Monitoring ARP Attack Using Responding Time and State ARP Cache

被引:0
|
作者
Wang, Zhenqi [1 ]
Zhou, Yu [1 ]
机构
[1] N China Elect Power Univ, Network Management Ctr, Boding 071000, Peoples R China
关键词
ARP cache poisoning; Stateful ARP cache; Normal Distribution Function; Hypothesis test;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
ARP cache poisoning is considered to be one of the easiest and the most dangerous attacks in local area networks. This paper proposes a solution to monitor the ARP poisoning problem, by extending the current ARP protocol implementation. Instead of the traditional stateless ARP cache, we use a state ARP cache in order to manage and secure the ARP cache. We also use a novel approach by monitoring responding time which is different between normal and malicious ARP reply. This method records ARP cache that may be malicious ARP reply, using the records we discover the attackers whose responding time is abnormal comparing with other responding time. Because the network condition is not smooth, the responding time is related to the Normal Distribution function, we use hypothesis testing to make sure who is the attacker.
引用
收藏
页码:701 / 709
页数:9
相关论文
共 50 条
  • [1] The Defense Against ARP Spoofing Attack Using Semi-Static ARP Cache Table
    Data, Mahendra
    PROCEEDINGS OF 2018 3RD INTERNATIONAL CONFERENCE ON SUSTAINABLE INFORMATION ENGINEERING AND TECHNOLOGY (SIET 2018), 2018, : 206 - 210
  • [2] Preventing ARP attacks using a fuzzy-based stateful ARP cache
    Trabelsi, Zouheir
    El-Hajj, Wassim
    2007 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-14, 2007, : 1355 - 1360
  • [3] A Distributed Security Approach against ARP Cache Poisoning Attack
    Nobakht, Mehdi
    Mahmoudi, Hadi
    Rahimzadeh, Omid
    CYSSS'22: PROCEEDINGS OF THE 1ST WORKSHOP ON CYBERSECURITY AND SOCIAL SCIENCES, 2022, : 27 - 32
  • [4] An Automated approach for Preventing ARP Spoofing Attack using Static ARP Entries
    Abdelsalam, Ahmed M.
    Elkilani, Wail S.
    Amin, Khalid M.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2014, 5 (01) : 105 - 112
  • [5] ARP Poisoning attack Detection based on ARP Update state in Software-Defined Networks.
    Kim, Youngpin
    Ahn, Sungwon
    Nguyen Canh Thang
    Choi, Dongho
    Park, Minho
    33RD INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2019), 2019, : 366 - 371
  • [6] Mitigating ARP Cache Poisoning Attack in Software-Defined Networking (SDN): A Survey
    Shah, Zawar
    Cosgrove, Steve
    ELECTRONICS, 2019, 8 (10)
  • [7] Learn ARP Spoofing Attack in a Game
    Xu, Jinsheng
    Yuan, Xiaohong
    Nallela, Swathi
    Hillard, Kevin
    Zhang, Jinghua
    2022 IEEE FRONTIERS IN EDUCATION CONFERENCE, FIE, 2022,
  • [8] Design and simulation of VHDL based ARP cache
    Tian-Hua, Liu
    Hong-Feng, Zhu
    Chuan-Sheng, Zhou
    Gui-Ran, Chang
    2007 THIRD INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING, VOL II, PROCEEDINGS, 2007, : 373 - 376
  • [9] An efficient solution to the ARP cache poisoning problem
    Goyal, V
    Tripathy, R
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2005, 3574 : 40 - 51
  • [10] A Mitigation System for ARP Cache Poisoning Attacks
    Prabadevi, B.
    Jeyanthi, N.
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,