ISSUES OF PROTECTING STP AGAINST ATTACKS USING THE ROOT GUARD MECHANISM ON ACCESS/DISTRIBUTION LAYER SWITCHES
Abstract
The article examines the problem of protecting the data link layer of a corporate network against attacks aimed at spoofing the root bridge in STP and RSTP protocols. The relevance of the study is determined by the fact that, without additional protection mechanisms, an attacker with access to a switch port can send forged BPDU packets with a higher priority and trigger an unauthorized topology change. This may lead to spanning tree recalculation, temporary loss of connectivity, and conditions for traffic interception or disruption. The purpose of the study is to experimentally evaluate the effectiveness of the Root Guard mechanism in a heterogeneous network infrastructure based on Cisco Catalyst 2960, MikroTik, and Eltex MES1428 switches. During the experiment, an attack was simulated using the Yersinia tool, the network behavior with disabled and enabled protection was compared, and vendor-specific differences in Root Guard configuration and diagnostics were analyzed. The results showed that, without protection, the attacking host successfully became the root bridge in all tested scenarios, causing instability in the network topology. After Root Guard was enabled, forged superior BPDU packets were blocked, and protected ports were placed into a blocking state, preventing unauthorized Root Bridge changes. The study concludes that Root Guard is an effective mechanism for protecting L2 topology, but its correct use requires consideration of vendor-specific implementation features and proper security event monitoring.
Online viewer
References
- Malygin, V. S., & Freiman, V. I. (2022). Study of the operation of STP and RSTP technologies under various performance characteristics. Innovative Technologies: Theory, Tools, Practice, 1, 327–333. EDN EAUKDH.
- Chaika, E. Yu., & Shkurenkov, E. S. (2025). Attack on the STP protocol: Man-in-the-Middle. Testing and protection techniques. Current Research, 27(262), 37–48. Retrieved from https://apni.ru/article/12611-ataka-na-protokol-stp-man-in-the-middle-metodiki-testirovaniya-i-zashity
- IEEE. (2004). *IEEE Std 802.1D-2004: IEEE Standard for Local and Metropolitan Area Networks: Media Access Control (MAC) Bridges*. IEEE. https://doi.org/10.1109/IEEESTD.2004.94569
- IEEE. (2001). *IEEE Std 802.1w-2001: IEEE Standard for Local and Metropolitan Area Networks — Common Specifications: Rapid Reconfiguration of Spanning Tree*. IEEE. https://doi.org/10.1109/IEEESTD.2001.93365
- Seaman, M. (2009). An overview of IEEE 802.1 spanning tree protocols [Paper presentation]. IEEE 802.1 Working Group Documents. Retrieved from https://www.ieee802.org/1/files/public/docs2009/aq-seaman-merged-spanning-tree-protocols-0509.pdf
- Cisco Systems. (2019). Understanding and configuring Spanning Tree Root Guard and BPDU guard [Technical documentation]. Cisco Documentation. Retrieved from https://www.cisco.com/c/en/us/support/docs/lan-switching/spanning-tree-protocol/10588-74.html
- Uymin, A. G. (2024). Computer networks. Layer 2 technologies: Practical workbook for secondary vocational education. Profobrazovanie, IPR Media.
License
Copyright (c) 2025 M. A. Rufin , M. V. Vasiliev (Authors)