A PRACTICAL INTRUSION DETECTION APPROACH FOR ARP SPOOFING AND MITM IN LOCAL AREA NETWORKS

Hiba Bazzi, Ali H. Nassar, Mustafa El Bizri, Ali Massoud Haidar · BAU Journal - Science and Technology · 2024

In modern network environments, the increasing sophistication of cyberattacks poses significant risks, particularly through Address Resolution Protocol (ARP) spoofing and Man-in-the-Middle (MITM) attacks, which exploit vulnerabilities in local area networks. Existing tools often focus on detection or protection at the client side, leaving network-wide detection and response largely unaddressed. This paper presents a novel intrusion detection tool specifically designed to identify ARP spoofing and MITM attacks in real-time within local area networks. The system leverages Python and Scapy for low-level packet analysis and Flask for an intuitive web-based dashboard. Key features include network monitoring, attack detection through ARP table comparisons, logging capabilities, and attack attribution by identifying malicious IP addresses. The tool was tested in a controlled lab environment, demonstrating high accuracy in detecting ARP spoofing attempts, even in complex network scenarios. The findings underscore the tool's potential as a foundational step toward developing comprehensive mitigation solutions for securing local networks. Future work aims to integrate automated mitigation strategies and expand the system's applicability to larger network infrastructures.

Read the paper · More papers on PaperTik