Secure network forensic investigation framework with elliptic curve cryptography-based encryption and enhanced message digest integrity verification
Résumé fourni par la source
Forensic evidence can be easily altered or disclosed to those who are not authorized, which reduces the evidence integrity, reliability, and admissibility in cyber forensic investigation. Current forensic approaches are mostly concerned with evidence collection and analysis, and give little attention to ensuring evidence transmission is secure. In this paper, a secure network forensic investigation framework is proposed that combines proactive and reactive forensic modules and means of providing network confidentiality and integrity protection. This framework uses an improved Koblitz encoding with Elliptic Curve Cryptography (ECC) to ensure the security of the transmission of forensic evidence, such as text, images and digital files. A lightweight three-cycle hashing mechanism is embedded to enhance integrity check and resistance against tampering with low computational cost. Architecture is designed for resource-constrained forensic environments and helps reduce computational and storage needs while maintaining security. The datasets consisted of text, images and digital files of different sizes and were subjected to experimental evaluation. The proposed framework successfully implemented the encoding, decoding, encryption, decryption and integrity checking for all type of evidence. The proposed hashing mechanism reduced the computational time of hash by around 20% compared to SHA-256 with a satisfactory integrity check. Moreover, the ECC-based approach provided security similar to RSA with much smaller key sizes, saving not only in computation costs, but in storage as well. The results show that the proposed framework is efficient, lightweight and integrated solution for secure transmission and verification of forensic evidence in resource constrained cyber forensic environments.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Secure network forensic investigation framework with elliptic curve cryptography-based encryption and enhanced message digest integrity verification
- Date Crossref
- 02/09/2026
- Éditeur
- Springer Science and Business Media LLC
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude et ne compte pas comme une seconde source scientifique indépendante.
Institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.