A system architecture against ARP spoofing based on packet filtering
Wang Kejian
Abstract
Wang Kejian
Abstract
This paper analyses the basic theory of ARP spoofing and some common attacking methods of ARP spoofing.The paper also discusses three preventive methods against ARP spoofing and their limitations.According to the analyses,an approach to designing a client-server model software is put forward in order to resist ARP spoofing.The system is based on the relative that every host in LAN has a unique IP address to its MAC address.The client detects header of all ARP packets that host receives and abandons the ARP packets of inconsistent-header.The server examines the authenticity of IP address and MAC address of source host in ARP packets from the client,then makes the client filter out the unsafe packets.Through this process,the system can effectively prevent local computer from ARP spoofing,and improve network security.The system is applicable to small and medium-sized local area networks,which need higher security requirements.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper analyses the basic theory of ARP spoofing and some common attacking methods of ARP spoofing.The paper also discusses three preventive methods against ARP spoofing and their limitations.According to the analyses,an approach to designing a client-server model software is put forward in order to resist ARP spoofing.The system is based on the relative that every host in LAN has a unique IP address to its MAC address.The client detects header of all ARP packets that host receives and abandons the ARP packets of inconsistent-header.The server examines the authenticity of IP address and MAC address of source host in ARP packets from the client,then makes the client filter out the unsafe packets.Through this process,the system can effectively prevent local computer from ARP spoofing,and improve network security.The system is applicable to small and medium-sized local area networks,which need higher security requirements.
Key concepts: ARP spoofing, IP address spoofing, Computer science, Spoofing attack, Computer network, Network packet, Header, Computer security