Research Article

Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security

Volume: 9 Number: 2 December 31, 2025
TR EN

Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security

Abstract

This study investigates security vulnerabilities in the Dynamic Host Configuration Protocol (DHCP), focusing on the limitations of DHCP Snooping when attackers exploit trusted ports. We propose an enhanced detection and prevention mechanism that integrates DHCP Snooping with Port Security to counter DHCP spoofing attacks. Unlike approaches based on Software-Defined Networking (SDN) or machine learning which require advanced infrastructure our method is lightweight, cost-effective, and deployable on conventional Layer 2 switches commonly used in enterprise and educational networks. DHCP Snooping was configured to classify switch ports as trusted or untrusted, while Port Security restricted access through MAC address verification. This integration effectively mitigated DHCP spoofing attempts, including those launched through trusted ports, where traditional DHCP Snooping alone is insufficient. Simulation results show that combining DHCP Snooping with Port Security significantly strengthens network security by enforcing MAC-based authentication at the switch port level. The method ensures that only legitimate DHCP servers can respond to client requests, prevents the exploitation of trusted ports, and maintains network performance without introducing instability. The findings demonstrate the practicality and effectiveness of the proposed approach in enhancing network integrity without additional hardware or complex detection systems.

Keywords

Supporting Institution

N/A

Ethical Statement

N/A

Thanks

Thanks for efforts.

References

  1. Adesemowo, A. K., & Gerber, M. (2014). E-skilling on fundamental ICT networking concepts–Overcoming the resource constraints at a South African university. Proceedings of e-Skills Knowledge Production and Innovation Conference, 1–16.
  2. Adjei, H. A., Shunhua, M. T., Agordzo, G. K., Li, Y., Peprah, G., & Gyarteng, E. S. (2021). SSL stripping technique (DHCP snooping and ARP spoofing inspection). 2021 23rd International Conference on Advanced Communication Technology (ICACT), 187–193.
  3. Ahmad, Z., Khan, A. S., Shiang, C. W., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150.
  4. Alsaadi, R. R., & Abdul-Zahra, D. S. (2021). Security DHCP server on LAN network. Turkish Journal of Physiotherapy and Rehabilitation, 32, 3.
  5. Ali, S. M., & Shareef, A. A. (2021). Designing a secure network solution against DHCP attacks. Iraqi Journal of Information & Communication Technology, 1(1), 45–57.
  6. Aldaoud, M., Al-Abri, D., Al Maashri, A., & Kausar, F. (2021). DHCP attacking tools: An analysis. Journal of Computer Virology and Hacking Techniques, 17, 119–129.
  7. Aldaoud, M., Al-Abri, D., Al Maashri, A., & Kausar, F. (2023). Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: A comprehensive approach. Journal of Computer Virology and Hacking Techniques, 19(4), 597–614.
  8. Banitalebi Dehkordi, A., Soltanaghaei, M., & Boroujeni, F. Z. (2021). The DDoS attacks detection through machine learning and statistical methods in SDN. Journal of Supercomputing, 77(3), 2383–2415.

Details

Primary Language

English

Subjects

System and Network Security

Journal Section

Research Article

Publication Date

December 31, 2025

Submission Date

August 16, 2025

Acceptance Date

October 4, 2025

Published in Issue

Year 2025 Volume: 9 Number: 2

APA
Alhajahmad, B. (2025). Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. International Journal of Management Information Systems and Computer Science, 9(2), 157-174. https://doi.org/10.33461/uybisbbd.1766477
AMA
1.Alhajahmad B. Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. UYBISBBD. 2025;9(2):157-174. doi:10.33461/uybisbbd.1766477
Chicago
Alhajahmad, Bashar. 2025. “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”. International Journal of Management Information Systems and Computer Science 9 (2): 157-74. https://doi.org/10.33461/uybisbbd.1766477.
EndNote
Alhajahmad B (December 1, 2025) Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. International Journal of Management Information Systems and Computer Science 9 2 157–174.
IEEE
[1]B. Alhajahmad, “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”, UYBISBBD, vol. 9, no. 2, pp. 157–174, Dec. 2025, doi: 10.33461/uybisbbd.1766477.
ISNAD
Alhajahmad, Bashar. “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”. International Journal of Management Information Systems and Computer Science 9/2 (December 1, 2025): 157-174. https://doi.org/10.33461/uybisbbd.1766477.
JAMA
1.Alhajahmad B. Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. UYBISBBD. 2025;9:157–174.
MLA
Alhajahmad, Bashar. “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”. International Journal of Management Information Systems and Computer Science, vol. 9, no. 2, Dec. 2025, pp. 157-74, doi:10.33461/uybisbbd.1766477.
Vancouver
1.Bashar Alhajahmad. Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. UYBISBBD. 2025 Dec. 1;9(2):157-74. doi:10.33461/uybisbbd.1766477