LAN Switch Security: What Hackers Know About Your Switches

本书详细解析了局域网(LAN)中以太网交换机的安全漏洞,并提供了相应的配置指南来预防或缓解攻击。内容覆盖了从交换机实现到控制平面及数据平面协议的各种安全风险,包括STP、CDP、ARP、DHCP等协议的安全问题。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

版权声明:原创作品,允许转载,转载时请务必以超链接形式标明文章原始出版、作者信息和本声明。否则将追究法律责任。 http://blog.youkuaiyun.com/topmvp - topmvp

Contrary to popular belief, Ethernet switches are not inherently secure. Security vulnerabilities in Ethernet switches are multiple: from the switch implementation, to control plane protocols (Spanning Tree Protocol [STP], Cisco® Discovery Protocol [CDP], and so on) and data plane protocols, such as Address Routing Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP). LAN Switch Security explains all the vulnerabilities in a network infrastructure related to Ethernet switches. Further, this book shows you how to configure a switch to prevent or to mitigate attacks based on those vulnerabilities. This book also includes a section on how to use an Ethernet switch to increase the security of a network and prevent future attacks. Use port security to protect against CAM attacks

*Prevent spanning-tree attacks
*Isolate VLANs with proper configuration techniques
*Protect against rogue DHCP servers
*Block ARP snooping
*Prevent IPv6 neighbor discovery and router solicitation exploitation
*Identify Power over Ethernet vulnerabilities
*Mitigate risks from HSRP and VRPP
*Stop information leaks with CDP, PaGP, VTP, CGMP and other Cisco ancillary protocols
*Understand and prevent DoS attacks against switches
*Enforce simple wirespeed security policies with ACLs
*Implement user authentication on a port base with IEEE 802.1x
*Use new IEEE protocols to encrypt all Ethernet frames at wirespeed.

http://rapidshare.com/files/58141592/1587052563.zip
http://depositfiles.com/files/1878887
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值