【24h】

Techniques To Secure Address Resolution Protocol

机译:确保地址解析协议的技术

获取原文

摘要

Address Resolution Protocol was developed to create a standard for translating IP addresses to physical addresses. ARP takes (IP, Protocol) as input and converts to physical address. ARP can be easily spoofed because it lacks security. The inventors of ARP thought that internal to the network threats were minimum, and ARP had to be simple for its efficient and dynamic working. A machine in the network, which can work at the data link layer, can be easily spoofed because of the vulnerability in ARP protocol, leading to a man-in-the-middle attack. Securing ARP is not an easy task because state information should be preserved for authentication of ARP frames. However, the protocol is stateless, and making changes to the ARP protocol itself is not practical since the protocol is currently being widely used. Our objective in this paper is to provide a solution to detect and mitigate ARP spoofing attacks without any changes to the protocol itself. The proposed system provides improvement to an existing solution using ICMP to detect ARP spoofing.
机译:开发地址解析协议是为了创建一个将IP地址转换为物理地址的标准。 ARP以(IP,协议)作为输入并将其转换为物理地址。由于ARP缺乏安全性,因此很容易被欺骗。 ARP的发明者认为,内部网络威胁是最小的,并且ARP必须简单,高效且动态地工作。可以在数据链路层工作的网络中的计算机由于ARP协议中的漏洞而容易被欺骗,从而导致中间人攻击。保护ARP并非易事,因为应保留状态信息以用于ARP帧的身份验证。但是,该协议是无状态的,并且由于该协议当前正在被广泛使用,因此对ARP协议本身进行更改是不切实际的。本文的目的是提供一种无需更改协议本身即可检测和缓解ARP欺骗攻击的解决方案。提出的系统对使用ICMP检测ARP欺骗的现有解决方案进行了改进。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号