| International Journal of Computer Applications |
| Foundation of Computer Science (FCS), NY, USA |
| Volume 187 - Number 122 |
| Year of Publication: 2026 |
| Authors: Muhammad Fauzan Taufiqurrahman, Imam Riadi |
10.5120/ijca3f7bffcd3699
|
Muhammad Fauzan Taufiqurrahman, Imam Riadi . Analysis and Detection of Distributed Denial of Service Attacks using National Institute of Standards and Technology Method. International Journal of Computer Applications. 187, 122 ( Jul 2026), 47-54. DOI=10.5120/ijca3f7bffcd3699
This research analyzes Distributed Denial of Service (DDoS) attacks of the UDP Flood type on a Linux-based server using a live forensic approach, conducted in a closed network environment with a Linux server as the target and a client as the attacker using Low Orbit Ion Cannon (LOIC). Evidence acquisition was performed using tcpdump in .pcap format, and the captured data was analyzed using Wireshark based on the NIST method stages: collection, examination, analysis, and reporting. The analysis parameters included protocol type, source and destination IP addresses, destination port, packet size, packet rate, time interval, and traffic distribution pattern. The results showed that 2,046,672 packets were captured in approximately 26 seconds, with average rate of 78,015 packets per second. The traffic was dominated by small UDP packets of 62 bytes, transmitted massively, repeatedly, and directly toward the target server, indicating the characteristics of a UDP Flood attack. Recommended mitigation strategies include filtering UDP traffic using iptables, restricting port access, and conducting regular network monitoring. This research demonstrates that live forensic analysis based on the NIST framework is effective for systematically identifying and analyzing UDP Flood attacks.