Analisis forensik jaringan serangan ARP Spoofing menggunakan metode National Institute of Justice (NIJ)
DOI:
https://doi.org/10.24246/itexplore.v4i2.2025.pp150-160Keywords:
Address Resoution Protocol, National of Justice, Man in the middle attack, WiresharkAbstract
This study aims to identify evidence of Address Resolution Protocol (ARP) Spoofing attacks in the form of the attacker's and victim's Media Access Control (MAC) addresses, as well as the time of the attack. With the increasing use of computer networks, ARP Spoofing attacks have become a serious threat that can lead to data theft, communication interception, and service disruption. ARP Spoofing can serve as a means to launch more complex attacks, such as Denial of Service (DoS) and Man in the Middle (MITM), which can cripple network systems and steal sensitive information. This study utilizes the Wireshark tool to monitor network traffic, specifically ARP, and applies the National Institute of Justice (NIJ) method as a framework for forensic investigation. The NIJ method was chosen because it provides a systematic approach to identifying, collecting, analyzing, and reporting digital evidence, enabling enhanced attack mitigation and supporting legal aspects in network security investigations. The specific approaches used in this forensic analysis include log analysis, packet capture and analysis using Wireshark, and traffic correlation to identify attack patterns based on time and involved devices. The attack simulation was conducted on Personal Computer (PC) 1 and a routerboard, where communication between these two devices was redirected through the attacker. Based on the test results, it was found that every device in the network experienced ARP Spoofing attacks, which could be detected and analyzed using the NIJ method. The contribution of this study is to provide a more systematic approach to forensic network investigations using the NIJ method, which not only aids in attack detection but also establishes a strong foundation for mitigation actions and legal enforcement in computer network security.
Downloads
References
R. Irawan, A, D Yusufianto, A Agustina, D Dean, “Laporan Survei Internet APJII 2019 – 2020,” Asos. Penyelenggara Jasa Internet Indones., vol. 2020, pp. 1–146, 2020, [Online]. Available: https://apjii.or.id/survei
R. D. Hapsari and K. G. Pambayun, “ANCAMAN CYBERCRIME DI INDONESIA: Sebuah Tinjauan Pustaka Sistematis,” J. Konstituen, vol. 5, no. 1, pp. 1–17, 2023, doi: 10.33701/jk.v5i1.3208.
N. R. Arofah and Y. Priatnasari, “Internet Banking Dan Cyber Crime : Sebuah Studi Kasus Di Perbankan Nasional,” J. Pendidik. Akunt. Indones., vol. 18, no. 2, pp. 107–119, 2020, doi: 10.21831/jpai.v18i2.35872.
R. F. Sri Supatmi, Taufiq Nuzwir Nizar, “Sistem Kontrol Peralatan Rumah Dan Monitoring Kondisi Rumah Melalui Internet Berbasis Web Dan Openwrt,” J. Tek. Komput. Unikom – Komputika – Vol. 3, No.2 - 2014 Sist., vol. 3, no. 2, pp. 23–28, 2014, [Online]. Available: http://komputika.tk.unikom.ac.id/_s/data/jurnal/v3no2/1-srisupatmi.pdf/ori/1-srisupatmi.pdf
L. Iriani and M. N. Hafizh, “Forensik Jaringan Terhadap Serangan DDOS Menggunakan Metode Network Forensic Development Life Cycle,” JSTIE (Jurnal Sarj. Tek. Inform., vol. 11, no. 3, p. 107, 2023, doi: 10.12928/jstie.v11i3.26544.
E. Permana and M. H. Sarip, “Pengembangan Jaringan Komputer,” J. Mitra Manaj., vol. 5, no. 1, pp. 1–10, 2016, [Online]. Available: https://journal.universitassuryadarma.ac.id/index.php/jmm/article/view/564
M. N. Hafizh, I. Riadi, and A. Fadlil, “Forensik Jaringan Terhadap Serangan ARP Spoofing menggunakan Metode Live Forensic,” J. Telekomun. dan Komput., vol. 10, no. 2, p. 111, 2020, doi: 10.22441/incomtech.v10i2.8757.
M. E. Ayuningtyas, “Mengenal Perbedaan IP Address dan MAC Address Dari Berbagai Aspek,” PuTI (Pusat Teknologi Informasi). [Online]. Available: https://it.telkomuniversity.ac.id/perbedaan-ip-address-dan-mac-address/
H. KHALID, P. ISMAEL, and A. AL-KHALIL, “Efficient Mechanism for Securing Software Defined Network Against Arp Spoofing Attack,” J. Univ. Duhok, vol. 22, no. 1, pp. 124–131, 2019, doi: 10.26682/sjuod.2019.22.1.14.
I. Riadi, A. Fadlil, and M. N. Hafizh, “Analisis Bukti Serangan Address Resolution Protocol Spoofing menggunakan Metode National Institute of Standard Technology,” Edumatic J. Pendidik. Inform., vol. 4, no. 1, pp. 21–29, 2020, doi: 10.29408/edumatic.v4i1.2046.
M. Abid and A. Singh, “Arp spoofing detection via wireshark and veracode,” Int. J. New Technol. Res., vol. 4, no. 5, pp. 27–30, 2018.
Imam Riadi, Abdul Fadlil, and Muhammad Immawan Aulia, “Investigasi Bukti Digital Optical Drive Menggunakan Metode National Institute of Standard and Technology (NIST),” J. RESTI (Rekayasa Sist. dan Teknol. Informasi), vol. 4, no. 5, pp. 820–828, 2020, doi: 10.29207/resti.v4i5.2224.
P. Pandit and P. D. Pandit, “A Study of Operation, Detection and Prevention for ARP Spoofing,” no. September, 2021, doi: 10.13140/RG.2.2.16764.05764.
M. N. Faiz, R. Umar, and A. Yudhana, “Implementasi Live Forensics untuk Perbandingan Browser pada Keamanan Email,” JISKA (Jurnal Inform. Sunan Kalijaga), vol. 1, no. 3, pp. 108–114, 2017, doi: 10.14421/jiska.2017.13-02.
I. Riadi, R. Umar, and I. M. Nasrulloh, “Analisis Forensik Digital Pada Frozen Solid State Drive Dengan Metode National Institute of Justice (Nij),” Elinvo (Electronics, Informatics, Vocat. Educ., vol. 3, no. 1, pp. 70–82, 2018, doi: 10.21831/elinvo.v3i1.19308.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Latifah Iriani, Muhammad Nasir Hafizh, Khairina Eka Setyaputri

This work is licensed under a Creative Commons Attribution 4.0 International License.

All articles published in IT-Explore: Jurnal Penerapan Teknologi Informasi dan Komunikasi is licensed under a Creative Commons Attribution 4.0 International License.




