This paper demonstrates the effectiveness of the method for determining spoofed MAC Addresses by extracting a fingerprint of constant traffic to specific IP destinations. This method, called DTF (Destination Traffic Fingerprint), was described in detail by the authors [8]. This paper presents results of the DTF method in a software tool called NetDTF, which is able to capture traffic in real time and analyze the MAC addresses of network stations based on fingerprints taken for each one of them.
Published in:
Computational Cybernetics and Technical Informatics (ICCC-CONTI), 2010 International Joint Conference on
Date of Conference: 27-29 May 2010