← Back to Attack / Defense Lab
OSI LAYER 2 // Data Link Layer

ARP Spoofing / ARP Poisoning

ARP spoofing sends misleading IP-to-MAC mappings on a local network so traffic can be redirected or intercepted.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

Hosts update their ARP cache from local network messages. An attacker can abuse that trust if the network lacks validation or segmentation.

02 // DETECTION

Indicators to watch

Frequent ARP changes, duplicate IP/MAC mappings, gateway MAC changes, and unexpected ARP replies.

03 // ATTACK FLOW

Concept diagram

01Local hosts↓
02Forged ARP mapping↓
03ARP cache changes↓
04Traffic redirected↓
05DAI + DHCP snooping
04 // PREVENTION

Defensive controls

Use DHCP snooping, Dynamic ARP Inspection, static bindings where practical, segmentation, secure management, and endpoint monitoring.

05 // SECURITY TOOL

Recommended security control

Switch DAI / arpwatch

Use a private virtual LAN or emulator for demonstrations.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.