TY - GEN
T1 - Spoofed ARP packets detection in switched LAN networks
AU - Trabelsi, Zouheir
AU - Shuaib, Khaled
N1 - Publisher Copyright:
© Springer-Verlag Berlin Heidelberg 2008.
PY - 2008
Y1 - 2008
N2 - Spoofed ARP packets are used by malicious users to redirect network’s traffic to their hosts. The potential damage to a network from an attack of this nature can be very important. This paper discusses first how malicious users redirect network traffic using spoofed ARP packets. Then, the paper proposes a practical and efficient mechanism for detecting malicious hosts that are performing traffic redirection attack against other hosts in switched LAN networks. The proposed mechanism consists of sending first spoofed packets to the network’s hosts. Then, by collecting and analyzing the responses packets, it is shown how hosts performing traffic redirection attack can be identified efficiently and accurately. The affect of the proposed mechanism on the performance of the network is discussed and shown to be minimal. The limits of current IDSs regarding their ability to detect malicious traffic redirection attack, based on spoofed ARP packets, in switched LAN networks are discussed. Our work is concerned with the detection of malicious network traffic redirection attack, at the Data Link layer. Other works proposed protection mechanisms against this attack, but at the Application layer, using cryptographic techniques and protocols.
AB - Spoofed ARP packets are used by malicious users to redirect network’s traffic to their hosts. The potential damage to a network from an attack of this nature can be very important. This paper discusses first how malicious users redirect network traffic using spoofed ARP packets. Then, the paper proposes a practical and efficient mechanism for detecting malicious hosts that are performing traffic redirection attack against other hosts in switched LAN networks. The proposed mechanism consists of sending first spoofed packets to the network’s hosts. Then, by collecting and analyzing the responses packets, it is shown how hosts performing traffic redirection attack can be identified efficiently and accurately. The affect of the proposed mechanism on the performance of the network is discussed and shown to be minimal. The limits of current IDSs regarding their ability to detect malicious traffic redirection attack, based on spoofed ARP packets, in switched LAN networks are discussed. Our work is concerned with the detection of malicious network traffic redirection attack, at the Data Link layer. Other works proposed protection mechanisms against this attack, but at the Application layer, using cryptographic techniques and protocols.
KW - ARP cache poisoning
KW - Intrusions detection systems
KW - Packet sniffers
KW - Spoofed ARP
UR - http://www.scopus.com/inward/record.url?scp=84994593785&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84994593785&partnerID=8YFLogxK
U2 - 10.1007/978-3-540-70760-8_7
DO - 10.1007/978-3-540-70760-8_7
M3 - Conference contribution
AN - SCOPUS:84994593785
SN - 9783540707592
T3 - Communications in Computer and Information Science
SP - 81
EP - 91
BT - E-Business and Telecommunication Networks - 3rd International Conference, ICETE 2006, Selected Papers
A2 - Filipe, Joaquim
A2 - Obaidat, Mohammad S.
PB - Springer Verlag
T2 - International Joint Conference on e-Business and Telecommunications, ICETE 2006
Y2 - 7 August 2006 through 10 August 2006
ER -