首页> 外文会议> >A middleware approach to asynchronous and backward compatible detection and prevention of ARP cache poisoning
【24h】

A middleware approach to asynchronous and backward compatible detection and prevention of ARP cache poisoning

机译:一种中间件方法,用于异步和向后兼容检测并防止ARP缓存中毒

获取原文

摘要

Discusses the Address Resolution Protocol (ARP) and the problem of ARP cache poisoning. ARP cache poisoning is the malicious act, by a host in a LAN, of introducing a spurious IP address to MAC (Ethernet) address mapping in another host's ARP cache. We discuss design constraints for a solution: the solution needs to be implemented in middleware, without any access or change to any operating system source code, it needs to be backward-compatible with the existing protocol and to be asynchronous. We present our solution and implementation aspects of it in a Streams-based networking subsystem. Our solution comprises two parts: a "bump in the stack" Streams module, and a separate Stream with a driver and user-level application. We also present the algorithm that is executed in the module and application to prevent ARP cache poisoning where possible, and to detect and raise alarms otherwise. We then discuss some limitations with our approach and present some preliminary performance figures for our implementation.
机译:讨论地址解析协议(ARP)和ARP缓存中毒的问题。 ARP缓存中毒是LAN中的主机的恶意行为,是在另一个主机的ARP缓存中将虚假IP地址引入到MAC(以太网)地址映射。我们讨论了解决方案的设计约束:该解决方案需要在中间件中实现,而无需任何访问或更改任何操作系统源代码,它需要与现有协议向后兼容,并且必须是异步的。我们在基于Streams的网络子系统中介绍其解决方案和实现方面。我们的解决方案包括两部分:“堆栈中的颠簸” Streams模块,以及带有驱动程序和用户级应用程序的单独Stream。我们还介绍了在模块和应用程序中执行的算法,以在可能的情况下防止ARP缓存中毒,并在其他情况下检测并发出警报。然后,我们讨论我们的方法的一些局限性,并提出一些初步的性能数据以供实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号