XU Dawei,DAI Cheng,ZHU Liehuang,SHE Yijie
. 2021, 20(4): 63-75.
Abstract (
)
Download PDF (
)
Knowledge map
Save
Security of a network has always been a prominent issue. In a local network, the ARP protocol works at a lower level, and the security is often overlooked, and it is vulnerable to hacker at tacks. In the new network SDN architecture, ARP attacks are still a serious network security problem, and in this network architecture, not only the network terminal nodes will be exposed to the risk of at tacks, but also the controllers. Therefore, this article proposes an ARP attack solution based on the SDN architecture. This solution develops a defense module in the controller and an information verifi cation software in the host, and uses the controller to control network information to verify the host that needs ARP communication. If the verification is passed, the target host will reply to the ARP response message instead of the target host. If the verification fails, the ARP attack will be reported to the administrator. Experiments show that the scheme can effectively defend against various forms of ARP at tacks and effectively improve the security of a local area network.