loading
Papers

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Zouheir Trabelsi and Khaled Shuaib

Affiliation: College of Information Technology, UAE University, United Arab Emirates

ISBN: 978-972-8865-63-4

Keyword(s): Intrusions Detection Systems, Spoofed ARP, ARP Cache Poisoning, Packet Sniffers.

Related Ontology Subjects/Areas/Topics: Information and Systems Security ; Intrusion Detection & Prevention

Abstract: Spoofed ARP packets are used by malicious users to redirect network’s traffic to their hosts. The potential damage to a network from an attack of this nature can be very important. This paper discusses first how malicious users redirect network traffic using spoofed ARP packets. Then, the paper proposes a practical and efficient mechanism for detecting malicious hosts that are performing traffic redirection attack against other hosts in switched LAN networks. The proposed mechanism consists of sending first spoofed packets to the network’s hosts. Then, by collecting and analyzing the responses packets, it is shown how hosts performing traffic redirection attack can be identified efficiently and accurately. The affect of the proposed mechanism on the performance of the network is discussed and shown to be minimal. The limits of current IDSs regarding their ability to detect malicious traffic redirection attack, based on spoofed ARP packets, in switched LAN networks are discussed. Our w ork is concerned with the detection of malicious network traffic redirection attack, at the Data Link layer. Other works proposed protection mechanisms against this attack, but at the Application layer, using cryptographic techniques and protocols. (More)

PDF ImageFull Text

Download
CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.229.122.219

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Trabelsi Z.; Shuaib K. and (2006). SPOOFED ARP PACKETS DETECTION IN SWITCHED LAN NETWORKS.In Proceedings of the International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2006) ISBN 978-972-8865-63-4, pages 40-47. DOI: 10.5220/0002102400400047

@conference{secrypt06,
author={Zouheir Trabelsi and Khaled Shuaib},
title={SPOOFED ARP PACKETS DETECTION IN SWITCHED LAN NETWORKS},
booktitle={Proceedings of the International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2006)},
year={2006},
pages={40-47},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0002102400400047},
isbn={978-972-8865-63-4},
}

TY - CONF

JO - Proceedings of the International Conference on Security and Cryptography - Volume 1: SECRYPT, (ICETE 2006)
TI - SPOOFED ARP PACKETS DETECTION IN SWITCHED LAN NETWORKS
SN - 978-972-8865-63-4
AU - Trabelsi, Z.
AU - Shuaib, K.
PY - 2006
SP - 40
EP - 47
DO - 10.5220/0002102400400047

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.