Python ARP欺骗检测软件 | 网络安全防护工具
Python ARP欺骗检测软件
本程序是一款使用Python编写的ARP欺骗检测软件,利用scapy库进行网络数据包捕获和分析,能够有效检测ARP欺骗攻击、ICMP flood攻击、TCP攻击等常见的网络攻击行为。
功能介绍
- ARP欺骗攻击检测: 检测目标主机和网关之间是否存在ARP欺骗攻击,并显示攻击源MAC地址。
- ICMP flood攻击检测: 检测网络中是否存在ICMP flood攻击,并记录攻击事件。
- TCP攻击检测: 检测网络中是否存在TCP攻击,并记录攻击事件。
- 攻击源检测: 扫描局域网主机,识别攻击源IP地址和MAC地址,并进行告警。
- 局域网扫描: 扫描局域网内的主机,获取主机IP地址和MAC地址。
- 检测记录查看: 查看攻击检测的记录。
代码实现
import os
import time
import sys
import platform
from scapy.all import *
from tkinter import *
from tkinter import messagebox
from scapy.layers.l2 import Ether
from scapy.layers.l2 import ARP
from scapy.all import srp
# 设置界面
root = Tk()
root.title('ARP欺骗检测软件')
root.geometry('400x300')
# 注册界面
def register():
register_window = Toplevel(root)
register_window.title('注册')
register_window.geometry('300x200')
Label(register_window, text='请输入用户名:').pack()
username = Entry(register_window)
username.pack()
Label(register_window, text='请输入密码:').pack()
password = Entry(register_window, show='*')
password.pack()
def register_confirm():
with open('user.txt', 'a') as f:
f.write(username.get() + ' ' + password.get() + '\n')
messagebox.showinfo('提示', '注册成功!')
register_window.destroy()
Button(register_window, text='确认', command=register_confirm).pack()
# 登录界面
def login():
global login_window
login_window = Toplevel(root)
login_window.title('登录')
login_window.geometry('300x200')
Label(login_window, text='请输入用户名:').pack()
username = Entry(login_window)
username.pack()
Label(login_window, text='请输入密码:').pack()
password = Entry(login_window, show='*')
password.pack()
def login_confirm():
with open('user.txt', 'r') as f:
users = f.readlines()
for user in users:
if user.split()[0] == username.get() and user.split()[1] == password.get():
messagebox.showinfo('提示', '登录成功!')
enter_func() # 登录成功后进入功能页面
return
messagebox.showerror('错误', '用户名或密码错误!')
Button(login_window, text='确认', command=login_confirm).pack()
# ICMP flood攻击检测
def icmp_flood():
sniff_filter = 'icmp and icmp[0]=8'
sniff_timeout = 60
sniff_count = 0
sniff_packets = sniff(filter=sniff_filter, timeout=sniff_timeout,iface='ens33')
if len(sniff_packets) > 100:
messagebox.showwarning('警告', '检测到ICMP flood攻击!')
with open('detection_log.txt', 'a') as f:
f.write('ICMP flood攻击检测 - 检测结果:检测到ICMP flood攻击\n')
else:
messagebox.showinfo('提示', '未检测到ICMP flood攻击!')
with open('detection_log.txt', 'a') as f:
f.write('ICMP flood攻击检测 - 检测结果:未检测到ICMP flood攻击\n')
return
# TCP攻击检测
def tcp_attack():
sniff_filter = 'tcp'
sniff_timeout = 10
sniff_count = 0
sniff_packets = sniff(filter=sniff_filter, timeout=sniff_timeout,iface='ens33')
for packet in sniff_packets:
sniff_count += 1
if sniff_count > 100:
messagebox.showwarning('警告', '检测到TCP攻击!')
with open('detection_log.txt', 'a') as f:
f.write('TCP攻击检测 - 检测结果:检测到TCP攻击\n')
else:
messagebox.showinfo('提示', '未检测到TCP攻击!')
with open('detection_log.txt', 'a') as f:
f.write('TCP攻击检测 - 检测结果:未检测到TCP攻击\n')
return
# ARP欺骗攻击检测
def arp_spoofing():
target_ip = '192.168.197.132' # 目标主机IP地址
target_mac = '' # 目标主机MAC地址
gateway_ip = '192.168.197.2' # 网关IP地址
gateway_mac = '' # 网关MAC地址
# 发送ARP请求获取目标主机MAC地址
arp_request = ARP(pdst=target_ip)
arp_response = sr1(arp_request, timeout=1, verbose=False)
if arp_response:
target_mac = arp_response.hwsrc
# 发送ARP请求获取网关MAC地址
arp_request = ARP(pdst=gateway_ip)
arp_response = sr1(arp_request, timeout=1, verbose=False)
if arp_response:
gateway_mac = arp_response.hwsrc
no_attack_count = 0
# 发送ARP欺骗数据包并监听响应
while True:
# 向目标主机发送ARP欺骗数据包
arp_spoofing_packet = ARP(op=2, pdst=target_ip, hwdst=target_mac, psrc=gateway_ip, hwsrc=gateway_mac)
send(arp_spoofing_packet, verbose=False)
# 向网关发送ARP欺骗数据包
arp_spoofing_packet = ARP(op=2, pdst=gateway_ip, hwdst=gateway_mac, psrc=target_ip, hwsrc=target_mac)
send(arp_spoofing_packet, verbose=False)
# 监听响应并检测是否存在ARP欺骗攻击
sniff_filter = 'arp and (host ' + target_ip + ' or host ' + gateway_ip + ')'
sniff_timeout = 10
sniff_packets = sniff(filter=sniff_filter, timeout=sniff_timeout,count=1)
if len(sniff_packets) == 0:
no_attack_count += 1
if no_attack_count >= 3:
messagebox.showinfo('提示', '未检测到ARP欺骗攻击!')
with open('detection_log.txt', 'a') as f:
f.write('ARP欺骗攻击检测 - 检测结果:未检测到ARP欺骗攻击\n')
return
else:
for packet in sniff_packets:
if packet[ARP].op == 2: # ARP响应数据包
if packet[ARP].psrc == target_ip and packet[ARP].hwsrc != target_mac:
messagebox.showwarning('警告', '检测到ARP欺骗攻击!攻击源MAC地址为' + packet[
ARP].hwsrc + ',目标MAC地址为' + target_mac + ',网关MAC地址为' + gateway_mac)
with open('detection_log.txt', 'a') as f:
f.write('ARP欺骗攻击检测 - 检测结果:检测到ARP欺骗攻击\n')
elif packet[ARP].psrc == gateway_ip and packet[ARP].hwsrc != gateway_mac:
messagebox.showwarning('警告', '检测到ARP欺骗攻击!攻击源MAC地址为' + packet[
ARP].hwsrc + ',目标MAC地址为' + gateway_mac + ',目标MAC地址为' + target_mac)
with open('detection_log.txt', 'a') as f:
f.write('ARP欺骗攻击检测 - 检测结果:检测到ARP欺骗攻击\n')
else:
messagebox.showinfo('提示', '未检测到ARP欺骗攻击!')
with open('detection_log.txt', 'a') as f:
f.write('ARP欺骗攻击检测 - 检测结果:未检测到ARP欺骗攻击\n')
return
# 扫描局域网主机
def scan_network():
network = '192.168.197.0/24'
arp_request = ARP(pdst=network)
broadcast = Ether(dst='ff:ff:ff:ff:ff:ff')
arp_broadcast = broadcast/arp_request
answered_list = srp(arp_broadcast, timeout=1, verbose=False)[0]
clients = []
for element in answered_list:
client = {'ip': element[1].psrc, 'mac': element[1].hwsrc}
clients.append(client)
with open('clients.txt', 'w') as f:
for client in clients:
f.write(client['ip'] + ' ' + client['mac'] + '\n')
messagebox.showinfo('提示', '扫描完成!')
def get_mac(ip):
arp = ARP(pdst=ip)
ether = Ether(dst='ff:ff:ff:ff:ff:ff')
packet = ether/arp
result = srp(packet, timeout=3, verbose=False)[0]
return result[0][1].hwsrc
# 检测攻击源
def detect_attack():
attack_sources = [] # 攻击源列表
with open('clients.txt', 'r') as f:
clients = f.readlines()
for client in clients:
ip = client.split()[0]
mac = get_mac(ip)
sniff_filter = 'arp and src host ' + ip
sniff_timeout = 10
sniff_count = 0
sniff_packets = sniff(filter=sniff_filter, timeout=sniff_timeout)
for packet in sniff_packets:
sniff_count += 1
if packet.haslayer(ARP) and packet[ARP].op == 2: # 判断是否为ARP响应包
src_mac = packet[ARP].hwsrc # 获取源MAC地址
dst_mac = packet[ARP].hwdst # 获取目标MAC地址
if src_mac != get_mac(ip) and src_mac != '00:00:00:00:00:00': # 判断是否存在伪造源MAC地址的情况
messagebox.showwarning('警告',
'检测到伪造源攻击!攻击源IP地址为' + ip + ',MAC地址为' + mac + ',伪造源MAC地址为' + src_mac + '!')
with open('detection_log.txt', 'a') as f:
f.write(
'警告' + '检测到伪造源攻击!攻击源IP地址为' + ip + ',MAC地址为' + mac + ',伪造源MAC地址为' + src_mac + '!\n')
attack_sources.append((ip, mac, src_mac)) # 将攻击源记录到列表中
if sniff_count > 100:
messagebox.showwarning('警告', '检测到攻击源IP地址为' + ip + ',MAC地址为' + mac + '!')
with open('detection_log.txt', 'a') as f:
f.write('警告' + '检测到攻击源IP地址为' + ip + ',MAC地址为' + mac + '!\n')
attack_sources.append((ip, mac, None)) # 将攻击源记录到列表中
else:
with open('detection_log.txt', 'a') as f:
f.write('提示' + '未检测到攻击源!\n')
if not attack_sources: # 如果攻击源列表为空,则表示未检测到攻击源
messagebox.showinfo('提示', '未检测到攻击源!')
return attack_sources # 返回攻击源列表
def view_detection_log():
with open('detection_log.txt', 'r') as f:
detection_log = f.read()
messagebox.showinfo('检测记录', detection_log)
# 创建用户和客户端记录文件
if not os.path.exists('user.txt'):
open('user.txt', 'w').close()
if not os.path.exists('clients.txt'):
open('clients.txt', 'w').close()
# 创建按钮
register_button = Button(root, text='注册', command=register)
register_button.pack(pady=10)
login_button = Button(root, text='登录', command=login)
login_button.pack(pady=10)
def enter_func():
# 关闭登录窗口
login_window.destroy()
# 创建新窗口
func_window = Toplevel(root)
func_window.title('功能页面')
func_window.geometry('400x300')
# 创建四个功能按钮
icmp_flood_button = Button(func_window, text='检测ICMP flood攻击', command=icmp_flood)
icmp_flood_button.pack(pady=10)
tcp_attack_button = Button(func_window, text='检测TCP攻击', command=tcp_attack)
tcp_attack_button.pack(pady=10)
arp_spoofing_button = Button(func_window, text='检测ARP欺骗攻击', command=arp_spoofing)
arp_spoofing_button.pack(pady=10)
detect_attack_button = Button(func_window, text='检测攻击源', command=detect_attack)
detect_attack_button.pack(pady=10)
scan_network_button = Button(func_window, text='扫描局域网主机',command=scan_network)
scan_network_button.pack(pady=10)
view_detection_log_button = Button(func_window, text='查看检测记录', command=view_detection_log)
view_detection_log_button.pack(pady=10)
root.mainloop()
用到什么技术内容:本程序使用了以下技术:
1. Python编程语言
2. tkinter库进行GUI界面设计
3. scapy库进行网络数据包的捕获和分析
4. ARP协议进行ARP欺骗攻击检测
5. ICMP协议进行ICMP flood攻击检测
6. TCP协议进行TCP攻击检测
7. 文件操作进行用户信息和客户端记录的存储和读取
使用说明
- 确保你的系统安装了Python、tkinter、scapy库。
- 运行代码,程序会启动GUI界面。
- 点击“注册”按钮,输入用户名和密码进行注册。
- 点击“登录”按钮,输入用户名和密码进行登录。
- 登录成功后,会进入功能页面。
- 选择需要执行的功能,例如“检测ARP欺骗攻击”、“检测ICMP flood攻击”等。
- 程序会根据选择的功能进行检测,并将结果显示在界面上。
注意事项
- 代码中的
ens33为网卡名称,请根据实际情况修改。 - 运行程序需要管理员权限。
- 程序会记录攻击检测的日志,保存在
detection_log.txt文件中。
总结
本程序能够有效检测常见的网络攻击行为,为网络安全提供一定的保障。当然,这只是一个简单的示例程序,实际应用中需要根据具体的需求进行改进和扩展。
原文地址: https://www.cveoy.top/t/topic/jomb 著作权归作者所有。请勿转载和采集!