Submitted:
08 August 2023
Posted:
10 August 2023
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Literature Review and Research Gaps

3. Research Methodology
4. Research Contributions and Novelty
5. Order of Volatility in Cyber Forensics
6. The Proposed High-Level Protocol
7. Detailed D2WF Protocol
- ➢
- Identify and Collect Suspect Devices: Identifying potential evidence that may have been used in a crime is crucial to ensuring it will be admissible in court. This can be achieved by examining the crime scene, speaking to witnesses, or reviewing surveillance footage.
- ➢
- Identify Extra Storages (e.g. Cloud and IoT): Once potential evidence has been identified, collecting and documenting accurately is crucial.
- ➢
- Identify Extra-Storages (e.g. Cloud and IoT): During the evidence identification phase, it is critical to identify extra-Storage (e.g., cloud and IoT) that may contain vital data, and a process technique to extract this data should be developed.
- ➢
- Determine the Required Hardware/Software: determining what is necessary to complete the evidence identification will include hardware, software, and storage requirements. Each task is unique, and it is critical to tailor the needs of the task to the hardware, software, and storage requirements.
- ➢
- Establish a Chain of Custody: a "chain of custody" is a paper trail or chronological documentation that shows the seizure, control, transfer, analysis, and disposition of physical or electronic evidence. When gathering evidence, it is critical to maintain a chain of custody to ensure its integrity and admissibility in court.
- ➢
- Acquire Volatile Data Following the Order of Volatility (OOV): Volatile data is information stored in a computer's temporary memory, and it is lost when the system is powered down. It is critical to acquire evidence in the Order of volatility to ensure that as much data as possible is recovered from a system. This means that the most volatile data, i.e. data in a system's temporary memory, should be acquired first.
- ➢
- Acquire Physical or Logical File System Image: a physical file system image is a bit-for-bit copy of a storage device, such as a hard drive, that can be used to forensically examine the device's contents, whereas a logical file system image is a copy of data on a storage device that can be created without creating an exact bit-for-bit copy of the device. Logical file system images typically include only the files and folders required for a specific investigation.
- ➢
- Import/Backup Cloud-Based Content: acquiring and backing up cloud-based content ensures that the evidence is not lost or tampered with if the cloud-based service is shut down or deleted.
- ➢
- Extract Networking and Logging Data: investigators will often need to collect networking and logging data from reconstructing events or tracking down suspects. This information can be obtained by obtaining it from network devices or servers.
- ➢
- Secure Evidence and Store Original Devices in Safe: Once the evidence has been collected, it must be secured and stored in a secure location. This will prevent the evidence from being lost or tampered with. Keeping the original devices in a safe location is also critical to ensure their integrity.
- ➢
- Analyse RAM and Examine URLs, Web Content, Search Queries, Logging Details, and Downloaded Files: Examine the running processes, visited websites, downloaded files, system logs, open files, and network connections to reconstruct events.
- ➢
- Analyse Browsing Data, File System/Registry, Examine URLs, Bookmarks, Usage Sessions, Timestamps, and Caches: we can begin by looking at web browser data to get an idea of what the user is doing on the system. This provides an overview of the websites the user visits and the types of activities carried out. The -r option returns a grep list of all bookmarks saved by the user. We can use the grep -c option to print the number of times each URL has been visited. To see a list of all the cookies stored on the system, use the -f option with grep. We can use the grep -s option to see how many times each cookie has been accessed.
- ➢
- Analyse Logs and Networking Cookies, Examine Downloads and Browsing: Examine the log files with the command-line tool grep to search for specific keywords in the log files. We can use the grep -r option to see a list of all the IP addresses that the user has accessed. We can use the grep -c option to see how many times each IP address has been accessed.
- ➢
- Analyse Cloud Backup and Examine Logging, Browsing, and Search Queries: this search can reveal user activities during the Examination and Analysis phase. However, the information that is stored in the remote location through a network such as the Internet is further analysed, the logging details of the activities and who was involved are examined, and the search behaviour of the user is evaluated so that the investigator can organise and get more insight on the user's activities and the incidents that happened.
- ➢
- Correlate Findings and Establish the Final Timeline: We reviewed the findings and looked for patterns or themes. If there are any gaps in the data, we conduct additional research to correlate the findings. Once we have a clear picture of what occurred, we create a detailed timeline of events that will serve as the foundation for the final report.
- ➢
- Process Finding, Correlate Finding, and Remove Duplication: At this stage, we process all of the evidence files' findings and correlate them to remove any duplication.
- ➢
- Summarise Findings in accordance with the Relevance and Acceptability to reconstruct the crime environment and ensure that the evidence is admissible.
- ➢
- Complete Findings and Present a Technical Report: When all the above digital forensics processes have been completed, the findings need to be presented and put in an orderly document that validates the evidence collected, tracked, and analysed. The findings should be protected and kept in a safe place for access when needed. Security of such information is vital to avoid tampering or loss of data.
8. Forensic Scenarios Design and Datasets Generation
9. Forensic Processing, Examination And Analysis
10. Results and Discussion
11. Conclusions and Future Works
Author Contributions
Data Availability Statement
Conflicts of Interest
Research Ethics Considerations
Research Funding
References
- Arshad, M. R., Hussain, M., Tahir, H. & Qadir, S. (2021). Forensic Analysis of Tor Browser on Windows 10 and Android 10 Operating Systems. IEEE Access, Volume 9, pp. 141273 - 141294. [CrossRef]
- Balduzzi, M. & Ciancaglini, V., 2015. Cybercrime in the Deep Web. Amsterdam, 2015 Black Hat EU Conference.
- Baronia, D., 2021. Dark Web and Tor Forensic. [Online] Available at: https://informaticss.com/dark-web-and-tor-forensic/ [Accessed 12 October 2022].
- Brinson, R., Wimmer, H., Cheng, L. (2022). Dark Web Forensics: An investigation of tracking dark web activity with digital forensics. Interdisciplinary Research in Technology and Management (IRTM). [CrossRef]
- Gehl, R.W., 2018. Weaving the dark web: Legitimacy on Freenet, Tor, and I2P. MIT Press.
- Cherty, A., Sharma, U. (2019). Memory forensic analysis for investigation of online crime- A review. IEEE 6th International Conference on Computing for Sustainable Global Development. IEEE Access.
- European Monitoring Centre for Drugs and Drug Addiction and Europol, (2017). Drugs and the darknet: Perspectives for enforcement, research and policy, Luxembourg: Publications Office of the European Union.
- Forensic-Pathways, 2020. Dark Web Investigations/Monitoring. [Online] Available at: https://www.forensic-pathways.com/dark-web-investigations monitoring/ [Accessed 12 October 2022]. 12 October.
- Godawatte, K., Raza, M., Murtaza, M. & Saeed, A., 2019. Dark Web Along with the Dark Web Marketing and Surveillance. 2019 20th International Conference on Parallel and Distributed Computing, Applications and Technologies (PDCAT). Gold Coast, QLD, Australia, IEEE.
- Goodison, S. E. et al. Research Report. 2019. Identifying Law Enforcement Needs for Conducting Criminal Investigations Involving Evidence on the Dark Web, California: RAND Corporation.
- Handalage, U., Prasanga, T. (2020). Dark Web, Its Impact on the Internet and the Society: A Review. (Online). [CrossRef]
- Protrka, N. (2021). Cybercrime. In Modern Police Leadership (pp. 143-155). Palgrave Macmillan, Cham.
- R. Brinson, H. Wimmer and L. Chen, "Dark Web Forensics: An Investigation of Tracking Dark Web Activity with Digital Forensics," 2022 Interdisciplinary Research in Technology and Management (IRTM), Kolkata, India, 2022, pp. 1-8. [CrossRef]
- M. F. B. Rafiuddin, H. Minhas and P. S. Dhubb, "A dark web story in-depth research and study conducted on the dark web based on forensic computing and security in Malaysia," 2017 IEEE International Conference on Power, Control, Signals and Instrumentation Engineering (ICPCSI), Chennai, India, 2017, pp. 3049-3055. [CrossRef]
- Leng, T., Yu, A. (2021). A framework of darknet forensics. International Conference on Advanced Information Science and Systems. (Online). https://dl.acm.org/doi/fullHtml/10.1145/3503047.3503082. [CrossRef]
- Maisammaguda, D., (2019). Digital Notes on Computer Forensics, India: Malla Reddy College of Engineering and Technology. Maryville University, 2017. Top 4 Data Analysis Techniques That Create Business Value. [Online] Available at: https://online.maryville.edu/blog/data-analysis-techniques/#qualitative [Ac- cessed 4 December 2022].
- Matic, S., Kotzias, P. and Caballero, J., 2015, October. Caronte: Detecting location leaks for deanonymizing tor hidden services. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (pp. 1455-1466).
- Naza, S., Huda, S., Abawajy, J., Hassan, M. M. (2020). The evolution of dark web threat and detection: a systematic approach. IEEE Access 8:171796-171819. [CrossRef]
- Rogers, B., 2017. Tor: Beginners to Expert Guide to Accessing the DarkNet, TOR Browsing, and Remaining Anonymous Online. 1st ed: CreateSpace Independent Publishing Platform.
- Tazi, F., Shrestha, S., Cruz, J. D. L., Das, S., (2020). SoK: An Evaluation of the Secure End User Experience on the Dark Net through Systematic Literature Review. J. Cybersecurity and Privacy. 2022, 2(2), 329–357. [CrossRef]
- Zeid, R. B., Moubarak, J., Bassil, C. (2020) Investigating the darknet (Online). International Wireless Communications and Mobile Computing (IWCMC). [CrossRef]
- Ozkaya, E., & Islam, R. (2019). Inside the Dark Web. CRC Press. [CrossRef]
- Popov, O., Bergman, J., & Valassi, C. (2018, November). A framework for forensically sound harvesting the dark web. Central European Cybersecurity Conference 2018 (pp. 1-7).
- Nazah, S., Huda, S., Abawajy, J., & Hassan, M. M. (2020). Evolution of dark web threat analysis and detection: A systematic approach. IEEE Access, 8, 171796-171819.
- Holland, B. J. (2020). Transnational cybercrime: The dark web. Encyclopedia of Criminal Activities and the Deep Web, 108-128.
- Jardine. E. (2015). The Dark Web Dilemma: Tor, Anonymity and Online Policing. Global Commission on Internet Governance Paper Series, Volume 21, pp. 1-11. [CrossRef]
- Ghanem, M.C. Cryptographically Upgrading TOR Network to Enforce Anonymity by Enhancing Security and Improving Performances. Preprints.org 2023, 2023070982. [Google Scholar] [CrossRef]
- Samtani, S., Zhu, H., & Chen, H. (2020). Proactively identifying emerging hacker threats from the dark web: A diachronic graph embedding framework. ACM Transactions on Privacy and Security (TOPS), 23(4), 1-33. [CrossRef]
- Dunsin, D., Ghanem, M., Ouazzane, K. (2022), 'The Use of Artificial Intelligence in Digital Forensics and Incident Response in a Constrained Environment', World Academy of Science, Engineering and Technology, Open Science Index 188, International Journal of Information and Communication Engineering, 16(8), 280 - 285.









| Evidence | Techniques | Tools | Purpose |
|---|---|---|---|
|
Host Machine |
Live RAM | Exterro FTK Imager Volatility Framework Magnet AXIOM |
Obtain the description of the types of URLs, wikis, and visited deep web websites, as well as other downloaded content. |
|
Host Machine |
File System Forensics |
Exterro FTK (Registry Viewer) Windows Registry Editor |
Regshot and analysis to obtain evidence of TOR installation and last executed date and other attributes |
| Network Traffic |
Network Forensics |
Wireshark Network Miner Kroll KAPE Cellebrite UFED |
Gather and analyse evidence of web traffic, established VPN and proxy connections and information on network connections available |
|
Host Machine |
Browser Forensics |
Magnet Internet Evidence Finder (IEF) Dumpzilla |
Locate, extract and retrieve evidence related to users or visited dark web content and activities |
| Application Forensics | Applications and Transactions | Exterro FTK Cellebrite UFED Magnet AXIOM |
Recover applications' related data, including usage session, timestamp and cookies |
| ARTEFACTS | Protocol | WINDOWS 10 | LINUX KALI 2021 |
ANDROID 11 | APPLE IOS 14.2 |
|---|---|---|---|---|---|
| BROWSING HISTORY | Regular D2WFP |
1094 1325 |
1086 1631 |
1238 1562 |
991 1133 |
| SECURITY & LOGINS | Regular D2WFP |
30 53 |
30 77 |
30 66 |
30 34 |
| CACHE & TEMP | Regular D2WFP |
6732 10938 |
5328 9677 |
3627 7201 |
4381 6320 |
| SQLITE DB FORM | Regular D2WFP |
227 636 |
328 801 |
196 786 |
188 295 |
| DOWNLOADS | Regular D2WFP |
106 317 |
106 429 |
112 299 |
112 243 |
| ARTEFACTS | Protocol | WINDOWS 10 | LINUX KALI 2021 |
ANDROID 11 | APPLE IOS 14.2 |
|---|---|---|---|---|---|
| BROWSING HISTORY | Regular D2WFP |
107 679 |
239 799 |
226 804 |
287 453 |
| SECURITY & LOGINS | Regular D2WFP |
07 17 |
09 19 |
06 20 |
02 09 |
| CACHE & TEMP | Regular D2WFP |
1126 4681 |
907 5414 |
1372 5755 |
774 2413 |
| SQLITE DB FORM | Regular D2WFP |
15 354 |
44 403 |
67 409 |
06 154 |
| DOWNLOADS | Regular D2WFP |
25 109 |
29 174 |
22 188 |
09 68 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2023 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).