DocumentCode
2210268
Title
A host based DES approach for detecting ARP spoofing
Author
Barbhuiya, Ferdous A. ; Biswas, Santosh ; Hubballi, Neminath ; Nandi, Sukumar
Author_Institution
Indian Inst. of Technol. Guwahati, Guwahati, India
fYear
2011
fDate
11-15 April 2011
Firstpage
114
Lastpage
121
Abstract
Address Resolution Protocol (ARP) based attacks are caused by compromised hosts in the LAN and mainly involve spoofing with falsified IP-MAC pairs. Since ARP is a stateless protocol such attacks are possible. Neither there are signatures available for these attacks nor any significant statistical behavior change can be observed. So existing signature or anomaly intrusion detection systems are unable to detect these type of attacks. Several schemes have been proposed in the literature to circumvent these attacks, however, these techniques either make IP-MAC pairing static, modify the existing ARP, violate network layering architecture etc. In this paper a host based Discrete Event System (DES) approach is proposed for detecting ARP spoofing attacks. This approach does not require any extra constraint like static IP-MAC, changing the ARP or violation of network layering architecture.
Keywords
computer network security; discrete event systems; local area networks; protocols; ARP spoofing attack detection; LAN; address resolution protocol; falsified IP-MAC pairs; host based DES approach; host based discrete event system approach; network layering architecture; stateless protocol; Clocks; Cryptography; Detectors; IP networks; Local area networks; Probes; Protocols; Address Resolution Protocol (ARP); Discrete Event systems; Failure Detection; Network Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Computational Intelligence in Cyber Security (CICS), 2011 IEEE Symposium on
Conference_Location
Paris
Print_ISBN
978-1-4244-9905-2
Type
conf
DOI
10.1109/CICYBS.2011.5949401
Filename
5949401
Link To Document