Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping
Abstract
Dynamic Host Configuration Protocol (DHCP) spoofing remains a critical security threat in modern networks, particularly when attackers exploit the assumption that traffic from trusted ports is always legitimate. Conventional DHCP Snooping mechanisms are unable to detect rogue servers connected to trusted interfaces, leaving networks vulnerable to man-in-the-middle and denial-of-service attacks. To address this overlooked weakness, we propose a machine learning–based enhancement to DHCP Snooping. A custom dataset was generated from simulated DHCP traffic, capturing relevant protocol-level features while excluding trivial identifiers such as MAC addresses to ensure fair evaluation. Multiple classifiers—including Logistic Regression, Naive Bayes, Decision Tree, K-Nearest Neighbors, Support Vector Machine, Random Forest, and Gradient Boosting Trees—were implemented and evaluated using k-fold cross-validation. The results demonstrate that ensemble models achieved superior performance, with Random Forest and Gradient Boosting Trees reaching up to 100.0% accuracy on the full dataset and maintaining above 96.0% accuracy, precision, recall, and F1-score even when MAC-based features were excluded. Confusion matrix analysis further confirmed their robustness in distinguishing spoofed from legitimate traffic. In addition, we compared our models against a rule-based baseline resembling conventional DHCP Snooping, which achieved only ~70–75% detection accuracy. Finally, deployment considerations such as latency, model size, and fail-safe behavior are discussed, and the dataset and workflow are made available to support reproducibility. These contributions establish a practical and adaptive framework for strengthening DHCP Snooping against spoofing attacks in real-world networks.
Keywords
Supporting Institution
N/A
Project Number
N/A
Thanks
Thanks for efforts.
References
- Syafei, W. A., Soetrisno, Y. A. A., & Prasetijo, A. B. (2020, November). Simple smart algorithm for flexibility of dynamic allocation in DHCP server for SOHO wireless router. In 2020 International Conference on Computer Engineering, Network, and Intelligent Multimedia (CENIM) (pp. 321–325). IEEE.
- Ahmad, Z., Shahid Khan, A., Wai Shiang, C., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150.
- Yan, A., Jing, S., Qi, Q., & Xiao, B. (2016, May). A study on campus network access and export management. In 2nd Workshop on Advanced Research and Technology in Industry Applications (WARTIA-16) (pp. 1812–1816). Atlantis Press.
- Pradana, D. A., & Budiman, A. S. (2021). The DHCP Snooping and DHCP Alert method in securing DHCP server from DHCP rogue attack. IJID (International Journal on Informatics for Development), 10(1), 38–46.
- Miftah, Z. (2018). Simulasi keamanan jaringan dengan metode DHCP Snooping dan VLAN. Fakt. Exacta, 11(2), 167–172.
- Tripathi, N., & Hubballi, N. (2018). Detecting stealth DHCP starvation attack using a machine-learning approach. Journal of Computer Virology and Hacking Techniques, 14, 233–244.
- Jony, A., & Islam, M. N. (2023, September). An effective technique to automatically detect and neutralize rogue DHCP server. In 2023 International Conference on Information and Communication Technology for Sustainable Development (ICICT4SD) (pp. 244–248). IEEE.
- Tok, M. S., & Demirci, M. (2021). Security analysis of SDN controller-based DHCP services and attack mitigation with DHCP guard. Computers & Security, 109, 102394.
Details
Primary Language
English
Subjects
Information Security Management
Journal Section
Research Article
Authors
Early Pub Date
October 26, 2025
Publication Date
December 16, 2025
Submission Date
May 20, 2025
Acceptance Date
October 23, 2025
Published in Issue
Year 2026 Volume: 10 Number: 1
APA
Alhajahmad, B. (2025). Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping. Turkish Journal of Engineering, 10(1), 24-38. https://doi.org/10.31127/tuje.1702914
AMA
1.Alhajahmad B. Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping. TUJE. 2025;10(1):24-38. doi:10.31127/tuje.1702914
Chicago
Alhajahmad, Bashar. 2025. “Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping”. Turkish Journal of Engineering 10 (1): 24-38. https://doi.org/10.31127/tuje.1702914.
EndNote
Alhajahmad B (December 1, 2025) Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping. Turkish Journal of Engineering 10 1 24–38.
IEEE
[1]B. Alhajahmad, “Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping”, TUJE, vol. 10, no. 1, pp. 24–38, Dec. 2025, doi: 10.31127/tuje.1702914.
ISNAD
Alhajahmad, Bashar. “Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping”. Turkish Journal of Engineering 10/1 (December 1, 2025): 24-38. https://doi.org/10.31127/tuje.1702914.
JAMA
1.Alhajahmad B. Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping. TUJE. 2025;10:24–38.
MLA
Alhajahmad, Bashar. “Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping”. Turkish Journal of Engineering, vol. 10, no. 1, Dec. 2025, pp. 24-38, doi:10.31127/tuje.1702914.
Vancouver
1.Bashar Alhajahmad. Fortifying Network Security: A Machine Learning-Based Approach to Improving DHCP Snooping. TUJE. 2025 Dec. 1;10(1):24-38. doi:10.31127/tuje.1702914
Cited By
A Comprehensive Machine Learning Framework for Employee Attrition Prediction
Turkish Journal of Engineering
https://doi.org/10.31127/tuje.1864152