How to use Wireshark to detect and prevent ARP spoofing

An Address Resolution Protocol attack can accomplish any task, ranging from collecting passwords off a network to taking an entire network offline. Such a potentially devastating attack would make any IT security team shudder.  Now consider the fact that the default configuration for most network switches allows ARP spoofing attacks to take place unchecked. How can an organization prevent ARP spoofing before an attack on its network is successful? The open source tool Wireshark may just be the answer.

In this screencast, Keith Barker, CISSP and trainer for CBT Nuggets, instructs viewers on how to use Wireshark to detect and prevent Address Resolution Protocol (ARP) spoofing attacks. ARP duplicate IP address detection is already turned on by default, but Barker delves further into Wireshark's features to uncover the "Detect ARP request storms" function. Wireshark can also provide summaries of ARP flooding and ARP spoofing attack events, and is even capable of indicating which frames should be further investigated because they were involved in an attack. And best of all, these features are available in the free version of Wireshark. If your organization is concerned about ARP spoofing, Keith's Wireshark walkthrough provides the necessary tools to allay any fears.

Editor’s note: While this video discusses general strategies that could be used maliciously, the techniques demonstrated in the video are intended for defensive purposes only, and should not be employed for any other reason.

