AI-ENHANCED DETECTION OF ARP SPOOFING-BASED MAN-IN-THE-MIDDLE ATTACKS IN LOCAL AREA NETWORKS

Authors

  • Penka Markova Computer Science and Engineering, Technical University of Varna, Varna, Bulgaria
  • Georgi Markov Department of Information Technologies, Nikola Vaptsarov Naval Academy, Varna, Bulgaria https://orcid.org/0000-0003-2997-491X

DOI:

https://doi.org/10.68302/std2026.vol3.52

Keywords:

anomaly detection, ARP spoofing, artificial intelligence, behavioral analysis, Dynamic ARP Inspection, intrusion detection system, LAN security, Man-in-the-Middle attack

Abstract

Man-in-the-Middle (MitM) attacks remain a significant threat to local area networks, particularly when implemented through Address Resolution Protocol (ARP) spoofing. Although infrastructure-level protection mechanisms such as Dynamic ARP Inspection (DAI) are effective against conventional ARP poisoning attempts, their detection capability is limited in low-rate and insider-like scenarios, where malicious behavior may appear formally valid while remaining anomalous in context. This paper proposes a hybrid LAN protection architecture that combines DAI with an AI-based behavioral detection module to improve the identification of stealthy and context-dependent MitM activity. The proposed approach analyzes ARP, DHCP, and switch-port events using interpretable traffic features and a two-stage detection logic that integrates anomaly filtering and supervised classification. The system was evaluated in a controlled laboratory environment under three attack scenarios: classic high-rate ARP spoofing, low-rate stealth spoofing, and insider spoofing. The experimental results show that DAI alone performs very well in classic spoofing conditions, but its effectiveness decreases substantially in low-rate and insider scenarios. In contrast, the proposed DAI+AI architecture achieves the best overall balance between recall, precision, F1-score, detection latency, and false positive rate. The findings indicate that AI can effectively complement traditional infrastructure-level network defenses by providing behavioral awareness and improved sensitivity to attack patterns that are difficult to detect through rule-based inspection alone.

Downloads

Download data is not yet available.

References

[1] C. Surianarayanan, “Integration of the Internet of Things and Cloud: Security Challenges and Solutions – A Review,” International Journal of Cloud Applications and Computing, vol. 13, pp. 1–30, Mar. 2023, doi:10.4018/IJCAC.325624.

[2] H. Fereidouni, O. Fadeitcheva, and M. Zalai, “IoT and Man‐in‐the‐Middle Attacks,” SECURITY AND PRIVACY, vol. 8, no. 2, p. e70016, Mar. 2025, doi: 10.1002/spy2.70016.

[3] D. C. Plummer, “An Ethernet Address Resolution Protocol: Or Converting Network Protocol Addresses to 48.bit Ethernet Address for Transmission on Ethernet Hardware,” Nov. 1982, doi:10.17487/rfc0826.

[4] S. Y. Nam, S. Jurayev, S. S. Kim, K. Choi, and G. S. Choi, “Mitigating ARP poisoning-based man-in-the-middle attacks in wired or wireless LAN,” EURASIP Journal on Wireless Communications and Networking 2012 2012:1, vol. 2012, no. 1, pp. 89-, Mar. 2012, doi: 0.1186/1687-1499-2012-89.

[5] D. Hanna, P. Veeraraghavan, and E. Pardede, “PrECast: An Efficient Crypto-Free Solution for Broadcast-Based Attacks in IPv4 Networks,” Electronics 2018, Vol. 7, Page 65, vol. 7, no. 5, p. 65, May 2018, doi:10.3390/electronics7050065.

[6] Z. Shah and S. Cosgrove, “Mitigating ARP Cache Poisoning Attack in Software-Defined Networking (SDN): A Survey,” Electronics 2019, Vol. 8, Page 1095, vol. 8, no. 10, p. 1095, Sep. 2019, doi:10.3390/electronics8101095.

[7] J. Asharf, N. Moustafa, H. Khurshid, E. Debie, W. Haider, and A. Wahab, “A Review of Intrusion Detection Systems Using Machine and Deep Learning in Internet of Things: Challenges, Solutions and Future Directions,” Electronics 2020, Vol. 9, Page 1177, vol. 9, no. 7, p. 1177, Jul. 2020, doi:10.3390/electronics9071177.

[8] T. Sowmya and E. A. Mary Anita, “A comprehensive review of AI based intrusion detection system,” Measurement: Sensors, vol. 28, p. 100827, Aug. 2023, doi:10.1016/j.measen.2023.100827.

[9] C. Yin, Y. Zhu, J. Fei, and X. He, “A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks,” IEEE Access, vol. 5, pp. 21954–21961, Oct. 2017, doi:10.1109/ACCESS.2017.2762418.

[10] P. Schummer, A. del Rio, J. Serrano, D. Jimenez, G. Sánchez, and Á. Llorente, “Machine Learning-Based Network Anomaly Detection: Design, Implementation, and Evaluation,” AI 2024, Vol. 5, Pages 2967-2983, vol. 5, no. 4, pp. 2967–2983, Dec. 2024, doi:10.3390/ai5040143.

[11] R. Chinnasamy, M. Subramanian, S. V. Easwaramoorthy, and J. Cho, “Deep learning-driven methods for network-based intrusion detection systems: A systematic review,” ICT Express, vol. 11, no. 1, pp. 181–215, Feb. 2025, doi:10.1016/j.icte.2025.01.005.

[12] M. M. Alani, A. I. Awad, and E. Barka, “ARP-PROBE: An ARP spoofing detector for Internet of Things networks using explainable deep learning,” Internet of Things, vol. 23, p. 100861, Oct. 2023, doi:10.1016/j.iot.2023.100861.

[13] K. Sauka, G. Y. Shin, D. W. Kim, and M. M. Han, “Adversarial Robust and Explainable Network Intrusion Detection Systems Based on Deep Learning,” Applied Sciences 2022, Vol. 12, Page 6451, vol. 12, no. 13, p. 6451, Jun. 2022, doi:10.3390/app12136451.

[14] M. Keshk, N. Koroniotis, N. Pham, N. Moustafa, B. Turnbull, and A. Y. Zomaya, “An explainable deep learning-enabled intrusion detection framework in IoT networks,” Inf. Sci. (N. Y)., vol. 639, no. 10, p. 119000, Aug. 2023, doi:10.1016/j.ins.2023.119000.

[15] M. M. Issa, M. Aljanabi, and H. M. Muhialdeen, “Systematic literature review on intrusion detection systems: Research trends, algorithms, methods, datasets, and limitations,” Journal of Intelligent Systems, vol. 33, no. 1, Jan. 2024, doi:10.1515/jisys-2023-0248.

Downloads

Published

17.09.2026

How to Cite

[1]
P. Markova and G. Markov, “AI-ENHANCED DETECTION OF ARP SPOOFING-BASED MAN-IN-THE-MIDDLE ATTACKS IN LOCAL AREA NETWORKS”, SysTechDev, vol. 3, pp. 173–179, Sep. 2026, doi: 10.68302/std2026.vol3.52.