Skip to content
Conference Open access

AI-ENHANCED DETECTION OF ARP SPOOFING-BASED MAN-IN-THE-MIDDLE ATTACKS IN LOCAL AREA NETWORKS

Sep 2026 · Proceedings of the International Conference on Secure Systems Design and Technology Development · 0 citations · 15 references

TL;DR

A hybrid LAN protection architecture that combines DAI with an AI-based behavioral detection module to improve the identification of stealthy and context-dependent MitM activity is proposed and indicates that AI can effectively complement traditional infrastructure-level network defenses by providing behavioral awareness and improved sensitivity to attack patterns that are difficult to detect through rule-based inspection alone.

Abstract

Man-in-the-Middle (MitM) attacks remain a significant threat to local area networks, particularly when implemented through Address Resolution Protocol (ARP) spoofing. Although infrastructure-level protection mechanisms such as Dynamic ARP Inspection (DAI) are effective against conventional ARP poisoning attempts, their detection capability is limited in low-rate and insider-like scenarios, where malicious behavior may appear formally valid while remaining anomalous in context. This paper proposes a hybrid LAN protection architecture that combines DAI with an AI-based behavioral detection module to improve the identification of stealthy and context-dependent MitM activity. The proposed approach analyzes ARP, DHCP, and switch-port events using interpretable traffic features and a two-stage detection logic that integrates anomaly filtering and supervised classification. The system was evaluated in a controlled laboratory environment under three attack scenarios: classic high-rate ARP spoofing, low-rate stealth spoofing, and insider spoofing. The experimental results show that DAI alone performs very well in classic spoofing conditions, but its effectiveness decreases substantially in low-rate and insider scenarios. In contrast, the proposed DAI+AI architecture achieves the best overall balance between recall, precision, F1-score, detection latency, and false positive rate. The findings indicate that AI can effectively complement traditional infrastructure-level network defenses by providing behavioral awareness and improved sensitivity to attack patterns that are difficult to detect through rule-based inspection alone.

Read PDF

Similar papers

Preprint Sep 2026

Improving the Reliability of Anomaly Detection for Encrypted OPC UA Traffic over Private 5G

Open Platform Communications Unified Architecture (OPC UA) is increasingly deployed over private 5G networks in industrial environments, where end-to-end encryption prevents payload inspection by network-based intrusion detection systems (IDSs). Although payload-agnostic statistical features extracted from encrypted tr...

Son-Ha Song, Florian Foerster, Henry Beuster et al. · 0 citations
Open access Sep 2026

AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments

In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architec...

Mohammed Imran Choudhary · 0 citations
Open access Aug 2026

Enhancing Security in Software-Defined Networking from ARP Spoofing Attack Using Adaptive Encryption-Assisted Explainable Mish-Activated Recurrent Neural Network Framework

Objectives: To develop an MARNN framework for accurate ARP spoofing-based MITM attack detection and secure communication in SDN environments. Method: The approach involves preprocessing raw data from the ARP Spoofing-Based MITM Attack Dataset using Variable Stability Scaling (Var-SS) normalization, followed by the MARN...

V. Mangaiyarkarasi, S. Malathi · 0 citations
Open access Aug 2026

A Comparative Effectiveness Analysis of Signature-Based IDS and Network Detection and Response (NDR) in a SIEM Environment

As cyber threats increasingly employ cryptographically concealed and stealthy communication, traditional signature-based Network Intrusion Detection Systems (NIDS) encounter severe limitations in achieving end-to-end operational visibility. This study delivers a quantitative comparative analysis contrasting signature-b...

Christian Hary, Muhammad Salman · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.