AI & Computingarticle2026-09-02

Secure network forensic investigation framework with elliptic curve cryptography-based encryption and enhanced message digest integrity verification

Open access0 citations

Abstract

Forensic evidence can be easily altered or disclosed to those who are not authorized, which reduces the evidence integrity, reliability, and admissibility in cyber forensic investigation. Current forensic approaches are mostly concerned with evidence collection and analysis, and give little attention to ensuring evidence transmission is secure. In this paper, a secure network forensic investigation framework is proposed that combines proactive and reactive forensic modules and means of providing network confidentiality and integrity protection. This framework uses an improved Koblitz encoding with Elliptic Curve Cryptography (ECC) to ensure the security of the transmission of forensic evidence, such as text, images and digital files. A lightweight three-cycle hashing mechanism is embedded to enhance integrity check and resistance against tampering with low computational cost. Architecture is designed for resource-constrained forensic environments and helps reduce computational and storage needs while maintaining security. The datasets consisted of text, images and digital files of different sizes and were subjected to experimental evaluation. The proposed framework successfully implemented the encoding, decoding, encryption, decryption and integrity checking for all type of evidence. The proposed hashing mechanism reduced the computational time of hash by around 20% compared to SHA-256 with a satisfactory integrity check. Moreover, the ECC-based approach provided security similar to RSA with much smaller key sizes, saving not only in computation costs, but in storage as well. The results show that the proposed framework is efficient, lightweight and integrated solution for secure transmission and verification of forensic evidence in resource constrained cyber forensic environments.

// Source

View paper (DOI)Open access versionOpenAlexScientific ReportsPublished 2026-09-02

Authors: A. Abirami, R. L. Priya, S. Karthik, Surjeet Dalal, Deepshikha Chaturvedi, Sultan Mesfer Aldossary, Mitiku Dubale Anamo, Arshad Hashmi

Institutions: Prince Sattam Bin Abdulaziz University, King Abdulaziz University, Centre for Development of Advanced Computing, University of Arts, Université de Moncton, Presidency University