Network Analysis Using Wireshark 2 Cookbook - Second Edition
by Nagendra Kumar Nainar, Yoram Orzach, Yogesh Ramdoss
ARP sweep-based DoS attacks
For network inventory, it is a common practice to use a management system and send a sweep of ARP requests to all IP addresses within the subnet. In such an approach, the target IP address will keep changing, but the sender IP address and sender MAC address will remain the same and be set to the management system address. For efficient communication, the default behavior of the end host is to learn the sender IP and MAC address from the ARP request and populate the local ARP cache. The ARP sweep, along with this behavior, can also be used by any malicious attacker to deplete the ARP cache of all end hosts within the LAN network by changing the sender's IP and MAC addresses.
ARP requests and replies are a part of ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access