ARP spoofing can be classified as pretending to be gateways and pretending to be other computers. This paper implements an infrastructure to deal with ARP spoofing. The first type can be found by analysing gateways' s Syslog messages. The second type can be found by analysing routers' ARP table. After finding the MAC address of ARP attacker, we can locate its access layer switch port, and then shut down the port so as to isolate ARP spoofing. By means of database and SNMP, all this processes can be done automatically.
Computer and Modernization