Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and device for detecting gateway ARP cheating

A technology of ARP spoofing and detection network, applied in the field of communication, can solve the problem of gateway ARP spoofing, which has not yet existed

Active Publication Date: 2017-03-08
RUIJIE NETWORKS CO LTD
View PDF11 Cites 5 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The principle is, assuming that the wireless terminals A and B are in the same WLAN and communicate with the access point (Access Point, AP), the wireless terminal A broadcasts an ARP request message to request the medium access control (Medium Access Control, MAC) address of the gateway , in addition to the AP, the wireless terminal B will also receive the ARP request message, and at the same time, the wireless terminal B can send an ARP response message. If the wireless terminal B has obtained the IP address of the gateway, the source of the ARP response message ( Internet Protocol, IP) address is filled with the IP address of the gateway, and the source MAC address is filled with its own MAC address. After receiving the ARP response message, wireless terminal A will regard wireless terminal B as the gateway, and wireless terminal A will send The packet destined for the gateway is sent to wireless terminal B, thus causing ARP spoofing of the gateway
At present, there is no effective method for detecting gateway ARP spoofing in WLAN

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and device for detecting gateway ARP cheating
  • Method and device for detecting gateway ARP cheating

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0041] In order to effectively detect gateway ARP spoofing in WLAN, an embodiment of the present invention provides a method for detecting gateway ARP spoofing, which is applied in APs. At present, APs have two forwarding modes: local forwarding and centralized forwarding. Applicable in forwarding mode. The process flow of the inventive method is as figure 1 As shown, the execution steps are as follows:

[0042] S11: After receiving the message, determine the type of the message, if the type of the message is a DHCP response message, execute S12; if the type of the message is an ARP response message, execute S13.

[0043] In the present invention, it is necessary to update the anti-gateway ARP spoofing mapping table according to the DHCP response message, and detect the gateway ARP spoofing according to the ARP response message. Therefore, after the AP receives the message, it needs to first determine the type of the message, and further determine Whether the packet is a DHC...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method and a device for detecting gateway ARP cheating. The method comprises steps of: after receiving a message, determining the type of the message; if message is a DHCP response message, acquiring a first WLAN identifier and an IP address of a gateway carried in the DHCP response message, and updating a gateway ARP cheating mapping table according to the first WLAN identifier and the IP address of the gateway; if the message is the ARP response message, acquiring a source IP address of the ARP response message and a carried second WLAN identifier, and searching the second WLAN identifier in the gateway ARP cheating mapping table; and if the second WLAN identifier is searched and the IP address of the gateway corresponding to the second WLAN is the same as the source IP address, determining that the gateway ARP cheating is detected. According to the invention, automatic detection of the gateway ARP cheating can be achieved.

Description

technical field [0001] The invention relates to the technical field of communications, in particular to a method and device for detecting gateway Address Resolution Protocol (Address Resolution Protocol, ARP) spoofing. Background technique [0002] With the large-scale deployment and implementation of the Wireless Local Area Networks (WLAN) of the Institute of Electrical and Electronics Engineers (Institute of Electrical and Electronics Engineers, IEEE) 802.11 protocol, and the rapid development of the mobile Internet, nowadays airports, universities, shopping malls Places with dense traffic, such as hotels, supermarkets, etc., can all access WLAN. Considering the easy-to-deploy feature of the WLAN, a Dynamic Host Configuration Protocol (Dynamic Host Configuration Protocol, DHCP) is used in the WLAN to manage the addresses of the wireless terminals. Due to the wide coverage of WLAN and the free access of wireless terminals, criminals often use different attack methods, such...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04W12/12H04L29/12H04W12/122
CPCH04W12/12H04L61/103H04L61/5014
Inventor 贺宏达黄庆新
Owner RUIJIE NETWORKS CO LTD