Meaning
Malicious actors can overwhelm a wireless access point by sending a massive volume of management frames that do not require an established security session. This type of denial of service attack known as unauthenticated frame flooding exploits the fact that certain messages must be processed before the device knows the identity of the sender. It forces the target to spend all its resources dealing with fake requests while legitimate traffic is ignored.
Protocol Vulnerability
Wireless standards like 802.11 include frames for discovery and authentication that are transmitted in the clear. Because unauthenticated frame flooding uses these basic message types, it is difficult for a simple radio to ignore them. The attacker sends thousands of association or probe requests per second, each with a different spoofed mac address.
This fills up the internal tables of the access point and prevents new devices from joining the network while the existing connections suffer from the overhead.
Network Congestion
High volumes of junk data consume the available airtime and prevent real data from getting through. Even if the processor in the access point is fast enough to discard the packets, the radio medium remains blocked by the unauthenticated frame flooding. This interference affects every device on the same channel regardless of their security settings.
Mitigation Technique
Modern network controllers use rate limiting to ignore a sudden burst of management traffic from a single area. Implementing the 802.11w standard for protected management frames also helps reduce the impact of unauthenticated frame flooding by encrypting certain control messages. Monitoring the ratio of management frames to data frames provides a way to detect an ongoing attack.