A security analyst notices that the DHCP server is responding to a large number of DHCP Discover messages from a single MAC address, but that client never sends a DHCP Request to complete the lease. This pattern repeats continuously. Which type of attack is most likely occurring?
Trap 1: ARP poisoning
ARP poisoning involves sending forged ARP messages to associate the attacker's MAC with a legitimate IP address. This does not directly target DHCP.
Trap 2: DNS amplification
DNS amplification is a type of DDoS attack that uses misconfigured DNS servers to flood a target with traffic. It is not related to DHCP.
Trap 3: Rogue DHCP server
A rogue DHCP server attack involves an unauthorized server offering IP addresses to clients, potentially intercepting traffic. Here, the legitimate server is being flooded, not spoofed.
- A
ARP poisoning
Why it fails: ARP poisoning involves sending forged ARP messages to associate the attacker's MAC with a legitimate IP address. This does not directly target DHCP.
- B
DNS amplification
Why it fails: DNS amplification is a type of DDoS attack that uses misconfigured DNS servers to flood a target with traffic. It is not related to DHCP.
- C
DHCP starvation
DHCP starvation floods the server with Discover messages using spoofed or repeated MAC addresses, exhausting the available address pool so legitimate clients cannot obtain leases. The absence of any DHCP Request confirms the attacker only consumes addresses rather than completing leases.
- D
Rogue DHCP server
Why it fails: A rogue DHCP server attack involves an unauthorized server offering IP addresses to clients, potentially intercepting traffic. Here, the legitimate server is being flooded, not spoofed.