Articles

PROTECTION AGAINST CAM TABLE OVERFLOW ATTACKS ON L2+ DEVICES

Download PDF Article on eLIBRARY.RU

Abstract

In modern local area networks, the CAM Table Overflow attack poses a critical L2 security threat, causing the switch's MAC address table to become flooded with a flood of fake addresses. A successful attack puts the device into flooding mode, allowing the attacker to intercept sensitive traffic and places a critical load on hardware resources (CPU up to 85%, RAM up to 75%), disrupting network service availability. The objective of this study was to compare mitigation methods for this threat: Port Security, Storm Control, and DHCP Snooping. The research methodology included attack simulation using the macof utility and an evaluation of the effectiveness of defense mechanisms on Cisco, Eltex, and MikroTik equipment. The selection criteria included response speed, blocking accuracy, and impact on traffic. The experimental results confirmed the superiority of Port Security technology. When this mechanism is activated, the switch instantly (within 2-5 seconds) blocks the intruder's port in secure-shutdown mode, limiting the table to two entries instead of 8124. CPU load is reduced to 10%, and RAM is unloaded to 35%, while legitimate nodes continue to operate. Unlike similar mechanisms, Port Security provides direct protection against the root cause of the attack, rather than merely mitigating its consequences. It is concluded that implementing Port Security is the most universal and reliable solution for protecting L2+ switches from CAM table overflows. It is recommended to use this mechanism as a basic one.

Online viewer

References

  1. Olifer, V. G., & Olifer, N. A. (2021). Computer networks: Principles, technologies, and protocols (5th anniversary ed.). Piter.
  2. CAM-table overflow attack: Protection methods. (n.d.). Security.Lab. Retrieved November 11, 2025, from https://cyberleninka.ru/article/n/ataka-cam-table-overflow-metody-zaschity
  3. NAG. (n.d.). Configuring Port Security on SNR switches. NAG Documentation. Retrieved November 11, 2025, from https://nag.wiki/pages/viewpage.action?pageId=25107728
  4. Uymin, A. G. (2024). Computer networks: L2 technologies. A practical course. IPR Media.
  5. Cisco Systems. (2023). Cisco Catalyst 2960 Series Switches Configuration Guide. https://www.cisco.com/c/en/us/support/switches/catalyst-2960-series-switches/products-installation-and-configuration-guides-list.html
  6. Fundamentals of network security: Protecting L2 switches. (2020). Habr. Retrieved January 11, 2025, from https://habr.com/ru/articles/502480/
  7. Treshchev, I. A. (2022). On the implementation of MAC-flood attacks. eLIBRARY.RU. Retrieved November 11, 2025, from https://elibrary.ru/item.asp?id=49992198
  8. Eltex. (n.d.). Configuring Port Security on Eltex MES1400/MES2400 switches. Eltex Knowledge Base. https://eltexcm.ru/baza-znanij/ethernet-kommutatory-mes/mes14xx24xx3400-xx37xx/interfejsy-vlan/mes-nastrojka-port-security-mes1400-mes2400.html

License

Copyright (c) 2025 A. V. Fomenko , Y. Y. Zelenov (Authors)

Keywords