STP Manipulation Attacks

STP prevents bridging loops in a redundant switched network environment. By avoiding loops, you can ensure that broadcast traffic does not become a traffic storm.

STP is a hierarchical tree-like topology with a "root" switch at the top. A switch is elected as root based on the lowest configured priority of any switch (0 through 65,535). When a switch boots up, it begins a process of identifying other switches and determining the root bridge. After a root bridge is elected, the topology is established from its perspective of the connectivity. The switches determine the path to the root bridge, and all redundant paths are blocked. STP sends configuration and topology change notifications and acknowledgments (TCN/TCA) using bridge protocol data units (BPDU).

An STP attack involves an attacker spoofing the root bridge in the topology. The attacker broadcasts out an STP configuration/topology change BPDU in an attempt to force an STP recalculation. The BPDU sent out announces that the attacker's system has a lower bridge priority. The attacker can then see a variety of frames forwarded from other switches to it. STP recalculation may also cause a denial-of-service (DoS) condition on the network by causing an interruption of 30 to 45 seconds each time the root bridge changes. Figure 14-4 shows an attacker using STP network topology changes to force its host to be elected as the root bridge.

Figure 14-4. STP Attack

[View full size imagel

Figure 14-4. STP Attack

[View full size imagel

Stp Attack
Network Attach Hosl

Continue reading here: Mitigating DHCP Starvation Attacks

Was this article helpful?

+31 -7

Readers' Questions

  • AMANDA GARDNER
    What is spanning tree protocol attacks?
    6 months ago
  • Spanning Tree Protocol (STP) attacks refer to malicious activities that exploit vulnerabilities within the Spanning Tree Protocol to disrupt network communication or gain unauthorized access to network resources.
    1. Spanning Tree Protocol (STP) Root Bridge Election Attack: This attack involves manipulating the Spanning Tree Protocol election process to make an attacker's device the root bridge. By becoming the root bridge, an attacker gains control over the network traffic flow, enabling them to intercept and modify network traffic or launch further attacks.
    2. Spanning Tree Protocol (STP) Spoofing Attack: In this attack, an attacker spoofs or impersonates a bridge (switch) or a switch interface in the network using forged MAC (Media Access Control) addresses. By doing so, the attacker can mislead the network and manipulate the Spanning Tree Protocol topology, causing network loops, service disruptions, or even network-wide outages.
    3. Spanning Tree Protocol (STP) Denial-of-Service (DoS) Attack: This attack involves overwhelming the Spanning Tree Protocol with excessive or invalid Bridge Protocol Data Units (BPDUs) or configuration changes, leading to high CPU utilization in switches and making them unresponsive. This results in network outages or service degradation.
    4. Spanning Tree Protocol (STP) Reconnaissance Attack: This attack comprises an attacker gaining unauthorized information about the network, including its topology, by capturing and analyzing Spanning Tree Protocol traffic. This information can be used for further attacks, such as network mapping or targeted exploitation.To mitigate these types of attacks, network administrators can implement various security measures, such as enabling Spanning Tree Protocol protection mechanisms like BPDU guard or Root Guard, implementing port security measures, regular monitoring and analysis of network traffic, and ensuring devices in the network run up-to-date software with security patches.