The study on protocol spoofing in active sniffing

Mingzeng Hu · Journal of China Institute of Communications · 2003

We present a protocol spoofing based active sniffing framework, which extends the application area of network sniffing. Four kinds of mapping relationship in network communication are discussed: server domain name to IP address, IP address to MAC address, remote server IP address to local router IP address, and client interface to server process. Destroying those four kinds of mapping relationship, protocol spoofing which can be applied in active sniffing is classified into four kinds respectively: ARP spoofing, route spoofing, DNS spoofing and application layer spoofing. The elements and implementation of them are analyzed in details.

Read the paper · More papers on PaperTik