摘要
ARP欺骗可以分为假冒网关和假冒计算机两种。本文实现了一种对抗ARP欺骗的架构,通过分析网关的Syslog事件,能够发现第一种ARP欺骗;通过分析路由器的ARP表,能够发现第二种ARP欺骗。在确定攻击者的MAC地址后,定位其接入交换机端口,然后关闭端口就能够隔离ARP攻击。并借助于数据库技术和SNMP协议,自动完成这些过程。
ARP spoofing can be classified as pretending to be gateways and pretending to be other computers. This paper implements an infrastructure to deal with ARP spoofing. The first type can be found by analysing gateways' s Syslog messages. The second type can be found by analysing routers' ARP table. After finding the MAC address of ARP attacker, we can locate its access layer switch port, and then shut down the port so as to isolate ARP spoofing. By means of database and SNMP, all this processes can be done automatically.
出处
《计算机与现代化》
2009年第6期134-136,140,共4页
Computer and Modernization