An detection algorithm for ARP man-in-the-middle attack based on data packet forwarding behavior characteristics

Ming Ren, Yanhui Tian, Siqi Kong, Dali Zhou, Danping Li · 2020 IEEE 5th Information Technology and Mechatronics Engineering Conference (ITOEC) · 2020

The ARP protocol is located at the data link layer. Because the ARP protocol itself lacks an authentication mechanism, an attacker can easily masquerade as a gateway or a target server to intercept user data packets to achieve malicious purposes. This article first analyzes the behavior characteristics of ARP spoofing on the access switch, and then proposes an algorithm for detecting man-in-the-middle attacks based on ARP spoofing. Experiments show that the algorithm can detect ARP spoofing attacks effectively and locate the attacker quickly.

Read the paper · More papers on PaperTik