Detecting Rogue Switch and Device Behaviour Using Network Anomalies in LAN
Vijay Bhuse · European Conference on Cyber Warfare and Security · 2025
Local Area Networks (LANs) are crucial for modern organizations, facilitating essential communication and dataexchange in wired environments. However, wired LANs are susceptible to internal threats, exacerbated by "Bring Your OwnDevice" (BYOD) policies that increase vulnerability to rogue switches. These unauthorized switches, connected with just anEthernet cable, can be installed by compromised employees or malicious insiders, undermining network security byintercepting and manipulating data traffic. These rogue switches, often plug-and-play devices, are particularly dangerousbecause they are difficult to detect and can be used to spy on network traffic or launch cyberattacks, further increasingorganizational risks. This study presents a hybrid detection and mitigation framework that combines Dynamic ARP Inspection(DAI) with DHCP Snooping, Root Guard, and Port Security with Sticky MAC, alongside AI-driven anomaly detection. Byintegrating rule-based security mechanisms with supervised machine learning models, the system detects subtle deviationsin network traffic and automates threat mitigation. This approach enhances detection accuracy, reduces false positives, andseamlessly integrates into existing security baselines. Experimental validation was conducted using GNS3-based labsimulations with a consistent network topology to evaluate detection effectiveness and dataset generation. Various Layer 2attacks, including ARP spoofing, MAC flooding, and STP root bridge manipulation, were introduced to assess detectionaccuracy. The AI-enhanced system, trained with supervised learning using Logistic Regression, achieved 100% accuracy andan F1-score of 100% across all three attack scenarios, demonstrating its reliability in mitigating Layer 2 threats. The findingsemphasise the effectiveness of combining AI-driven anomaly detection with traditional network security mechanisms toenhance LAN security. Unlike conventional reactive approaches, this framework enables proactive, real-time detection andmitigation, adapting to evolving threats and eliminating reliance on manual monitoring. The ability to detect subtle variationsin network traffic behaviour ensures greater adaptability against sophisticated attacks. By continuously learning and refiningdetection models, the system provides scalable, intelligent, and future-ready network protection against increasinglyadvanced Layer 2 threats.