{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:04:19Z","timestamp":1777806259924,"version":"3.51.4"},"reference-count":68,"publisher":"SAGE Publications","issue":"5","license":[{"start":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T00:00:00Z","timestamp":1706745600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2024,11,18]]},"abstract":"<jats:p>The increased adoption of the Internet Protocol (IP) in ICSs has made these systems vulnerable to the same security risks that are present in traditional IT environments. The legacy nature of ICSs and their unique operational requirements make them vulnerable to security threats that are different from those in IT environments. In this paper, we describe a protocol, named ArpON, which is able to wipe out in quasi real time any ARP cache poisoning attempt, thus making it ineffective. Contrarily to solutions presented in the literature for contrasting ARP cache poisoning, ArpON incurs in low operational costs, is backward compatible, transparent to the ARP protocol and does not use any HW feature nor cryptography functionality. We also model and validate ArpON in the OMNET[Formula: see text] network simulator. The simulation results show that ArpON is effective in avoiding ARP poisoning, and its communication overhead is negligible with respect to classical ARP protocol.<\/jats:p>","DOI":"10.3233\/jcs-230023","type":"journal-article","created":{"date-parts":[[2024,2,2]],"date-time":"2024-02-02T10:51:48Z","timestamp":1706871108000},"page":"447-475","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":2,"title":["Ensuring cybersecurity for industrial networks: A solution for ARP-based MITM attacks"],"prefix":"10.1177","volume":"32","author":[{"given":"Danilo","family":"Bruschi","sequence":"first","affiliation":[{"name":"Computer Science Department, Universit\u00e0 degli Studi di Milano, via G. Celoria 18, 20133 Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Di Pasquale","sequence":"additional","affiliation":[{"name":"Accenture S.p.A., via Sciangai, 53, 00144 Roma (RM), Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Lanzi","sequence":"additional","affiliation":[{"name":"Computer Science Department, Universit\u00e0 degli Studi di Milano, via G. Celoria 18, 20133 Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elena","family":"Pagani","sequence":"additional","affiliation":[{"name":"Computer Science Department, Universit\u00e0 degli Studi di Milano, via G. Celoria 18, 20133 Milano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2024,2,1]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"A.M.\u00a0Abdel Salam, W.S.\u00a0Elkilani and K.M.\u00a0Amin, An automated approach for preventing ARP spoofing attack using static ARP entries, International Journal of Advanced Computer Science and Applications(IJACSA) 5(1) (2014).","DOI":"10.14569\/IJACSA.2014.050114"},{"key":"ref002","doi-asserted-by":"publisher","DOI":"10.1109\/ICCTA37466.2015.9513433"},{"key":"ref003","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2022.107757"},{"key":"ref004","doi-asserted-by":"publisher","DOI":"10.1109\/SoutheastCon45413.2021.9401860"},{"key":"ref005","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-05152-9"},{"key":"ref006","doi-asserted-by":"publisher","DOI":"10.1109\/CINE.2015.34"},{"key":"ref007","unstructured":"Arpalert, ARP spoofing detector, www.arpalert.org."},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.1016\/j.micpro.2020.103741"},{"key":"ref009","unstructured":"Barnaba, Anticap, 2003, http:\/\/cvs.antifork.org\/cvsweb.cgi\/anticap."},{"key":"ref010","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66845-1_26"},{"key":"ref011","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3118448"},{"key":"ref012","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2003.1254311"},{"key":"ref013","doi-asserted-by":"publisher","DOI":"10.1063\/5.0110596"},{"key":"ref014","doi-asserted-by":"crossref","unstructured":"S.\u00a0Cheshire, IPv4 address conflict detection, RFC 5227, IETF, 2008, Internet Engineering Task Force, http:\/\/www.ietf.org\/rfc\/rfc5227.txt.","DOI":"10.17487\/rfc5227"},{"key":"ref015","doi-asserted-by":"publisher","DOI":"10.17487\/rfc3927"},{"key":"ref016","unstructured":"CISCO, Cisco systems. \u201cConfiguring Dynamic Arp Inspection\u201d. Catalyst 6500 Series Switch Cisco IOS Software Configuration guide, release 12.2SX. Chapter\u00a039, 2003, http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/switches\/lan\/catalyst6500\/ios\/12-2SX\/configuration\/guide\/book\/dynarp.html."},{"key":"ref017","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA.2014.7005074"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"D.\u00a0Deb, S.R.\u00a0Chakraborty, M.\u00a0Lagineni and K.\u00a0Singh, Security analysis of MITM attack on SCADA network, in: Machine Learning, Image Processing, Network Security and Data Sciences, Springer, 2020, pp.\u00a0501\u2013512. ISBN 978-981-15-6318-8.","DOI":"10.1007\/978-981-15-6318-8_41"},{"key":"ref019","unstructured":"S.\u00a0Djiev, Industrial network for communication and control (Ch. 5), Academia, last visited: 7 May 2022, https:\/\/www.academia.edu\/8865431\/Industrial_Networks."},{"key":"ref020","unstructured":"Emerson Electric Co., PACSystems RSTi-EP quick start guide, 2021, Last visited: 12 Sep., 2023, https:\/\/emerson-mas.my.site.com\/communities\/en_US\/Documentation\/PACSystems-RSTi-EP-EPSCPE115-CPU-Quick-Start-Guide-GFK-3039."},{"key":"ref021","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3544475"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"S.\u00a0Fuchs, H.P.\u00a0Schmidt and S.\u00a0Witte, Test and on-line monitoring of real-time ethernet with mixed pysical layer for industry 4.0, in: 2016 IEEE 21st International Conference on Emerging Technologies and Factory Automation (ETFA), IEEE, 2016, pp.\u00a01\u20134.","DOI":"10.1109\/ETFA.2016.7733518"},{"key":"ref023","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2018.05.004"},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14203-1_3"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"T.\u00a0Girdler and V.G.\u00a0Vassilakis, Implementing an intrusion detection and prevention system using software-defined networking: Defending against ARP spoofing attacks and blacklisted MAC addresses, Computers and Electrical Engineering J. 90 (2021).","DOI":"10.1016\/j.compeleceng.2021.106990"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1109\/CSASE48920.2020.9142092"},{"key":"ref027","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2009.2017259"},{"key":"ref028","doi-asserted-by":"crossref","unstructured":"B.\u00a0Kang, P.\u00a0Maynard, K.\u00a0McLaughlin, S.\u00a0Sezer, F.\u00a0Andr\u00e9n, C.\u00a0Seitl, F.\u00a0Kupzog and T.\u00a0Strasser, Investigating cyber-physical attacks against IEC 61850 photovoltaic inverter installations, in: 2015 IEEE 20th Conference on Emerging Technologies & Factory Automation (ETFA), IEEE, 2015, pp.\u00a01\u20138.","DOI":"10.1109\/ETFA.2015.7301457"},{"key":"ref029","doi-asserted-by":"publisher","DOI":"10.1109\/ETSecIoT50046.2020.00009"},{"key":"ref030","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-10-4585-1_2"},{"issue":"3","key":"ref031","first-page":"431","volume":"2","author":"Kaur R.","year":"2015","journal-title":"International Journal of Computer and Communication System Engineering (IJCCSE)"},{"key":"ref032","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-81645-2_14"},{"key":"ref033","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2020.04.257"},{"key":"ref034","doi-asserted-by":"crossref","unstructured":"D.\u00a0Kushner, The real story of Stuxnet, IEEE Spectrum (2013), https:\/\/spectrum.ieee.org\/the-real-story-of-stuxnet.","DOI":"10.1109\/MSPEC.2013.6471059"},{"key":"ref035","unstructured":"Lawrence Berkeley National Laboratory, ARPWATCH: ARP spoofing detector, ftp:\/\/ftp.ee.lbl.gov\/ARPwatch.tar.gz."},{"key":"ref036","unstructured":"D.\u00a0Lee, H.\u00a0Kim, K.\u00a0Kim and P.D.\u00a0Yoo, Simulated attack on dnp3 protocol in scada system, in: Proceedings of the 31th Symposium on Cryptography and Information Security, Kagoshima, Japan, 2014, pp.\u00a021\u201324."},{"key":"ref037","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2007.05.007"},{"key":"ref038","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3172329"},{"key":"ref039","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2013.09.011"},{"key":"ref040","doi-asserted-by":"publisher","DOI":"10.1109\/MED.2010.5547790"},{"key":"ref041","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1908.03964"},{"key":"ref042","unstructured":"OpenPLC, OpenPLC documentation, 2022, Last visited: 5 July 2022, https:\/\/openplcproject.com\/docs\/openplc-overview\/."},{"key":"ref043","doi-asserted-by":"crossref","unstructured":"A.P.\u00a0Ortega, X.E.\u00a0Marcos, L.D.\u00a0Chiang and C.L.\u00a0Abad, Preventing ARP cache poisoning attacks: A proof of concept using OpenWrt, in: Network Operations and Management Symposium, 2009. LANOMS 2009. Latin American, IEEE, 2009, pp.\u00a01\u20139.","DOI":"10.1109\/LANOMS.2009.5338799"},{"key":"ref044","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM42002.2020.9322295"},{"key":"ref045","doi-asserted-by":"publisher","DOI":"10.17487\/rfc826"},{"key":"ref046","doi-asserted-by":"publisher","DOI":"10.1109\/MOCAST49295.2020.9200287"},{"key":"ref047","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.2019.8888399"},{"key":"ref048","unstructured":"M.\u00a0Rash, Linux Firewalls: Attack Detection and Response with iptables, psad, and fwsnort, No Starch Press, 2007."},{"key":"ref049","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2019.01.002"},{"key":"ref050","unstructured":"C.\u00a0Schluting, Configure your Catalyst for a more secure layer 2, 2005, Last accessed: Nov. 9, 2022, https:\/\/www.enterprisenetworkingplanet.com\/security\/configure-your-catalyst-for-a-more-secure-layer-2\/."},{"key":"ref051","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-71756-8_19"},{"key":"ref052","doi-asserted-by":"publisher","DOI":"10.35940\/ijrte.D6814.118419"},{"key":"ref053","doi-asserted-by":"publisher","DOI":"10.1007\/978-81-322-2656-7_35"},{"key":"ref054","unstructured":"Siemens, IWLAN\u00a0\u2013 the wireless LAN for demanding industrial applications, Last visited: 5 Sep. 2023, https:\/\/www.siemens.com\/global\/en\/products\/automation\/industrial-communication\/industrial-wireless-lan.html."},{"key":"ref055","unstructured":"D.\u00a0Song, 2003, http:\/\/www.monkey.org\/~dugsong\/dsniff."},{"key":"ref056","unstructured":"StackExchange, Is there any point of arp spoofing on a wifi network? Last visited: 5 Sep. 2023, https:\/\/security.stackexchange.com\/questions\/225985\/is-there-any-point-of-arp-spoofing-on-a-wifi-network."},{"key":"ref057","unstructured":"StackExchange, ARP spoofing over WLAN, Last visited: 5 Sep. 2023, https:\/\/networkengineering.stackexchange.com\/questions\/60697\/arp-spoofing-over-wlan."},{"key":"ref058","unstructured":"StackExchange, ARP poisoning between a wired and wireless network, Last visited: 5 Sep. 2023, https:\/\/security.stackexchange.com\/questions\/41961\/arp-poisoning-between-a-wired-and-wireless-network."},{"key":"ref059","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-73100-7_53"},{"key":"ref060","unstructured":"I.\u00a0Tetrin, Antidote, 2003, http:\/\/online.securityfocus.com\/archive\/1\/299929."},{"key":"ref061","doi-asserted-by":"publisher","DOI":"10.1145\/2699026.2699123"},{"key":"ref062","doi-asserted-by":"publisher","DOI":"10.3390\/s19194191"},{"key":"ref063","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2015.2426953"},{"key":"ref064","unstructured":"M.V.\u00a0Tripunitara and P.\u00a0Dutta, Middle approach to asynchronous and backward-compatible detection and prevention of ARP cache poisoning, Google Patents, 2004, Patent 6,771,649."},{"key":"ref065","doi-asserted-by":"publisher","DOI":"10.4108\/ICST.SIMUTOOLS2008.3027"},{"key":"ref066","unstructured":"W.\u00a0Voss, Industrial ethernet guide\u00a0\u2013 network topologies, in: A Comprehensible Guide to Industrial Ethernet, Copperhill Technologies, 2019, Online book, last visited: 7 Sep. 2023, https:\/\/copperhilltech.com\/blog\/industrial-ethernet-guide-network-topologies\/."},{"key":"ref067","unstructured":"W.\u00a0Voss, Industrial ethernet guide\u00a0\u2013 topology and communication features, in: A Comprehensible Guide to Industrial Ethernet, Copperhill Technologies, 2019, Online book, last visited: 7 Sep. 2023, https:\/\/copperhilltech.com\/blog\/industrial-ethernet-guide-topology-and-communication-features\/."},{"key":"ref068","unstructured":"Xarp, Advanced ARP spoofing detection, 2011, http:\/\/www.xarp.net."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-230023","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-230023","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-230023","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:50Z","timestamp":1777495550000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-230023"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2,1]]},"references-count":68,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,11,18]]}},"alternative-id":["10.3233\/JCS-230023"],"URL":"https:\/\/doi.org\/10.3233\/jcs-230023","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,2,1]]}}}