RSA UGM integrates healthcare, education, and research services, making it highly dependent on reliable wireless network infrastructure. However, the performance of the RSA UGM wireless network often deteriorates when user demand approaches the maximum capacity of access points, particularly in public areas such as auditoriums and patient waiting rooms. This condition may result in channel interference, reduced throughput, and increased response times. This study analyzes wireless network performance based on Quality of Service (QoS) parameters while integrating a digital forensics approach to distinguish legitimate user traffic surges (flash crowds) from Distributed Denial-of-Service (DDoS) attacks. The study employs an Action Research methodology consisting of diagnosis, planning, action implementation, and evaluation. QoS measurements were conducted using iPerf3 and Wireshark/tcpdump over three days across three time sessions, accompanied by a SYN Flood attack simulation in a laboratory environment replicating the hospital network topology. QoS parameters were analyzed based on the TIPHON standard, including throughput, packet loss, delay, and jitter, while the integrity of digital evidence was verified using SHA-256 hashing and a chain-of-custody procedure. The results show that under normal conditions (11 samples), throughput ranged from 9,877.75 to 23,452.12 Kbps, with a TIPHON Index of 4.00, indicating very good performance. Under flash crowd conditions, throughput increased sharply to 104,602.77 Kbps, while the other QoS parameters remained stable, resulting in a TIPHON Index of 4.00. In contrast, during the DDoS attack condition (7 samples), packet loss increased substantially to 42.64%, accompanied by significant increases in delay and jitter, causing the TIPHON Index to decline to 3.25–3.75. These findings indicate that throughput alone is insufficient to distinguish between flash crowds and DDoS attacks, whereas packet loss represents the most significant distinguishing parameter. All 19 digital evidence items (C-01–C-19) matched during SHA-256 hash verification, demonstrating that data integrity was preserved throughout the investigation. The study concludes that integrating TIPHON-based QoS analysis with digital forensics can support early detection and accurate investigation of network security incidents, particularly in hospital environments where high network reliability is essential.
Copyrights © 2026