Abstract
Security is assured to minimize losses caused by network security attack. Network security system is an important factor to ensure the ability, integrity and validity of data. Such security can be built using the Network Forensic Approach. Network forensic focuses on data obtained based on observation on the network. Observing attacks can use Snort Intrusion Detection System (IDS) tool. Snort is an open source-based NIDS software, widely used to secure a network from malicious activity. The working of snort similar to tcpdump, but focus as a security packet sniffing. The aim of this study is to analyze the log snort as a result of network forensic. In the experiment using topology star. There is 1 PC as a snort, 3 PC client that perform attacks, 7 PC as a client too. In the test conducted set as rules as intelegence. The experimental results show that snort is able to monitor network traffic, so that when the suspicious packet containing the attack will send alerts snort, but it also stores the data in the log. The logs can be investigated using the forensic process model. The results of the investigation indicate there are 3 IP attack, as well as showing the attack data are the date of the attack, attacker IP, attack time, and type of attack.
Cite
CITATION STYLE
Dewi, E. K. (2017). ANALISIS LOG SNORT MENGGUNAKAN NETWORK FORENSIC. JIPI (Jurnal Ilmiah Penelitian Dan Pembelajaran Informatika), 2(2). https://doi.org/10.29100/jipi.v2i2.370
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.