Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.2.1. DoS and Layer 2 Attacks

Denial of Service (DoS):
  • DoS: Single source overwhelms target
  • DDoS: Distributed sources (botnet) overwhelm target
  • Amplification: Small request triggers large response (DNS, NTP)
Layer 2 Attacks:
AttackMethodDefense
MAC floodingOverflow switch CAM table → switch floods all trafficPort security (limit MACs per port)
ARP spoofing/poisoningFalse ARP replies redirect trafficDynamic ARP Inspection (DAI)
VLAN hoppingExploit trunk or double-tagging to access other VLANsDon't use VLAN 1, change native VLAN
Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications