Skip to content
Conference

ARP Spoofing Prevention in SDN using Host Agents and Cryptographically Verified IP-MAC Bindings

Aug 2026 · Moratuwa Engineering Research Conference · pp. 694-699 · 0 citations · 16 references

Abstract

The inherently trustless nature of the Address Resolution Protocol (ARP) enables attackers to intercept network traffic using forged messages. While traditional reactive defences, like machine learning, attempt to mitigate this, they often suffer from deployment complexity, poor scalability, and high latency. To overcome these limitations, we introduce a proactive prevention mechanism for Software-Defined Networking (SDN) environments that leverages centralised visibility to eliminate trust-based vulnerabilities. The SDN controller acts as a "Root of Trust" by observing Dynamic Host Configuration Protocol (DHCP) transactions and accepting authorised static infrastructure mappings via a Northbound Application Programming Interface (API) to generate verified Internet Protocol (IP) to Media Access Control (MAC) bindings. These bindings are cryptographically signed using Ed25519 to ensure high-speed verification and integrity. A persistent distribution layer (e.g., Redis Streams) manages these mappings using monotonic IDs, ensuring state replayability for offline hosts. Lightweight host-side agents subscribe to the stream, verify digital signatures, and install local static ARP entries, which the operating system (OS) kernel prioritises over malicious updates. Experiments confirm that combining SDN visibility and cryptographic enforcement neutralises spoofing with minimal overhead. Consequently, our solution provides a proactive alternative to detection-based approaches, offering stronger security, streamlined deployment, and immediate enforcement of authorised mappings.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.