Skip to main content

Spoofed ARP Packets Detection in Switched LAN Networks

  • Conference paper
E-Business and Telecommunication Networks (ICETE 2006)

Part of the book series: Communications in Computer and Information Science ((CCIS,volume 9))

Included in the following conference series:

Abstract

Spoofed ARP packets are used by malicious users to redirect network’s traffic to their hosts. The potential damage to a network from an attack of this nature can be very important. This paper discusses first how malicious users redirect network traffic using spoofed ARP packets. Then, the paper proposes a practical and efficient mechanism for detecting malicious hosts that are performing traffic redirection attack against other hosts in switched LAN networks. The proposed mechanism consists of sending first spoofed packets to the network’s hosts. Then, by collecting and analyzing the responses packets, it is shown how hosts performing traffic redirection attack can be identified efficiently and accurately. The affect of the proposed mechanism on the performance of the network is discussed and shown to be minimal. The limits of current IDSs regarding their ability to detect malicious traffic redirection attack, based on spoofed ARP packets, in switched LAN networks are discussed. Our work is concerned with the detection of malicious network traffic redirection attack, at the Data Link layer. Other works proposed protection mechanisms against this attack, but at the Application layer, using cryptographic techniques and protocols.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 84.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. ftp://ftp.ee.lbl.gov/arpwatch.tar.gz

  2. http://www.snort.org

  3. Plummer, D.C.: An Ethernet Address Resolution Protocol-Converting Network Protocol to 48 bit Ethernet Address for Transmission on Ethernet Hardware, RFC-826 (1982)

    Google Scholar 

  4. Postel, J.: Internet Control Message Protocol, RFC-792 (1981)

    Google Scholar 

  5. Stevens, R.: TCP/IP Illustrated: vol. 1 (2001)

    Google Scholar 

  6. Sanai, D.: Detection of Promiscuous Nodes Using ARP Packets (2004), http://www.securityfriday.com

  7. Trabelsi, Z., et al.: Detection of Sniffers in an Ethernet Network. In: Zhang, K., Zheng, Y. (eds.) ISC 2004. LNCS, vol. 3225, pp. 170–182. Springer, Heidelberg (2004)

    Google Scholar 

  8. Trabelsi, Z., et al.: An Anti-Sniffer Based on ARP Cache Poisoning Attack. Information System Security Journal 13(6) (2005)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Joaquim Filipe Mohammad S. Obaidat

Rights and permissions

Reprints and permissions

Copyright information

© 2008 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Trabelsi, Z., Shuaib, K. (2008). Spoofed ARP Packets Detection in Switched LAN Networks. In: Filipe, J., Obaidat, M.S. (eds) E-Business and Telecommunication Networks. ICETE 2006. Communications in Computer and Information Science, vol 9. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-70760-8_7

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-70760-8_7

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-70759-2

  • Online ISBN: 978-3-540-70760-8

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics