TR
EN
Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security
Abstract
This study investigates security vulnerabilities in the Dynamic Host Configuration Protocol (DHCP), focusing on the limitations of DHCP Snooping when attackers exploit trusted ports. We propose an enhanced detection and prevention mechanism that integrates DHCP Snooping with Port Security to counter DHCP spoofing attacks. Unlike approaches based on Software-Defined Networking (SDN) or machine learning which require advanced infrastructure our method is lightweight, cost-effective, and deployable on conventional Layer 2 switches commonly used in enterprise and educational networks. DHCP Snooping was configured to classify switch ports as trusted or untrusted, while Port Security restricted access through MAC address verification. This integration effectively mitigated DHCP spoofing attempts, including those launched through trusted ports, where traditional DHCP Snooping alone is insufficient. Simulation results show that combining DHCP Snooping with Port Security significantly strengthens network security by enforcing MAC-based authentication at the switch port level. The method ensures that only legitimate DHCP servers can respond to client requests, prevents the exploitation of trusted ports, and maintains network performance without introducing instability. The findings demonstrate the practicality and effectiveness of the proposed approach in enhancing network integrity without additional hardware or complex detection systems.
Keywords
Supporting Institution
N/A
Ethical Statement
N/A
Thanks
Thanks for efforts.
References
- Adesemowo, A. K., & Gerber, M. (2014). E-skilling on fundamental ICT networking concepts–Overcoming the resource constraints at a South African university. Proceedings of e-Skills Knowledge Production and Innovation Conference, 1–16.
- Adjei, H. A., Shunhua, M. T., Agordzo, G. K., Li, Y., Peprah, G., & Gyarteng, E. S. (2021). SSL stripping technique (DHCP snooping and ARP spoofing inspection). 2021 23rd International Conference on Advanced Communication Technology (ICACT), 187–193.
- Ahmad, Z., Khan, A. S., Shiang, C. W., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150.
- Alsaadi, R. R., & Abdul-Zahra, D. S. (2021). Security DHCP server on LAN network. Turkish Journal of Physiotherapy and Rehabilitation, 32, 3.
- Ali, S. M., & Shareef, A. A. (2021). Designing a secure network solution against DHCP attacks. Iraqi Journal of Information & Communication Technology, 1(1), 45–57.
- Aldaoud, M., Al-Abri, D., Al Maashri, A., & Kausar, F. (2021). DHCP attacking tools: An analysis. Journal of Computer Virology and Hacking Techniques, 17, 119–129.
- Aldaoud, M., Al-Abri, D., Al Maashri, A., & Kausar, F. (2023). Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: A comprehensive approach. Journal of Computer Virology and Hacking Techniques, 19(4), 597–614.
- Banitalebi Dehkordi, A., Soltanaghaei, M., & Boroujeni, F. Z. (2021). The DDoS attacks detection through machine learning and statistical methods in SDN. Journal of Supercomputing, 77(3), 2383–2415.
Details
Primary Language
English
Subjects
System and Network Security
Journal Section
Research Article
Authors
Publication Date
December 31, 2025
Submission Date
August 16, 2025
Acceptance Date
October 4, 2025
Published in Issue
Year 2025 Volume: 9 Number: 2
APA
Alhajahmad, B. (2025). Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. International Journal of Management Information Systems and Computer Science, 9(2), 157-174. https://doi.org/10.33461/uybisbbd.1766477
AMA
1.Alhajahmad B. Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. UYBISBBD. 2025;9(2):157-174. doi:10.33461/uybisbbd.1766477
Chicago
Alhajahmad, Bashar. 2025. “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”. International Journal of Management Information Systems and Computer Science 9 (2): 157-74. https://doi.org/10.33461/uybisbbd.1766477.
EndNote
Alhajahmad B (December 1, 2025) Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. International Journal of Management Information Systems and Computer Science 9 2 157–174.
IEEE
[1]B. Alhajahmad, “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”, UYBISBBD, vol. 9, no. 2, pp. 157–174, Dec. 2025, doi: 10.33461/uybisbbd.1766477.
ISNAD
Alhajahmad, Bashar. “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”. International Journal of Management Information Systems and Computer Science 9/2 (December 1, 2025): 157-174. https://doi.org/10.33461/uybisbbd.1766477.
JAMA
1.Alhajahmad B. Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. UYBISBBD. 2025;9:157–174.
MLA
Alhajahmad, Bashar. “Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security”. International Journal of Management Information Systems and Computer Science, vol. 9, no. 2, Dec. 2025, pp. 157-74, doi:10.33461/uybisbbd.1766477.
Vancouver
1.Bashar Alhajahmad. Improving Switch Security Against MITM Attacks Using DHCP Snooping and Port Security. UYBISBBD. 2025 Dec. 1;9(2):157-74. doi:10.33461/uybisbbd.1766477
