Uppsats
Evaluating VLAN Segmentation as a Defense Against VLAN Hopping,DHCP and DNS Spoofing
Yrkesexamen på grundnivå
Mälardalens universitet/Akademin för innovation, design och teknik
Publicerad: 2026
Språk: Engelska
Sammanfattning
Network segmentation using Virtual Local Area Networks (VLANs) is a widely adopted securitypractice in small and medium-sized enterprise environments. However, VLANs can still beexploited through layer‑two attack vectors when not properly configured. This thesisinvestigates the extent to which basic VLAN segmentation limits the lateral spread of DHCPspoofing and DNS spoofing attacks, examines the susceptibility of segmented networks to VLANhopping, and evaluates which configuration‑level security mechanisms are required totransition from attack mitigation to full attack prevention. To answer these questions, two GNS3virtual environments were developed to isolate the effects of network hardening. The firstserved as a baseline VLAN segmented network, tested both in its default state and with VLANhopping enabled. The second was an identically structured hardened network, reinforced withdisabled DTP negotiation, DHCP snooping, and DNS interface restrictions to evaluatedefensive performance. Attacks such as DHCP spoofing, DNS spoofing, and VLAN hopping(via DTP manipulation and double‑tagging) were performed using tools such as Yersinia andEttercap, while Wireshark was used to validate and analyze the results. The results indicatedthat basic VLAN segmentation can mitigate certain attacks by restricting their impact to asingle broadcast domain, thereby limiting the spread. Attackers could break isolation if theswitch was spoofed through DTP exploitation, and with additional safety configurations,mainly disabling DTP, adding DHCP snooping, and DNS packet filtering on the switch,prevented all attacks carried out in this work. The conclusion drawn was that VLANsegmentation can mitigate attacks such as DHCP and DNS spoofing but not prevent them.VLAN hopping attacks couldn't be mitigated or prevented, meaning all attacks need additionalsupport for prevention.
Information
- Författare
- Bergstedt, Martin
- Lärosäte / institution
- Mälardalens universitet/Akademin för innovation, design och teknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- Yrkesexamen på grundnivå
- Språk
- Engelska