|
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
|
| Volume 187 - Issue 122 |
| Published: July 2026 |
| Authors: Muhammad Fauzan Taufiqurrahman, Imam Riadi |
10.5120/ijca3f7bffcd3699
|
Muhammad Fauzan Taufiqurrahman, Imam Riadi . Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method. International Journal of Computer Applications. 187, 122 (July 2026), 47-54. DOI=10.5120/ijca3f7bffcd3699
@article{ 10.5120/ijca3f7bffcd3699,
author = { Muhammad Fauzan Taufiqurrahman,Imam Riadi },
title = { Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method },
journal = { International Journal of Computer Applications },
year = { 2026 },
volume = { 187 },
number = { 122 },
pages = { 47-54 },
doi = { 10.5120/ijca3f7bffcd3699 },
publisher = { Foundation of Computer Science (FCS), NY, USA }
}
%0 Journal Article
%D 2026
%A Muhammad Fauzan Taufiqurrahman
%A Imam Riadi
%T Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method%T
%J International Journal of Computer Applications
%V 187
%N 122
%P 47-54
%R 10.5120/ijca3f7bffcd3699
%I Foundation of Computer Science (FCS), NY, USA
This research analyzes Distributed Denial of Service (DDoS) attacks of the UDP Flood type on a Linux-based server using a live forensic approach, conducted in a closed network environment with a Linux server as the target and a client as the attacker using Low Orbit Ion Cannon (LOIC). Evidence acquisition was performed using tcpdump in .pcap format, and the captured data was analyzed using Wireshark based on the NIST method stages: collection, examination, analysis, and reporting. The analysis parameters included protocol type, source and destination IP addresses, destination port, packet size, packet rate, time interval, and traffic distribution pattern. The results showed that 2,046,672 packets were captured in approximately 26 seconds, with average rate of 78,015 packets per second. The traffic was dominated by small UDP packets of 62 bytes, transmitted massively, repeatedly, and directly toward the target server, indicating the characteristics of a UDP Flood attack. Recommended mitigation strategies include filtering UDP traffic using iptables, restricting port access, and conducting regular network monitoring. This research demonstrates that live forensic analysis based on the NIST framework is effective for systematically identifying and analyzing UDP Flood attacks.