首页> 外文会议>International Conference on e-Business and Telecommunications >SPOOFED ARP PACKETS DETECTION IN SWITCHED LAN NETWORKS
【24h】

SPOOFED ARP PACKETS DETECTION IN SWITCHED LAN NETWORKS

机译:切换LAN网络中的欺骗ARP数据包检测

获取原文

摘要

Spoofed ARP packets are used by malicious users to redirect network's traffic to their hosts. The potential damage to a network from an attack of this nature can be very important. This paper discusses first how malicious users redirect network traffic using spoofed ARP packets. Then, the paper proposes a practical and efficient mechanism for detecting malicious hosts that are performing traffic redirection attack against other hosts in switched LAN networks. The proposed mechanism consists of sending first spoofed packets to the network's hosts. Then, by collecting and analyzing the responses packets, it is shown how hosts performing traffic redirection attack can be identified efficiently and accurately. The affect of the proposed mechanism on the performance of the network is discussed and shown to be minimal. The limits of current IDSs regarding their ability to detect malicious traffic redirection attack, based on spoofed ARP packets, in switched LAN networks are discussed. Our work is concerned with the detection of malicious network traffic redirection attack, at the Data Link layer. Other works proposed protection mechanisms against this attack, but at the Application layer, using cryptographic techniques and protocols.
机译:恶意用户使用恶意的ARP数据包将网络的流量重定向到主机。从这种性质的攻击中对网络的潜在损害可能非常重要。本文首先讨论了恶意用户如何使用欺骗ARP数据包重定向网络流量。然后,本文提出了一种用于检测对切换LAN网络中其他主机执行流量重定向攻击的恶意主机的实用和有效的机制。所提出的机制包括向网络主机发送首先欺骗数据包。然后,通过收集和分析响应分组,显示了可以有效且准确地识别执行流量重定向攻击的主机。讨论了拟议机制对网络性能的影响,并显示为最小。讨论了当前IDS的限制,他们在切换LAN网络中基于欺骗式ARP数据包检测恶意流量重定向攻击的能力。我们的工作涉及在数据链路层中检测到恶意网络流量重定向攻击。其他作品提出了对此攻击的保护机制,但在应用层使用加密技术和协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号