计算机与现代化 ›› 2011, Vol. 1 ›› Issue (6): 193-6.doi: 10.3969/j.issn.1006-2475.2011.06.054

• 信息安全 • 上一篇    下一篇

ARP欺骗研究综述

石利平   

  1. 广东女子职业技术学院信息技术系,广东 广州 510450
  • 收稿日期:2011-02-23 修回日期:1900-01-01 出版日期:2011-06-29 发布日期:2011-06-29

Survey on ARP Spoofing

SHI Li-ping   

  1. Department of Information Technology, Guangdong Women′s Polytechnic College, Guangzhou 510450, China
  • Received:2011-02-23 Revised:1900-01-01 Online:2011-06-29 Published:2011-06-29

摘要: 近年来,ARP欺骗已成为网络安全的首要威胁,ARP欺骗的相关研究已成为网络安全领域的热点课题。本文分析ARP协议的工作原理以及ARP欺骗原理,阐述ARP欺骗的主要类型:欺骗主机、欺骗网关和双向欺骗,并在此基础上,研究近几年来ARP欺骗主要的检测和防御方法,如IP与MAC地址匹配方法、SACT检测方法、改进或扩展ARP协议和S_UARP协议等,分析这些方法的工作原理及其优缺点。改进和完善ARP协议将成为ARP欺骗防御的发展趋势。

关键词: ARP协议, ARP欺骗, ARP欺骗监测, ARP欺骗防御, 网络安全

Abstract: Recently, ARP spoofing has become the primary threat to network security, ARP spoofingrelated research has become a hot topic in network security. This paper analyzes the principle of ARP protocol and ARP spoofing, describes the types and symptoms of ARP spoofing: cheat host, cheat gateway, cheat host and gateway. Some ARP spoofing detection and prevention methods are researched based on it, such as IP and MAC address matching, SACT detection, improvement or expanding ARP protocol and S_UARP agreement, analyzes these methods works, advantages and disadvantages. To improve and perfect the ARP protocol will become the development trend of ARP spoofing prevention.

Key words: ARP protocol, ARP spoofing, ARP spoofing detection, ARP spoofing prevention, network security