← Back to Attack / Defense Lab
OSI LAYER 2 // Data Link Layer

DHCP Starvation

DHCP starvation exhausts available addresses in a DHCP scope by causing the server to see many apparently unique clients.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

The attacker generates many client identities, consuming leases and preventing legitimate clients from obtaining addresses.

02 // DETECTION

Indicators to watch

Rapid lease allocation, many short-lived client identifiers, scope exhaustion, and sudden DHCP request volume.

03 // ATTACK FLOW

Concept diagram

01DHCP clients↓
02Many client identities↓
03Lease pool consumed↓
04Legitimate client denied↓
05DHCP snooping + rate limits
04 // PREVENTION

Defensive controls

Use DHCP snooping, port security, rate limits, appropriately sized scopes, and monitoring of lease churn.

05 // SECURITY TOOL

Recommended security control

DHCP snooping / SIEM

Use a lab DHCP server with a small test scope.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.