Switch Device Port Reliability for ARP Spoofing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In closed networks, authenticated terminals can transmit wrong ARP packets, leading to communication interruption and wiretapping by rewriting the ARP table, allowing cyber attacks to occur.
Innovation Solution
A switch device with a packet analyzing unit that distinguishes between reliable and unreliable ports, discarding or preventing the transmission of wrong ARP packets by comparing the MAC address of the transmission origin with the router MAC address stored in the reliable port information table, ensuring that only legitimate packets are relayed through the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MAC authentication is implemented to control terminal access in a closed network, then network security against external attacks is improved, but authenticated terminals can still transmit wrong ARP packets causing communication interruption and wiretapping
Solution Approach 1:
The switch device acts as an intermediary between authenticated terminals and the network. It monitors ARP packets transmitted by authenticated terminals and filters out wrong ARP packets by comparing source MAC addresses with registered MAC addresses in the reliable port information table, thereby preventing communication interruption and wiretapping while maintaining network security
Solution Approach 2:
The switch device implements a feedback mechanism by continuously monitoring ARP packets from authenticated terminals and comparing them against registered MAC address information. When a wrong ARP packet is detected (source MAC address does not match the registered MAC address for that port), the switch device blocks the packet and can notify the management device, providing real-time security feedback
2Productivity
If all authenticated terminals are permitted to transmit packets freely, then network communication efficiency is improved, but wrong packets from authenticated terminals can rewrite ARP tables enabling cyber attacks
Solution Approach 1:
The switch device applies different quality control to different ARP packets based on their source. Packets from reliable ports (authenticated terminals with matching MAC addresses) are permitted to maintain communication efficiency, while packets from unreliable ports (authenticated terminals transmitting wrong ARP packets) are blocked to prevent cyber attacks
Solution Approach 2:
The switch device performs preliminary verification of ARP packets by checking if the source MAC address matches the registered MAC address in the reliable port information table before allowing packet transmission. This preliminary action prevents wrong ARP packets from rewriting ARP tables and enabling attacks, while maintaining efficient communication for legitimate packets
Data Source
AI summary
A system manager sets a port connected to a specific device (for example, a router device) among a plurality of ports of a switch device as a reliable port. If a packet is received in the reliable port, the switch device manages an IP address and a MAC address of the router device by a reliable port information table. When a packet is received from a port not set as the reliable port, the switch device refers to the reliable port information table. At this time, when the received packet is an address resolution packet having impersonated a router device, the switch device discards the packet without transmitting the packet, thereby preventing a cyber attack on a terminal.


