| An enhanced secure ARP protocol and LAN switch for preveting ARP based attacks |
| Full text |
Pdf
(383 KB)
|
| Source
|
International Conference On Communications And Mobile Computing
archive
Proceedings of the 2009 International Conference on Wireless Communications and Mobile Computing: Connecting the World Wirelessly
table of contents
Leipzig, Germany
SESSION: Security II (Computer and Network Security symposium)
table of contents
Pages 942-946
Year of Publication: 2009
ISBN:978-1-60558-569-7
|
|
Authors
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 34, Downloads (12 Months): 64, Citation Count: 0
|
|
|
ABSTRACT
After the ARP protocol was drafted, a subtle weakness in the protocol was discovered. In fact, ARP provides no means to establish the authenticity of the source of incoming ARP packets. That's why any host of a LAN network can forge an ARP message containing malicious information to poison the ARP caches of target hosts. This lack of authentication mechanisms has made ARP vulnerable to a raft of IP-based impersonation, Man-in-the-Middle (MiM) and DoS attacks. In this paper we discuss a security solution to solve the ARP vulnerabilities and authenticity issues. For that purpose, a novel secure extended ARP protocol is proposed. In addition, the LAN switch has been enhanced to assume the role of "Trusted Authority" and assure the hosts authentication while exchanging ARP messages.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
LBNL's Network Research Group, "Arpwatch: Ethernet Monitor Program", http://wwwnrg.ee.lbl.gov.pht.com/antisniff/.
|
| |
2
|
Snort: http://www.snort.org/.
|
| |
3
|
|
| |
4
|
|
| |
5
|
K. Seo, C. Lynn, and S. Kent. Public-Key Infrastructure for the Secure Border Gateway Protocol (S-BGP). In Proceedings of DARPA Information Survivability Conference and Exposition II. IEEE, June 2001.
|
| |
6
|
D. Song. dsniff: a collection of tools for network auditing and penetration testing. http://www.monkey.org/dugsong/dsniff, accessed May 2005.
|
| |
7
|
T. Demuth and A. Leitner. ARP spoofing and poisoning: Traffic tricks. Linux Magazine, 56:26--31, July 2005.
|
| |
8
|
C. Schluting. Configure your Catalyst for a more secure layer 2, Jan. 2005. <http://www.enterprisenetworkingplanet.com/netsecur/article.php/3462211>. (Last accessed April 17, 2006).
|
| |
9
|
|
| |
10
|
|
 |
11
|
|
| |
12
|
|
| |
13
|
|
|