Welcome to the Underground

Your Hacking Bookstore & Information Headquarters
 
Menu
Categories
Sponsor
Tag cloud
defcon speaker org hacker show media mystery challenge contest security update computer html team hack hook year wall talks live

HOME » Hacker Books

LAN Switch Security: What Hackers Know About Your Switches (Networking Technology: Security)

LAN Switch Security: What Hackers Know About Your Switches


A practical guide to hardening Layer 2 devices and stopping campus network attacks


Eric Vyncke

Christopher Paggen, CCIE® No. 2659


Contrary to popular belief, Ethernet switches are not inherently secure. Security vulnerabilities in Ethernet switches are multiple: from the switch implementation, to control plane protocols (Spanning Tree Protocol [STP], Cisco® Discovery Protocol [CDP], and so on) and data plane protocols, such as Address Routing Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP). LAN Switch Security explains all the vulnerabilities in a network infrastructure related to Ethernet switches. Further, this book shows you how to configure a switch to prevent or to mitigate attacks based on those vulnerabilities. This book also includes a section on how to use an Ethernet switch to increase the security of a network and prevent future attacks.


Divided into four parts, LAN Switch Security provides you with steps you can take to ensure the integrity of both voice and data traffic traveling over Layer 2 devices. Part I covers vulnerabilities in Layer 2 protocols and how to configure switches to prevent attacks against those vulnerabilities. Part II addresses denial-of-service (DoS) attacks on an Ethernet switch and shows how those attacks can be mitigated. Part III shows how a switch can actually augment the security of a network through the utilization of wirespeed access control list (ACL) processing and IEEE 802.1x for user authentication and authorization. Part IV examines future developments from the LinkSec working group at the IEEE. For all parts, most of the content is vendor independent and is useful for all network architects deploying Ethernet switches.


After reading this book, you will have an in-depth understanding of LAN security and be prepared to plug the security holes that exist in a great number of campus networks.


Eric Vyncke has a master’s degree in computer science engineering from the University of Liège in Belgium. Since 1997, Eric has worked as a Distinguished Consulting Engineer for Cisco, where he is a technical consultant for security covering Europe. His area of expertise for 20 years has been mainly security from Layer 2 to applications. He is also guest professor at Belgian universities for security seminars.


Christopher Paggen, CCIE® No. 2659, obtained a degree in computer science from IESSL in Liège (Belgium) and a master’s degree in economics from University of Mons-Hainaut (UMH) in Belgium. He has been with Cisco since 1996 where he has held various positions in the fields of LAN switching and security, either as pre-sales support, post-sales support, network design engineer, or technical advisor to various engineering teams. Christopher is a frequent speaker at events, such as Networkers, and has filed several U.S. patents in the security area.


Contributing Authors:

Jason Frazier is a technical leader in the Technology Systems Engineering group for Cisco.

Steinthor Bjarnason is a consulting engineer for Cisco.

Ken Hook is a switch security solution manager for Cisco.

Rajesh Bhandari is a technical leader and a network security solutions architect for Cisco.


  • Use port security to protect against CAM attacks

  • Prevent spanning-tree attacks

  • Isolate VLANs with proper configuration techniques

  • Protect against rogue DHCP servers

  • Block ARP snooping

  • Prevent IPv6 neighbor discovery and router solicitation exploitation

  • Identify Power over Ethernet vulnerabilities

  • Mitigate risks from HSRP and VRPP

  • Stop information leaks with CDP, PaGP, VTP, CGMP and other Cisco ancillary protocols

  • Understand and prevent DoS attacks against switches

  • Enforce simple wirespeed security policies with ACLs

  • Implement user authentication on a port base with IEEE 802.1x

  • Use new IEEE protocols to encrypt all Ethernet frames at wirespeed.


This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.


Category: Cisco Press—Security

Covers: Ethernet Switch Security


$60.00 USA / $69.00 CAN

LAN Switch Security: What Hackers Know About Your Switches


A practical guide to hardening Layer 2 devices and stopping campus network attacks


Eric Vyncke

Christopher Paggen, CCIE® No. 2659


Contrary to popular belief, Ethernet switches are not inherently secure. Security vulnerabilities in Ethernet switches are multiple: from the switch implementation, to control plane protocols (Spanning Tree Protocol [STP], Cisco® Discovery Protocol [CDP], and so on) and data plane protocols, such as Address Routing Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP). LAN Switch Security explains all the vulnerabilities in a network infrastructure related to Ethernet switches. Further, this book shows you how to configure a switch to prevent or to mitigate attacks based on those vulnerabilities. This book also includes a section on how to use an Ethernet switch to increase the security of a network and prevent future attacks.


Divided into four parts, LAN Switch Security provides you with steps you can take to ensure the integrity of both voice and data traffic traveling over Layer 2 devices. Part I covers vulnerabilities in Layer 2 protocols and how to configure switches to prevent attacks against those vulnerabilities. Part II addresses denial-of-service (DoS) attacks on an Ethernet switch and shows how those attacks can be mitigated. Part III shows how a switch can actually augment the security of a network through the utilization of wirespeed access control list (ACL) processing and IEEE 802.1x for user authentication and authorization. Part IV examines future developments from the LinkSec working group at the IEEE. For all parts, most of the content is vendor independent and is useful for all network architects deploying Ethernet switches.


After reading this book, you will have an in-depth understanding of LAN security and be prepared to plug the security holes that exist in a great number of campus networks.


Eric Vyncke has a master’s degree in computer science engineering from the University of Liège in Belgium. Since 1997, Eric has worked as a Distinguished Consulting Engineer for Cisco, where he is a technical consultant for security covering Europe. His area of expertise for 20 years has been mainly security from Layer 2 to applications. He is also guest professor at Belgian universities for security seminars.


Christopher Paggen, CCIE® No. 2659, obtained a degree in computer science from IESSL in Liège (Belgium) and a master’s degree in economics from University of Mons-Hainaut (UMH) in Belgium. He has been with Cisco since 1996 where he has held various positions in the fields of LAN switching and security, either as pre-sales support, post-sales support, network design engineer, or technical advisor to various engineering teams. Christopher is a frequent speaker at events, such as Networkers, and has filed several U.S. patents in the security area.


Contributing Authors:

Jason Frazier is a technical leader in the Technology Systems Engineering group for Cisco.

Steinthor Bjarnason is a consulting engineer for Cisco.

Ken Hook is a switch security solution manager for Cisco.

Rajesh Bhandari is a technical leader and a network security solutions architect for Cisco.


  • Use port security to protect against CAM attacks

  • Prevent spanning-tree attacks

  • Isolate VLANs with proper configuration techniques

  • Protect against rogue DHCP servers

  • Block ARP snooping

  • Prevent IPv6 neighbor discovery and router solicitation exploitation

  • Identify Power over Ethernet vulnerabilities

  • Mitigate risks from HSRP and VRPP

    ...
    Item tags:
    security, network, switch, cisco
N/A



Related Items - EBay
LAN Switch Security: What Hackers Know About Your Switches (Networking Technology: Security)
LAN Switch Security: What Hackers Know About Your Switches A practical guide to hardening Layer 2 devices and stopping campus network attacks Eric Vyncke Christopher Paggen, CCIE® No. 2659 Contrary to popular belief, Ethernet switches are ...
$49.02

LAN Switch Security: What Hackers Know About Your Switches
Review by Chris Gates (content/category/7/32/24/), CISSP, GCIH, C|EH, CPTS In addition to his regular column, Chris Gates does some great work on EH-Net including participating in our growing forums as well as doing various book reviews. He is back with a ...

Cyber Adversary Characterization: Auditing the Hacker Mind
Develop a Well-Measured Defense Against CybercriminalsWhen we speak of the hacker mind, then, we have come to mean the mind of a miscreant motivated by a broad range of ulterior purposes. We mean script kiddies who download scripts written by others and ...
$36.68

Cyber Adversary Characterization: Auditing the Hacker Mind
Develop a Well-Measured Defense Against CybercriminalsWhen we speak of the hacker mind, then, we have come to mean the mind of a miscreant motivated by a broad range of ulterior purposes. We mean script kiddies who download scripts written by others and ...
$36.68

OS X for Hackers at Heart: The Apple of Every Hacker's Eye
Rediscover Apple and OS X, the Preferred Platform for Discerning Hackers With sexy hardware, a powerful operating system, and easy-to-use applications, Apple has made OS X the operating system of choice for hackers everywhere. But as great as OS X is out ...
$42.30

Hacker Cracker: A Journey from the Mean Streets of Brooklyn to the Frontiers of Cyberspace
One of the most gripping yet improbable stories spawned by the computer revolution, Hacker Crocker is a classic American-dream success story set on the razor edge of high technology. Ejovi Nuwere takes the reader on the roller-coaster ride of his ...
$24.95

First round of DEFCON 16 speakers selected!
The first round of speakers have been selected for DEFCON 16, and it looks like we have a great lineup going! The selection process is coming along nicely and we should have the next batch of speakers online by the middle of next week. Here are the titles ...

First round of DEFCON 16 speakers selected!
The first round of speakers have been selected for DEFCON 16, and it looks like we have a great lineup going! The selection process is coming along nicely and we should have the next batch of speakers online by the middle of next week. Here are the titles ...

First round of DEFCON 16 speakers selected!
The first round of speakers have been selected for DEFCON 16, and it looks like we have a great lineup going! The selection process is coming along nicely and we should have the next batch of speakers online by the middle of next week. Here are the titles ...

First round of DEFCON 16 speakers selected!
The first round of speakers have been selected for DEFCON 16, and it looks like we have a great lineup going! The selection process is coming along nicely and we should have the next batch of speakers online by the middle of next week. Here are the titles ...

First round of DEFCON 16 speakers selected!
The first round of speakers have been selected for DEFCON 16, and it looks like we have a great lineup going! The selection process is coming along nicely and we should have the next batch of speakers online by the middle of next week. Here are the titles ...

Hacker's Challenge 3 (Hacking Exposed)
The stories about phishing attacks against banks are so true-to-life, it’s chilling.” --Joel Dubin, CISSP, Microsoft MVP in Security Every day, hackers are devising new ways to break into your network. Do you have what it takes to stop them? Find out ...
$32.99

NEW The Chemistry and Technology of Coal - Speight, ...
US $295.46 End Date: Tuesday Mar-09-2010 21:48:57 PST Buy It Now for only: US $295.46 Buy it now | Add to watch list ...
295.46

NEW Seeing with Your Ears: Spirituality for Those Wh...
US $17.26 End Date: Tuesday Mar-09-2010 21:48:59 PST Buy It Now for only: US $17.26 Buy it now | Add to watch list ...
17.26

1,Momentary Red Light SPDT ON-(ON) Switch,12V,R11E
US $14.99 End Date: Tuesday Mar-09-2010 21:49:00 PST Buy It Now for only: US $14.99 Buy it now | Add to watch list ...
14.99

DICTIONARY OF WORD ORIGINS trade PB + WHAT'S IN A WORD?
US $5.00 (0 Bid) End Date: Tuesday Mar-09-2010 21:49:00 PST Bid now | Add to watch list ...
5

NEW What the Bible Says Is in Your Hand! - Dunn, Rev...
US $29.80 End Date: Tuesday Mar-09-2010 21:49:01 PST Buy It Now for only: US $29.80 Buy it now | Add to watch list ...
29.8

We Convert YOUR cassette TAPE to CD & EMAIL mp3 version
US $75.00 End Date: Tuesday Mar-09-2010 21:49:04 PST Buy It Now for only: US $75.00 Buy it now | Add to watch list ...
75

WWE SmackDown! Shut Your Mouth (PlayStation 2, 2002)
US $4.99 (0 Bid) End Date: Tuesday Mar-09-2010 21:49:15 PST Bid now | Add to watch list ...
4.99

1995 95 Buick Lesabre Park Ave Roadmaster Window Switch
US $50.56 End Date: Tuesday Mar-09-2010 21:49:21 PST Buy It Now for only: US $50.56 Buy it now | Add to watch list ...
50.56

Nuts About Nuts, Wilmer HC
US $0.99 (0 Bid) End Date: Tuesday Mar-09-2010 21:49:21 PST Buy It Now for only: US $7.50 Bid now | Buy it now | Add to watch list ...
0.99

GE Security Homelink Transceiver
US $21.50 (0 Bid) End Date: Tuesday Mar-09-2010 21:49:22 PST Bid now | Add to watch list ...
21.5