ARP Spoofing / ARP Poisoning
ARP spoofing sends misleading IP-to-MAC mappings on a local network so traffic can be redirected or intercepted.
Mechanism
Hosts update their ARP cache from local network messages. An attacker can abuse that trust if the network lacks validation or segmentation.
Indicators to watch
Frequent ARP changes, duplicate IP/MAC mappings, gateway MAC changes, and unexpected ARP replies.
Concept diagram
Defensive controls
Use DHCP snooping, Dynamic ARP Inspection, static bindings where practical, segmentation, secure management, and endpoint monitoring.
Recommended security control
Switch DAI / arpwatch
Use a private virtual LAN or emulator for demonstrations.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.