Router Forensic Analysis against Distributed Denial of Service (DDoS) Attacks
Oldy Ray Prayogo, Imam Riadi · International Journal of Computer Applications · 2020
A Distributed Denial of Service (DDoS) attack is a multicomputer attack targeting a single device to increase the amount of network traffic and paralyze the target.The number of DDoS attacks continues to increase and has a more sophisticated variety of attacks so that an effective technique is needed to find out information related to these attacks.This research uses the Network Forensic Generic Process Model which has 8 stages, namely preparation, detection, collection, preservation, examination, analysis, investigation, presentation, and using the live forensic method in the data acquisition process.This research uses the help of tools including Snort, Wireshark, Elasticsearch, Kibana, and Logstash.This research succeeded in obtaining digital evidence containing information related to the attack, namely, there were 5 IP addresses for the attacker, attacks that occurred on port 80 TCP with one target IP address, attacker ID, the total number of attacks totaling 126,286 attack packets and the time of the attack.This research succeeded in obtaining data and information derived from the evidence obtained, from these results it can make it easier to strengthen security at existing points of vulnerability, or as digital evidence in court.