4

Wireshark detect highly suspicious network activity on my system. As you can see in the attached screen capture, broadcast traffic repeatedly sends weird packet information and suspicious requests, such as:

[TCP retransmission] [TCP spurious retransmission] [TCP fast retransmission] 443 > 449560 [RST, ACK] [TCP out-of-order]

enter image description here

enter image description here

In addition to Wireshark, I installed xARP software, and it consistently sends me alerts regarding potential ARP attacks, like:

"DirectedRequestFilter: targeted request. destination mac of arp request not set to broadcast/invalid address"

I am new to Wireshark. Could anyone help me to decipher this traffic activity and tell me if it's indication of ARP spoofing attack? And, what can I do to prevent it?

HelpDesk
  • 59
  • 3

0 Answers0