MITM Attack Based Detection and Prevention for ARP Poisoning in Wireless Network Environment

J. Chandru, C. Bagyalakshmi · 2025

In a wireless environment, a Man-in-the-Middle (MITM) attack takes place whilst a threat actor intercepts communication between two devices, generally a user's device and a Wi-Fi access point. At a point, an attacker can eavesdrop, inj ect malware, or steal delicate information. This study focuses on address resolution protocol (ARP) poisoning. An ARP is a type of cyberattack in which a threat actor impersonates someone else and use local area network (LAN) to transmit fictitious ARP (Address Resolution Protocol) packets in an attempt to create a parallel connection to their own MAC (Media Access Control) address with the IP address of a legitimate device in the access point. These lead to intercepting data intended for a legitimate device, stealing sensitive information, or launching further attacks. So, with the help of Kali Linux using a virtual box the Arp poisoning attack is initially tested using Ettercap for ARP poisoning, followed by the implementation of the MR ARP technique to detect and prevent anomalies. The tools utilized include Wireshark for network analysis, Ettercap for testing ARP poisoning, and a Python script for detection and prevention. Further enhancements may include the addition of a graphical user interface (GUI), Automated Blocking Mechanism, integration with intrusion detection systems (IDS), or extended support for IPv6.

Read the paper · More papers on PaperTik