A method for assessment, reporting and blocking OSI layer 2 security attacks on network devices on a port and VLAN basis

The method of periodic auditing and automated security hardening on network devices addresses the ineffectiveness of existing systems by proactively detecting and preventing OSI Layer 2 attacks, ensuring continuous security and real-time threat detection across various devices.

WO2025144242A1PCT designated stage Publication Date: 2025-07-03SECHARD BILGI TEKNOLOJILERI LTD SIRKETI
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/TR2024/051364
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing network security systems are ineffective in detecting and preventing OSI Layer 2 attacks originating from within the LAN, as they are designed to respond only after the attack occurs, lacking the capability to predict or block such threats proactively.

Method used

A method for periodic auditing of network devices using SSH and Telnet protocols to identify vulnerabilities, applying security hardening settings on ports and VLANs to prevent OSI Layer 2 attacks before they occur, utilizing automated and agentless security measures to ensure consistent management across diverse device types.

Benefits of technology

Enables proactive detection and prevention of OSI Layer 2 attacks, ensuring continuous security hardening and real-time alerts, thereby maintaining network integrity and reducing the risk of internal threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TR2024051364_03072025_PF_FP_ABST
    Figure TR2024051364_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The invention is a method for enabling security hardening settings to be applied on device ports and VLANs by applying port security controls on network devices in batches for multiple ports when necessary, in order to detect and prevent OSI Layer 2 attacks before they occur.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A METHOD FOR ASSESSMENT, REPORTING AND BLOCKING OSI LAYER 2 SECURITY ATTACKS ON NETWORK DEVICES ON A PORT

[0002] AND VLAN BASIS

[0003] FIELD OF THE INVENTION

[0004] The present invention is a method for preventing layer 2 security attacks on network devices.

[0005] The present invention is specifically a method to prevent layer 2 attacks before they occur. It provides periodic auditing of security vulnerabilities using SSH, Telnet, WinRM protocols and remediation of security vulnerabilities detected as a result of the audit by hardening. In this way, it ensures that network devices are always ready against OSI layer 2 security attacks.

[0006] STATE OF THE ART

[0007] Today, as the use of networks and network devices becomes more widespread, the number and severity of OSI layer 2 security attacks increase accordingly. Rapidly developing cyber threats threaten networks and network devices more and more every day.

[0008] The biggest problem in the known state of the art is that OSI Layer 2 attacks are made from inside the LAN (Local Area Networks), so firewall or intrusion detection systems do not have the ability to block these attacks. Generally, attack detection or blocking systems are used to detect or prevent attacks that may come from the external network to the internal network. Since these systems are designed for layer four and layer seven security, they do not have the capability to detect or prevent attacks from an attacker in the internal network to the switchers in the internal network. In order to ensure network security, it is necessary to ensure the security of all OSI layers. Moreover, these systems mentioned are systems that have the logic of preventing an attack after it occurs.

[0009] In this context, the biggest problem in the current situation is that the structures with wide network device systems cannot take action against OSI Layer 2 attacks before the attack occurs and do not have any system that can predict these threats.

[0010] OSI Layer 2 threats aim to disrupt networks or compromise network users' access to sensitive information. Having access to this sensitive information is a significant threat to companies. For this reason, taking precautions before possible OSI Layer 2 attacks occur will eliminate problems that may arise later.

[0011] Due to the abovementioned disadvantages and the insufficiency of the solutions regarding the subject matter, a development is required to be made in the relevant technical field.

[0012] OBJECT OF THE INVENTION

[0013] In this context, the main object of the development of the invention for the prevention of OSI Layer 2 attacks before they occur is to minimize the threat and possible effects of the attack by eliminating the deficiencies of the security systems operating when the attack occurs.

[0014] Another object of the invention is to eliminate possible errors that may arise from manual hardening of vulnerabilities with automatic and agentless security measures against OSI Layer 2 attacks, and to detect and eliminate the possibility of attack in advance by performing routine or optional vulnerability assessments and hardening. Only in this way can a consistent management process be provided.

[0015] Another object of the invention is to keep network device systems safe by continuously hardening them, while ensuring that this can be done regardless of the make and model of the devices on the network, in other words, unified for all devices on the network.

[0016] Another indirect object of the invention is to establish a central security detection and improvement system and to enable panoramic monitoring of the system from a single center.

[0017] Another object of the invention is to ensure that security audits and hardening can be carried out routinely or optionally and that companies can be informed about the security situation through continuous reporting. Another object is to ensure that companies, or in general terms all structures with network device systems, are one step ahead against attacks by detecting security vulnerabilities and developing threats before they occur with real-time alerts.

[0018] The structural and characteristic features of the present invention will be understood clearly by the following detailed description. Therefore the evaluation shall be made by taking this detailed description into consideration.

[0019] Figures Clarifying the Invention

[0020] Figure 1 is the workflow diagram of the assessment and remediation processes related to the early detection of possible OSI layer 2 attacks,

[0021] DETAILED DESCRIPTION OF THE INVENTION

[0022] In this detailed description, the subject matter of the invention ‘Detection and prevention of OSI layer 2 attacks on network devices before they occur’ will be explained only for a better understanding of the subject matter and without any limiting effect.

[0023] The inventive development enables security hardening settings to be applied on device ports and VLANs by implementing port security checks on network devices to detect and prevent OSI Layer 2 atacks before they occur. It checks the security status of network devices routinely and simultaneously for all network devices and immediately initiates the necessary hardening process if any security vulnerability is detected. In case of a security vulnerability detected during routine audits, it closes the Telnet protocol, which is known to be insecure beyond fixing the vulnerability, and creates a 100% security hardening process by recommending the secure use of the SSH protocol.

[0024] It would be appropriate to clarify some concepts in order to understand the subject more easily.

[0025] Network Devices: Switch, router

[0026] OSI Layer 2 Attacks: Mac Flooding Attack, Cdp atack, LLDP Atack, STP Manipulation Attack, DHCP Starvation Atack, Arp Spoofing Atack, Telnet Attack, Vian Hopping Attack, ICMP Based Attack

[0027] The main logic of the invention is to prevent possible security vulnerabilities by checking them on a PORT and VLAN basis. The connection is opened without entering any commands via the protocols supported by the network devices (SSH / Telnet) and connected to the network device without using a terminal tool. After connecting to the network device, an assessment is performed simultaneously for all network devices in order to detect possible security vulnerabilities on the device. As a result of the audit, if an atack type (Mac Flooding Attack, Cdp attack, LLDP Attack, STP Manipulation Attack, DHCP Starvation Attack, Arp Spoofing Attack, Vian Hopping Attack, ICMP Based Attack) is detected on the port, commands / scripts prepared accordingly are sent to prevent the atack before it occurs. Commands are sent to multiple ports simultaneously, providing mass security hardening. Device configurations are saved in the database and percentage score / reporting is made.

[0028] The detailed workflow mentioned comprises the following process steps; • Automatic or manual identification of network devices to the system (1001), (assessment)

[0029] • Accessing the network device using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices, (1002), (assessment)

[0030] • Execution of codes / scripts created in accordance with the target network device on the target device (1003), (hardening)

[0031] • Saving the ports with their scripts in the database and monitoring their status instantly before hardening the security against OSI Layer 2 attacks, (1004) (hardening)

[0032] • Checking the current configurations of network devices with predefined prescriptions and saving the outputs in the database (1005) (assessment)

[0033] • Checking each supported Layer 2 attack on a port, vlan basis and reporting in advance which attacks will be exposed to a percentage (1007), (assessment)

[0034] • Ensuring a collective security hardening by sending the commands / scripts prepared in accordance with the layer 2 attack type detected in the assessment studies to the target network device and performing the remediation process for multiple ports at the same time when necessary (1007), (remediation)

[0035] • Retrieving transaction data, saving in the database, 100% scoring / reporting with the rollback feature in the implemented Layer 2 security process, (1008), (rollback).

[0036] Figure 1 shows the flow diagram of the algorithm for preventing and eliminating OSI layer 2 attacks before they occur.

[0037] As can be seen, firstly, OSI layer 2 attacks are audited / detected (assessment) and possible security vulnerabilities encountered as a result of the assessment are remediated before the attack occurs by running the appropriate codes prepared for the relevant port, vlan on the target asset.

Claims

CLAIMS1. A method for detecting and preventing possible OSI layer 2 attacks on network devices before they occur, comprising the following process steps;• Automatic or manual identification of network devices to the system (1001),• Accessing the network device using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices so as to make assessment, (1002),• Accessing the network device using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices so as to make hardening, (1005), characterized in that, it comprises the following process steps;• Performing assessment with the execution of codes / scripts created in accordance with the target network device on the target device (1003),• Saving the ports with their scripts in the database and monitoring their status instantly before hardening the security against OSI Layer 2 attacks, (1004)• Checking the current configurations of network devices with predefined prescriptions and saving the outputs in the database (1006),• Checking each supported Layer 2 attack on a port, vlan basis and reporting in advance which attacks will be exposed to a percentage (1007),• Ensuring a collective security hardening by sending the commands / scripts prepared in accordance with the layer 2 attack type detected in the assessment studies to the target network device and performing the remediation process for multiple ports at the same time when necessary (1008).

2. A method according to claim 1, characterized in that; it comprises the steps of retrieving the transaction data with the rollback feature, saving the transaction data in the database, and performing percentage scoring / reporting (1009) in orderto be 100% sure of the correctness of the auditing process performed before the layer 2 attacks applied.

Citation Information

Patent Citations

  • Scalable inline behavioral ddos attack mitigation

    US20150026800A1

  • Systems and methods for preventing replay attacks

    US20210120033A1

  • A method for predicting possible attacks on wireless communication systems

    WO2022146362A1