddenly sees other users’ traffic. Candidates are expected to identify MAC flooding and to choose port security as the control.