Detection and Prevention against ARP Poisoning Attack Using Modified ICMP and Voting

Prerna Arote, K. V. Arya · 2015

Address Resolution Protocol (ARP) poisoning is the leading point for refined LAN attacks like denial-of-service (DOS) and Man-In-The-Middle (MITM). Weak point of ARP that is being Stateless, directly affects security standards of Network and specially Ethernet. In proposed mechanism of detection, initially traffic over the network is sniffed by Central Server (CS). Then, CS sends trap ICMP ping packet, analyze the response in terms of ICMP reply and successfully detects attacker. In order to prevent ARP poisoning over centralized system, voting process is used to elect legitimate CS. Validating and Correctingpair entries residing in hosts cache tables, CS successfully prevents ARP poisoning while maintaining performance of the system. Our technique is based on ICMP and Voting such mechanism with Backward Compatibility, Less Cost, Minimal Traffic and Easily Deployable is proposed to detect and prevent MITM based ARP poisoning which is effectual version overcoming weaknesses of ARP.

Read the paper · More papers on PaperTik