<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Emulation and Detection of ARP Attacks in GNS3 Environment: Modelling and Development of a Defense Strategy</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Tetiana Vakaliuk</string-name>
          <email>tetianavakaliuk@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yelyzaveta Trokoz</string-name>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandra Pokotylo</string-name>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Viacheslav Osadchyi</string-name>
          <email>v.osadchyi@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Viktoriia Bolotina</string-name>
          <email>viktoriia.polish@gmail.com</email>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudriavska str, Kyiv, 04053</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Institute for Digitalisation of Education of the NAES of Ukraine</institution>
          ,
          <addr-line>9 M. Berlynskoho str., Kyiv, 04060</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Kryvyi Rih State Pedagogical University</institution>
          ,
          <addr-line>54 Gagarin ave., Kryvyi Rih, 50086</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Zhytomyr Polytechnic State University</institution>
          ,
          <addr-line>103 Chudnivsyka str., Zhytomyr, 10005</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>376</fpage>
      <lpage>383</lpage>
      <abstract>
        <p>The article discusses various types of attacks on the ARP protocol and the tools used to implement and detect them. The principal network vulnerabilities related to the lack of authentication and encryption were identified through modeling, and methods to prevent or reduce the risk were proposed. A network design was created in the GNS3 environment, which is as close to the real environment as possible. Specialized tools such as Nping, Arpspoof, and Ettercap were used to carry out the ARP-Flooding, ARP-Spoofing, and ARP-Poisoning attacks, and XArp software was used for detection.</p>
      </abstract>
      <kwd-group>
        <kwd>1 ARP</kwd>
        <kwd>GNS3</kwd>
        <kwd>attack emulation</kwd>
        <kwd>ARP-flooding</kwd>
        <kwd>ARP-spoofing</kwd>
        <kwd>ARP-poisoning</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Due to the widespread spread of cyber threats
and their constant improvement in the modern
information environment, the issue of network
security is highly relevant. As technologies are
constantly evolving, it is essential to ensure
appropriate detection and protection against
various types of attacks. One of the most
common threats to network security is ARP
attacks aimed at unauthorized interception
and acquiring confidential information. The
risk of their impact in the context of the Internet
of Things (IoT) expansion is growing due to the
constant increase in the number of connected
devices in the network [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1–3</xref>
        ]. Therefore, to
avoid vulnerabilities in new environments and
effectively manage network infrastructure, it is
essential to understand the algorithm of attacks
on this protocol, consider methods of detecting
them, and develop and implement means of
protection against them [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ].
1.1.
      </p>
      <sec id="sec-1-1">
        <title>Theoretical Background</title>
        <p>An analysis of research on this topic has shown
that there are many ways to detect and conduct
various specialized attacks on network
protocols, particularly on ARP, to increase the
resilience of network systems.</p>
        <p>
          In particular, the article by Swati Jadhav,
Arjun Thakur, Shravani Nalbalwar, Shubham
Shah, and Sankalp Chordia [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ] proposes
various methods for detecting an ARP
poisoning attack at both the user and
organizational levels. It is noted that after the
attack on the client device, the traffic was
intercepted and analyzed using a Python
algorithm and other software products. The
result of the work highlights the options for
protecting a computer in the event of potential
attacks.
        </p>
        <p>
          The study by Zhaozhan Chen [
          <xref ref-type="bibr" rid="ref7">7</xref>
          ] includes an
analysis of the principles of operation and
attack modes based on the ARP protocol, IP,
and MAC addresses. The author examines the
format of the ARP packet, the process of data
exchange during its operation, and the
structure of attacks such as Counterfeit
gateway, Spoofing gateway, Spoofing user
attack, and Man-in-the-middle. The paper
proposes a method for improving network
security by implementing appropriate security
measures based on practical experience.
        </p>
        <p>
          In the work of Xiaohan Zhang, Lu Cao,
Zuojun Meng, and Xiaohui Yao [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ], a solution
for the SDN (Software Defined Network)
network was proposed that allows the
accurate detection of ARP attacks by checking
the veracity of the IP to MAC address mapping
and the MAC address during the ARP packet
processing by the controller. The authors have
conducted experiments in a simulated SDN
network, which confirms the possibility of
detecting attacks without affecting the
network performance as a whole and reducing
the time of ARP interaction between hosts.
        </p>
        <p>
          In a study by Akinul Islam Jony and Arjun
Kumar Bose Arnob [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ], Long Short-Term
Memory (LSTM) networks are used for
intrusion detection as a new strategy to
enhance IoT security. The proposed
LSTMbased model demonstrates excellent results in
detecting both known and novel cyberattack
patterns with an accuracy of 98.75% and an F1
score of 98.59% in extensive experimental
evaluations using the large CIC-IoT2023
dataset, which represents a diverse set of IoT
network traffic scenarios. This research
contributes significantly to IoT security by
addressing the urgent need for adaptive
intrusion detection systems to protect against
evolving cyber threats.
        </p>
        <p>
          In the article by Cristina L. Abad, Rafael I.
Bonilla [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] proposed several schemes to
mitigate, detect, and prevent attacks on the
ARP protocol, but each has its drawbacks. This
article will analyze these schemes, identify
their strengths and weaknesses, and offer
recommendations for developing an
alternative and (possibly) better solution to
the ARP cache poisoning problem.
        </p>
        <p>
          Anjana Kawshan [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] found that the ARP
protocol is vulnerable to an ARP-spoofing
attack, as it lacks authentication. As a result, it
can lead to Man-in-the-Middle attacks, denial
of service, and others. The author discusses the
algorithm of actions in the case of MITM and
shows how to detect ARP-spoofing attacks
using your code.
        </p>
        <p>
          The article by Huixing Xi [
          <xref ref-type="bibr" rid="ref12">12</xref>
          ] includes a
systematization of the current state of research
and critical technologies related to the ARP
protocol. The author analyses the mechanisms
of ARP vulnerability formation and considers
possible attack techniques. Based on the
generalization of commonly used protection
methods, their advantages and disadvantages
are presented. Experiments and tests are
conducted for each advanced security algorithm.
        </p>
        <p>
          The study of Mehdi Nobakht, Hadi
Mahmoudi, and Omid Rahimzadeh [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]
proposes a distributed security mechanism for
detecting and counteracting the ARP cache
poisoning attack. It can detect a more advanced
type of such an attack, in which the attacker
leaves a minimum of traces. The prototype of
the proposed mechanism is implemented in
Python, and its viability and effectiveness are
demonstrated through extensive experiments
in a local network with 15 hosts. The
evaluation results indicate instant detection
with millisecond accuracy and minimal impact
on network traffic.
        </p>
        <p>During the analysis of publications on this
topic, it was found that they pay little attention
to the process of modeling threats to the ARP
protocol, which is essential for understanding
both the specific vulnerability and the
algorithm of actions and provides an
opportunity to study the network’s response to
specific actions of attackers. In addition to
analyzing the ARP-Flooding, ARP-Spoofing,
and ARP-Poisoning attacks, this article
discusses their sequential execution in the
modeled network, provides an overview of the
reactions of network devices and end nodes,
and explores the possibility of detecting
attacks using the XArp tool. This allows you to
identify network vulnerabilities and choose
effective methods and means to eliminate
them.
1.2.</p>
      </sec>
      <sec id="sec-1-2">
        <title>Methods</title>
        <p>To achieve this goal, this study used analysis
and simulation methods. The analysis allowed
us to identify vulnerabilities of the ARP
protocol, potential attacks on it, and their
possible consequences. The simulation was
used to model attacks using the Nping,
Arpspoof, and Ettercap tools in the GNS3
environment. This made it possible to
practically study a network similar to a real
one and identify its vulnerabilities to choose an
effective method of protection in the future.
The object of research is the ARP protocol and
its vulnerabilities, and the subject is methods
and tools for modeling attacks on the ARP
protocol in the GNS3 environment and their
detection using XArp.</p>
        <p>The purpose of the article is to study
various vulnerabilities of the ARP protocol and
to simulate ARp-flooding, ARP-Spoofing, and
ARp-poisoning attacks on the nodes of a
network created in the GNS3 environment
using specialized tools Nping, Arpspoof, and
Ettercap and detect them using XArp.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2. Results</title>
      <p>ARP (Address et al.) establishes a
correspondence between the logical IP address
and the physical MAC address of a device on a
local network. It allows for more efficient
routing and traffic forwarding, ensuring
correct communication and addressing on the
network. When one device needs to
communicate with another and uses its IP
address, ARP makes it possible to determine
the corresponding MAC address. If the latter is
already known, the device can send data
immediately, and if it is unknown, an ARP
request is sent to obtain this information.</p>
      <p>ARP is an integral part of the network
infrastructure, so the growth of threats in the
field of network security requires a detailed
study of attacks on this protocol and the
development of effective methods for
detecting and protecting against them. The
study of attacks on the ARP protocol is
essential in ensuring the privacy of network
communications and improving the overall
security of computer systems.</p>
      <p>The principal vulnerabilities of ARP include
the following: lack of authentication and
encryption of information, which makes it
vulnerable to interception and cache poisoning
attacks; the ability to send fake ARP messages,
as there are no authentication checks for
requests, responses, and ARP tables
themselves; ease of cache poisoning, which
leads to a violation of the correctness of
network interaction.</p>
      <p>
        The peculiarities of the algorithm and the
above shortcomings have led to the threat of
the following attacks:
1. ARP-Flooding is an attack carried out by
creating a broadcast storm, i.e., sending
many ARP requests to the network to
overflow ARP caches. As a result,
network performance decreases, devices
fail, incorrect ARP tables are built, which
leads to conflicts and incorrect routing,
and there is a possibility of traffic
interception.
2. ARP-Spoofing is an attack that involves
sending fake ARP responses to the
network. An attacker impersonates a
legitimate device and indicates its own
MAC address in response to requests to
redirect network traffic through itself. As
a result, unauthorized interception of
confidential information occurs with its
subsequent viewing and modification.
3. ARP-Poisoning is an attack that is a type
of ARP-Spoofing aimed at a specific
device or a group of them. The logic of its
operation is the same, i.e., the attacker
sends fake ARP responses to poison the
ARP caches of nodes, resulting in
incorrect correspondences between IP
and MAC addresses and the possibility of
redirecting traffic to illegitimate users
[
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>These attacks are rarely used in the form
described above, usually combining their
capabilities and using different implementations.</p>
      <p>These potential threats are critical for
corporate networks, where reliable and
uninterrupted operation is vital. Understanding
all the stages of such attacks becomes essential
for assessing the possible impact on the
network and further determining the necessary
measures to protect the network infrastructure.</p>
      <p>
        Various programs and utilities are used to
implement attacks on the ARP protocol,
including Ettercap, Cain&amp;Abel, BetterCAP,
Scapy, Gobbler, Nping, Arpspoof, Arroison,
ARPBuilder, and others. Each has its
functionality and features, and the choice of a
particular tool depends on the user’s needs and
the goal to be achieved by the attack [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>In this study, the Nping tool was chosen for
the ARP-Flooding attack, Arpspoof for
ARPSpoofing, and Ettercap for ARP-Poisoning, as
their functionality is sufficient to achieve the
goal.
Detecting the fact of an attack is a necessary
element for ensuring information security, so it
is essential to monitor the network to identify
characteristic signs constantly. In the case of the
ARP protocol, it is crucial to monitor whether
the device’s response time to various network
operations increases, whether the ARP activity
on the interfaces is too high, whether entries
with the same addresses appear in the ARP
tables, etc. Specialized software applications
can be used for this purpose.</p>
      <p>Table 1 compares ArpWatch, XArp,
WinARPWatch, ArpStar, ARPScan, NetCut
Defender, and Colasoft Capsa by their primary
functions and support for different operating
systems.</p>
      <p>Considering the above comparison, the
choice was made to use the XArp software tool
to detect ARP attacks planned to be carried out.</p>
      <p>The GNS3 (Graphical Network Simulator-3)
tool was chosen as the modeling environment,
as it allows emulating networks and testing
them interactively and using authentic
operating system images. An essential factor
for using GNS3 is the ability to perform attacks
in an isolated environment without affecting
the performance of a real network.
To emulate attacks on the ARP protocol, we
will develop a realistic network topology in the
GNS3 environment. We will add network
devices and configure them to reproduce the
attack scenarios—we will use Nping, Arpspoof,
and Ettercap to launch the ARP-Flooding,
ARPSpoofing, and ARP-Poisoning attacks. The next
step is to observe the impact of these attacks
on the network, detect them with XArp, and
develop an effective defense strategy.</p>
      <p>To illustrate, it is enough to create a
compact network that includes a Cisco router,
based on which you can configure a DHCP
server for dynamic configuration of endpoint
IP addressing parameters, a switch, and four
workstations. Three of them will be legitimate
Windows workstations (Win10-Admin,
Win7User1, WinXP-User2), and the fourth will be
malicious (KaliLinux-Hacker), from which
attacks will be carried out using the above
tools (Fig. 1).
The successful configuration of the DHCP
server is confirmed by the end nodes receiving
IP addressing parameters (Fig. 2). There is
communication between legitimate devices,
and the ARP tables of network devices and
workstations before the attacks are shown in
Fig. 3.</p>
      <p>The Win10-Admin workstation has the
XArp application installed to detect attacks on
the ARP protocol. The KaliLinux-Hacker user
received the address 192.168.1.4/24.</p>
      <p>Let us start the ARP-Flooding attack using
the Nping utility. To do this, execute the
corresponding command on the attacker’s
workstation, which generates many ARP
messages and sends them to the same network
as the sending device (Fig. 4a). During the
attack, the XArp application installed on the
Win10-Admin workstation signals the
presence of an attack in real-time (Fig. 4b).</p>
      <p>During the attack, the switch displays
relevant system messages, and the connection
between endpoints is either absent or unstable
with long delays (Fig. 5).</p>
      <p>The next attack that will be modeled is
ARPSpoofing using the Arpspoof utility. We use the
corresponding command, in the parameters of
which we specify the IP addresses of one of the
legal workstations (for example,
Win10Admin) and one of the network devices (for
example, a router) (Fig. 6a). The attack is
successfully detected using the installed XArp
application (Fig. 6b).
(c) (d)
Figure 3: ARP tables of devices before the attack
(b)
Figure 4: ARP-Flooding (a) attack execution
(b) attack detection
(b)
Figure 5: Network device response to an
ARPFlooding attack
(b)
Figure 6: ARP-Spoofing (a) carrying out an
attack (b) detecting an attack
Let us display the router’s ARP table (Fig. 7). As
you can see, the MAC address of the interface
of the legitimate Win10-Admin workstation
and the KaliLinux-Hacker workstation are the
same (different IP addresses have the same
MAC address). The ARP-Spoofing attack was
successful. The MAC address of the network
interface of the legitimate workstation has
been spoofed to the MAC address of the
attacker’s network interface, which means that
the attacker will be able to intercept the
network traffic of the legitimate workstation.
Let us simulate an ARP-Poisoning attack using
the Ettercap utility. To do this, select Hosts in
the menu after launching it, then Scan for
Hosts. As a result, the hosts are scanned
(Fig. 8a). To view them again, select Hosts in
the menu and click Host list (Fig. 8b).
(b)
Figure 8: The process of (a) scanning and (b)
the result of scanning hosts in Ettercap
From this list, you need to select the hosts that
will be attacked. Since the application for
detecting ARP attacks is installed on
Win10Admin, select the IP address corresponding to
this workstation and add it using Add to Target 1.
As the second target address, select, for example,
the IP address of the switch interface and add it
using Add to Target 2 (Fig. 9).
In the MITM attacks menu, select ARP
poisoning, then Sniff remote connections and
click OK. The attack process in the Ettercap
utility is shown in Fig. 10.
(b)
Figure 10: Performing an ARP-Poisoning attack
The attack is successfully detected by the XArp
application (Fig. 11.a). Display the ARP table of
the switch (Fig. 11.b).</p>
      <p>We can see that the MAC address of the
interface of the legitimate Win10-Admin
workstation and the KaliLinux-Hacker
workstation are the same. The ARP-poisoning
attack was successful, and the MAC address
was spoofed. The attacker was able to
intercept the traffic of a legitimate
workstation.</p>
      <p>(a)
After emulating attacks on the ARP protocol, it
was determined that they can cause a decrease
in network performance, disrupt the
correctness of ARP tables of devices, open up
the possibility of intercepting network traffic,
and lead to devise failures and other negative
consequences.</p>
      <p>Having identified the weaknesses of the
network, it is worth developing a strategy to
protect it from this type of attack, which will
include the following steps:
1. Use static ARP records to reduce the risk
of unauthorized table changes.
2. Install ARP traffic monitoring and
filtering systems to detect suspicious
activity promptly.
3. Use traffic encryption at the link layer to
complicate the analysis of ARP packets.
4. Configuring security mechanisms to
protect against attacks (Dynamic ARP
Inspection, DHCP Snooping, IP Source
Guard).
5. Use VLANs to limit the propagation of</p>
      <p>ARP traffic.
6. Use personal firewalls on endpoints to
block unauthorized ARP packets and
changes to ARP tables.</p>
      <p>Implementing this strategy will reduce the
risk of successful ARP attacks and increase the
security of the network infrastructure.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Conclusion</title>
      <p>As a result of step-by-step modeling of attacks
on the ARP protocol using the Nping, Arpspoof,
and Ettercap utilities, it was found that the
built network has specific weaknesses related
to insufficient control and security of the
internal network infrastructure. The resulting
possibility of unauthorized access can cause
device malfunctions, MAC address spoofing,
and network traffic interception. Following the
proposed security strategy, it is essential to
consider these risks when designing and
configuring the network to prevent
unauthorized access. Further research may
include analyzing the vulnerabilities of other
protocols and developing effective security
methods with practical demonstrations of
their operation.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          , et al.,
          <article-title>Method for Increasing the Various Sources Data Consistency for IoT Sensors</article-title>
          , in: IEEE 9th International Conference on Problems of Infocommunications,
          <source>Science and Technology (PICST)</source>
          (
          <year>2023</year>
          )
          <fpage>522</fpage>
          -
          <lpage>526</lpage>
          . doi:
          <volume>10</volume>
          .1109/PICST57299.
          <year>2022</year>
          .
          <volume>10238518</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kuzminykh</surname>
          </string-name>
          , et al.,
          <article-title>Investigation of the IoT Device Lifetime with Secure Data Transmission, Internet of Things, Smart Spaces, and Next Generation Networks and Systems</article-title>
          , vol.
          <volume>11660</volume>
          (
          <year>2019</year>
          )
          <fpage>16</fpage>
          -
          <lpage>27</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          -30859-
          <issue>9</issue>
          _
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hu</surname>
          </string-name>
          , et al.,
          <source>Bandwidth Research of Wireless IoT Switches, in: IEEE 15th International Conference on Advanced Trends in Radioelectronics, Telecommunications and Computer Engineering</source>
          (
          <year>2020</year>
          ). doi:
          <volume>10</volume>
          .1109/tcset49122.
          <year>2020</year>
          .
          <volume>2354922</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>O.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <article-title>Methods of the Objects Identification and Recognition Research in the Networks with the IoT Concept Support</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>2923</volume>
          (
          <year>2021</year>
          )
          <fpage>277</fpage>
          -
          <lpage>282</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>B.</given-names>
            <surname>Zhurakovskyi</surname>
          </string-name>
          , et al.,
          <source>Secured Remote Update Protocol in IoT Data Exchange System, in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>67</fpage>
          -
          <lpage>76</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Jadhav</surname>
          </string-name>
          , et al.,
          <source>Detection and Mitigation of ARP Spoofing Attack, International Conference on Innovative Computing and Communications</source>
          ,
          <string-name>
            <surname>LNNS</surname>
          </string-name>
          (
          <year>2023</year>
          )
          <fpage>395</fpage>
          -
          <lpage>405</lpage>
          . doi:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          -981-99-3010- 4_
          <fpage>33</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Chen</surname>
          </string-name>
          , Research on ARP Attack Principle and Defense Measures in
          <string-name>
            <surname>LAN</surname>
          </string-name>
          ,
          <source>International Conference on Computer Network Security and Software Engineering (CNSSE</source>
          <year>2023</year>
          )
          <volume>12714</volume>
          (
          <year>2023</year>
          ) doi: 10.1117/12.2683288.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>X.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , et al.,
          <article-title>A Solution for ARP Attacks in Software Defined Network</article-title>
          ,
          <source>The Second International Conference on Artificial Intelligence, Information Processing and Cloud Computing</source>
          (
          <year>2021</year>
          )
          <fpage>1</fpage>
          -
          <lpage>9</lpage>
          . doi:
          <volume>10</volume>
          .1109/AIIPCC53292.
          <year>2021</year>
          .
          <volume>9474466</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>A.</given-names>
            <surname>Jony</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Arnob</surname>
          </string-name>
          ,
          <article-title>A Long Short-Term Memory Based Approach for Detecting Cyber Attacks in IoT Using CIC-IoT2023 dataset</article-title>
          ,
          <source>J. Edge Comput</source>
          .
          <article-title>(</article-title>
          <year>2024</year>
          ). doi:
          <volume>10</volume>
          .55056/jec.648.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>C.</given-names>
            <surname>Abad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Bonilla</surname>
          </string-name>
          ,
          <article-title>An Analysis on the Schemes for Detecting and Preventing ARP Cache Poisoning Attacks</article-title>
          ,
          <source>27th International Conference on Distributed Computing Systems Workshops (ICDCSW'07)</source>
          (
          <year>2007</year>
          )
          <fpage>60</fpage>
          -
          <lpage>60</lpage>
          . doi:
          <volume>10</volume>
          .1109/ICDCSW.
          <year>2007</year>
          .
          <volume>19</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kawshan</surname>
          </string-name>
          ,
          <string-name>
            <surname>Create ARP Spoofing Attack Using Scapy</surname>
          </string-name>
          (
          <year>2022</year>
          ).
          <source>doi: 10.13140/RG.2.2.19490.09923.</source>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>H.</given-names>
            <surname>Xi</surname>
          </string-name>
          ,
          <source>Research and Application of ARP Protocol Vulnerability Attack and Defense Technology Based on Trusted Network, AIP Conference Proceedings</source>
          ,
          <year>1820</year>
          (1) (
          <year>2017</year>
          ),
          <volume>090019</volume>
          . doi:
          <volume>10</volume>
          .1063/1.4977403.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>M.</given-names>
            <surname>Nobakht</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Mahmoudi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Rahimzadeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Distributed</given-names>
            <surname>Security</surname>
          </string-name>
          <article-title>Approach against ARP Cache Poisoning Attack</article-title>
          ,
          <source>ACM Transactions on Internet Technology (TOIT) 22(1)</source>
          (
          <year>2022</year>
          )
          <fpage>1</fpage>
          -
          <lpage>21</lpage>
          . doi:
          <volume>10</volume>
          .1145/3494108.3522765.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>I. Anfalovas</surname>
          </string-name>
          , What Is Address Resolution Protocol?
          <article-title>A Beginner's Guide to ARP (</article-title>
          <year>2024</year>
          ). URL: https://www.ipxo.com/ blog/address-resolution-protocol/
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>T.</given-names>
            <surname>Vakaliuk</surname>
          </string-name>
          , et al., (
          <year>2023</year>
          ).
          <article-title>Modeling Attacks on the DHCP Protocol in the GNS3 Environment and Determining Methods of Security Against Them</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          II Vol.
          <volume>3350</volume>
          (
          <year>2023</year>
          )
          <fpage>209</fpage>
          -
          <lpage>216</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>