05.08.2013 Views

Download - D-Link

Download - D-Link

Download - D-Link

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ARP Packet Content ACL<br />

Appendix E<br />

Address Resolution Protocol (ARP) is the standard method for finding a host's hardware address (MAC address) when only its IP<br />

address is known. This protocol is vulnerable so hackers can spoof the IP and MAC information in the ARP packets to attack a<br />

LAN (known as ARP spoofing). This document is intended to introduce ARP protocol, ARP spoofing attacks, and the<br />

countermeasure devised by D-<strong>Link</strong> to put an end to ARP spoofing attacks.<br />

How Address Resolution Protocol works<br />

In the process of ARP, PC A will, firstly, issue an ARP request to query PC B’s MAC address. The network structure is shown in<br />

Figure-1.<br />

Figure - 1<br />

In the mean time, PC A’s MAC address will be written into the “Sender H/W Address” and its IP address will be written into the<br />

“Sender Protocol Address” in ARP payload. As PC B’s MAC address is unknown, the “Target H/W Address” will be “00-00-00-<br />

00-00-00” while PC B’s IP address will be written into the “Target Protocol Address”, shown in Table-1.<br />

H/W<br />

type<br />

Protocol<br />

type<br />

H/W<br />

address<br />

length<br />

Protocol<br />

address<br />

length<br />

Operation<br />

ARP request<br />

Sender<br />

H/W address<br />

00-20-5C-01-11-11<br />

Table - 1 (ARP Payload)<br />

Sender<br />

protocol<br />

address<br />

10.10.10.1<br />

Target<br />

H/W address<br />

00-00-00-00-00-00<br />

Target<br />

protocol<br />

address<br />

10.10.10.2<br />

The ARP request will be encapsulated into the Ethernet frame and sent out. As can be seen in Table-2, the “Source Address” in<br />

the Ethernet frame will be PC A’s MAC address. Since the ARP request is sent via a broadcast method, the “Destination address”<br />

is in the format of Ethernet broadcast (FF-FF-FF-FF-FF-FF).<br />

Destination<br />

address<br />

FF-FF-FF-FF-FF-FF<br />

Source address<br />

00-20-5C-01-11-11<br />

Ether-type ARP FCS<br />

Table - 2 (Ethernet frame format)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!