• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2010, Vol. 32 ›› Issue (12): 15-18.doi: 10.3969/j.issn.1007130X.2010.

• 论文 • Previous Articles     Next Articles

Design and Implementation of the Sniffer Prototype Based on the MAC Spoofing

CHEN Xinnan1,Hu Huaping1,2,YUE Hong2   

  1. (1.School of Mathematics and Computer Science,Fuzhou University,Fuzhou 350108;2.Corps 61070,Fuzhou 350003,China)
  • Received:2009-11-02 Revised:2010-01-20 Online:2010-12-25 Published:2010-12-25

Abstract:

In the switchbased LAN environment,the means of defending the ARP spoofing is maturing,leading to the sniffer based on the ARP spoofing is vulnerable to being intercepted and killed by security software,so it lacks sniffing effect. In this paper,one nonARP spoofing,which is called MAC spoofing,is proposed,and a LAN sniffer prototype based on the MAC spoofing is also designed and implemented. Compared with the  traditional ARP spoofing,the MAC spoofing can bypass a variety of ARP spoofing defense tools and succeed to intercept the network data,as well as carrying on the Denial of Service attacks. Through the use of a timealternate mechanism,a filtering mechanism and other key technologies,the efficiency and accuracy of the sniffer can be highly improved. The testing result shows that the sniffer may be better to break through the interception and killing of security software,and achieve the effect of sniffing.

Key words: ARP spoofing;MAC spoofing;switch environment;LAN;sniffer