Articles

STP SECURITY ISSUES: TCN DOS (TOPOLOGY CHANGE NOTIFICATION)

Download PDF Article on eLIBRARY.RU

Abstract

Abstract. The article examines the security issues of the Spanning Tree Protocol (STP) in the context of Topology Change Notification Denial of Service (TCN DoS) attacks aimed at disrupting the stability of Ethernet networks. The relevance of the study is determined by the fact that the classical STP standard does not provide authentication mechanisms for BPDU messages. As a result, an attacker with access to a Layer 2 segment can generate false topology change notifications and force switches to repeatedly flush their MAC address tables. The purpose of the study is to analyze the mechanism of TCN DoS attacks and to develop a protection model applicable to corporate network infrastructures. The research includes an overview of STP, RSTP and MSTP operation principles, an analysis of typical threats to data link layer protocols, and practical attack simulation in a VirtualBox environment using Alt Linux. In addition, the response of Cisco, MikroTik and Eltex network devices to increasing TCN BPDU flood intensity is compared. The results show that, in the absence of protective mechanisms, the attack causes a significant increase in switch CPU utilization, while memory consumption remains relatively stable. Based on the analysis, a comprehensive protection model is proposed, including BPDU Guard, BPDU rate limiting, Root Guard, Loop Guard, STP event monitoring and migration to more advanced protocol versions. It is concluded that the combined use of these measures reduces the risk of denial of service and improves the resilience of Layer 2 infrastructure.

Online viewer

References

  1. Spanning Tree Protocol. — Текст : электронный // Cisco : [сайт]. — URL: https://www.cisco.com/c/en/us/td/docs/routers/access/3200/software/wireless/SpanningTree.html (дата обращения: 14.03.2025).
  2. STP — Spanning Tree Protocol. — Текст : электронный // SelfDocsIng : [сайт]. — URL: https://icebale.readthedocs.io/en/latest/networks/protocols-tech/STP/ (дата обращения: 22.04.2025).
  3. Рудзейт, О. Ю. Оценка уязвимостей протоколов передачи данных в информационных системах / О. Ю. Рудзейт, Ю. В. Добржинский, В. М. Титанов // Отходы и ресурсы. — 2022. — Т. 9, № 1. — URL: https://mir-nauki.com/PDF/16ITOR122.pdf (дата обращения: 18.05.2025). — DOI: 10.15862/16ITOR122.
  4. to_0day. Атакуем L2-протоколы / to_0day. — Текст : электронный // Codeby.net : [сайт]. — URL: https://codeby.net/threads/atakuyem-l2-protokoly.69263/ (дата обращения: 07.06.2025).
  5. Мажугин, Я. О. Исследование защищенности протокола STP на предмет атак типа DDoS TCN / Я. О. Мажугин, А. К. Романов // Актуальные исследования. — 2025. — № 27-1 (262). — С. 10–19. — URL: https://apni.ru/article/12609-issledovanie-zashishennosti-protokola-stp-na-predmet-atak-tipa-ddos-tcn (дата обращения: 16.08.2025).
  6. Иванов, Ю. Б. Сетевые атаки на уровне сетевого доступа модели TCP/IP / Ю. Б. Иванов, И. А. Чубуткин // Cifra. Информационные технологии и телекоммуникации. — 2025. — № 1 (5). — DOI: 10.60797/itech.2025.5.2. — URL: https://itech.cifra.science/media/articles/15682.pdf (дата обращения: 29.09.2025).
  7. Мажугин, Я. О. Исследование защищенности протокола STP на предмет атак типа DDoS TCN / Я. О. Мажугин, А. К. Романов // Актуальные исследования. — 2025. — № 27-1 (262). — С. 10–19. — EDN XHKDKI.
  8. Уймин, А. Г. Применение отечественного сетевого оборудования Eltex и EcoRouter в рамках специальности 09.02.06 «Сетевое и системное администрирование». Вопросы импортозамещения и подготовки квалифицированных кадров в сетевом оборудовании / А. Г. Уймин, И. М. Толмачев // Автоматизация и информатизация ТЭК. — 2025. — № 11 (628). — С. 58–62. — EDN DMHQJU.
  9. RFC 1493. Definitions of Managed Objects for Bridges. — Текст : электронный // IETF Datatracker : [сайт]. — URL: https://datatracker.ietf.org/doc/html/rfc1493 (дата обращения: 11.10.2025).
  10. RFC 4188. Definitions of Managed Objects for Bridges. — Текст : электронный // IETF Datatracker : [сайт]. — URL: https://datatracker.ietf.org/doc/html/rfc4188 (дата обращения: 24.11.2025).

License

Copyright (c) 2025 I. V. Islibaev , U. A. Proshenko (Authors)

Keywords