摘要
ARP协议设计使之易受到ARP缓存污染的攻击。ARP缓存污染又衍生出中间人攻击等各种网络安全问题。现有的解决方案多种多样但各有优缺点。本文基于ARP缓存污染攻击规律,利用动态IP-MAC绑定算法配合交换机ARP检查功能,设计了1种适用于大型网络的、灵活易部署的ARP缓存污染解决方案。实验证明了解决方案的有效性。
ARP protocol is vulnerable to ARP Cache Poisoning, which fosters a variety of security issues such as Man-In-The-Middle attack. There are pros and cons of existing approaches to this issue.Based on the characteristics of ARP Cache Poisoning attacks,we combine the ARP inspection function of switches with dynamic IP-MAC binding algorithms to design a new solution to ARP Cache Poisoning.Our solution is flexible and deployment-friendly to large-scale networks.Experiment demonstrates the effectiveness of the sol...
出处
《中国海洋大学学报(自然科学版)》
CAS
CSCD
北大核心
2008年第S1期134-138,共5页
Periodical of Ocean University of China