首页> 外文会议>International Conference on Information Systems Security >Detecting ARP Spoofing: An Active Technique
【24h】

Detecting ARP Spoofing: An Active Technique

机译:检测ARP欺骗:一种有源技术

获取原文

摘要

The Address Resolution Protocol (ARP) due to its stateless-ness and lack of an authentication mechanism for verifying the identity of the sender has a long history of being prone to spoofing attacks. ARP spoofing is sometimes the starting point for more sophisticated LAN attacks like denial of service, man in the middle and session hijacking. The current methods of detection use a passive approach, monitoring the ARP traffic and looking for inconsistencies in the Ethernet to IP address mapping. The main drawback of the passive approach is the time lag between learning and detecting spoofing. This sometimes leads to the attack being discovered long after it has been orchestrated. In this paper, we present an active technique to detect ARP spoofing. We inject ARP request and TCP SYN packets into the network to probe for inconsistencies. This technique is faster, intelligent, scalable and more reliable in detecting attacks than the passive methods. It can also additionally detect the real mapping of MAC to IP addresses to a fair degree of accuracy in the event of an actual attack.
机译:由于其无状态的状态和缺乏用于验证发件人的身份的身份验证机制而缺乏验证的地址解析协议(ARP)具有较长的历史悠闲地倾向于欺骗攻击。 ARP欺骗有时是更复杂的LAN攻击的起点,如拒绝服务,中间和会话中的人劫持。目前的检测方法使用被动方法,监视ARP流量并寻找以太网中的不一致性到IP地址映射。被动方法的主要缺点是学习和检测欺骗之间的时间滞后。这有时会导致在被策划后长时间发现的攻击。在本文中,我们提出了一种检测ARP欺骗的积极技术。我们将ARP请求和TCP SYN数据包注入网络以探测不一致。这种技术在检测攻击方面比被动方法更快,智能,可伸缩,更可靠。它还可以另外检测MAC到IP地址的真实映射,以便在实际攻击时进行公平的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号