Method to Uncover IP Spoofing Attack On Network Forensics Using NFAT And IP Correlation As Combined Approach

Suryo Pranoto Utomo, Bayu Pramudiono, Andika Muharram · 2019 International Conference on Information and Communications Technology (ICOIACT) · 2019

The attack on the government system has risen following electronic government implementation. One of the cases is an attack on Indonesian General Election's tabulation system. The impact of the offense is decreasing on the government's public image. The attack on the system is using IP Spoofing to cover the digital track of the assailant. IP spoofing has become infamous for a technique to avoid trace from law enforcer agency. This is because the IP address which has been used by the perpetrators usually using a foreign IP address. The law enforcer agency sees this as a problem since the IP address is outside their jurisdiction.There is already previous research to address this issue such as NFAT, strategy (Packet Probability Marking) and method approach (Dempster-Shafer Theory) and use of the algorithm (PAS with bloom filter). This paper will propose a method to uncover the IP spoofing attack by combining a network forensic analysis tool, IP correlation technique, and previous research to create a model prototype. The model will inherit strength and benefit from previous research that included in the proposed model prototype.

Read the paper · More papers on PaperTik