Register: Jurnal Ilmiah Teknologi Sistem Informasi
Vol. 8 No. 2 (2022): July

Network Forensics Against Address Resolution Protocol Spoofing Attacks Using Trigger, Acquire, Analysis, Report, Action Method

Agus Wijayanto (Universitas Islam Indonesia)
Imam Riadi (Universitas Ahmad Dahlan)
Yudi Prayudi (Universitas Islam Indonesia)
Tri Sudinugraha (Universiti Malaysia Sarawak)



Article Info

Publish Date
07 Jan 2023

Abstract

This study aims to obtain attack evidence and reconstruct commonly used address resolution protocol attacks as a first step to launch a moderately malicious attack. MiTM and DoS are the initiations of ARP spoofing attacks that are used as a follow-up attack from ARP spoofing. The impact is quite severe, ranging from data theft and denial of service to crippling network infrastructure systems. In this study, data collection was conducted by launching an test attack against a real network infrastructure involving 27 computers, one router, and four switches. This study uses a Mikrotik router by building a firewall to generate log files and uses the Tazmen Sniffer Protocol, which is sent to a syslog-ng computer in a different virtual domain in a local area network. The Trigger, Acquire, Analysis, Report, Action method is used in network forensic investigations by utilising Wireshark and network miners to analyze network traffic during attacks. The results of this network forensics obtain evidence that there have been eight attacks with detailed information on when there was an attack on the media access control address and internet protocol address, both from the attacker and the victim. However, attacks carried out with the KickThemOut tool can provide further information about the attacker’s details through a number of settings, in particular using the Gratuitous ARP and ICMP protocols.

Copyrights © 2022






Journal Info

Abbrev

register

Publisher

Subject

Computer Science & IT

Description

Register: Jurnal Ilmiah Teknologi Sistem Informasi published by the Department of Information Systems Unipdu Jombang. Register published twice a year, in January and July, Registerincludes research in the field of Information Technology, Information Systems Engineering, Intelligent Business Systems, ...