Penerapan Digital Forensic Research Workshop Framework pada Layanan Virtual Machine


  • Asruddin Asruddin * Mail Universitas Ahmad Dahlan, Yogyakarta, Indonesia
  • Imam Riadi Universitas Ahmad Dahlan, Yogyakarta, Indonesia
  • Rusydi Umar Universitas Ahmad Dahlan, Yogyakarta, Indonesia
  • (*) Corresponding Author
Keywords: ICMP Flooding; DFRWS; Network Forensics; Virtualization; PCAP

Abstract

ICMP flooding is a denial-of-service attack that overwhelms a target with high-rate ICMP packets, degrading service availability. End-to-end network forensic reporting from identification to evidence presentation remains limited. This study applies the Digital Forensic Research Workshop (DFRWS) process model - Identification, Preservation, Collection, Examination, Analysis, and Presentation - to investigate ICMP flooding in a controlled virtualized environment. Primary artifacts consist of baseline PCAPs (5 runs) and attack PCAPs (5 runs) analyzed using capinfos to extract capture duration (T), packet count (N), average et rate (pps), and file size. Results indicate that the baseline traffic (normal system activity in the VM laboratory) at 9 pps over 58.91 s with approximately 66 kB file size, while attack traffic reaches 2,000 pps over 6.39 s with an average file size of approximately 18.2 MB. Comparison of both conditions yields a packet-rate amplification of F = 2000/9 = 222× and a file-size increase of approximately 280× (18.2 MB versus 66 kB). The extreme pps spike observed during the attack condition reflects a volumetric attack pattern that operationally correlates with resource exhaustion and reduced service availability, indicating that the PCAP artifacts support not only statistical anomaly detection but also event-level evidence of a denial-of-service incident. All attack runs exceed 1,000 pps (5/5; 100%), and all baseline runs remain stable at 9 pps (5/5; 100% [1]), indicating consistent volumetric evidence. Preservation procedures using read-only storage and SHA-256 hashing ensure artifact integrity and traceability, thereby supporting the admissibility of the PCAPs as valid digital evidence in controlled virtual machine experiments.

Downloads

Download data is not yet available.

References

I. Riadi, S. Sunardi, and F. T. Fitri, “Spamming Forensic Analysis Using Network Forensics Development Life Cycle Method,” INTENSIF J. Ilm. Penelit. Dan Penerapan Teknol. Sist. Inf., vol. 6, no. 1, pp. 108–117, Feb. 2022, doi: 10.29407/intensif.v6i1.16830.

L. F. Sikos, “Packet Analysis for Network Forensics: A Comprehensive Survey,” Forensic Sci. Int. Digit. Investig., vol. 32, p. 200892, Mar. 2020, doi: 10.1016/j.fsidi.2019.200892.

S. Q. Ali Shah, F. Zeeshan Khan, and M. Ahmad, “The Impact and Mitigation of ICMP Based Economic Denial of Sustainability Attack in Cloud Computing Environment Using Software Defined Network,” Comput. Netw., vol. 187, p. 107825, Mar. 2021, doi: 10.1016/j.comnet.2021.107825.

W. Yunus and M. E. Lasulika, “Security System Analysis Against Flood Attacks Using TCP, UDP, and ICMP Protocols on Mikrotik Routers,” Int. J. Adv. Data Inf. Syst., vol. 3, no. 1, pp. 11–19, Apr. 2022, doi: 10.25008/ijadis.v3i1.1231.

M. Cermak, T. Fritzová, V. Rusňák, and D. Sramkova, “Using Relational Graphs for Exploratory Analysis of Network Traffic Data,” Forensic Sci. Int. Digit. Investig., vol. 45, p. 301563, Jul. 2023, doi: 10.1016/j.fsidi.2023.301563.

P. Rajesh, M. Ismail. Ismail. B., M. Alam, M. Tahernezhadi, and M. A., “Network Forensics Investigation in Virtual Data Centers Using ELK,” in 2021 International Symposium on Electrical, Electronics and Information Engineering, Seoul Republic of Korea: ACM, Feb. 2021, pp. 175–179. doi: 10.1145/3459104.3459135.

A. Yudhana, Imam Riadi, and Budi Putra, “Digital Forensic on Secure Digital High Capacity using DFRWS Method,” J. RESTI Rekayasa Sist. Dan Teknol. Inf., vol. 6, no. 6, pp. 1021–1027, Dec. 2022, doi: 10.29207/resti.v6i6.4615.

M. Komisarek, M. Pawlicki, T. Simic, D. Kavcnik, R. Kozik, and M. Choraś, “Modern NetFlow Network Dataset with Labeled Attacks and Detection Methods,” in Proceedings of the 18th International Conference on Availability, Reliability and Security, Benevento Italy: ACM, Aug. 2023, pp. 1–8. doi: 10.1145/3600160.3605094.

G. Aceto et al., “Synthetic and Privacy-preserving Traffic Trace Generation Using Generative AI Models for Training Network Intrusion Detection Systems,” J. Netw. Comput. Appl., vol. 229, p. 103926, Sep. 2024, doi: 10.1016/j.jnca.2024.103926.

I. S. Alansari, “A Detection and Investigation Model for the Capture and Analysis of Network Crimes,” Eng. Technol. Appl. Sci. Res., vol. 13, no. 5, pp. 11871–11877, Oct. 2023, doi: 10.48084/etasr.6316.

S. Aktar and A. Yasin Nur, “Towards DDoS Attack Detection Using Deep Learning Approach,” Comput. Secur., vol. 129, p. 103251, Jun. 2023, doi: 10.1016/j.cose.2023.103251.

A. A. Alashhab et al., “Enhancing DDoS Attack Detection and Mitigation in SDN Using an Ensemble Online Machine Learning Model,” IEEE Access, vol. 12, pp. 51630–51649, 2024, doi: 10.1109/ACCESS.2024.3384398.

S. Ratan Kumar and V. K. Vatsavayi, “Performance Analysis of Machine Learning Techniques for Server Health Monitoring Using Time Series Data Against DDOS Attacks,” IEEE Access, vol. 13, pp. 53321–53346, 2025, doi: 10.1109/ACCESS.2025.3553558.

A. Abualhassan, I. Rashid, F. Binbeshr, and M. Imam, “DDoS Attack Detection in IoT: A Comparative Resource and Performance Analysis of Deep Learning and Machine Learning Models,” IEEE Access, vol. 13, pp. 116529–116547, 2025, doi: 10.1109/ACCESS.2025.3583855.

D. Spiekermann and J. Keller, “Challenges of Network Forensic Investigation in Fog and Edge Computing,” Future Internet, vol. 15, no. 10, p. 342, Oct. 2023, doi: 10.3390/fi15100342.

H. Alazzam, O. AbuAlghanam, Q. M. Al-zoubi, A. Alsmady, and E. Alhenawi, “A New Network Digital Forensics Approach for Internet of Things Environment Based on Binary Owl Optimizer,” Cybern. Inf. Technol., vol. 22, no. 3, pp. 146–160, Sep. 2022, doi: 10.2478/cait-2022-0033.

Y. Salem and M. M. N. Hamarsheh, “Forensically Analyzing IoT Smart Camera Using MAoIDFF-IoT Framework,” Forensic Sci. Int. Digit. Investig., vol. 51, p. 301829, Dec. 2024, doi: 10.1016/j.fsidi.2024.301829.

T. Wu, F. Breitinger, and S. Niemann, “IoT Network Traffic Analysis: Opportunities and Challenges for Forensic Investigators?,” Forensic Sci. Int. Digit. Investig., vol. 38, p. 301123, Oct. 2021, doi: 10.1016/j.fsidi.2021.301123.

S. Batool, M. Aslam, E. Akpokodje, and S. F. Jilani, “A Comprehensive Review of DDoS Detection and Mitigation in SDN Environments: Machine Learning, Deep Learning, and Federated Learning Perspectives,” Electronics, vol. 14, no. 21, p. 4222, Oct. 2025, doi: 10.3390/electronics14214222.

S. Sunardi, I. Riadi, R. Umar, and M. F. Gustafi, “Audio Forensics on Smartphone with Digital Forensics Research Workshop (DFRWS) Method,” CommIT Commun. Inf. Technol. J., vol. 15, no. 1, pp. 41–47, Mar. 2021, doi: 10.21512/commit.v15i1.6739.

Imam Riadi, Rusydi Umar, and M. I. Syahib, “Akuisisi Bukti Digital Viber Messenger Android Menggunakan Metode National Institute of Standards and Technology (NIST),” J. RESTI Rekayasa Sist. Dan Teknol. Inf., vol. 5, no. 1, pp. 45–54, Feb. 2021, doi: 10.29207/resti.v5i1.2626.

I. Riadi, Sunardi, and F. T. Nani, “Analisis Forensik pada Email Menggunakan Metode National Institute of Standards Technology,” JISKA J. Inform. Sunan Kalijaga, vol. 7, no. 2, pp. 83–90, May 2022, doi: 10.14421/jiska.2022.7.2.83-90.

M. Muammar, I. Riadi, and R. Umar, “Pengembangan Alat Forensik Whatsapp Menggunakan Android Debug Bridge Sebagai Metode Akuisisi Data,” JIPI J. Ilm. Penelit. Dan Pembelajaran Inform., vol. 10, no. 2, pp. 1099–1110, Mar. 2025, doi: 10.29100/jipi.v10i2.5968.

F. D. Setiawan Sumadi, A. R. Widagdo, A. F. Reza, and - Syaifuddin, “SD-Honeypot Integration for Mitigating DDoS Attack Using Machine Learning Approaches,” JOIV Int. J. Inform. Vis., vol. 6, no. 1, p. 39, Mar. 2022, doi: 10.30630/joiv.6.1.853.

I. M. Razzanda and Muhammad Koprawi, “Implementasi IDS dan IPS terhadap Serangan TCP Port Scanning dan ICMP Flooding,” Indones. J. Comput. Sci., vol. 13, no. 4, Aug. 2024, doi: 10.33022/ijcs.v13i4.4212.

F. Antony and R. Gustriansyah, “Deteksi Serangan Denial of Service pada Internet of Things Menggunakan Finite-State Automata,” MATRIK J. Manaj. Tek. Inform. Dan Rekayasa Komput., vol. 21, no. 1, pp. 43–52, Nov. 2021, doi: 10.30812/matrik.v21i1.1078.

R. Wang, J. Zhao, H. Zhang, L. He, H. Li, and M. Huang, “Network Traffic Analysis Based on Graph Neural Networks: A Scoping Review,” Big Data Cogn. Comput., vol. 9, no. 11, p. 270, Oct. 2025, doi: 10.3390/bdcc9110270.

Y. Yang, T. Song, W. Yuan, and J. An, “Towards Reliable and Efficient Data Retrieving in ICN-based Satellite Networks,” J. Netw. Comput. Appl., vol. 179, p. 102982, Apr. 2021, doi: 10.1016/j.jnca.2021.102982.


Bila bermanfaat silahkan share artikel ini

Berikan Komentar Anda terhadap artikel Penerapan Digital Forensic Research Workshop Framework pada Layanan Virtual Machine

Dimensions Badge
Article History
Submitted: 2025-12-25
Published: 2026-01-31
Abstract View: 39 times
PDF Download: 23 times
How to Cite
Asruddin, A., Riadi, I., & Umar, R. (2026). Penerapan Digital Forensic Research Workshop Framework pada Layanan Virtual Machine. Journal of Information System Research (JOSH), 7(2), 599-608. https://doi.org/10.47065/josh.v7i2.9034
Section
Articles