ACM Home Page
Please provide us with feedback. Feedback
An enhanced secure ARP protocol and LAN switch for preveting ARP based attacks
Full text PdfPdf (383 KB)
Source International Conference On Communications And Mobile Computing archive
Proceedings of the 2009 International Conference on Wireless Communications and Mobile Computing: Connecting the World Wirelessly table of contents
Leipzig, Germany
SESSION: Security II (Computer and Network Security symposium) table of contents
Pages 942-946  
Year of Publication: 2009
ISBN:978-1-60558-569-7
Authors
Senda Hammouda  MEDIATRON, SUP'COM, Cité El Ghazela, Tunisia
Zouheir Trabelsi  UAE University, CIT, Al Ain, UAE
Sponsors
ACM: Association for Computing Machinery
: Wiley-Blackwell
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 34,   Downloads (12 Months): 64,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1582379.1582584
What is a DOI?

ABSTRACT

After the ARP protocol was drafted, a subtle weakness in the protocol was discovered. In fact, ARP provides no means to establish the authenticity of the source of incoming ARP packets. That's why any host of a LAN network can forge an ARP message containing malicious information to poison the ARP caches of target hosts. This lack of authentication mechanisms has made ARP vulnerable to a raft of IP-based impersonation, Man-in-the-Middle (MiM) and DoS attacks. In this paper we discuss a security solution to solve the ARP vulnerabilities and authenticity issues. For that purpose, a novel secure extended ARP protocol is proposed. In addition, the LAN switch has been enhanced to assume the role of "Trusted Authority" and assure the hosts authentication while exchanging ARP messages.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
LBNL's Network Research Group, "Arpwatch: Ethernet Monitor Program", http://wwwnrg.ee.lbl.gov.pht.com/antisniff/.
 
2
Snort: http://www.snort.org/.
 
3
 
4
 
5
K. Seo, C. Lynn, and S. Kent. Public-Key Infrastructure for the Secure Border Gateway Protocol (S-BGP). In Proceedings of DARPA Information Survivability Conference and Exposition II. IEEE, June 2001.
 
6
D. Song. dsniff: a collection of tools for network auditing and penetration testing. http://www.monkey.org/dugsong/dsniff, accessed May 2005.
 
7
T. Demuth and A. Leitner. ARP spoofing and poisoning: Traffic tricks. Linux Magazine, 56:26--31, July 2005.
 
8
C. Schluting. Configure your Catalyst for a more secure layer 2, Jan. 2005. <http://www.enterprisenetworkingplanet.com/netsecur/article.php/3462211>. (Last accessed April 17, 2006).
 
9
 
10
11
 
12
 
13

Collaborative Colleagues:
Senda Hammouda: colleagues
Zouheir Trabelsi: colleagues