Virtual local area network over HTTP for launching an insider attack
Yuksel Arslan

TL;DR
This paper reveals a novel insider attack method that exploits unused IP addresses and HTTP to covertly expose a LAN to the Internet, bypassing traditional security defenses.
Contribution
It introduces a new technique demonstrating how external attackers can leverage internal network vulnerabilities via HTTP to launch insider attacks.
Findings
External attacker can access LAN through unused IP addresses.
HTTP can be exploited to bypass firewalls and IDS.
Significant internal security vulnerabilities are exposed.
Abstract
Computers and computer networks have become integral to virtually every aspect of modern life, with the Internet playing an indispensable role. Organizations, businesses, and individuals now store vast amounts of proprietary, confidential, and personal data digitally. As such, ensuring the security of this data from unauthorized access is critical. Common security measures, such as firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and antivirus software, are constantly evolving to safeguard computer systems and networks. However, these tools primarily focus on defending against external threats, leaving systems vulnerable to insider attacks. Security solutions designed to mitigate risks originating from within the organization are relatively limited and often ineffective. This paper demonstrates how a Local Area Network (LAN) can be covertly exposed to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsIPv6, Mobility, Handover, Networks, Security · Network Security and Intrusion Detection · Information and Cyber Security
