Carbon Black Cloud: How does CBC protect/detect against ARP spoofing/poisoning?
book
Article ID: 288518
calendar_today
Updated On:
Products
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
How does CBC protect/detect against ARP spoofing/poisoning?
Environment
Carbon Black Cloud: All Supported Versions
Resolution
CBC does not detect/protect against ARP spoofing/poisoning. However it can detect malware which is deployed to do such activity based on reputation.
ARP spoofing is usually deployed on one endpoint in order to attack other endpoints. If there's a CB sensor on the attack endpoint, it can detect the malware doing the ARP spoofing. But the CB sensors on the targeted/receiving endpoints, which are having their traffic intercepted by the ARP spoofing host, are not going to know anything is wrong.
If ARP spoofing has been conducted on the Network level, it cannot be detected. It is advised to use high level of encryption when transmitting data, so that attacker cannot intercept it.
Additional Information
On CBC side, we can use the following MITRE TTP's to detect and follow these attacks: https://community.carbonblack.com/t5/Endpoint-Standard-Discussions/Resources-for-Carbon-Black-Cloud-updating-to-MITRE-ATT-amp-CK/m-p/111226/thread-id/9434