Shadow APR-ing for APR Poisoning Detection
Durjoy Majumdar, Radhika Rani Chintala · 2023
The Address Resolution Protocol (ARP) is a part of today’s networking which is used for IP-to-MAC address mapping. In the ’90s ARP was designed for speed not for security. As a result, it has a long history of spoofing which lead to ARP poisoning and is sometimes the starting point of more complex attack like MITM attack, DDoS attack and many more. This paper proposes an active technique to detect ARP Poisoning as fast as possible. Still in 2022, the best way of detecting ARP spoofing is manually searching for inconsistency in the ARP table. The main drawback is the time lag between learning and detecting one attack. In our proposed method, we focused to minimize the time gap and implemented a simple and automated OS-based monitoring instead of manual monitoring.