• DocumentCode
    3241521
  • Title

    Stealth and semi-stealth MITM attacks, detection and defense in IPv4 networks

  • Author

    Samineni, Naga Rohit ; Barbhuiya, F.A. ; Nandi, Sukumar

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Indian Inst. of Technol., Guwahati, Guwahati, India
  • fYear
    2012
  • fDate
    6-8 Dec. 2012
  • Firstpage
    364
  • Lastpage
    367
  • Abstract
    A Man-In-The-Middle(MITM) attack is one of the most well known attack on the computer networks. Out of the several variations of MITM, Address Resolution Protocol(ARP) Spoofing/Poisoning is widely used in packet interception and on-the-fly manipulation. Traditional MITM attacks by ARP Poisoning expose the attacker´s identity and thereby physical location. In this paper, to the best of our knowledge it is for the first time that an MITM attack has been added with stealth capabilities. We propose two new attacks namely Stealth MITM(SMITM) and Semi-Stealth MITM(SSMITM) at the Data Link Layer using ARP Spoofing which add stealth capabilities to MITM attacks, thereby concealing the identity of an attacker. Finally, we give a detection and defense technique for the attacks. All the attacks proposed in the paper have been verified and successfully validated in a 300+ node real production network and test beds which include nodes with latest Linux and Windows operating systems under default and secured network scenarios. The results have been 100% effective and have proved the reproducibility of the proposed attacks.
  • Keywords
    IP networks; computer network security; protocols; ARP poisoning; ARP spoofing; IPv4 network; Linux operating system; Windows operating system; address resolution protocol poisoning; address resolution protocol spoofing; computer network; data link layer; defense technique; detection technique; on-the-fly manipulation; packet interception; real production network; semistealth man-in-the-middle attack; stealth capability; Local area networks; Switches; ARP Poisoning; IPv4 Network Security; Man In The Middle Attacks (MITM); Networks and Information Security; Stealth Man In The Middle Attacks (SMITM);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel Distributed and Grid Computing (PDGC), 2012 2nd IEEE International Conference on
  • Conference_Location
    Solan
  • Print_ISBN
    978-1-4673-2922-4
  • Type

    conf

  • DOI
    10.1109/PDGC.2012.6449847
  • Filename
    6449847