Detection of MITM attack in LAN environment using payload matching

Dawood Al Abri*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

8 Citations (Scopus)

Abstract

Man-in-the-Middle (MITM) attack enables an attacker to monitor the communication exchange between two parties by directing the traffic between them to pass through the attacker's machine. Most existing schemes for discovering MITM attack focus on detecting the mechanism used to direct the traffic through the attacker machine. This paper presents a new detection scheme that is based on matching the payload of frames exchanged in the network. The proposed scheme is independent of the mechanism used to launch the MITM attack. Experimental result shows that the proposed scheme can achieve excellent detection performance with proper choice of the scheme's tuning parameters.

Original languageEnglish
Title of host publication2015 IEEE International Conference on Industrial Technology, ICIT 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1857-1862
Number of pages6
EditionJune
ISBN (Electronic)9781479978007
DOIs
Publication statusPublished - Jun 16 2015
Event2015 IEEE International Conference on Industrial Technology, ICIT 2015 - Seville, Spain
Duration: Mar 17 2015Mar 19 2015

Publication series

NameProceedings of the IEEE International Conference on Industrial Technology
NumberJune
Volume2015-June

Other

Other2015 IEEE International Conference on Industrial Technology, ICIT 2015
Country/TerritorySpain
CitySeville
Period3/17/153/19/15

Keywords

  • ARP poisoning
  • MITM
  • attack
  • detection
  • security
  • traffic analysis

ASJC Scopus subject areas

  • Computer Science Applications
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Detection of MITM attack in LAN environment using payload matching'. Together they form a unique fingerprint.

Cite this