Penerapan Digital Forensic Research Workshop Framework pada Layanan Virtual Machine
Abstract
ICMP flooding is a denial-of-service attack that overwhelms a target with high-rate ICMP packets, degrading service availability. End-to-end network forensic reporting from identification to evidence presentation remains limited. This study applies the Digital Forensic Research Workshop (DFRWS) process model - Identification, Preservation, Collection, Examination, Analysis, and Presentation - to investigate ICMP flooding in a controlled virtualized environment. Primary artifacts consist of baseline PCAPs (5 runs) and attack PCAPs (5 runs) analyzed using capinfos to extract capture duration (T), packet count (N), average et rate (pps), and file size. Results indicate that the baseline traffic (normal system activity in the VM laboratory) at 9 pps over 58.91 s with approximately 66 kB file size, while attack traffic reaches 2,000 pps over 6.39 s with an average file size of approximately 18.2 MB. Comparison of both conditions yields a packet-rate amplification of F = 2000/9 = 222× and a file-size increase of approximately 280× (18.2 MB versus 66 kB). The extreme pps spike observed during the attack condition reflects a volumetric attack pattern that operationally correlates with resource exhaustion and reduced service availability, indicating that the PCAP artifacts support not only statistical anomaly detection but also event-level evidence of a denial-of-service incident. All attack runs exceed 1,000 pps (5/5; 100%), and all baseline runs remain stable at 9 pps (5/5; 100% [1]), indicating consistent volumetric evidence. Preservation procedures using read-only storage and SHA-256 hashing ensure artifact integrity and traceability, thereby supporting the admissibility of the PCAPs as valid digital evidence in controlled virtual machine experiments.
Downloads
References
I. Riadi, S. Sunardi, and F. T. Fitri, “Spamming Forensic Analysis Using Network Forensics Development Life Cycle Method,” INTENSIF J. Ilm. Penelit. Dan Penerapan Teknol. Sist. Inf., vol. 6, no. 1, pp. 108–117, Feb. 2022, doi: 10.29407/intensif.v6i1.16830.
L. F. Sikos, “Packet Analysis for Network Forensics: A Comprehensive Survey,” Forensic Sci. Int. Digit. Investig., vol. 32, p. 200892, Mar. 2020, doi: 10.1016/j.fsidi.2019.200892.
S. Q. Ali Shah, F. Zeeshan Khan, and M. Ahmad, “The Impact and Mitigation of ICMP Based Economic Denial of Sustainability Attack in Cloud Computing Environment Using Software Defined Network,” Comput. Netw., vol. 187, p. 107825, Mar. 2021, doi: 10.1016/j.comnet.2021.107825.
W. Yunus and M. E. Lasulika, “Security System Analysis Against Flood Attacks Using TCP, UDP, and ICMP Protocols on Mikrotik Routers,” Int. J. Adv. Data Inf. Syst., vol. 3, no. 1, pp. 11–19, Apr. 2022, doi: 10.25008/ijadis.v3i1.1231.
M. Cermak, T. Fritzová, V. Rusňák, and D. Sramkova, “Using Relational Graphs for Exploratory Analysis of Network Traffic Data,” Forensic Sci. Int. Digit. Investig., vol. 45, p. 301563, Jul. 2023, doi: 10.1016/j.fsidi.2023.301563.
P. Rajesh, M. Ismail. Ismail. B., M. Alam, M. Tahernezhadi, and M. A., “Network Forensics Investigation in Virtual Data Centers Using ELK,” in 2021 International Symposium on Electrical, Electronics and Information Engineering, Seoul Republic of Korea: ACM, Feb. 2021, pp. 175–179. doi: 10.1145/3459104.3459135.
A. Yudhana, Imam Riadi, and Budi Putra, “Digital Forensic on Secure Digital High Capacity using DFRWS Method,” J. RESTI Rekayasa Sist. Dan Teknol. Inf., vol. 6, no. 6, pp. 1021–1027, Dec. 2022, doi: 10.29207/resti.v6i6.4615.
M. Komisarek, M. Pawlicki, T. Simic, D. Kavcnik, R. Kozik, and M. Choraś, “Modern NetFlow Network Dataset with Labeled Attacks and Detection Methods,” in Proceedings of the 18th International Conference on Availability, Reliability and Security, Benevento Italy: ACM, Aug. 2023, pp. 1–8. doi: 10.1145/3600160.3605094.
G. Aceto et al., “Synthetic and Privacy-preserving Traffic Trace Generation Using Generative AI Models for Training Network Intrusion Detection Systems,” J. Netw. Comput. Appl., vol. 229, p. 103926, Sep. 2024, doi: 10.1016/j.jnca.2024.103926.
I. S. Alansari, “A Detection and Investigation Model for the Capture and Analysis of Network Crimes,” Eng. Technol. Appl. Sci. Res., vol. 13, no. 5, pp. 11871–11877, Oct. 2023, doi: 10.48084/etasr.6316.
S. Aktar and A. Yasin Nur, “Towards DDoS Attack Detection Using Deep Learning Approach,” Comput. Secur., vol. 129, p. 103251, Jun. 2023, doi: 10.1016/j.cose.2023.103251.
A. A. Alashhab et al., “Enhancing DDoS Attack Detection and Mitigation in SDN Using an Ensemble Online Machine Learning Model,” IEEE Access, vol. 12, pp. 51630–51649, 2024, doi: 10.1109/ACCESS.2024.3384398.
S. Ratan Kumar and V. K. Vatsavayi, “Performance Analysis of Machine Learning Techniques for Server Health Monitoring Using Time Series Data Against DDOS Attacks,” IEEE Access, vol. 13, pp. 53321–53346, 2025, doi: 10.1109/ACCESS.2025.3553558.
A. Abualhassan, I. Rashid, F. Binbeshr, and M. Imam, “DDoS Attack Detection in IoT: A Comparative Resource and Performance Analysis of Deep Learning and Machine Learning Models,” IEEE Access, vol. 13, pp. 116529–116547, 2025, doi: 10.1109/ACCESS.2025.3583855.
D. Spiekermann and J. Keller, “Challenges of Network Forensic Investigation in Fog and Edge Computing,” Future Internet, vol. 15, no. 10, p. 342, Oct. 2023, doi: 10.3390/fi15100342.
H. Alazzam, O. AbuAlghanam, Q. M. Al-zoubi, A. Alsmady, and E. Alhenawi, “A New Network Digital Forensics Approach for Internet of Things Environment Based on Binary Owl Optimizer,” Cybern. Inf. Technol., vol. 22, no. 3, pp. 146–160, Sep. 2022, doi: 10.2478/cait-2022-0033.
Y. Salem and M. M. N. Hamarsheh, “Forensically Analyzing IoT Smart Camera Using MAoIDFF-IoT Framework,” Forensic Sci. Int. Digit. Investig., vol. 51, p. 301829, Dec. 2024, doi: 10.1016/j.fsidi.2024.301829.
T. Wu, F. Breitinger, and S. Niemann, “IoT Network Traffic Analysis: Opportunities and Challenges for Forensic Investigators?,” Forensic Sci. Int. Digit. Investig., vol. 38, p. 301123, Oct. 2021, doi: 10.1016/j.fsidi.2021.301123.
S. Batool, M. Aslam, E. Akpokodje, and S. F. Jilani, “A Comprehensive Review of DDoS Detection and Mitigation in SDN Environments: Machine Learning, Deep Learning, and Federated Learning Perspectives,” Electronics, vol. 14, no. 21, p. 4222, Oct. 2025, doi: 10.3390/electronics14214222.
S. Sunardi, I. Riadi, R. Umar, and M. F. Gustafi, “Audio Forensics on Smartphone with Digital Forensics Research Workshop (DFRWS) Method,” CommIT Commun. Inf. Technol. J., vol. 15, no. 1, pp. 41–47, Mar. 2021, doi: 10.21512/commit.v15i1.6739.
Imam Riadi, Rusydi Umar, and M. I. Syahib, “Akuisisi Bukti Digital Viber Messenger Android Menggunakan Metode National Institute of Standards and Technology (NIST),” J. RESTI Rekayasa Sist. Dan Teknol. Inf., vol. 5, no. 1, pp. 45–54, Feb. 2021, doi: 10.29207/resti.v5i1.2626.
I. Riadi, Sunardi, and F. T. Nani, “Analisis Forensik pada Email Menggunakan Metode National Institute of Standards Technology,” JISKA J. Inform. Sunan Kalijaga, vol. 7, no. 2, pp. 83–90, May 2022, doi: 10.14421/jiska.2022.7.2.83-90.
M. Muammar, I. Riadi, and R. Umar, “Pengembangan Alat Forensik Whatsapp Menggunakan Android Debug Bridge Sebagai Metode Akuisisi Data,” JIPI J. Ilm. Penelit. Dan Pembelajaran Inform., vol. 10, no. 2, pp. 1099–1110, Mar. 2025, doi: 10.29100/jipi.v10i2.5968.
F. D. Setiawan Sumadi, A. R. Widagdo, A. F. Reza, and - Syaifuddin, “SD-Honeypot Integration for Mitigating DDoS Attack Using Machine Learning Approaches,” JOIV Int. J. Inform. Vis., vol. 6, no. 1, p. 39, Mar. 2022, doi: 10.30630/joiv.6.1.853.
I. M. Razzanda and Muhammad Koprawi, “Implementasi IDS dan IPS terhadap Serangan TCP Port Scanning dan ICMP Flooding,” Indones. J. Comput. Sci., vol. 13, no. 4, Aug. 2024, doi: 10.33022/ijcs.v13i4.4212.
F. Antony and R. Gustriansyah, “Deteksi Serangan Denial of Service pada Internet of Things Menggunakan Finite-State Automata,” MATRIK J. Manaj. Tek. Inform. Dan Rekayasa Komput., vol. 21, no. 1, pp. 43–52, Nov. 2021, doi: 10.30812/matrik.v21i1.1078.
R. Wang, J. Zhao, H. Zhang, L. He, H. Li, and M. Huang, “Network Traffic Analysis Based on Graph Neural Networks: A Scoping Review,” Big Data Cogn. Comput., vol. 9, no. 11, p. 270, Oct. 2025, doi: 10.3390/bdcc9110270.
Y. Yang, T. Song, W. Yuan, and J. An, “Towards Reliable and Efficient Data Retrieving in ICN-based Satellite Networks,” J. Netw. Comput. Appl., vol. 179, p. 102982, Apr. 2021, doi: 10.1016/j.jnca.2021.102982.
Bila bermanfaat silahkan share artikel ini
Berikan Komentar Anda terhadap artikel Penerapan Digital Forensic Research Workshop Framework pada Layanan Virtual Machine
Pages: 599-608
Copyright (c) 2026 Asruddin Asruddin, Imam Riadi, Rusydi Umar

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under Creative Commons Attribution 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (Refer to The Effect of Open Access).






















