Research Article

Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method

by  Muhammad Fauzan Taufiqurrahman, Imam Riadi
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 122
Published: July 2026
Authors: Muhammad Fauzan Taufiqurrahman, Imam Riadi
10.5120/ijca3f7bffcd3699
PDF

Muhammad Fauzan Taufiqurrahman, Imam Riadi . Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method. International Journal of Computer Applications. 187, 122 (July 2026), 47-54. DOI=10.5120/ijca3f7bffcd3699

                        @article{ 10.5120/ijca3f7bffcd3699,
                        author  = { Muhammad Fauzan Taufiqurrahman,Imam Riadi },
                        title   = { Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 122 },
                        pages   = { 47-54 },
                        doi     = { 10.5120/ijca3f7bffcd3699 },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Muhammad Fauzan Taufiqurrahman
                        %A Imam Riadi
                        %T Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 122
                        %P 47-54
                        %R 10.5120/ijca3f7bffcd3699
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

This research analyzes Distributed Denial of Service (DDoS) attacks of the UDP Flood type on a Linux-based server using a live forensic approach, conducted in a closed network environment with a Linux server as the target and a client as the attacker using Low Orbit Ion Cannon (LOIC). Evidence acquisition was performed using tcpdump in .pcap format, and the captured data was analyzed using Wireshark based on the NIST method stages: collection, examination, analysis, and reporting. The analysis parameters included protocol type, source and destination IP addresses, destination port, packet size, packet rate, time interval, and traffic distribution pattern. The results showed that 2,046,672 packets were captured in approximately 26 seconds, with average rate of 78,015 packets per second. The traffic was dominated by small UDP packets of 62 bytes, transmitted massively, repeatedly, and directly toward the target server, indicating the characteristics of a UDP Flood attack. Recommended mitigation strategies include filtering UDP traffic using iptables, restricting port access, and conducting regular network monitoring. This research demonstrates that live forensic analysis based on the NIST framework is effective for systematically identifying and analyzing UDP Flood attacks.

References
  • M. Adam, E. I. Alwi, and I. As’ad, “Analisis Forensik terhadap Serangan DDoS Ping of Death pada Server,” 2022.
  • A. A. R. Nisa, A. D. Wijayanto, A. P. J. Priana, and A. Setiawan, “Analisis Log Server untuk mendeteksi Serang DDoS pada Keamaan Jaringan di Website,” J. Internet Softw. Eng., vol. 1, no. 3, p. 17, 2024, doi: 10.47134/pjise.v1i3.2612.
  • A. Nurudin and I. Mubariq, “Intrusion Prevention System to Protect Dos Attack,” vol. 2, no. 1, pp. 49–59, 2024, doi: 10.62885/improsci.v2i1.441.
  • A. R. P. Anisa, “Literature Review Jurnal Memahami Faktor-Faktor Yang Mempengaruhi Popularitas Windows Dibandingkan Linux,” Jamastika, vol. 3, no. April, pp. 28–33, 2024.
  • H. Alfidzar and B. P. Zen, “Implementasi HoneyPy Dengan Malicious Traffic Detection System (Maltrail) Menggunakan Analisis Deskriptif Guna Untuk Mendeteksi Serangan DDOS Pada Server,” J. Informatics, Inf. Syst. Softw. Eng. Appl., vol. 4, no. 2, pp. 32–45, 2022, doi: 10.20895/inista.v4i2.534.
  • M. M. Shafi, A. H. Lashkari, V. Rodriguez, and R. Nevo, “Toward Generating a New Cloud-Based Distributed Denial of Service (DDoS) Dataset and Cloud Intrusion Traffic Characterization,” Inf., vol. 15, no. 4, 2024, doi: 10.3390/info15040195.
  • A. H. Jatmika and A. Zubaidi, “Analisis Perbandingan Performa Mode Trafik Tcp Dan Udp Menggunakan Protokol Routing Aodv Dan Dsr Pada Jaringan Manet(Comparisonal Analysis of TCP And UDP Traffic Mode Performance Using AODV And DSR Routing Protocols On Manet Networks),” J. Teknol. Informasi, Komput. dan Apl., vol. 4, no. 1, pp. 21–26, 2022.
  • W. Warcita, “Deteksi Serangan DDoS UDP Flood pada Jaringan IoT Menggunakan Recurrent Neural Network (RNN),” no. 2504, pp. 1–9, 2024.
  • F. Nova, M. D. Pratama, and D. Prayama, “Wazuh sebagai Log Event Management dan Deteksi Celah Keamanan pada Server dari Serangan Dos,” JITSI J. Ilm. Teknol. Sist. Inf., vol. 3, no. 1, pp. 1–7, 2022, doi: 10.30630/jitsi.3.1.59.
  • K. F. I. Ilham, E. I. Alwi, and F. Fattah, “Penerapan dan Analisis Network Security Snort Menggunakan Intrusion Detection System pada Serangan UDP Flood,” INFORMAL Informatics J., vol. 8, no. 1, p. 94, 2023, doi: 10.19184/isj.v8i1.34003.
  • H. W. Aripradono, “JTIM : Jurnal Teknologi Informasi dan Multimedia Perbandingan Support Vector Machine, Random Forest Classi- fier, dan K-Nearest Neighbour dalam Pendeteksian Anomali,” vol. 7, no. 1, pp. 23–33, 2025.
  • W. Haniyah, M. C. Hidayat, Z. F. I. Putra, V. A. Pertama, and A. Setiawan, “Simulasi Serangan Denial of Service (DoS) menggunakan Hping3 melalui Kali Linux,” J. Internet Softw. Eng., vol. 1, no. 2, p. 8, 2024, doi: 10.47134/pjise.v1i2.2654.
  • W. Y. Sulistyo, S. A. Pratiwi, M. Haedar, and Z. Hidayatullah, “Analisis Forensik Citra di Platform X Menggunakan Metode Digital Forensic Research Workshop (DFRWS),” vol. 8, pp. 10–20, 2025.
  • A. M. Kurniawan, D. G. Purnama, and B. Al Ghiffari, “Analisis Keamanan Jaringan Pada Rumah Menggunakan Metode Nist,” JATI (Jurnal Mhs. Tek. Inform., vol. 8, no. 2, pp. 1659–1664, 2024, doi: 10.36040/jati.v8i2.9071.
  • A. Syahputra, Y. Yuhandri, and S. Arlis, “Jurnal KomtekInfo Penerapan Metode Live Forensik untuk Analisis Serangan DoS pada Router Mikrotik,” vol. 11, no. 4, pp.247–255, 2024, doi: 10.35134/komtekinfo.v11i4.
  • M. Ilman Aqilaa, D. Firdaus, and N. Naofal, “Identifikasi Serangan Lowrate Distributed Denial Of Services Dalam Jaringan Dengan Menggunakan Algoritma Adaboost,” Simpatik J. Sist. Inf. dan Inform., vol. 3, no. 1, pp. 34–41, 2023, doi: 10.31294/simpatik.v3i1.1829.
  • S. E. Prasetyo, H. Haeruddin, and K. Ariesryo, “Website Security System from Denial of Service attacks, SQL Injection, Cross Site Scripting using Web Application Firewall,” Antivirus J. Ilm. Tek. Inform., vol. 18, no. 1, pp. 27–36, 2024, doi: 10.35457/antivirus.v18i1.3339.
  • S. R. N. Suwaryo, I. Nawangsih, “Deteksi Serangan Pada Intrusion Detection System ( Ids ) Untuk Klasifikasi Serangan Dengan Algoritma Naïve Bayes, C.45 Dan K-Nn Dalam Meminimalisasi Resiko Terhadap Pengguna,” 2021.
  • D. R. Anggraeni and M. Salsabila, “Analisis Yuridis Peran Digital Forensik Dalam Pembuktian Tindak Pidana di Indonesia,” Media Huk. Indones., vol. 2, no. 2, pp. 593–600, 2024.
  • R. J. A. Saputra, “Analisis Sistem Inventori dengan Metode National Institute of Standards and Technology NIST Studi Kasus Lotte Mart Grosir Palembang,” 2023, [Online]. Available: http://repository.binadarma.ac.id/id/eprint/9263
  • O. Aljumaiah, W. Jiang, S. R. Addula, and M. A. Almaiah, “Analyzing Cybersecurity Risks and Threats in IT Infrastructure based on NIST Framework,” vol. 2025, no. 2, 2025.
  • M. R. H. Tambunan and S. N. Neyman, “Implementasi Firewall pada Linux untuk Pencegahan Dari Serangan DoS,” J. Technol. Syst. Inf., vol. 1, no. 4, p. 10, 2024, doi: 10.47134/jtsi.v1i4.2648.
  • A. B. Pratomo, “Pengembangan Sistem Firewall Pada Jaringan Komputer Berbasis Mikrotik Routeros,” Bull. Netw. Eng. Informatics, vol. 1, no. 2, p. 51, 2023, doi: 10.59688/bufnets.v1i2.10.
  • M. Syaffiq, A. Malek, and A. R. Amran, “A Study of Packet Sniffing as an Imperative Security Solution in Cybersecurity,” J. Eng. Technol., vol. 9, no. 1, pp. 96–101, 2021.
  • W. Yunanri, “Analisis Serangan Botnet pada Website Aplikasi Facebook dengan Menggunakan Metode National Institute of Standards and Technology (NIST),” vol. 6, no. 2, 2024.
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

Distributed Denial of Service Forensics Digital NIST UDP Flood

Powered by PhDFocusTM