Detection of ARP Spoofing Attack in Healthcare Networks Using a LSTM Model
Salam Al-E’mari, Yousef K. Sanjalawe, Ghader Reda Kurdi, Budoor Ahmad Allehyani · 2025
Healthcare networks face significant cybersecurity threats due to their extensive interconnectivity, with Address Resolution Protocol (ARP) spoofing posing a major risk to the confidentiality and integrity of medical data. ARP spoofing is a Man-in-the-Middle (MITM) attack where an attacker sends falsified ARP messages to associate their MAC address with the IP address of a legitimate device, enabling unauthorized interception or manipulation of network traffic. In this paper, we propose an LSTM-based detection model designed to effectively identify ARP spoofing attacks in healthcare environments. Unlike traditional methods that rely on static markers at fixed time intervals, the LSTM model leverages temporal dependencies in network traffic, enhancing detection accuracy and adaptability to evolving attack patterns. Experimental results based on the CICIoMT Dataset 2024 demonstrate that the proposed model achieves a detection accuracy of 98.5%, significantly outperforming conventional approaches. These findings highlight the effectiveness of LSTM networks in mitigating ARP spoofing threats, offering a scalable solution for securing healthcare networks.