• DocumentCode
    597762
  • Title

    ARP spoofing detection algorithm using ICMP protocol

  • Author

    Gao Jinhua ; Xia Kejian

  • Author_Institution
    Sch. of Comput. & Commun. Eng., Univ. of Sci. & Technol. Beijing, Beijing, China
  • fYear
    2013
  • fDate
    4-6 Jan. 2013
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Today, there are an increasing number of attack technologies among which ARP spoofing attack is considered as one of the easiest but dangerous method in local area networks. This paper discusses ARP spoofing attack and some related works about it first. On these bases, the paper proposed an efficient algorithm based on ICMP protocol to detect malicious hosts that are performing ARP spoofing attack. The technique includes collecting and analyzing the ARP packets, and then injecting ICMP echo request packets to probe for malicious host according to its response packets. It won´t disturb the activities of the hosts on the network. It can also detect the real address mappings during an attack.
  • Keywords
    access protocols; local area networks; security of data; transport protocols; ARP packet analysis; ARP packet collection; ARP spoofing detection algorithm; ICMP protocol; MAC address; attack technology; host activity; injecting ICMP echo request packet; local area network; malicious host detection; malicious host probing; real address mapping detection; response packet; Computers; Databases; Hardware; IP networks; Informatics; Protocols; Routing; ARP cache; ARP protocol; ARP spoofing attack; ICMP protocol;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communication and Informatics (ICCCI), 2013 International Conference on
  • Conference_Location
    Coimbatore
  • Print_ISBN
    978-1-4673-2906-4
  • Type

    conf

  • DOI
    10.1109/ICCCI.2013.6466290
  • Filename
    6466290