A Feasible Method for Realizing Leakage of DHCP Transactions under the Implementation of DHCP Snooping

Yao Tong, Shigeo Akashi · 2019

It is well known that DHCP snooping is a famous countermeasure against DHCP spoofing. Actually, to what extent DHCP snooping can protect the DHCP clients from being injected malicious DHCP transactions running over the network segment where the DHCP clients and the malicious DHCP servers co-exist? The answer to this question is that DHCP snooping can protect DHCP spoofing to a certain extent. In other words, DHCP snooping cannot protect DHCP spoofing completely. In the former half of this paper, it is shown that DHCP spoofing can be classified into two cases, namely DHCP spoofing from inside and DHCP spoofing from outside, and in the latter half of this paper, it is shown that a more sophisticated method of solving the problem which remains to be solved by the malicious wiretapper for the purpose of realizing DHCP spoofing from outside. As for the concrete method of implementing DHCP spoofing from outside, we can refer to Tong and Akashi [1] explaining how to apply the longest matching prefix rule to the artificial leakage of the DHCP transactions beforehand.

Read the paper · More papers on PaperTik