首页> 外文期刊>Communications and Network >Address Resolution Protocol (ARP): Spoofing Attack and Proposed Defense
【24h】

Address Resolution Protocol (ARP): Spoofing Attack and Proposed Defense

机译:地址解析协议(ARP):欺骗攻击和建议的防御

获取原文
           

摘要

Networks have become an integral part of today’s world. The ease of deployment, low-cost and high data rates have contributed significantly to their popularity. There are many protocols that are tailored to ease the process of establishing these networks. Nevertheless, security-wise precautions were not taken in some of them. In this paper, we expose some of the vulnerability that exists in a commonly and widely used network protocol, the Address Resolution Protocol (ARP) protocol. Effectively, we will implement a user friendly and an easy-to-use tool that exploits the weaknesses of this protocol to deceive a victim’s machine and a router through creating a sort of Man-in-the-Middle (MITM) attack. In MITM, all of the data going out or to the victim machine will pass first through the attacker’s machine. This enables the attacker to inspect victim’s data packets, extract valuable data (like passwords) that belong to the victim and manipulate these data packets. We suggest and implement a defense mechanism and tool that counters this attack, warns the user, and exposes some information about the attacker to isolate him. GNU/Linux is chosen as an operating system to implement both the attack and the defense tools. The results show the success of the defense mechanism in detecting the ARP related attacks in a very simple and efficient way.
机译:网络已成为当今世界不可或缺的一部分。易于部署,低成本和高数据速率极大地促进了它们的普及。有许多旨在简化建立这些网络的过程的协议。但是,其中一些措施并未采取安全措施。在本文中,我们揭示了一种普遍存在且广泛使用的网络协议(地址解析协议(ARP)协议)中存在的漏洞。有效地,我们将实施一种用户友好且易于使用的工具,该工具利用该协议的弱点,通过制造一种中间人(MITM)攻击来欺骗受害者的机器和路由器。在MITM中,所有传出或发送到受害计算机的数据将首先通过攻击者的计算机。这使攻击者可以检查受害者的数据包,提取属于受害者的有价值的数据(例如密码)并操纵这些数据包。我们建议并实施一种防御机制和工具,以抵抗这种攻击,警告用户并公开一些有关攻击者的信息以隔离他。选择GNU / Linux作为同时实现攻击和防御工具的操作系统。结果表明,该防御机制以非常简单和有效的方式成功地检测了ARP相关攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号