节点文献

园区网ARP欺骗攻击防御模式设计与实现

Design and Implementation of Defense System for ARP Spoofing in Campus Network

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 赵晓峰汪精明王平水

【Author】 ZHAO Xiao-feng,WANG Jing-ming,WANG Ping-shui (Anhui University of Finance & Economics,Bengbu 233041,China)

【机构】 安徽财经大学网络中心安徽财经大学网络中心 安徽蚌埠233041安徽蚌埠233041

【摘要】 地址解析协议(ARP)工作于OSI参考模型第二层,在园区网VLAN中实现IP地址到网络接口硬件地址(MAC)的映射功能,攻击者利用ARP协议安全缺陷,在网关与主机(整个网段)之间实施ARP欺骗攻击,将会对VALN内主机产生巨大安全威胁。针对此类攻击设计与实现的网络防御模式,通过IP地址与接入层交换机端口绑定、定期在VLAN广播网关MAC地址等方法,可有效阻止该类攻击发生。

【Abstract】 Address Resolution Protocol(ARP)works in Layer 2 of the OSI reference model.It implements the mapping between IP and MAC in VLAN of campus network.The attacker uses the ARP shortage of security,implements the ARP spoofing attack between the gateway and the host computer,will be serious threat to the security of host computer in VLAN.Design and implementation of defense system for this kind of attack,through IP address and switch port binding,broadcast gateway MAC address and so on methods,can prevent this kind of attack to occur effectively.

【基金】 安徽省2006年教育厅自然科学基金项目(2006kJ017C)
  • 【文献出处】 计算机技术与发展 ,Computer Technology and Development , 编辑部邮箱 ,2007年07期
  • 【分类号】TP393.08
  • 【被引频次】10
  • 【下载频次】164
节点文献中: 

本文链接的文献网络图示:

本文的引文网络