IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: How does CBC protect/detect against ARP spoofing/poisoning?

Carbon Black Cloud: How does CBC protect/detect against ARP spoofing/poisoning?

Environment

  • Carbon Black Cloud: All Supported Versions

Question

How does CBC protect/detect against ARP spoofing/poisoning?

Answer

  • CBC does not detect/protect against ARP spoofing/poisoning. However it can detect malware which is deployed to do such activity based on reputation.
  • ARP spoofing is usually deployed on one endpoint in order to attack other endpoints. If there's a CB sensor on the attack endpoint, it can detect the malware doing the ARP spoofing. But the CB sensors on the targeted/receiving endpoints, which are having their traffic intercepted by the ARP spoofing host, are not going to know anything is wrong.
  • If ARP spoofing has been conducted on the Network level, it cannot be detected. It is advised to use high level of encryption when transmitting data, so that attacker cannot intercept it.



 

Additional Notes

On CBC side, we can use the following MITRE TTP's to detect and follow these attacks:
Cb Connect Sessions & Presentation Material
 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎06-28-2022
Views:
410
Contributors