Citation
Asmawi, Aziah and Md Yasin, Sharifah and Mohd Shah, Nur Hazierah
(2024)
Improving collection of data type evidence and the integrity of evidence collected using SHA-256 hashing algorithm for web browsers.
Journal of Theoretical and Applied Information Technology, 103 (2).
pp. 375-383.
ISSN 1992-8645; eISSN: 1817-3195
Abstract
This study introduces a method to enhance web browser evidence collection in digital forensic investigations. The focus of this study specifically operating 3 evidence collection software forensic toolkits in one developed forensic toolkit called ForenWebSight (FWS). Data is collected from 4 most popular web browsers, Google Chrome, Mozilla Firefox, Microsoft Edge, and Opera in the Windows 11 environment in the context of evidence collection, emphasizing the significance of 35 data types such as history visits, history search, search keyword, cookies, cache, file, session, bookmarks, downloaded files and many more in digital forensic investigations. The existing tools for evidence collection primarily rely on SHA-1 hashing and using older version windows and software toolkits version. Therefore, this study proposes the addition in toolkits implementation, the latest software tools version and the latest solution, an improvement proof-of-concept utilizes SHA-256 hashing algorithm to improve the collection of evidence and enhance integrity. The use of the SHA-256 hash algorithm currently considered secure and resistant to collision attacks. It offers a higher level of security than SHA-1. The evaluation involves comparing the ForenWebSight (FWS) with previous study shows the importance of robust evidence collection tools and methodologies in combating cybercrimes.
Download File
Additional Metadata
Actions (login required)
 |
View Item |