ARP viruses are also called ARP Address Spoofing viruses, which are a special type of viruses. This virus is generally a trojan that does not have the characteristics of active transmission and does not replicate itself. However, due to its attack, it will send forged ARP packets to the whole network, seriously interfering with the normal operation of the entire network, the harm is even more serious than some worms.
When an ARP virus attack occurs, the network is usually disconnected, but the network connection is normal. Some computers in the Intranet cannot access the Internet, or all computers cannot access the Internet, the failure to open or open a webpage is slow, the LAN connection is interrupted, and the network speed is slow, which seriously affects the normal operation of the enterprise network, Internet cafe, campus network and other LAN.
The following six steps can effectively prevent ARP viruses:
1, do a good job of IP-MAC Address binding (will be bound to the IP address and hardware identification address), in the switch and client must be bound, this is a good way to make the LAN immune ARP virus intrusion.
2, the whole network of all computers are installed with MS06-014 and MS07-017 these two patches, this can be immune to the vast majority of Web Trojans, to prevent browsing the Web page when the virus. MS06-014 Chinese Version system patch: http://www.microsoft.com/china/technet/security/bulletin/MS06-014.mspxMS07-017 Chinese Version system patch: http://www.microsoft.com/china/technet/security/bulletin/MS07-017.mspx