Affiliation:
1. Korea University, Seoul, Republic of Korea
2. Soongsil University, Seoul, Republic of Korea
Abstract
The address resolution protocol (ARP) is one of the most important communication protocols in a local area network (LAN). However, since there is no authentication procedure, the ARP is vulnerable to cyberattack such as ARP spoofing. Since ARP spoofing can be connected to critical attacks, including a man-in-the-middle (MITM) attack, detecting ARP spoofing initially without returning false-positive alarms is important. In general, however, existing works for ARP spoofing are unable to distinguish between ARP spoofing and connections from virtual machine (VM) guests, which results in false-positive alarms. In this article, we propose an access point-based ARP Spoofing Detector (ASD) that can detect ARP spoofing attacks without returning a false-positive rate. Our proposed system distinguishes between ARP spoofing and connections from VM guests using three information tables, AssocList, ARP cache table, and DHCP table, which are commonly managed by the access point based on a Linux system. We evaluated the performance of ASD on ARP spoofing attack experiments.
Funder
National Research Foundation of Korea
Subject
Computer Networks and Communications,Information Systems
Reference24 articles.
1. Using JPCAP to Prevent Man-in-the-Middle Attacks in a Local Area Network Environment
2. Rfc 826: an ethernet address resolution protocol;D. C. Plummer;InterNet Network Working Group,1982
Cited by
4 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献