节点文献
园区网ARP欺骗攻击防御模式设计与实现
Design and Implementation of Defense System for ARP Spoofing in Campus Network
【摘要】 地址解析协议(ARP)工作于OSI参考模型第二层,在园区网VLAN中实现IP地址到网络接口硬件地址(MAC)的映射功能,攻击者利用ARP协议安全缺陷,在网关与主机(整个网段)之间实施ARP欺骗攻击,将会对VALN内主机产生巨大安全威胁。针对此类攻击设计与实现的网络防御模式,通过IP地址与接入层交换机端口绑定、定期在VLAN广播网关MAC地址等方法,可有效阻止该类攻击发生。
【Abstract】 Address Resolution Protocol(ARP)works in Layer 2 of the OSI reference model.It implements the mapping between IP and MAC in VLAN of campus network.The attacker uses the ARP shortage of security,implements the ARP spoofing attack between the gateway and the host computer,will be serious threat to the security of host computer in VLAN.Design and implementation of defense system for this kind of attack,through IP address and switch port binding,broadcast gateway MAC address and so on methods,can prevent this kind of attack to occur effectively.
【Key words】 switch network; ARP spoofing; network attack; network defense;
- 【文献出处】 计算机技术与发展 ,Computer Technology and Development , 编辑部邮箱 ,2007年07期
- 【分类号】TP393.08
- 【被引频次】10
- 【下载频次】164