Decision Tree-Based Anomaly Traffic Detection for Local Area Network (LAN) Security Using Wireshark and Nmap Data Analysis
Abstrak
The development of information technology encourages the use of LAN networks as primary infrastructure in educational environments. The high intensity of network usage at the Faculty of Engineering and Computer Science increases security risks such as unauthorized access, open ports, and anomalous traffic, making comprehensive network security analysis necessary. This study aims to analyze LAN network security at the Faculty of Engineering and Computer Science using MikroTik (RB951Ui-2HnD) and TP-Link (TL-WR841N) devices, and to apply the Decision Tree algorithm for network traffic classification. The methods include router configuration analysis, port scanning using Nmap (Zenmap), packet sniffing analysis with Wireshark, and network traffic classification using the Decision Tree algorithm implemented in RapidMiner Studio. Port scanning results indicate that from 1000 scanned ports, only 5 ports (0.5%) were detected as open. Wireshark packet capture over 5 minutes collected 6,708 packets, revealing the presence of unencrypted HTTP packets and TCP errors. The Decision Tree model achieved an accuracy of 86.05%, precision of 99.94%, and recall of 73.85% in classifying normal and anomalous traffic. This approach effectively provides an overview of LAN security conditions and can serve as a reference for improving network security in educational institutions.
Unduhan
Diterbitkan
Cara Mengutip
Terbitan
Bagian
Lisensi
Hak Cipta (c) 2026 Komputasi: Jurnal Ilmiah Ilmu Komputer dan Matematika

Artikel ini berlisensiCreative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.









