CND (312-38) Network Defense Simulation

Investigate reported network degradation masking as a potential DoS attack. Analyze the interface statistics to understand physical and data-link layer behaviors and identify the underlying IEEE standard governing the traffic flow.

Network Scenario

Users in the Finance department are reporting severe network slowness and intermittent connection drops to the internal database. The helpdesk escalated the issue to the security team, suspecting a localized Denial-of-Service (DoS) attack or an infected host flooding the subnet.

You log into the access switch serving that floor to check for broadcast storms, anomalous traffic volumes, or MAC flooding. Instead, you find a specific port showing severe degradation, but the packet per second (PPS) count doesn't indicate a flood. You pull the interface statistics for analysis.

Traffic & Logs

Excerpt from Switch Interface Diagnostics:

Switch# show interfaces GigabitEthernet1/0/12 GigabitEthernet1/0/12 is up, line protocol is up (connected) Hardware is Gigabit Ethernet, address is 001a.2b3c.4d5e Half-duplex, 100Mb/s, media type is 10/100/1000BaseTX Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 124000 bits/sec, 122 packets/sec 5 minute output rate 234000 bits/sec, 204 packets/sec 14562 packets input, 1230459 bytes, 0 no buffer Received 2345 broadcasts (0 multicasts) 0 runts, 0 giants, 0 throttles 1845 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored 3458 packets output, 456783 bytes, 0 underruns 2104 output errors, 1890 collisions, 214 interface resets 125 late collisions, 0 deferred

Question

CSMA/CD is specified in which of the following IEEE standards?

Hint: Look at the logs showing "collisions" and "Half-duplex". CSMA/CD is the foundational access method for wired Ethernet. Which IEEE standard defines wired Ethernet?

Expert Analysis

1. What is happening in the network

The network interface `GigabitEthernet1/0/12` is experiencing a massive number of `collisions` (1890) and `late collisions` (125). Notice that the port is operating at `Half-duplex`. In a half-duplex environment, a device cannot send and receive data simultaneously. The legacy access method used to handle these transmissions is CSMA/CD.

2. Identify attack or behavior

This is not a DoS attack, although the symptom (network degradation and dropping connections) mimics one. This is an operational network issue, likely a "duplex mismatch" or the port being connected to a legacy shared-media hub. The high collision rate is triggering exponential backoff algorithms, severely throttling legitimate traffic.

3. Why the correct answer is correct

A. 802.3: IEEE 802.3 is the standard that defines Ethernet. Originally, this standard strictly governed Carrier Sense Multiple Access with Collision Detection (CSMA/CD) for shared media networks. Although modern full-duplex networks essentially disable the collision detection mechanism, CSMA/CD remains the foundational protocol defined under 802.3.

4. Why others are wrong

  • B. 802.2: This standard defines the Logical Link Control (LLC) sublayer, which is the upper portion of the Data Link Layer. It does not handle media access or collision detection.
  • C. 802.1: This group of standards handles higher-level LAN architectures, bridging, and management (such as VLANs in 802.1Q and Spanning Tree Protocol in 802.1D).
  • D. 802.15: This standard specifies Wireless Personal Area Networks (WPANs), such as Bluetooth and Zigbee, which have completely different media access control methods.

5. Defensive action

To resolve this issue and improve network stability, defenders should:

  • Investigate what is plugged into Gi1/0/12. If it is an unmanaged, legacy hub brought in by an employee, confiscate and replace it with a managed switch.
  • Verify interface configurations on both ends of the link. Hardcode `speed 1000` and `duplex full` if auto-negotiation is failing and causing a duplex mismatch.
  • Modernize access layer switch security by enforcing Port Security and 802.1X to prevent unauthorized network equipment (like hubs) from being plugged into the enterprise network.

6. MINI LESSON: Network Degradation vs. Active Attacks

Traffic Pattern Recognition: Analysts must distinguish between malicious floods (high PPS, abnormal SYN counts, fragmented packets) and physical/data-link layer failures. A duplex mismatch generating massive collisions acts exactly like a localized DoS by filling the segment with retransmissions. Knowing baseline 802.3 Ethernet behavior prevents wasted hours hunting for non-existent malware.

Explore more CND simulations