Abstract:The reliability of data packet transmission within the deployed Wireless Local Area Network (WLAN) security protocol is highly crucial to ensure user data confidentiality. This study aims to analyze the security implementation…
tation of the WPA2-Personal protocol-based WLAN through direct observation of data packet traffic. A qualitative-descriptive research method was applied by conducting packet capturing using the Wireshark application on a small-scale test network utilizing a smartphone as an access point and a laptop as a client. The results demonstrate that all local and internet data communication activities operated stably and were recorded consistently. Packet analysis successfully identified various major protocols, including ARP, DNS, TCP, UDP, TLS, and HTTPS. The implementation of TLS encryption on HTTPS traffic proved capable of protecting the confidentiality of application data content, preventing it from being read in plaintext even though the packets were successfully captured. This study concludes that the combination of WPA2-Personal authentication and the HTTPS communication protocol still provides adequate security protection and remains highly viable for small-scale wireless network environments.
Abstract:Abstract: Man-in-the-Middle (MITM) attacks are a threat that can occur on public wireless networks, including campus Wi-Fi environments. This study aims to analyze MITM attacks on the Wi-Fi network at Universitas ‘Aisyiyah…
iyah Yogyakarta using the National Institute of Standards and Technology (NIST) digital forensics methodology. The study applied the four NIST phases: collection, examination, analysis, and reporting. The digital evidence analyzed included packet capture (PCAP) files, as well as digital traces such as browser history, cookies, and cache data obtained from the victim’s device. The analysis process utilized Wireshark, the SQLite Database Browser, and ChromeCacheView to identify suspicious activity and correlate the discovered digital traces. The results of the study show that the MITM attack was successfully reconstructed through the correlation of digital traces, leading to the identification of ARP spoofing and DNS spoofing originating from a device with the IP address 192.168.200.12 and the MAC address a0:47:d7:73:ef:fb. The correlation of digital traces in the victim’s network and system traffic revealed communication redirection and web access manipulation. This study concludes that the NIST method is capable of reconstructing MITM attacks and identifying digital evidence from activity traces on both the network and the system.
Keywords: ARP spoofing; digital forensics; DNS spoofing; MITM; NIST
Abstrak: Serangan Man-in-the-Middle (MITM) merupakan ancaman yang dapat terjadi pada jaringan nirkabel publik, termasuk lingkungan WiFi kampus. Penelitian ini bertujuan menganalisis serangan MITM pada jaringan WiFi Universitas ‘Aisyiyah Yogyakarta menggunakan metode forensik digital National Institute of Standards and Technology (NIST). Penelitian menerapkan empat tahapan NIST, yaitu collection, examination, analysis, dan reporting. Bukti digital yang dianalisis meliputi file packet capture (PCAP), jejak digital berupa history browser, cookies, dan cache yang diperoleh dari perangkat korban. Proses analisis menggunakan Wireshark, SQLite Database Browser, dan ChromeCacheView untuk mengidentifikasi aktivitas mencurigakan serta mengorelasikan jejak digital yang ditemukan. Hasil penelitian menunjukkan bahwa serangan MITM berhasil direkonstruksi melalui korelasi jejak digital yang mengarah pada identifikasi ARP spoofing dan DNS spoofing dari perangkat dengan alamat IP 192.168.200.12 dan MAC address a0:47:d7:73:ef:fb. Korelasi jejak digital pada lalu lintas jaringan dan sistem korban menunjukkan adanya pengalihan komunikasi serta manipulasi akses web. Penelitian ini menyimpulkan bahwa metode NIST mampu merekonstruksi serangan MITM dan mengidentifikasi bukti digital dari jejak aktivitas pada jaringan maupun sistem.
Kata kunci: ARP spoofing; DNS spoofing; forensik digital; MITM; NIST