A Secure Mechanism to Prevent ARP Spoofing and ARP Broadcasting in SDN

Harman Y. Ibrahim, Parishan M. Ismael, A. A. Albabawat, A. Al-Khalil
{"title":"A Secure Mechanism to Prevent ARP Spoofing and ARP Broadcasting in SDN","authors":"Harman Y. Ibrahim, Parishan M. Ismael, A. A. Albabawat, A. Al-Khalil","doi":"10.1109/CSASE48920.2020.9142092","DOIUrl":null,"url":null,"abstract":"Conventional networks had several security problems, some of them solved using Software Defined Networking SDN and some others still exist such as Address Resolution Protocol ARP spoofing. In this paper, the SDN controller has been extended by a module which checks every ARP packet in the network to detect and stop the possible spoofed ones. The drawback of this mechanism begging to appear when the network gets larger and the traffic increase. As a result, this will increase the controller’s CPU load and Roundtrip time. As a solution to this problem, the extended module has been modified to handle ARP traffic to reduce ARP overhead in the network via giving the proxy ARP functionality to the controller. The emulation results showed that the proposed mechanism is robust against ARP spoofing attack and successfully prevented ARP broadcast messages in large networks and improved the response time by centrally responding to ARP requests.","PeriodicalId":254581,"journal":{"name":"2020 International Conference on Computer Science and Software Engineering (CSASE)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Conference on Computer Science and Software Engineering (CSASE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSASE48920.2020.9142092","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

Conventional networks had several security problems, some of them solved using Software Defined Networking SDN and some others still exist such as Address Resolution Protocol ARP spoofing. In this paper, the SDN controller has been extended by a module which checks every ARP packet in the network to detect and stop the possible spoofed ones. The drawback of this mechanism begging to appear when the network gets larger and the traffic increase. As a result, this will increase the controller’s CPU load and Roundtrip time. As a solution to this problem, the extended module has been modified to handle ARP traffic to reduce ARP overhead in the network via giving the proxy ARP functionality to the controller. The emulation results showed that the proposed mechanism is robust against ARP spoofing attack and successfully prevented ARP broadcast messages in large networks and improved the response time by centrally responding to ARP requests.
SDN中防止ARP欺骗和广播的安全机制
传统网络存在一些安全问题,其中一些问题通过软件定义网络SDN解决,而另一些问题仍然存在,如地址解析协议ARP欺骗。本文将SDN控制器扩展为一个模块,该模块可以检查网络中的每个ARP数据包,以检测和阻止可能的欺骗。当网络变大,流量增加时,这种机制的缺点就会显现出来。因此,这将增加控制器的CPU负载和往返时间。为了解决这个问题,扩展模块被修改为通过向控制器提供代理ARP功能来处理ARP流量,以减少网络中的ARP开销。仿真结果表明,该机制对ARP欺骗攻击具有较强的鲁棒性,能够有效阻止大型网络中的ARP广播消息,并通过集中响应ARP请求提高响应时间。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信