• DocumentCode
    3467800
  • Title

    A middleware approach to asynchronous and backward compatible detection and prevention of ARP cache poisoning

  • Author

    Tripunitara, Mahesh V. ; Dutta, Partha

  • Author_Institution
    CERIAS, Purdue Univ., West Lafayette, IN, USA
  • fYear
    1999
  • fDate
    1999
  • Firstpage
    303
  • Lastpage
    309
  • Abstract
    Discusses the Address Resolution Protocol (ARP) and the problem of ARP cache poisoning. ARP cache poisoning is the malicious act, by a host in a LAN, of introducing a spurious IP address to MAC (Ethernet) address mapping in another host´s ARP cache. We discuss design constraints for a solution: the solution needs to be implemented in middleware, without any access or change to any operating system source code, it needs to be backward-compatible with the existing protocol and to be asynchronous. We present our solution and implementation aspects of it in a Streams-based networking subsystem. Our solution comprises two parts: a “bump in the stack” Streams module, and a separate Stream with a driver and user-level application. We also present the algorithm that is executed in the module and application to prevent ARP cache poisoning where possible, and to detect and raise alarms otherwise. We then discuss some limitations with our approach and present some preliminary performance figures for our implementation
  • Keywords
    cache storage; client-server systems; computer crime; local area networks; memory protocols; transport protocols; ARP cache poisoning; Address Resolution Protocol; Ethernet; LAN host; MAC address mapping; Streams-based networking subsystem; alarms; asynchronous solution; backward compatibility; bump-in-the-stack Streams module; design constraints; driver; malicious act; middleware; operating system source code; performance; spurious IP address; user-level application; Arm; Electronic switching systems; Ethernet networks; Information security; Internet; Local area networks; Microwave integrated circuits; Middleware; Operating systems; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 1999. (ACSAC '99) Proceedings. 15th Annual
  • Conference_Location
    Phoenix, AZ
  • ISSN
    1063-9527
  • Print_ISBN
    0-7695-0346-2
  • Type

    conf

  • DOI
    10.1109/CSAC.1999.816040
  • Filename
    816040