TY - JOUR
T1 - Advancing web browser forensics
T2 - Critical evaluation of emerging tools and techniques
AU - Chand, Rishal Ravikesh
AU - Sharma, Neeraj Anand
AU - Kabir, Ashad
PY - 2025/4
Y1 - 2025/4
N2 - As the use of web browsers continues to grow, the potential for cybercrime and web-related criminal activities also increases. Digital forensic investigators must understand how different browsers function and the critical areas to consider during web forensic analysis. Web forensics, a subfield of digital forensics, involves collecting and analyzing browser artifacts, such as browser history, search keywords, and downloads, which serve as potential evidence. While existing research has provided valuable insights, many studies focus on individual browsing modes or limited forensic scenarios, leaving gaps in understanding the full scope of data retention and recovery across different modes and browsers. This paper addresses these gaps by defining four browsing scenarios and critically analyzing browser artifacts across normal, private, and portable modes using various forensic tools. We define four browsing scenarios to perform a comprehensive evaluation of popular browsers—Google Chrome, Mozilla Firefox, Brave, Tor, and Microsoft Edge—by monitoring changes in key data storage areas such as cache files, cookies, browsing history, and local storage across different browsing modes. Overall, this paper contributes to a deeper understanding of browser forensic analysis and identifies key areas for enhancing privacy protection and forensic methodologies.
AB - As the use of web browsers continues to grow, the potential for cybercrime and web-related criminal activities also increases. Digital forensic investigators must understand how different browsers function and the critical areas to consider during web forensic analysis. Web forensics, a subfield of digital forensics, involves collecting and analyzing browser artifacts, such as browser history, search keywords, and downloads, which serve as potential evidence. While existing research has provided valuable insights, many studies focus on individual browsing modes or limited forensic scenarios, leaving gaps in understanding the full scope of data retention and recovery across different modes and browsers. This paper addresses these gaps by defining four browsing scenarios and critically analyzing browser artifacts across normal, private, and portable modes using various forensic tools. We define four browsing scenarios to perform a comprehensive evaluation of popular browsers—Google Chrome, Mozilla Firefox, Brave, Tor, and Microsoft Edge—by monitoring changes in key data storage areas such as cache files, cookies, browsing history, and local storage across different browsing modes. Overall, this paper contributes to a deeper understanding of browser forensic analysis and identifies key areas for enhancing privacy protection and forensic methodologies.
UR - http://www.scopus.com/inward/record.url?scp=105002743737&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=105002743737&partnerID=8YFLogxK
U2 - 10.1007/s42979-025-03921-6
DO - 10.1007/s42979-025-03921-6
M3 - Article
SN - 2662-995X
VL - 6
JO - SN Computer Science
JF - SN Computer Science
IS - 4
M1 - 355
ER -