Typical severity: High. Likelihood of attack: Low. An adversary masquerades as a legitimate Dynamic Host Configuration Protocol (DHCP) server by spoofing DHCP traffic, with the goal of redirecting network traffic or denying service to DHCP.
Design: MAC-Forced Forwarding | Implementation: Port Security and DHCP snooping | Implementation: Network-based Intrusion Detection Systems