Artigo Acesso aberto

A New Approach for Detecting and Mitigating Address Resolution Protocol (ARP) Poisoning

2022; Science and Information Organization; Volume: 13; Issue: 6 Linguagem: Inglês

10.14569/ijacsa.2022.0130647

ISSN

2158-107X

Autores

Ahmed A. Galal, Atef Z. Ghalwash, Mona Nasr,

Tópico(s)

Software-Defined Networks and 5G

Resumo

Address Resolution Protocol (ARP) Poisoning attack is considered as one of the most devastating attacks in a network context. As a result of its stateless nature and lack of authentication, this protocol suffers from many spoofing attacks in which attackers poison the cache of hosts on the network. By sending spoofed ARP requests and replies. This paper proposes an approach for detecting and mitigating ARP poisoning. This approach includes three modules: Module 1 for giving permission for first time and to store information in the database. There a security measure using MD5 hash is used. Module 2 is for avoiding internal ARP. Module 3 is for detecting whether a MAC has two IPs or an IP has two MACs. The architecture includes a database that gives a great facility and support for storing ARP table information. As ARP table entries generally expire after a short amount of time. To ensure changes in the network are accounted for. Experiments were conducted on real life network environment using Ettercap to check the functionality of the proposed mechanism. The results of experiments show that the proposed approach was able to detect and mitigate ARP poisoning. Especially, whether a MAC has two IPs or an IP has two MACs.

Referência(s)