ARP spoofing (ARP cache poisoning)
A local-network attack in which forged ARP replies bind the attacker's MAC address to another host's IP address, so traffic meant for that host passes through the attacker.
ARP spoofing, also called ARP cache poisoning, abuses the lack of authentication in the Address Resolution Protocol. An attacker on the same local segment sends forged ARP replies claiming that a chosen IP address, commonly the default gateway’s, belongs to the attacker’s MAC address. Victims commonly update their caches without any check and from then on send frames for that address to the attacker. If the attacker also poisons the gateway’s entry for the victim, traffic in both directions passes through the attacker: a man-in-the-middle attack. Forwarding the traffic keeps the victim unaware; dropping it turns the attack into a denial of service.
The attack is local. ARP does not cross a router, so the attacker needs a foothold on the same layer 2 segment, and the defences sit there too: dynamic ARP inspection on the switch, which checks ARP messages against trusted address bindings; static entries for critical hosts; network access control to keep unknown devices off the segment; and encryption such as TLS, which limits what an interceptor in the path can read or change.
Exam relevance: a scenario is likely to describe a gateway whose MAC address has suddenly changed in users’ caches, or traffic unexpectedly flowing through another workstation. Candidates are expected to recognise ARP poisoning and to know that it is confined to the local segment.