Close menu

SURE

Sunderland Repository records the research produced by the University of Sunderland including practice-based research and theses.

Dynamic ARP Cache Poisoning Detection and Enhanced Prevention in Virtual Networks Using SDN and Real-Time Traffic Analysis with Scapy

Ali, Ala’a Alsheikh, McGarry, Kenneth, Baglee, David and Eliot, Neil (2025) Dynamic ARP Cache Poisoning Detection and Enhanced Prevention in Virtual Networks Using SDN and Real-Time Traffic Analysis with Scapy. In: UNSPECIFIED Springer. (In Press)

Item Type: Book Section

Abstract

This study presents an advanced detection and mitigation framework against ARP spoofing—a major threat exploiting authentication gaps in the ARP protocol. Leveraging Scapy integrated with Software-Defined Networking (SDN) technologies, including the Ryu controller and Open vSwitch, the research introduces a custom ARP cache poisoning script that covertly reroutes network traffic to an attacker-controlled node with precision and control. Deployed in a virtualized environment, the script was evaluated against tools like Ettercap and Bettercap, achieving superior manipulation capabilities and a 100% ARP table compromise rate. The tailored SDN-based detection tool further demonstrated impressive performance, identifying 98.33% of spoofing activities with a low detection latency of 0.024 seconds and minimal CPU usage, ensuring network efficiency. This research sets a new benchmark in ARP spoofing mitigation and paves the way for future enhancements such as ARP table pre-population and broader protocol support, strengthening defenses in virtualized environments.

[img] PDF (Author Accepted Manuscript on publisher's template (LaTex))
AlaaPaper V4.pdf
Restricted to Repository staff only

Download (1MB)

More Information

Uncontrolled Keywords: ARP Spoofing Detection, Software-Defined Networking (SDN), Scapy, ARP Cache Poisoning,
Depositing User: Kenneth McGarry

Identifiers

Item ID: 19244
URI: http://sure.sunderland.ac.uk/id/eprint/19244
Official URL: https://american-cse.org/csce2025/

Users with ORCIDS

ORCID for Kenneth McGarry: ORCID iD orcid.org/0000-0002-9329-9835
ORCID for David Baglee: ORCID iD orcid.org/0000-0002-7335-5609
ORCID for Neil Eliot: ORCID iD orcid.org/0000-0002-7591-7783

Catalogue record

Date Deposited: 21 Jul 2025 15:21
Last Modified: 21 Jul 2025 15:21

Contributors

Author: Kenneth McGarry ORCID iD
Author: David Baglee ORCID iD
Author: Neil Eliot ORCID iD
Author: Ala’a Alsheikh Ali

University Divisions

Faculty of Business and Technology

Subjects

Computing > Cybersecurity
Computing > Artificial Intelligence
Computing

Actions (login required)

View Item (Repository Staff Only) View Item (Repository Staff Only)