LECTURE 12

LAN Security and Network Attacks

Duration: 115 min of teaching Level: bachelor, year III - no prior knowledge assumed Course: Local Area Networks Related lab: Laboratory 07 PDF: download the notes RO versiunea română

The firewall at the edge of the network, however well configured, sees absolutely nothing of what happens between two computers in the same room. Their traffic never crosses it. This lecture deals with exactly that blind spot: the attacks that work inside the local network, almost all of them exploiting mechanisms we built ourselves, in lectures 3 and 4, and which do exactly what they were designed to do. We shall not repair the protocols - that cannot be done. We shall add around them the checks they lack.

1From the switching lectures5 min

What to keep in mind
  • A switch learns MAC addresses from the source field of the frames it receives.
  • The CAM table has a finite size; whatever is not found in it is flooded on every port.
  • ARP associates an IP address with a MAC address, by asking through broadcast.
  • The native VLAN travels untagged over a trunk.
  • STP elects as root the switch with the lowest Bridge ID.
  • DHCP works through broadcast; the client accepts the first offer to arrive.

Every one of these six sentences is, today, the starting point of an attack. Not because they are wrongly implemented, but because they are implemented exactly as they were conceived - in an age when the local network was, implicitly, a space of trust.

Learning outcomes

  • Classify an attack by its purpose and say which mechanism it exploits
  • Explain the mechanics of CAM overflow, ARP poisoning and VLAN hopping
  • Describe how a single cable can bring down an entire network through STP
  • Configure port security, DHCP snooping and Dynamic ARP Inspection
  • Close VLAN hopping through three settings
  • Explain what a salt does and, above all, what it does not do
  • Apply a complete hardening list to an access switch

2Three families of attack8 min

Why the firewall does not help here

A firewall sits between two networks and sees only the traffic that crosses it.

If host A and host B are in the same VLAN, on the same switch, the traffic between them never reaches a router, and so never reaches the firewall. The switch forwards it directly, at layer 2.

Every attack in this lecture is conducted below the level at which a classic firewall looks. The defence must be there too - on the switch.

FamilyPurposeExamples in a LAN
Reconnaissancefinding out what exists and what is runningping sweep, port scan, sniffing, DNS queries
Denial (DoS)making a service unavailableSYN flood, smurf, CAM overflow, STP attack
Accessobtaining undeserved privilegesARP poisoning, VLAN hopping, password cracking, social engineering
The observation that organises the whole lecture Almost every attack here exploits a mechanism that works exactly as designed.

ARP authenticates nothing - by design. A switch believes any source MAC - by design. STP accepts any BPDU - by design. DHCP accepts the first offer - by design.

All of them were conceived in an age when being physically connected to the network meant being trusted. The countermeasures do not repair the protocols; they add around them the checks that are missing.
Analogy It is like an office building where every internal door stands open, because anybody who has got past reception is taken to be an employee.

The firewall is reception. The measures in this lecture are the locks on the internal doors - and the reason they are called, collectively, defence in depth.

3Reconnaissance9 min

Before any serious attack comes the gathering of information: which IP addresses are alive, what services run on them, in what version, what operating systems, and whom the users of the network trust.

The same tools are used daily by administrators too - the difference is the authorisation, not the instrument.

UtilityWhat it doesExample
nmapdiscovers live hosts, open ports, services, versions, operating systemnmap -sV 192.168.1.0/24
tcpdumptraffic capture from the command line, with filterstcpdump -i eth0 -c 10 dst port 80
Wiresharkgraphical capture and analysis; requires the interface in promiscuous modelibpcap format, shared with tcpdump
whoisadministrative information about a domainwhois example.com
host, digDNS queries: name servers, mail servershost -t MX example.com
The golden rule of this course All the tools above are to be used exclusively on the laboratory network, on your own devices.

Scanning or intercepting somebody else's traffic - even on the same network, even "just to see whether it works" - is illegal and punishable. The purpose of this course is that you should understand what an attacker sees, so that you can build the defence; not that you should practise on other people's systems.
Terminal: what reconnaissance sees

Look at the third command. Two different IP addresses with the same MAC address is the anomaly that betrays a man-in-the-middle attack - and it is the cheapest check you can make on a suspect host.

What a firewall can do against reconnaissance: block the answer to ICMP echo, close vulnerable ports, forbid connections being initiated from outside, limit the rate of requests. What it cannot do: stop an attacker already inside the local network. Hence the rest of the lecture.

4Denial-of-service attacks9 min

The smurf attack

The smurf attack: amplification

TCP SYN flood

We met it in lecture 8: the attacker sends thousands of SYN segments with forged source addresses, and the server allocates an entry in the queue of half-open connections for each. When the queue fills, legitimate connections are refused.

Defences: SYN cookies, which let the server allocate nothing until confirmation; limiting the number of half-open connections per source; and, as always, monitoring the traffic under normal conditions - an anomaly is noticed only if you know what normal looks like.

5CAM overflow10 min

This is the attack that directly exploits the mechanism from lecture 3. A switch's memory is finite - typically between 8,000 and 32,000 entries - so the CAM table can be filled. And when it fills, the switch can no longer learn new addresses and floods every unknown frame on every port. In other words: it becomes a hub again.

CAM overflow, step by step

Go back to the CAM table simulator from lecture 3 and watch what happens with every frame: the switch learns only from the source address and floods any unknown destination. The attack does nothing but push those two rules to their limit.

CAM table simulator - learning and flooding
the countermeasure: port security
SW(config)# interface fastEthernet 0/5
SW(config-if)# switchport mode access
SW(config-if)# switchport port-security
SW(config-if)# switchport port-security maximum 2
SW(config-if)# switchport port-security mac-address sticky
SW(config-if)# switchport port-security violation restrict
SW(config-if)# switchport port-security aging time 60

SW# show port-security interface fastEthernet 0/5
SW# show mac address-table count
Action on violationWhat it doesWhen to use it
protectsilently discards the excess framesrarely - you never find out that anything happened
restrictdiscards, increments a counter, sends SNMP and syslogthe recommended default
shutdownshuts the port down (err-disable)sensitive areas; requires manual intervention or errdisable recovery
What sticky means Addresses learned dynamically are written automatically into the running configuration, as though you had entered them by hand. The advantage: you do not have to know every computer's address in advance.

Beware, however: if you do not save the configuration, they are lost on reboot - and if you do save them, the port stays tied to that particular computer, which becomes a problem the first time a machine is replaced.

6Man-in-the-middle through ARP poisoning11 min

ARP, as we studied it in lecture 5, has a property that today seems inconceivable: it authenticates nothing. What is more, most implementations accept an ARP reply even if they never sent a request - a mechanism called gratuitous ARP, useful for announcing an address change, but exploitable.

A C B the attacker SWITCH ARP cache: IP_C → MAC_B ARP cache: IP_A → MAC_B "IP_C is me" "IP_A is me"
Fig. 1 - ARP poisoning. B sends each of the two an unsolicited ARP reply. Both hosts update their cache and begin addressing frames to B MAC address. The switch forwards them correctly - to the attacker.
ARP poisoning and how it is closed
the countermeasure: DHCP snooping + Dynamic ARP Inspection
! 1. the switch learns which IP address each port received, through DHCP
SW(config)# ip dhcp snooping
SW(config)# ip dhcp snooping vlan 10,20
SW(config)# interface gigabitEthernet 0/1
SW(config-if)# ip dhcp snooping trust

! 2. on the basis of that record, every ARP message is checked
SW(config)# ip arp inspection vlan 10,20
SW(config)# interface gigabitEthernet 0/1
SW(config-if)# ip arp inspection trust

! 3. for hosts with a static address, the record is written by hand
SW(config)# arp access-list SERVERS
SW(config-arp-nacl)# permit ip host 192.168.1.50 mac host 000c.2911.2233
SW(config)# ip arp inspection filter SERVERS vlan 10

SW# show ip dhcp snooping binding
SW# show ip arp inspection statistics
An additional benefit: rogue DHCP DHCP snooping stops, at the same time, an entirely different attack: somebody starts their own DHCP server and announces themselves as everybody's gateway. Clients accept the first offer to arrive - and a local server, in the same room, answers faster than the legitimate one.

Untrusted ports are not allowed to send server messages (Offer, Ack), so the attack never even starts. One command, two attacks closed.

7VLAN hopping11 min

We built VLANs precisely in order to isolate departments. There are two techniques by which the isolation can be got round - both exploiting default behaviours of switches.

Switch spoofing

Many Cisco switches have DTP (Dynamic Trunking Protocol) enabled by default, which automatically negotiates whether a port becomes access or trunk. An attacker can present themselves as a switch and negotiate a trunk. Once obtained, they can send and receive 802.1Q-tagged frames for any VLAN.

the countermeasure: no negotiation on access ports
SW(config)# interface range fastEthernet 0/1 - 22
SW(config-if-range)# switchport mode access
SW(config-if-range)# switchport nonegotiate
SW(config-if-range)# switchport access vlan 10

! unused ports: shut down and moved into a dead VLAN
SW(config)# interface range fastEthernet 0/23 - 24
SW(config-if-range)# switchport access vlan 999
SW(config-if-range)# shutdown

Double tagging

The technique exploits the native VLAN, which we know from lecture 4 travels untagged over a trunk. It requires no special protocol on the attacker's side - only the ability to build a frame with two tags.

Double tagging, step by step
Three rules that close VLAN hopping 1. Make the native VLAN of the trunks an unused VLAN, with no host in it.
2. Make access ports explicitly switchport mode access with switchport nonegotiate.
3. On trunks, declare the list of allowed VLANs explicitly (switchport trunk allowed vlan 10,20,30), rather than leaving it at the default of "all".

8Attacks against STP10 min

STP uses no form of authentication whatever: any device that sends BPDUs takes part in the root election. An attacker connected anywhere in the network can announce BPDUs with a very low Bridge ID and become the root bridge - at which point a considerable part of the traffic begins to pass through them.

The root election and the port roles

Lower the priority of a switch to 0 in the simulator above and watch the whole topology reorganise itself around it. That is exactly what the attacker does - except that the switch with priority 0 is their laptop, under the desk.

  1. The attacker connects to the switched network, with a single cable.
  2. They announce BPDUs with priority 0, hence with the lowest possible BID.
  3. STP reconverges; they become the root, and the port roles are recomputed around them.
  4. Traffic between segments now passes through their machine, where it can be captured.

The denial-of-service variant is simpler still: the attacker changes their BID continually, forcing permanent recomputations. The ports never reach the forwarding state, and the network is, in practice, stopped - with one cable and no exploit at all.

the STP countermeasures
! ports towards hosts: go straight into forwarding...
SW(config)# interface range fastEthernet 0/1 - 22
SW(config-if-range)# spanning-tree portfast

! ...and shut down if a BPDU appears from there
SW(config-if-range)# spanning-tree bpduguard enable

! the root is set explicitly, on the switch at the centre of the network
SW_CORE(config)# spanning-tree vlan 1-100 root primary

! ports towards switches that must not become the root
SW(config)# interface gigabitEthernet 0/2
SW(config-if)# spanning-tree guard root

! automatic reactivation of shut-down ports, after 5 minutes
SW(config)# errdisable recovery cause bpduguard
SW(config)# errdisable recovery interval 300
MechanismWhat it doesWhere it goes
PortFastskips listening and learning on access portsports towards hosts; never towards switches
BPDU Guardshuts the port down if it receives a BPDUtogether with PortFast, always
Root Guardprevents a port from becoming a root porton ports towards switches that must not be the root
BPDU Filterstops the sending and receiving of BPDUs entirelyrarely; to be used with caution, it can create loops
PortFast without BPDU Guard is dangerous PortFast alone protects nobody: it merely hastens the move into forwarding. If somebody connects a switch to that port, a loop can form before STP has time to react.

The two always go together. The mnemonic: PortFast promises there is no switch there; BPDU Guard checks the promise.

9Passwords, hashes and salt9 min

MethodHow it worksCountermeasure
Sniffingpasswords sent in the clear (Telnet, FTP, HTTP) are read straight out of the trafficSSH, HTTPS - anything encrypted
Brute forceevery possible combination is triedlong passwords; limiting the attempts
Dictionary attackcommon words and simple variations of them are triedpasswords that are not words
Rainbow tableschains of precomputed hashes, trading space for timesalt
Why passwords are not stored, but their hashes

A hash is a one-way function: it is computed instantly from the password, but from the result the password cannot be recovered.

The server stores only the hash. At authentication it computes the hash of the password entered and compares. If the database is stolen, the attacker does not have the passwords - only the hashes.

The problem: if two users have the same password, they also have the same hash. And an attacker can precompute the hashes of the few million commonest passwords and look them up directly. This is where rainbow tables come in.

A rainbow table does not store every possible hash - that would be impossible - but the starting points of chains of hashes, from which the intermediate values are recomputed as needed. It is a classic memory-time trade-off, and public tables of thousands of gigabytes are available on the Internet.

The salt

A salt is a random segment, generated for each user and concatenated to the password before hashing. It is stored alongside the hash, in the clear - it is not secret and does not need to be.

a line from /etc/shadow
trudy:$6$/tKy92iM$/.cIxbEX49qHpZt74D5L0W1vXO2fJuXjyXJnsT0.M...
#      ^   ^        ^
#      |   |        the hash itself
#      |   the salt, randomly generated
#      the algorithm: 6 = SHA-512
What a salt does and what it does not do A salt does not prevent rainbow table attacks and does not make a password harder to guess.

What it does: it forces the attacker to build a new table for every individual user - which turns a few-minute attack on the whole database into a separate effort per account. And it makes two users with the same password have different hashes.

It is a measure of scale, not of impossibility: a weak password stays weak with a salt too. For real resistance, deliberately slow functions are used - bcrypt, scrypt, Argon2 - which make each attempt expensive.

10The human factor and hostile code7 min

Social engineering

The most effective avenue of access is not technical. The attacker convinces a person that they are trustworthy - a colleague from IT, a supplier, a superior in a hurry - and obtains the information directly. The target usually has no technical background, wants to help, and does not realise the value of what they hold.

Social engineering bypasses any technical mechanism, however well configured. There is no port security for a telephone. The only real defence is periodic training of non-technical staff and the existence of clear procedures for unusual requests - for instance, the rule that a password is never given out over the telephone, whoever is calling.

Phishing is the industrialised version of the same idea: instead of one call, a million messages.

Hostile executable code

TypeHow it spreadsWhat characterises it
Virusattached to a program; it needs the user to run ita direct effect, often visible
Trojanhidden inside an apparently useful applicationa subtle effect - usually it opens a back door; hard to detect
Wormexploits vulnerabilities; it does not need a uservery rapid spread; it often builds botnets
Ransomwareany of the routes aboveencrypts the data and demands a ransom; it spreads laterally within the LAN
Why segmentation matters so much today Modern ransomware is not content with the host it infected: it spreads laterally, exploiting precisely the implicit trust of the local network.

VLANs, the ACLs between them and the measures in this lecture do not prevent the initial infection - but they dramatically limit how far it gets. That is the difference between an incident and a disaster.

11The short list for hardening a switch8 min

Everything discussed above comes down to a few configurations that apply to any access switch, in any organisational network.

The measure and the corresponding attack
MeasureAgainst what
port-security with maximum and stickyCAM overflow, unauthorised devices
ip dhcp snoopingrogue DHCP servers
ip arp inspectionARP poisoning, man-in-the-middle
switchport mode access + nonegotiateswitch spoofing
an unused native VLAN, explicitly allowed VLANsdouble tagging
portfast + bpduguardSTP attacks
unused ports: shutdown, in a dead VLANunauthorised connections
SSH instead of Telnet, with an ACL on the VTY linesinterception of management passwords
management through SSH, not Telnet
SW(config)# hostname SW1
SW(config)# ip domain-name networks.local
SW(config)# crypto key generate rsa modulus 2048
SW(config)# ip ssh version 2
SW(config)# username admin privilege 15 secret AStrongPassword
SW(config)# service password-encryption

SW(config)# access-list 20 permit 10.0.100.0 0.0.0.255
SW(config)# line vty 0 15
SW(config-line)# transport input ssh
SW(config-line)# login local
SW(config-line)# access-class 20 in
SW(config-line)# exec-timeout 5 0
The order in which a new switch is hardened

12Common mistakes4 min

  • "I put portfast on every port, towards switches included" A loop can form before STP reacts - and a layer 2 loop stops the network within seconds. PortFast only towards hosts, always with BPDU Guard alongside.
  • "I enabled DAI, and now the servers with static addresses cannot communicate" DAI relies on the record built by DHCP snooping. A host that never used DHCP does not appear there. Add manual entries with arp access-list for the servers with fixed addresses.
  • "I set port-security maximum 1 everywhere" An IP telephone with a PC behind it has two addresses; a bridged virtual machine adds more. Choose the maximum from what actually connects there. 2 or 3 is more realistic.
  • "I left VLAN 1 as the native VLAN" It is the default value and, often, the very VLAN the hosts are in - the exact precondition of the double tagging attack. A dedicated, empty native VLAN, different from 1 and from any user VLAN.
  • "I configured everything, but did not save" The sticky addresses and the whole configuration disappear at the first reboot. copy running-config startup-config. The same lesson as in lecture 6.
  • "Port security with violation shutdown, and now half the ports are shut" A user who changes their laptop shuts the port, and reactivating it requires manual intervention. restrict for ordinary areas; errdisable recovery where you do use shutdown.
  • "We have a firewall, so the internal network is safe" The firewall does not see the traffic between two hosts in the same VLAN. Defence in depth: segmentation, measures on the switch, end-to-end encryption.

13Summary and glossary5 min

What should stay with you
  • The edge firewall does not see the traffic inside a VLAN.
  • Almost every LAN attack exploits protocols that are working correctly.
  • CAM overflow forges source MAC addresses → closed with port-security.
  • ARP poisoning exploits the absence of authentication in ARP → closed with DHCP snooping + DAI.
  • Switch spoofing exploits DTP → nonegotiate.
  • Double tagging exploits the native VLAN → an unused native VLAN.
  • The STP attack exploits the absence of BPDU authentication → PortFast + BPDU Guard.
  • The salt does not strengthen the password: it forces the attacker into one table per account.
  • Social engineering bypasses every technical measure. It is defended against with procedures and training.
  • Security is in depth: no single measure is enough.
CAM overflowfilling the switch table with false addresses
port securitylimiting the number of MAC addresses per port
stickydynamically learned addresses, written into the configuration
ARP poisoningfalse ARP replies, which redirect the traffic
gratuitous ARPan ARP reply sent without having been asked for
DHCP snoopinga record of port–MAC–IP triples, from DHCP transactions
DAIchecking ARP messages against that record
rogue DHCPan unauthorised DHCP server, announcing itself as gateway
VLAN hoppinggetting round the isolation between VLANs
DTPthe protocol for automatic trunk negotiation
double tagginga frame with two tags, exploiting the native VLAN
BPDU Guardshuts the port down if a BPDU appears from there
Root Guardprevents a port from becoming a root port
salta random segment added to a password before hashing
rainbow tablechains of precomputed hashes

14Self-check questions7 min

15Closing2 min

With this lecture the course comes to a close. We started, in lecture 1, from an electrical signal on a wire and the question of how a bit becomes a voltage. We have arrived at a local network segmented into VLANs, dynamically routed, filtered with access lists, translated on the way out, extended without wires and defended against the attacks from within it.

What is worth keeping, beyond the commands: almost every mechanism we studied was invented as the solution to a concrete problem, and almost every one later became somebody else's problem. The switch solved collisions and created CAM overflow. The VLAN solved broadcast and created VLAN hopping. NAT rescued IPv4 and broke peer-to-peer. There is no design decision without a cost - there are only decisions taken knowingly and decisions taken out of habit.

Laboratory 7 carries out, under control, three of the attacks from here and then closes their doors, one by one.

  • Cisco - Catalyst Switch Security Configuration Guide: port security, DHCP snooping, DAI
  • RFC 2827 / BCP 38 - ingress filtering against address spoofing
  • RFC 3704 - ingress filtering for multihomed networks
  • OWASP - resources on passwords, hashing and authentication
  • The nmap and Wireshark documentation - for strictly authorised use