Experimental Analysis of UDP Flood DDoS Attacks Using Network Forensic Methods
DOI:
https://doi.org/10.69616/mcs.v3i1.274Keywords:
Network Forensics, DDoS, Anomaly Detection, Attack Reconstruction, WiresharkAbstract
In the ever-evolving digital era, computer networks have become the backbone of various information and communication systems. However, increased network usage has also led to increased security threats, such as Distributed Denial of Service (DDoS) attacks, ARP Spoofing, and other attacks. To address these threats, an approach capable of detecting, analyzing, and recovering networks from cyberattacks is needed. This study aims to analyze DDoS attacks using network forensics methods with an anomaly identification and attack reconstruction approach. This process includes collection, examination, analysis, and reporting stages using tools such as Wireshark and Winbox. Attack simulations were conducted using the LOIC application on a MikroTik router. The analysis results showed that the DDoS attack caused a CPU spike of up to 100%, which made the router unresponsive. Wireshark successfully identified the attack pattern in the form of UDP packet flooding, while Winbox showed a direct impact on device performance. The anomaly identification technique proved effective in detecting traffic spikes, and the reconstruction process helped understand the chronology and methods of the attack. This research contributes to the understanding and mitigation of cyber attacks through a network forensics approach, as well as being a guide in the implementation of security systems based on anomaly identification and attack reconstruction.
References
M. Na’im and A. Jum’ah, “Analisa Keamanan Dan Hukum Untuk Pelindungan Data Privasi,” CyberSecurity dan Forensik Digital, vol. 1, no. 2, pp. 39–44, 2018, https://doi.org/10.14421/csecurity.2018.1.2.1370.
A. Milenius, D. Marly, W . Ardiyasa, and W. K. Utama, “Analisis Keamanan Jaringan Dengan Menggunakan Metode Penetration Testing (Studi Kasus ITB STIKOM Bali),” Prosiding Seminar Hasil Penelitian Informatika dan Komputer 2025, vol. 2, no. 1, p. 2025, 2025.
M. Adam, E. I. Alwi, and I. As’ad, “Analisis Forensik Terhadap Serangan Ddos Ping Of Death Pada Server,” 2022.
W. Agustiono, D. Wulan Suci, and N. Prastiti, “Analisis Forensik Digital Menggunakan Metode NIST untuk Memulihkan Barang Bukti yang Dihapus Digital Forensic Analysis Using the NIST Method for Recovering Deleted Evidence,” Jurnal Teknologi dan Informasi (JATI), vol. 14, 2024, https://doi.org/10.34010/jati.v14i2.
M. I. Aqilaa, D. Firdaus, and N. Naofal, “Identifikasi Serangan Lowrate Distributed Denial Of Services Dalam Jaringan Dengan Menggunakan Algoritma Adaboost,” Simpatik: Jurnal Sistem Informasi dan Informatika, 2023, [Online]. Available: https://api.semanticscholar.org/CorpusID:259552303
Akamai, “Application Security Research Report 2024 Download | Akamai,” 2024.
I. Riadi et al., “Analisis Forensik Bukti Digital Pada Frozen Solid State Drive Dengan Metode National Institute Of Standards And Technology (NIST),” Jurnal Insand Comtech, vol. 2, no. 2, 2017.
A. R. Supriyono, B. Sugiantoro, and Y. Prayudi, “Eksplorasi Bukti Digital Pada Smart Router Menggunakan Metode Live Forensics,” Jurnal Infotekmesin, vol. 10, no. 02, 2019, https://doi.org/10.35970/infotekmesin.v10i2.48.
R. H. W. Murti, I. Riadi, N. Anwar, and T. Ismail, “Forensik Jaringan Terhadap Serangan DDOS Menggunakan Metode Network Forensic Development Life Cycle,” JSTIE (Jurnal Sarjana Teknik Informatika) (E-Journal), vol. 11, no. 3, p. 107, Oct. 2023, https://doi.org/10.12928/jstie.v11i3.26544.
I. G. N. A. W. Sucipta I Made Widhi; Muliantara, Agus, “ANALISIS KINERJA ANOMALY-BASED INTRUSION DETECTION SYSTEM (IDS) DALAM MENDETEKSI SERANGAN DOS (DENIAL OF SERVICES) PADA JARINGAN KOMPUTER,” JELIKU (Jurnal Elektron. Ilmu Komput. Udayana), no. Volume 1 No 2-Nopember 2012, pp. 8–13, 2012, [Online]. Available: https://ojs.unud.ac.id/index.php/JLK/article/view/4894/3677.
E. Muhati and D. Rawat, “Data-Driven Network Anomaly Detection with Cyber Attack and Defense Visualization,” Journal of Cybersecurity and Privacy, vol. 4, no. 2, pp. 241–263, Jun. 2024, https://doi.org/10.3390/jcp4020012.
M. Ahmed, A. Naser Mahmood, and J. Hu, “A survey of network anomaly detection techniques,” Journal of Network and Computer Applications, vol. 60, pp. 19–31, 2016, https://doi.org/10.1016/j.jnca.2015.11.016.
Published
Issue
Section
Copyright (c) 2026 Muhammad Na'im Al Jum'ah, Mustamin Mustamin

This work is licensed under a Creative Commons Attribution 4.0 International License.











