Publication:
Detection and Prevention of ARP Cache Poisoning in Advanced Persistent Threats Using Multiphase Validation and Firewall

dc.contributor.authorAl-Mwald M.N.en_US
dc.contributor.authorJamil N.en_US
dc.contributor.authorIbrahim Z.A.en_US
dc.contributor.authorCob Z.C.en_US
dc.contributor.authorAbdul Rahim F.en_US
dc.contributor.authorid57980856700en_US
dc.contributor.authorid36682671900en_US
dc.contributor.authorid57203863738en_US
dc.contributor.authorid25824919900en_US
dc.contributor.authorid57981022800en_US
dc.date.accessioned2023-05-29T09:39:12Z
dc.date.available2023-05-29T09:39:12Z
dc.date.issued2022
dc.descriptionSecurity of data; Security systems; Address Resolution Protocol; Address resolution protocol cache poisoning; Address resolution protocol spoofing attack; Cache poisoning; Internet control message protocol protocol; Internet control message protocols; MITM; Spoofing attacks; Internet protocolsen_US
dc.description.abstractProtocols define a set of rules that govern the communication between hosts connected via a network. Under normal circumstances, the operation proceeds without incident. However, attackers are always on the lookout for ways to exploit loopholes in protocols. This study aimed to investigate Address Resolution Protocol (ARP) issues and develop a technique to detect and prevent malicious ARP activity and anomalies caused by its various implementations. We propose sending three Internet Control Message Protocol (ICMP) probe packets to each host to validate the new binding, one to the previous binding and the other two to the contemporary binding. ARP packets are used together with these ICMP packets to provide multiphase validation for new entries that have no previous ARP cache entries. The asynchronous nature of the proposed scheme requires no changes to the existing protocol. In addition, the proposed technique uses a host-based firewall to block malicious hosts without affecting the ARP�s performance. � 2022, The Author(s), under exclusive license to Springer Nature Switzerland AG.en_US
dc.description.natureFinalen_US
dc.identifier.doi10.1007/978-3-031-13181-3_12
dc.identifier.epage170
dc.identifier.scopus2-s2.0-85142626234
dc.identifier.spage155
dc.identifier.urihttps://www.scopus.com/inward/record.uri?eid=2-s2.0-85142626234&doi=10.1007%2f978-3-031-13181-3_12&partnerID=40&md5=9f2b60897a7b1299ee08a73268f6c44d
dc.identifier.urihttps://irepository.uniten.edu.my/handle/123456789/27065
dc.publisherSpringer Science and Business Media Deutschland GmbHen_US
dc.sourceScopus
dc.sourcetitleSignals and Communication Technology
dc.titleDetection and Prevention of ARP Cache Poisoning in Advanced Persistent Threats Using Multiphase Validation and Firewallen_US
dc.typeBook Chapteren_US
dspace.entity.typePublication
Files
Collections