TY - GEN
T1 - Securing Low-Computational-Power Devices Against ARP Spoofing Attacks Through a Lightweight Android Application
AU - Phetchai, Ponpat
AU - Ndibwile, Jema David
AU - Fall, Doudou
AU - Kashihara, Shigeru
AU - Tuarob, Suppawong
N1 - Publisher Copyright:
© 2017 IEEE.
PY - 2018/8/21
Y1 - 2018/8/21
N2 - ARP spoofing is one of the most common attacks in the network and it has been around for quite some time. It is one of the simplest attacks to launch and most difficult to defend. The attacking simplicity is due to ARP stateless nature, i.e., lacks an ARP reply authentication for a subsequent request. Moreover, the attack is convenient because of the vast amount of free online spoofing tools. Many solutions have been developed to address this issue; however, most of them suffer from a single point of failure (SPOF), high-computational overhead and unsuitability for low-computational-power devices such as smartphones. In this paper, we propose a solution for protecting those devices from the ARP spoofing attacks. Our solution is lightweight, scalable and immune to SPOF. The solution is fundamentally based on the followed concept: a legitimate ARP cache mapping of a device is replicated and saved to a secure long-term application memory, then later it periodically checks against the ARP cache map to determine the alteration and alert the user, so that appropriate actions can be taken. The results of our experiment show that the proposed solution significantly prevents the ARP spoofing attacks with a low-computational overhead on mobile devices while consuming less than 0.60% and 7.83% memory and CPU usage respectively.
AB - ARP spoofing is one of the most common attacks in the network and it has been around for quite some time. It is one of the simplest attacks to launch and most difficult to defend. The attacking simplicity is due to ARP stateless nature, i.e., lacks an ARP reply authentication for a subsequent request. Moreover, the attack is convenient because of the vast amount of free online spoofing tools. Many solutions have been developed to address this issue; however, most of them suffer from a single point of failure (SPOF), high-computational overhead and unsuitability for low-computational-power devices such as smartphones. In this paper, we propose a solution for protecting those devices from the ARP spoofing attacks. Our solution is lightweight, scalable and immune to SPOF. The solution is fundamentally based on the followed concept: a legitimate ARP cache mapping of a device is replicated and saved to a secure long-term application memory, then later it periodically checks against the ARP cache map to determine the alteration and alert the user, so that appropriate actions can be taken. The results of our experiment show that the proposed solution significantly prevents the ARP spoofing attacks with a low-computational overhead on mobile devices while consuming less than 0.60% and 7.83% memory and CPU usage respectively.
KW - ARP Spoofing
KW - Android
KW - Mobile Device Security
UR - https://www.scopus.com/pages/publications/85053468465
U2 - 10.1109/ICSEC.2017.8443953
DO - 10.1109/ICSEC.2017.8443953
M3 - Conference contribution
AN - SCOPUS:85053468465
SN - 9781538607879
T3 - ICSEC 2017 - 21st International Computer Science and Engineering Conference 2017, Proceeding
SP - 157
EP - 162
BT - ICSEC 2017 - 21st International Computer Science and Engineering Conference 2017, Proceeding
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 21st International Computer Science and Engineering Conference, ICSEC 2017
Y2 - 15 November 2017 through 18 November 2017
ER -