Articles

IMPACT OF MAC-FLOODING ATTACKS ON L2 SWITCHES IN A HYBRID NETWORK INFRASTRUCTURE

Download PDF Article on eLIBRARY.RU

Abstract

The conducted research reveals the critical vulnerability of L3 devices in hybrid networks during attacks at the channel level. It has been experimentally shown that a classic MAC flooding attack aimed at overflowing the CAM tables of access switches leads not only to a violation of the confidentiality of traffic at the L2 level, but also causes a cascading increase in load on routers (L3) due to the massive generation of unknown unicast traffic. This traffic is redirected to the router, leading to a critical load on its processor, increased response time, and a possible denial of service for the entire network infrastructure. The paper provides comparative testing of standard protection mechanisms (Port Security, Storm Control) on equipment from various manufacturers under simulated attack conditions. Experiments were conducted on the stand using Cisco, Mikrotik, and Eltex equipment, and the attack was generated using Kali Linux tools. The results demonstrate that activating Port Security in shutdown mode on access ports is the most effective way to block an attack at the source. To ensure the integrated stability of a hybrid network, this measure must be complemented by limiting broadcast traffic at the router level. The data obtained is of great practical importance for ensuring the fault tolerance and security of modern hybrid network infrastructures combining equipment from various vendors, and allows us to formulate practical recommendations for configuring security for networks combining equipment from various manufacturers in order to prevent the escalation of L2 attacks to the L3 layer.

Online viewer

References

  1. ServerGate. (2024). OSI Layers: A Simple Explanation and Differences Between L1, L2, and L3 Switches. ServerGate. Retrieved November 5, 2025, from https://servergate.ru/articles/otlichiya-kommutatorov-l1-l2-i-l3/ (accessed: 05.11.2025).
  2. Alexhost. (2024). What is MAC Flooding? How to prevent it? Alexhost. Retrieved November 20, 2025, from https://alexhost.com/ru/faq/what-is-mac-flooding-how-to-prevent-it/ (accessed: 20.11.2025).
  3. Gontharet, F. (2015). Man-in-The-Middle Attacks & Countermeasures Analysis [Master's thesis, University of Abertay Dundee]. ResearchGate. Retrieved December 10, 2025, from https://www.researchgate.net/publication/340720434_Man-in-The-Middle_Attacks_Countermeasures_Analysis (accessed: 10.12.2025).
  4. Thakur, S., Khan, A., Dave, J., & Kaulgud, S. (2018). Three tier architecture with enhanced security at layer 2 and layer 3. International Advanced Research Journal in Science, Engineering and Technology, 5(Special Issue 3), 13–18. Retrieved December 10, 2025, from https://clck.ru/3Qy9Ak (accessed: 10.12.2025).
  5. Skorobogatov, S. Yu., Zhdanova, I. M., Kuznetsov, A. V., Osipenko, A. A., & Khabushev, R. R. (2023). A methodology for predicting the impact of cyberattacks on software-defined network elements. Bulletin of the Tula State University. Technical Sciences, (2), 269–274. https://cyberleninka.ru/article/n/metodika-prognozirovaniya-vozdeystviya-kompyuternyh-atak-na-elementy-programmno-konfiguriruemoy-seti (accessed: 11.12.2025).
  6. Cisco. (2018). Configure Dynamic Host Configuration Protocol (DHCP) Snooping on a Switch through the Command Line Interface (CLI). Cisco Support. Retrieved December 20, 2025, from https://www.cisco.com/c/en/us/support/docs/smb/switches/cisco-small-business-300-series-managed-switches/smb5515-configure-dynamic-host-configuration-protocol-dhcp-snooping.html (accessed: 20.12.2025).
  7. Uymin, A. G. (2024). Computer Networks. L2 Technologies: A Practical Guide for Secondary Vocational Education. Profobrazovanie; IPR MEDIA. Retrieved November 15, 2025, from https://www.iprbookshop.ru/135231.html (accessed: 15.11.2025).
  8. Brezular, R. (2024, January 3). Protection against MAC flooding attack. Brezular.com. Retrieved December 9, 2025, from https://brezular.com/2024/01/03/protecting-against-mac-flooding-attack/ (accessed: 09.12.2025).

License

Copyright (c) 2025 E. A. Eremina , A. N. Prostova (Authors)

Keywords