摘要
介绍ARP地址解析协议的含义和工作原理,分析ARP协议所存在的安全漏洞,给出了网段内和跨网段ARP欺骗的实现过程。结合网络管理的实际工作,重点介绍了IP地址和MAC地址绑定、交换机端口和MAC地址绑定、VLAN隔离等几种技术能够有效防御ARP欺骗攻击的安全防范策略,并通过实验验证了该安全策略的有效性。
The article introduces the concept and the principle of ARP Address Resolution Protocol, analyzing the security leak which ARP agreement exists, describing implementation process of ARP spoofing in network segment and crossover network segments. Finally, the emphasis is on some technologies which can defend ARP spoofing effectively such as IP address and MAC address binding, switchboard port and MAC address binding, VLAN isolation based on network management, which proves that the security strategies are reliable and practical.
出处
《南钢科技与管理》
2008年第4期4-7,共4页
NISCO Technology and Management