CND (312-38) Network Defense Simulation
Investigate reported network degradation masking as a potential DoS attack. Analyze the interface statistics to understand physical and data-link layer behaviors and identify the underlying IEEE standard governing the traffic flow.
Network Scenario
Users in the Finance department are reporting severe network slowness and intermittent connection drops to the internal database. The helpdesk escalated the issue to the security team, suspecting a localized Denial-of-Service (DoS) attack or an infected host flooding the subnet.
You log into the access switch serving that floor to check for broadcast storms, anomalous traffic volumes, or MAC flooding. Instead, you find a specific port showing severe degradation, but the packet per second (PPS) count doesn't indicate a flood. You pull the interface statistics for analysis.
Traffic & Logs
Excerpt from Switch Interface Diagnostics:
Question
CSMA/CD is specified in which of the following IEEE standards?
Expert Analysis
1. What is happening in the network
The network interface `GigabitEthernet1/0/12` is experiencing a massive number of `collisions` (1890) and `late collisions` (125). Notice that the port is operating at `Half-duplex`. In a half-duplex environment, a device cannot send and receive data simultaneously. The legacy access method used to handle these transmissions is CSMA/CD.
2. Identify attack or behavior
This is not a DoS attack, although the symptom (network degradation and dropping connections) mimics one. This is an operational network issue, likely a "duplex mismatch" or the port being connected to a legacy shared-media hub. The high collision rate is triggering exponential backoff algorithms, severely throttling legitimate traffic.
3. Why the correct answer is correct
A. 802.3: IEEE 802.3 is the standard that defines Ethernet. Originally, this standard strictly governed Carrier Sense Multiple Access with Collision Detection (CSMA/CD) for shared media networks. Although modern full-duplex networks essentially disable the collision detection mechanism, CSMA/CD remains the foundational protocol defined under 802.3.
4. Why others are wrong
- B. 802.2: This standard defines the Logical Link Control (LLC) sublayer, which is the upper portion of the Data Link Layer. It does not handle media access or collision detection.
- C. 802.1: This group of standards handles higher-level LAN architectures, bridging, and management (such as VLANs in 802.1Q and Spanning Tree Protocol in 802.1D).
- D. 802.15: This standard specifies Wireless Personal Area Networks (WPANs), such as Bluetooth and Zigbee, which have completely different media access control methods.
5. Defensive action
To resolve this issue and improve network stability, defenders should:
- Investigate what is plugged into Gi1/0/12. If it is an unmanaged, legacy hub brought in by an employee, confiscate and replace it with a managed switch.
- Verify interface configurations on both ends of the link. Hardcode `speed 1000` and `duplex full` if auto-negotiation is failing and causing a duplex mismatch.
- Modernize access layer switch security by enforcing Port Security and 802.1X to prevent unauthorized network equipment (like hubs) from being plugged into the enterprise network.
6. MINI LESSON: Network Degradation vs. Active Attacks
Traffic Pattern Recognition: Analysts must distinguish between malicious floods (high PPS, abnormal SYN counts, fragmented packets) and physical/data-link layer failures. A duplex mismatch generating massive collisions acts exactly like a localized DoS by filling the segment with retransmissions. Knowing baseline 802.3 Ethernet behavior prevents wasted hours hunting for non-existent malware.