DocumentCode :
2210268
Title :
A host based DES approach for detecting ARP spoofing
Author :
Barbhuiya, Ferdous A. ; Biswas, Santosh ; Hubballi, Neminath ; Nandi, Sukumar
Author_Institution :
Indian Inst. of Technol. Guwahati, Guwahati, India
fYear :
2011
fDate :
11-15 April 2011
Firstpage :
114
Lastpage :
121
Abstract :
Address Resolution Protocol (ARP) based attacks are caused by compromised hosts in the LAN and mainly involve spoofing with falsified IP-MAC pairs. Since ARP is a stateless protocol such attacks are possible. Neither there are signatures available for these attacks nor any significant statistical behavior change can be observed. So existing signature or anomaly intrusion detection systems are unable to detect these type of attacks. Several schemes have been proposed in the literature to circumvent these attacks, however, these techniques either make IP-MAC pairing static, modify the existing ARP, violate network layering architecture etc. In this paper a host based Discrete Event System (DES) approach is proposed for detecting ARP spoofing attacks. This approach does not require any extra constraint like static IP-MAC, changing the ARP or violation of network layering architecture.
Keywords :
computer network security; discrete event systems; local area networks; protocols; ARP spoofing attack detection; LAN; address resolution protocol; falsified IP-MAC pairs; host based DES approach; host based discrete event system approach; network layering architecture; stateless protocol; Clocks; Cryptography; Detectors; IP networks; Local area networks; Probes; Protocols; Address Resolution Protocol (ARP); Discrete Event systems; Failure Detection; Network Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence in Cyber Security (CICS), 2011 IEEE Symposium on
Conference_Location :
Paris
Print_ISBN :
978-1-4244-9905-2
Type :
conf
DOI :
10.1109/CICYBS.2011.5949401
Filename :
5949401
Link To Document :
بازگشت