Research Article

Analysis of Phishing Attacks on Ecommerce Services using National Institute of Standards and Technology Method

by  Dio Andrean, Imam Riadi
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 122
Published: July 2026
Authors: Dio Andrean, Imam Riadi
10.5120/ijcaf00270018320
PDF

Dio Andrean, Imam Riadi . Analysis of Phishing Attacks on Ecommerce Services using National Institute of Standards and Technology Method. International Journal of Computer Applications. 187, 122 (July 2026), 63-70. DOI=10.5120/ijcaf00270018320

                        @article{ 10.5120/ijcaf00270018320,
                        author  = { Dio Andrean,Imam Riadi },
                        title   = { Analysis of Phishing Attacks on Ecommerce Services using National Institute of Standards and Technology Method },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 122 },
                        pages   = { 63-70 },
                        doi     = { 10.5120/ijcaf00270018320 },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Dio Andrean
                        %A Imam Riadi
                        %T Analysis of Phishing Attacks on Ecommerce Services using National Institute of Standards and Technology Method%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 122
                        %P 63-70
                        %R 10.5120/ijcaf00270018320
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

The rapid growth of e-commerce has increased the risk of phishing attacks targeting users' sensitive information. This study aims to analyze phishing attacks on e-commerce services using the National Institute of Standards and Technology (NIST) digital forensic methodology. The investigation was conducted through the collection, examination, analysis, and reporting phases. A phishing attack scenario was simulated by sending phishing emails containing links to a fake login website. Network traffic was captured using Wireshark and analyzed using .pcapng files and sslkeylog.log to identify digital evidence from encrypted HTTPS communications. The investigation successfully identified the phishing domain (soppieeeee.free.nf), server IP address (185.27.134.228), TCP and TLS handshake activities, HTTP POST requests, and the victim's transmitted login credentials. The integrity of the collected evidence was verified using MD5 hash values. The results demonstrate that the NIST methodology, combined with Wireshark, provides a systematic and effective approach for collecting, examining, analyzing, and reporting digital evidence related to phishing attacks on e-commerce services.

References
  • H. Irawan, A. H. Muhammad, and A. Nasiri, “Design of Cybersecurity Maturity Assessment Framework Using NIST CSF v1.1 and CIS Controls v8,” vol. 9, no. 1, p. 2024.
  • Isaac Dawandakpoye Ohwosoro, “A Filter-Based Feature Selection for Robust Phishing Attack Detection using XGBoost,” International Journal of Advanced Research in Science, Communication and Technology, pp. 558–571, Aug. 2024, doi: 10.48175/ijarsct-19372.
  • P. H. Hussan and S. M. Mangj, “BERTPHIURL: A Teacher-Student Learning Approach Using DistilRoBERTa and RoBERTa for Detecting Phishing Cyber URLs,” Journal of Future Artificial Intelligence and Technologies, vol. 1, no. 4, pp. 417–428, Feb. 2025, doi: 10.62411/faith.3048-3719-71.
  • T. R. Karin, R. R. Sani, F. Alzami, and A. Rohmani, “Enhancing Bank Customer Protection Against Phishing Attacks Through Xgboost-Based Feature Analysis,” Transmisi: Jurnal Ilmiah Teknik Elektro, vol. 26, no. 3, pp. 114–121, Jul. 2024, doi: 10.14710/transmisi.26.3.114-121.
  • F. Ferdynandus, J. Natu Prihanto, and W. Winarno, “Implementing NIST Framework and the People, Process, Technology approach in Indonesian Financial Services,” International Journal of Engineering Continuity, vol. 3, no. 1, pp. 172–182, Jul. 2024, doi: 10.58291/ijec.v3i1.265.
  • I. Riadi, R. Umar, and M. I. Syahib, “Akuisisi Bukti Digital Viber Messenger Android Menggunakan Metode National Institute of Standards and Technology (NIST),” Jurnal RESTI, vol. 5, no. 1, pp. 45–54, Feb. 2021, doi: 10.29207/resti.v5i1.2626.
  • A. Wijayanto, I. Riadi, and Y. Prayudi, “TAARA Method to Processing on the Network Forensics in the Event of an ARP Spoofing Attack,” Jurnal RESTI, vol. 7, no. 2, pp. 208–217, Apr. 2023, doi: 10.29207/resti.v7i2.4589.
  • R. Hidayat and N. Anwar, “Forensic Analysis Of Web Phishing And Social Engineering Using The National Institute Of Standards And Technology Method Case Study Of Facebook Account Data Theft,” Journal of Digital Security and Forensics, vol. 1, no. 1, Jul. 2024, doi: 10.29121/digisecforensics.v1.i1.2024.14.
  • A. Wibowo Noor Fikri et al., “Analisis Keamanan Sistem Operasi dalam Menghadapi Ancaman Phishing dalam Layanan Online Banking,” Jurnal Ilmu Multidisplin, vol. 2, no. 1, pp. 84–91, Jun. 2023, doi: 10.38035/jim.v2i1.228.
  • M. A. H Nasution and J. D. Santoso, “Analysis of Community Awareness Against Threats to Personal Data Security Through Phishing Websites,” The IJICS (International Journal of Informatics and Computer Science), vol. 5, no. 2, p. 102, Aug. 2021, doi: 10.30865/ijics.v5i2.3053.
  • D. Wina et al., “The Importance of Security Awareness in Combating Phishing Attacks: A Case Study of Bank Rakyat Indonesia Article Info ABSTRACT,” Journal of Social Sciences and Humanities, vol. 14, no. 3, 2024.
  • R. Hanipah and H. Dhika, “Analisa Pencegahan Aktivitas Ilegal Didalam Jaringan Dengan Wireshark,” Journal of Computer and Information Technology, vol. 4, no. 1, 2020, [Online]. Available: http://e-journal.unipma.ac.id/index.php/doubleclickTelepon:
  • A. Nofiyan, “Analisis Forensik pada Web Phishing Menggunakan Metode National Institute of Standards and Technology,” CYBERNETICS, vol. 4, no. 02, pp. 79–92, 2020, [Online]. Available: https://centralops.net
  • G. Nurmansyah, G. Arya, B. Wiranata, A. I. Fardiansyah, and S. V. Mladenov, “Preventing AI-based phishing crimes across national borders through the reconstruction of personal data protection laws,” Nurmansyah, vol. 15, no. 2, pp. 286–311, 2024, [Online]. Available: http://www.apwg.org.
  • I. Ainur Rafiq, I. Riadi, F. Teknologi Industri, and U. Ahmad Dahlan, “Perbandingan Forensic Tools pada Instagram Menggunakan Metode NIST,” MEI, 2022.
  • R. Andhika Surya, F. Ridho, and D. T. Yuwono, “Analisis Bibliometrik Menggunakan Vosviewer Terhadap Trend Digital Forensik Pada Saat Pemilu Indonesia The Bibliometric Analysis Using VOSviewer on Digital Forensics Trends During the Indonesian Election,” 2024. [Online]. Available: http://journal.umpalangkaraya.ac.id/index.php/pencerah
  • M. Nadhif Hermanto, “Analisis Forensic Berbasis Web Phising Menggunakan Metode National Institute Of Standards And Technology,” Cipta Cendikia Kotabumi Jurnal informasi dan Komputer, vol. 11, no. 1, p. 2023, 2023.
  • R. Adiputera Tangahu, A. Bode, M. Kom, and S. Taliki, “Analisa Kualitas Layanan Jaringan Internet Pada Wireless Lan Menggunakan Metode Qos (Quality Of Service) (Studi kasus : Kedai Mako),” Jurnal Ilmiah Ilmu Komputer Banthayo Lo Komputer, vol. 3, no. 1, 2024.
  • S. Keputusan Dirjen Penguatan Riset dan Pengembangan Ristek Dikti, I. Riadi, N. Hamida Siregar, P. Studi Sistem Informasi, F. Sains dan Teknologi Terapan, and U. Ahmad Dahlan, “Terakreditasi SINTA Peringkat 4 Forensik Mobile Pada Kasus Cyber Fraud Layanan Signal Messenger Menggunakan Metode NIST,” 2018.
  • I. Riadi, F. Tella, S. Informasi, F. Sains dan Teknologi Terapan, and U. Ahmad Dahlan, “Analisis Forensik pada Email Menggunakan Metode National Institute of Standards Technology,” MEI, 2022.
  • R. Nur, R. Pusdiklat, B. Siber, and S. Negara, “Cendekia Niaga Journal of Trade Development and Studies Upaya Membangun Kesadaran Keamanan Siber pada Konsumen E-commerce di Indonesia,” 2022.
  • A. E. Saragih, N. Christian, and P. Khoirunisa, “Media Hukum Indonesia (MHI) Analisis Penggunaan Barang Bukti Digital di Dalam Sistem Hukum di Indonesia (Studi Kasus Putusan Nomor 3 K/PID.SUS/2019),” vol. 2, no. 2, p. 504, 2024, doi: 10.5281/zenodo.12082755.
  • I. Ainur Rafiq, I. Riadi, F. Teknologi Industri, and U. Ahmad Dahlan, “Perbandingan Forensic Tools pada Instagram Menggunakan Metode NIST,” MEI, 2022.
  • Shinta Widhaningroem and Yeni Widowaty, “Digital Evidence Tracing in the Investigation of Identity Theft in the E-Commerce Era,” Formosa Journal of Social Sciences (FJSS), vol. 3, no. 2, pp. 287–300, Jun. 2024, doi: 10.55927/fjss.v3i2.9797.
  • K. Sarpong Adu-Manu, R. Kwasi Ahiable, J. Kwame Appati, and E. Essel Mensah, “Phishing Attacks in Social Engineering: A Review,” Journal of Cyber Security, vol. 4, no. 4, pp. 239–267, 2022, doi: 10.32604/jcs.2023.041095.
  • E. W. Tyas Darmaningrat et al., “Sosialisasi Bahaya dan Upaya Pencegahan Social Engineering untuk Meningkatkan Kesadaran Masyarakat tentang Keamanan Informasi,” Sewagati, vol. 6, no. 2, Feb. 2022, doi: 10.12962/j26139960.v6i2.92.
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

E-commerce Digital Forensics NIST Phishing Wireshark

Powered by PhDFocusTM