Experimental Analysis of UDP Flood DDoS Attacks Using Network Forensic Methods
Abstract
In the ever-evolving digital era, computer networks have become the backbone of various information and communication systems. However, increased network usage has also led to increased security threats, such as Distributed Denial of Service (DDoS) attacks, ARP Spoofing, and other attacks. To address these threats, an approach capable of detecting, analyzing, and recovering networks from cyberattacks is needed. This study aims to analyze DDoS attacks using network forensics methods with an anomaly identification and attack reconstruction approach. This process includes collection, examination, analysis, and reporting stages using tools such as Wireshark and Winbox. Attack simulations were conducted using the LOIC application on a MikroTik router. The analysis results showed that the DDoS attack caused a CPU spike of up to 100%, which made the router unresponsive. Wireshark successfully identified the attack pattern in the form of UDP packet flooding, while Winbox showed a direct impact on device performance. The anomaly identification technique proved effective in detecting traffic spikes, and the reconstruction process helped understand the chronology and methods of the attack. This research contributes to the understanding and mitigation of cyber attacks through a network forensics approach, as well as being a guide in the implementation of security systems based on anomaly identification and attack reconstruction.