A PRACTICAL INTRUSION DETECTION APPROACH FOR ARP SPOOFING AND MITM IN LOCAL AREA NETWORKS
Hiba Bazzi, Ali H. Nassar, Mustafa El Bizri, Ali Massoud Haidar · BAU Journal - Science and Technology · 2024
In modern network environments, the increasing sophistication of cyberattacks poses significant risks, particularly through Address Resolution Protocol (ARP) spoofing and Man-in-the-Middle (MITM) attacks, which exploit vulnerabilities in local area networks. Existing tools often focus on detection or protection at the client side, leaving network-wide detection and response largely unaddressed. This paper presents a novel intrusion detection tool specifically designed to identify ARP spoofing and MITM attacks in real-time within local area networks. The system leverages Python and Scapy for low-level packet analysis and Flask for an intuitive web-based dashboard. Key features include network monitoring, attack detection through ARP table comparisons, logging capabilities, and attack attribution by identifying malicious IP addresses. The tool was tested in a controlled lab environment, demonstrating high accuracy in detecting ARP spoofing attempts, even in complex network scenarios. The findings underscore the tool's potential as a foundational step toward developing comprehensive mitigation solutions for securing local networks. Future work aims to integrate automated mitigation strategies and expand the system's applicability to larger network infrastructures.