查看交换机日志,有这种信息是代表被ARP攻击了吗?怎么溯源处理呀,求大神指教!!!
Sec 24 01:20:49 IP ARP: 192.168.0.120 moved from 90:b1:1c:24:4e:23 to 90:b1:1c:26:02:c8
Sec 24 01:20:48 IP ARP: 192.168.0.120 moved from d0:67:e5:ec:55:b9 to 90:b1:1c:24:4e:23
Sec 24 01:20:47 IP ARP: 192.168.0.120 moved from 90:b1:1c:24:4f:fb to d0:67:e5:ec:55:b9
Sec 24 01:20:45 IP ARP: 192.168.0.120 moved from 00:26:b9:8d:c5:c3 to 90:b1:1c:24:4f:fb
Sec 24 01:20:43 IP ARP: 192.168.0.120 moved from 90:b1:1c:25:fb:30 to 00:26:b9:8d:c5:c3
Sec 24 01:20:38 IP ARP: 192.168.0.120 moved from 90:b1:1c:26:03:d0 to 90:b1:1c:25:fb:30
Sec 24 01:20:38 IP ARP: 192.168.0.120 moved from 00:26:b9:8d:c5:d2 to 90:b1:1c:26:03:d0
Sec 24 01:20:36 IP ARP: 192.168.0.120 moved from 90:b1:1c:25:f6:1e to 00:26:b9:8d:c5:d2
Sec 24 01:20:26 IP ARP: 192.168.0.120 moved from 90:b1:1c:26:02:c8 to 90:b1:1c:25:f6:1e