Detection and Prevention of Poisoning Targets with ARP Cache using Scapy

D. Ruban Thomas, Prabhu. V, W. Nancy, G Sowmiya, T P Adhithya, Vijayakumar Peroumal · 2024

The Address Resolution Protocol (ARP) provides essential guidelines to ascertain the correspondence between MAC and IP addresses. Exploiting ARP's vulnerabilities, attackers can disrupt local area networks through ARP poisoning or spoofing, both involving the fabrication of ARP packets. To execute these attacks, adversaries inject malicious ARP packets to the network's gateway, permitting the manipulation of stored IP-MAC address pairs within the ARP cache. In response, we present a comprehensive strategy to counter such ARP cache-based threats. Our approach involves the development of a script utilizing the Scapy library and Python to carry out ARP spoof attacks. Furthermore, we propose a detection algorithm, integrated into a Python program with Scapy, capable of identifying not only the described ARP poisoning attack but also other similar attacks. This algorithm systematically examines physical packet addresses and response MAC addresses, seeking irregularities indicative of malicious activity. As a final security measure, we advocate the inclusion of static entries in the ARP table as a preemptive measure against ARP poisoning attacks. This combined approach enhances network security by addressing vulnerabilities, bolstering detection capabilities, and implementing proactive measures to safeguard network integrity.

Read the paper · More papers on PaperTik