The invention discloses an
ARP spoofing attack detection method based on a
local area network, and relates to the technical field. The method comprises the following steps: acquiring a data packet byusing a packet capturing tool and analyzing the data packet to obtain MAC and IP pairs of a destination and a
source address of the data packet; independently monitoring a port corresponding to the unreasonable
MAC address; detecting MAC and IP mapping pairs in the response packet, and judging whether mapping of a
source address in the response packet is reasonable or not within a certain period of time; and when the mapping of the
source address in the packet is unreasonable, finding a port corresponding to the switch by using the
MAC address, and quickly finding out the fraud host. Accordingto the packet capturing tool, an ARP detection
system is realized. In cooperation with the
port mirroring technology, the static IP is used for carrying out bidirectional binding on the MAC and the IP under the condition that the IPV4 protocol is not changed, meanwhile, the VLAN is used for reducing the
local area network, the retrieval efficiency is improved, the ARP deception defense efficiencyis improved, and the burden generated to the network is avoided.