S-ARP: a secure Address Resolution Protocol

被引:70
作者
Bruschi, D [1 ]
Ornaghi, A [1 ]
Rosti, E [1 ]
机构
[1] Univ Milan, Dipartimento Informat & Comunicaz, Milan, Italy
来源
19TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS | 2003年
关键词
D O I
10.1109/CSAC.2003.1254311
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Tapping into the communication between two hosts on a LAN has become quite simple thanks to tools that can be downloaded from the Internet. Such tools use the Address Resolution Protocol (ARP) poisoning technique, which relies on hosts caching reply messages even though the corresponding requests were never sent. Since no message authentication is provided, any host of the LAN can forge a message containing malicious information. This paper presents a secure version of ARP that provides protection against ARP poisoning. Each host has a public/private key pair certified by a local trusted party on the LAN, which acts as a Certification Authority Messages are digitally signed by the sender, thus preventing the injection of spurious and/or spoofed information. As a proof of concept, the proposed solution was implemented on a Linux box. Performance measurements show that PKI based strong authentication is feasible to secure even low level protocols, as long as the overhead for key validity, verification is kept small.
引用
收藏
页码:66 / 74
页数:9
相关论文
共 19 条
  • [1] [Anonymous], 1994, FIPS PUB
  • [2] BARNABA M, 2003, ANTICAP
  • [3] Fleck B., Wireless Access Points and ARP Poisoning: Wireless Vulnerabilities that Expose the Wired Network
  • [4] FREIER AO, 1996, SECURE SOCKET LAYER
  • [5] Householder A, 2002, SECURING INTERNET NA
  • [6] HUNLETH F, 1998, 2401 RFC
  • [7] LAUBACH M, 1994, 1577 RFC
  • [8] ORNAGHI A, MULTIPURPOSE SNIFFER
  • [9] ORNAGHI A, 2003, SARP SECURE ARP
  • [10] Plummer D., 1982, Technical report