Media access control address spoofing attacks against port security

Andrew Buhr, Dale Lindskog, Pavol Zavarsky, Ron Ruhl · 2011

Abstract — In this paper we describe three separate Media Access Control (MAC) address spoofing attacks that, when deployed in specific yet common layer 2 network topologies, circumvent Cisco’s port security. We show first that, with full knowledge of the network, the vendor recommended implementation of port security is both ineffective at preventing all three of these attacks, and actually decreases the difficulty of performing two of them. Next, we re-examine the attacks under less ideal conditions and demonstrate that they are feasible. Finally, we describe mitigation strategies that reduce the likelihood of success, but we argue that the use of port security as a preventative measure is difficult and may require tradeoffs between security and performance, flexibility, administrative cost, and ease of use. Keywords-port security; spoofing attacks; mitigation stratigies I.

Read the paper · More papers on PaperTik